CCPA vs GDPR is a regulatory comparison that defines how two landmark privacy laws, California's Consumer Privacy Act and the EU's General Data Protection Regulation, differ in scope, legal basis, enforcement, and the compliance obligations they impose on global businesses. The asymmetry is not cosmetic. One law assumes processing is permitted until a consumer objects; the other forbids processing until a controller can name a lawful basis for processing. For operators shipping a single product into both California and the EU, that single architectural distinction drives consent flows, data inventories, breach response, and the size of the compliance budget. Three regimes layer onto the same program: the COPPA compliance guide for under-13 users, the biometric data protection frameworks for special category identifiers, and the AI content copyright analysis for training-data exposure. The IPv6 adoption guide covers the adjacent infrastructure angle.
What CCPA and GDPR Are

CCPA vs GDPR pairs two of the most influential personal data privacy laws in the world, built on different legal traditions and serving different regulatory objectives. The California regime is a state statute with a consumer-protection lineage. The European regime is a fundamental-rights regulation with direct effect in 27 member states. The CPRA amendment narrowed the gap on data minimization and purpose limitation, but the underlying defaults still diverge.
- California Consumer Privacy Act (CCPA)
- A California state law (Cal. Civil Code Sections 1798.100 to 1798.199), as amended by the California Privacy Rights Act (CPRA, Proposition 24, effective January 1 2023), that grants California residents rights over personal information held by qualifying for-profit businesses. Enforced by the California Attorney General and the California Privacy Protection Agency (CPPA).
- General Data Protection Regulation (GDPR)
- Regulation (EU) 2016/679, effective May 25 2018, applying directly across all 27 EU member states. It grants data subject rights over personal data processed by controllers and processors, and is enforced by national supervisory authorities coordinated through the European Data Protection Board (EDPB).
- CPRA amendment context
- CPRA substantially amended CCPA to introduce data minimization, purpose limitation, sensitive personal information protections, and the CPPA as an independent enforcement agency. Every reference to CCPA in this guide means CCPA-as-amended-by-CPRA unless otherwise noted.
The framing throughout the rest of this comparison rests on one structural fact. CCPA operates on an opt-out model: default permission, with a consumer right to opt out of the sale or sharing of personal information. GDPR operates on a lawful-basis model in which processing requires a prior legal justification, with consent acting as one of six lawful bases. Consumer rights under CCPA and data subject rights under GDPR sit on top of those two opposite defaults.
Territorial Scope and Who Must Comply
CCPA vs GDPR diverges sharply on territorial reach and on which roles are directly regulated. CCPA targets for-profit businesses with a California nexus and meeting size thresholds. GDPR applies to any data controller or data processor handling personal data of people in the EU, regardless of where the organization is incorporated. That extraterritorial reach is why most US software companies end up GDPR-bound long before they meet any CCPA threshold.
| Dimension | CCPA (as amended by CPRA) | GDPR |
|---|---|---|
| Applicability trigger | For-profit businesses doing business in California meeting any threshold: annual gross revenues exceeding $25 million; annually buying, selling, or receiving personal information of 100,000 or more consumers or households; or deriving 50% or more of annual revenues from selling or sharing personal information. | Any controller or processor established in the EU; or controllers and processors outside the EU when processing relates to offering goods or services to EU data subjects, or monitoring their behavior (Article 3). |
| Covered individuals | California residents (consumers). | Natural persons in the EU (data subjects), regardless of citizenship. |
| Data covered | Personal information: information that identifies, relates to, or could reasonably be linked to a consumer or household. | Personal data: any information relating to an identified or identifiable natural person. |
| Who is regulated | Businesses (controllers) only. Service providers carry obligations by contract. | Both controllers (Article 4(7)) and processors (Article 4(8)), with direct obligations under Articles 28 and 29. |
The practical consequence: a US company with no California office and no California revenue threshold can still be a GDPR controller the moment it offers a service to a user in Berlin. The supervisory authority in that user's member state has jurisdiction. CCPA exposure is gated by thresholds; GDPR exposure is gated by user geography.
Legal Basis, Consent, and the Opt-In vs Opt-Out Divide
CCPA vs GDPR diverges most sharply on the question of when processing personal data is permitted in the first place. GDPR Article 6 lists six lawful bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Without one of those, processing is unlawful. CCPA carries no equivalent lawful-basis requirement. Businesses may process personal information by default; the consumer's opt-out right governs the sale or sharing of personal information and cross-context behavioral advertising under CCPA Section 1798.120 as expanded by CPRA.
| Consent Dimension | CCPA / CPRA | GDPR |
|---|---|---|
| Default state | Opt-out. Processing permitted unless the consumer exercises the opt-out right against sale or sharing. | Opt-in. No processing without a lawful basis for processing under Article 6. |
| Consent definition | No general definition. CPRA requires opt-in consent for the sale or sharing of sensitive personal information. | Article 4(11): freely given, specific, informed, unambiguous indication of agreement; must be as easy to withdraw as to give. |
| Consent for minors | Opt-in required for sale or sharing of personal information of consumers under 16. Parent or guardian consent required for those under 13. | Article 8: member state laws set the age of digital consent between 13 and 16. Controllers must make reasonable verification efforts. |
| Consent records | No explicit consent-record-keeping requirement for general processing. | Article 7(1): controllers must demonstrate that consent was given. Records must be maintained. |
The operational fallout lands on consent management. A platform serving both jurisdictions has to handle two incompatible default states inside one user-facing flow. For EU traffic, the consent management interface must present an opt-in wall before any non-essential processing begins, and it must record the receipt for later demonstration under Article 7. For California traffic, the same surface must honor the Global Privacy Control (GPC) browser signal as a valid opt-out request under CPPA regulations, present a clear "Do Not Sell or Share My Personal Information" link, and record the opt-out for audit. Consent management platforms that paper over the difference with one universal banner tend to fail both regimes simultaneously.
EDPB Guidelines 05/2020 on consent set the binding interpretation of valid GDPR consent. For the California side, the California Attorney General's CCPA resources and the CPPA implementing regulations govern recognition of opt-out preference signals.
Rights Taxonomy: Consumer Rights vs Data Subject Rights
CCPA vs GDPR grants overlapping but not identical bundles of rights, and the statutory language differs. CCPA frames its grants as consumer rights. GDPR frames them as data subject rights under Articles 12 to 22. The CPRA amendment closed several gaps, but the right to data portability and the prior-justification model still mark GDPR as the broader regime.
| Right | CCPA / CPRA | GDPR | Key Differences |
|---|---|---|---|
| Access / right to know | Section 1798.100. Categories and specific pieces of personal information on verifiable consumer request. | Article 15. Copy of personal data plus processing metadata: purposes, recipients, retention, automated decision-making. | GDPR access is broader and includes metadata. CPRA removed the prior 12-month lookback cap on the specific-pieces request. |
| Right to deletion / erasure | Section 1798.105. Right to deletion subject to exceptions for completing a transaction, legal obligation, security, and research. | Article 17. Right to erasure with six grounds and exceptions for freedom of expression, legal claims, and public health. | CCPA exceptions are broader and more business-friendly. GDPR adds a third-party notification duty under Article 17(2). |
| Opt out of sale or sharing / object | Section 1798.120. Opt-out right against sale and, post-CPRA, sharing for cross-context behavioral advertising. | Article 21. Right to object to processing based on legitimate interests and an absolute right against direct marketing. | CCPA targets sale and sharing specifically. GDPR objection applies only to certain lawful bases. |
| Right to correct / rectification | Section 1798.106 (CPRA addition). Right to correct inaccurate personal information. | Article 16. Right to rectification. | Convergence point added by CPRA to align with GDPR. |
| Data portability | No standalone portability right. | Article 20. Receive personal data in structured, commonly used, machine-readable format and transmit to another controller. | GDPR-only obligation. Requires data export APIs that CCPA does not mandate. |
| Automated decision-making | Section 1798.185(a)(16). CPPA regulations on automated decision-making opt-out pending. | Article 22. Right not to be subject to solely automated decisions with significant effects, with defined exceptions. | GDPR right exists today. California rules are still being finalized by the CPPA. |
| Data minimization (convergence) | Section 1798.100(a)(1) (CPRA). Collection and use limited to what is reasonably necessary. | Article 5(1)(c). Adequate, relevant, and limited to what is necessary. | CPRA aligned CCPA with GDPR on data minimization as of January 2023. |
Two architectural items deserve attention outside the table. First, the CPRA category of sensitive personal information mirrors the GDPR concept of special categories of personal data under Article 9, although the lists are not identical and the consent mechanics differ. Second, privacy by design as set out in GDPR Article 25 has no direct CCPA analog by name, but CPRA's purpose limitation and minimization provisions impose comparable engineering obligations on California operators. Citing ISO 31700 as the operational standard for privacy by design gives engineering teams a single specification that satisfies both regimes. Readers building a parallel HIPAA control set should also review the adjacent GDPR compliance vs HIPAA compliance analysis.
Enforcement, Penalties, and the Compliance Cost Differential
CCPA vs GDPR enforcement looks similar on the surface and behaves very differently in practice. Both regimes empower public enforcers, allow administrative fines, and address security failures. GDPR adds a revenue-linked penalty cap that scales with the size of the controller, plus a 72-hour notification window that compresses incident response. CCPA imposes a per-violation cap with no revenue link and a longer, less specific breach notification timeline.
| Enforcement Dimension | CCPA / CPRA | GDPR |
|---|---|---|
| Enforcement body | California Attorney General (civil penalties) and the California Privacy Protection Agency (CPPA) for administrative enforcement and rulemaking. | National supervisory authorities (Ireland's DPC, Germany's BfDI, France's CNIL, among others) coordinated by the EDPB for cross-border matters. |
| Penalty structure | Up to $2,500 per unintentional violation. Up to $7,500 per intentional violation or violation involving minors (Civil Code Section 1798.155). No revenue-percentage cap. | Article 83(4): up to EUR 10 million or 2% of total worldwide annual turnover, whichever is higher. Article 83(5): up to EUR 20 million or 4% of total worldwide annual turnover, whichever is higher, for the most serious violations. |
| Private right of action | Section 1798.150. Civil action for data breaches caused by failure to implement reasonable security, with statutory damages of $100 to $750 per consumer per incident. No private right of action for general CCPA violations. | Article 82. Any person who has suffered material or non-material damage has a right to compensation from the controller or processor. |
| Personal data breach notification | California Civil Code Section 1798.82. Notice without unreasonable delay; no statutory hour-based deadline. Regulators treat 45 days as a practical benchmark. | Article 33: notification to the supervisory authority within 72 hours of becoming aware. Article 34: notification to data subjects without undue delay for high-risk breaches. |
| Data protection officer | No equivalent requirement. | Article 37: mandatory appointment of a data protection officer (DPO) for public authorities and for controllers or processors whose core activities involve large-scale systematic monitoring or large-scale processing of special categories. |
| Privacy impact assessment | CPRA Section 1798.185(a)(15). CPPA regulations require risk assessments for high-risk processing. | Article 35. Data Protection Impact Assessment (DPIA) mandatory for processing likely to result in high risk. |
The headline numbers matter for board-level risk reporting. A $7,500 per-violation cap is bounded; a 4% global turnover cap is not. The European Data Protection Board coordinates cross-border enforcement, and individual supervisory authorities have issued fines in the hundreds of millions of euros under the Article 83(5) tier. The data privacy impact assessment guide sets out a DPIA methodology aligned with both Article 35 and the CPPA's risk assessment regulations.
Building a Dual-Compliance Program: Closing the CCPA-GDPR Gap
CCPA vs GDPR rarely lands as an either/or for a serious software operator; most run a single product into both jurisdictions and need one program that satisfies both. The six stages below treat GDPR as the more demanding baseline and use CPRA's convergence points to avoid duplicating work. The dual-compliance program design assumes engineering, legal, and data teams share one inventory and one workflow rather than maintaining parallel California and EU stacks.
- Unify the data inventory under GDPR's broader scope. Map every processing activity using the GDPR vocabulary first: data category, processing purpose, lawful basis for processing, retention period, third-party recipients, and international transfers. Tag each record with a CCPA flag for sale or sharing status and a sensitive personal information flag. Because GDPR covers more data types and more activities than CCPA, the GDPR inventory is a superset for most operations, and CCPA compliance falls out of the same record.
- Deploy a consent management platform that handles opt-in and opt-out together. The same consent management surface must present an opt-in interface for EU users, record the receipt for Article 7 demonstration, honor the Global Privacy Control signal for California users, and maintain opt-out records that satisfy CPPA audit requests. Treating consent management as one system with two policy profiles avoids the duplicate-banner antipattern that fails both regimes.
- Adopt data-minimization principle and purpose limitation as the baseline engineering standard. CPRA added minimization requirement at Section 1798.100(a)(1) and purpose-limitation rule at Section 1798.100(a)(2), converging with GDPR Articles 5(1)(b) and 5(1)(c). Designing collection forms, APIs, and analytics pipelines to gather only what the stated purpose requires satisfies both laws simultaneously, and it shrinks the breach blast radius as a side effect.
- Build one data subject request workflow with jurisdiction-specific timers. Statutory response windows differ: CCPA grants 45 days extendable by another 45, while GDPR grants one month extendable by two for complex requests. The mechanics, however, are identical: identity verification, data lookup, deletion or correction execution, and third-party notification. One workflow with configurable timers and jurisdiction routing covers both consumer rights and data subject rights without forking the code path.
- Appoint a data protection officer where Article 37 requires it, and a CCPA privacy contact in parallel. GDPR DPO obligations are non-waivable for covered organizations and carry independence requirements under Article 38. CCPA requires a designated contact for consumer requests. The roles can be filled by the same person or the same team, provided the DPO retains the access and reporting line GDPR demands.
- Run a unified privacy impact assessment program against the NIST Privacy Framework. Map the framework's functions (Identify, Govern, Control, Communicate, Protect) to both GDPR Article 35 DPIA criteria and the CPPA's risk assessment regulations. The NIST Privacy Framework Cross-walks to security controls live in NIST SP 800-53 Rev 5; protocol-layer privacy considerations are framed in IETF RFC 6973 Privacy Considerations. gives the program one risk taxonomy and one set of artifacts, instead of two parallel assessment binders covering the same processing. Pair the assessment program with the cross-border transfer architecture covered in the data localization and cloud services hub.
The five GDPR principles that anchor the architecture, including minimization obligation, limited-purpose obligation, and accountability, are codified in GDPR Article 5. The six lawful bases sit in GDPR Article 6. Reading both before scoping the program saves a round of rework.
Further reading
- Data localization laws and cloud services impact for the cross-border transfer dimension of dual-compliance programs.
- Conducting a data privacy impact assessment for DPIA methodology aligned with GDPR Article 35 and CPPA risk-assessment regulations.
- GDPR compliance vs HIPAA compliance for readers operating in the US healthcare data perimeter.
Frequently Asked Questions
What is the main structural difference between CCPA and GDPR?
The foundational difference is the legal default. GDPR requires a lawful basis for processing personal data before processing begins: consent, contract, legal obligation, vital interests, public task, or legitimate interests (Article 6). CCPA operates on an opt-out model, so businesses may process personal information by default, with consumers retaining the opt-out right against the sale or sharing of their personal information. The result is that GDPR compliance requires a prior-justification architecture, while CCPA compliance centers on the opt-out mechanism and the request-handling workflow.
Do the GDPR penalties apply to US companies with no EU offices?
Yes. GDPR Article 3(2) applies the regulation to any controller or processor not established in the EU when processing relates to offering goods or services to data subjects in the EU, or monitoring the behavior of data subjects in the EU. A US company with no EU office that operates a website accessible to EU residents and collects their personal data is subject to GDPR. The regulation requires such controllers to designate an EU representative under Article 27 unless processing is occasional, does not involve special categories at large scale, and is unlikely to result in a risk to the rights of natural persons.
When does a breach require notification under 72 hours versus 45 days?
GDPR Article 33 requires personal data breach notification to the competent supervisory authority within 72 hours of becoming aware, where feasible. If the breach is likely to result in a high risk to natural persons, Article 34 also requires notification to the affected data subjects without undue delay. California's breach notification law (Civil Code Section 1798.82) requires notification in the most expedient time possible and without unreasonable delay but sets no specific hour-based deadline; California regulators treat 45 days as a practical benchmark. For organizations subject to both, the 72-hour GDPR clock is the binding constraint, and meeting it satisfies both regimes.









