PrivacyCache← All articles
GDPR

GDPR vs CCPA: Key Differences Every Business Must Know (2026)

8 min read
California and European privacy frameworks balanced around shared consumer data rights

If your business serves customers in both Europe and California, you're subject to two of the world's most significant privacy laws. While GDPR and CCPA share the goal of protecting personal information, their approaches differ in ways that matter for implementation.

Here's a practical comparison of GDPR vs CCPA that goes beyond surface-level similarities.

GDPR vs CCPA: The Short Answer

The core difference is philosophy. GDPR is permission-based: you need a valid legal basis before you process anyone's personal data. CCPA (as amended by the CPRA) is notice-and-choice: you can collect data as long as you disclose it and let consumers opt out of its sale or sharing. GDPR also applies to every organisation touching EU data regardless of size, while CCPA only bites above set revenue or data-volume thresholds.

At a glance GDPR (EU) CCPA / CPRA (California)
Who it covers Any org processing EU data — no size threshold For-profits over $25M revenue, 100k+ consumers, or 50%+ data-sale revenue
Model Opt-in; legal basis required Notice + opt-out of sale/sharing
Core rights Access, delete, correct, port, object, restrict Know, delete, correct, opt-out, limit sensitive PI
DSAR deadline 1 calendar month (+2) 45 days (+45)
Max penalty €20M or 4% of global turnover $7,500 per intentional violation
Private lawsuits Yes, broadly Data breaches only

Each of these is unpacked in detail below.

Scope: Who's Covered

GDPR

Applies to any organization that:

There is no revenue or size threshold. A one-person startup processing EU personal data is subject to GDPR.

CCPA/CPRA

Applies to for-profit businesses that:

Non-profits and government entities are excluded. Small businesses below all three thresholds are not covered.

Key difference: GDPR applies to everyone. CCPA has a meaningful size threshold that exempts smaller businesses.

What Counts as Personal Data

GDPR: Personal Data

Any information relating to an identified or identifiable natural person. This includes:

Employee data is fully covered.

CCPA: Personal Information

Information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to a consumer or household. This explicitly includes:

Employee and B2B contact data were previously exempt but are now covered under CPRA.

Key difference: Both are broadly defined. CCPA's inclusion of "household" data is unique — GDPR focuses on natural persons only.

Legal Bases for Processing

GDPR: Six Legal Bases

Processing requires one of six explicit legal bases:

  1. Consent
  2. Contract performance
  3. Legal obligation
  4. Vital interests
  5. Public interest
  6. Legitimate interests (with balancing test)

Every processing activity must be mapped to a legal basis before processing begins.

CCPA: No Equivalent

CCPA does not require a legal basis for collection or processing. Instead, it focuses on:

Key difference: GDPR requires affirmative justification for processing. CCPA requires transparency and opt-out mechanisms. This is a fundamental philosophical difference — GDPR is permission-based, CCPA is notice-and-choice.

Consumer/Data Subject Rights

Right GDPR CCPA/CPRA
Access/Know Yes (Art. 15) Yes
Deletion Yes (Art. 17) Yes
Rectification/Correction Yes (Art. 16) Yes (CPRA added)
Portability Yes (Art. 20) Yes
Opt-out of sale N/A Yes
Opt-out of sharing N/A Yes (CPRA added)
Restrict processing Yes (Art. 18) Yes (CPRA: sensitive PI)
Object to processing Yes (Art. 21) Limited
Automated decisions Yes (Art. 22) Yes (CPRA added)
Non-discrimination Implied Explicit

Response Deadlines

GDPR CCPA
Standard 1 calendar month 45 calendar days
Extension +2 months (complex) +45 days
Total maximum 3 months 90 days
Extension notification Within first month Within first 45 days

Key difference: CCPA's 45-day deadline gives slightly more time than GDPR's calendar month, but GDPR's extension is more generous (2 extra months vs. 45 extra days). For how these deadlines compare against other regimes, see our DSAR deadline comparison by jurisdiction, or work out an exact due date with the DSAR Deadline Calculator.

Consent

GDPR: Opt-In

CCPA: Opt-Out

Key difference: GDPR defaults to "no processing without permission." CCPA defaults to "processing is permitted, but consumers can opt out of sale/sharing."

Enforcement and Penalties

GDPR

CCPA/CPRA

Key difference: GDPR fines are percentage-based and can be enormous. CCPA fines are per-violation, which can also scale significantly (10,000 violated consumers × $7,500 = $75 million). GDPR allows broader private litigation.

Practical Implications for Dual Compliance

If You're Already GDPR Compliant

You're most of the way to CCPA compliance. Key additions needed:

If You're Starting Fresh

Build for GDPR first — it's the stricter standard. Then layer CCPA-specific requirements:

  1. Data mapping: Required by both laws, but GDPR's Article 30 ROPA is more prescriptive
  2. Privacy notice: Cover both sets of required disclosures in one policy (with jurisdiction-specific sections)
  3. Rights handling: Build a unified DSAR process that accounts for different deadlines per jurisdiction
  4. Consent management: Implement GDPR-style opt-in consent (satisfies both laws)
  5. Vendor management: DPAs for GDPR, service provider agreements for CCPA

Ongoing Management

The challenge isn't achieving compliance — it's maintaining it across both frameworks simultaneously. This requires:

Automation isn't optional for dual-jurisdiction compliance. Manual tracking across different deadline rules, exemption criteria, and documentation requirements breaks down quickly as request volume grows.

The Bottom Line

GDPR and CCPA share a goal but differ in philosophy: GDPR asks permission first, CCPA asks for transparency and an opt-out. Build to GDPR's stricter standard and layer California's opt-out and "Do Not Sell or Share" requirements on top, and you cover most of both. Remember, too, that CCPA is only the start of the US picture — a growing number of states now have their own privacy laws, as our roundup of the privacy laws impacting business in 2026 explains. To see how regulators enforce these rules in practice, browse our enforcement monitor.

Stay ahead of privacy regulations

Get compliance insights delivered to your inbox — new regulations, enforcement actions, and practical tips.

We respect your privacy. Privacy Policy

Related articles

Professional choosing between a payment card and a two-option consent screen on a laptop in a café
GDPR6 min read

Consent or Pay: Are 'Pay-or-Okay' Cookie Walls Legal in 2026?

Are 'pay-or-okay' cookie walls legal under GDPR in 2026? What the EDPB opinion on consent-or-pay models means for your site.

Contract files, encrypted drive, and cable crossing a relief map between Europe and North America
GDPR7 min read

International Data Transfers Under GDPR: The 2026 Guide to DPF, SCCs, and TIAs

How EU data transfers really work in 2026: the Data Privacy Framework, SCCs, transfer impact assessments, and where the real GDPR risk sits.

Analytics dashboard, EU data map, and consent gate for GDPR-compliant tracking
GDPR6 min read

Google Analytics and GDPR in 2026: Is GA4 Legal in the EU?

Is Google Analytics 4 legal under GDPR in 2026? Where GA4 stands after the EU-US Data Privacy Framework, what still creates risk, and how to check.

Track real GDPR enforcement actions

Monitor fines from 30+ European data protection authorities. Understand what violations get penalized and benchmark your risk.

Browse Enforcement Actions