The GDPR and the California Consumer Privacy Act pursue the same goal by opposite defaults: the General Data Protection Regulation requires opt-in consent before a business touches an EU resident’s personal data and covers almost any organization that handles it, while the California Consumer Privacy Act lets covered businesses collect first and gives California residents the right to opt out, applying only to for-profit companies that cross set revenue or data-volume thresholds. Everything else — which rights individuals get, how fast a business must respond, what happens after a breach, whether data can leave the country — flows from that split.
Who Each Law Covers
The GDPR reaches any organization that processes the personal data of people in the EU, wherever the organization sits. A company in Texas or Tokyo falls under it if it offers goods or services to EU residents or monitors their online behavior.1Your Europe. Data Protection Under GDPR Public authorities, nonprofits, and small businesses are all in scope. Both data controllers, who decide why and how data is processed, and data processors, the vendors who handle data on a controller’s behalf, carry direct legal duties.
The CCPA is narrower. It applies only to for-profit businesses that meet at least one of three thresholds: annual gross revenue of $26.625 million or more, buying or selling the personal information of 100,000 or more California consumers or households, or deriving at least half of annual revenue from selling or sharing personal information.2California Privacy Protection Agency. Frequently Asked Questions The revenue figure is adjusted periodically for inflation; the $26.625 million mark took effect in January 2025. Businesses that fall below all three triggers are generally exempt.
Both laws care about where the people are, not where the servers sit. A U.S. e-commerce store shipping to Germany is subject to the GDPR. A London subscription service with enough California customers crossing the revenue or volume lines is subject to the CCPA.
The definitions of protected information line up on most points but diverge at the edges. The GDPR protects “personal data,” meaning any information relating to an identified or identifiable person, including IP addresses, cookie IDs, and location data.3General Data Protection Regulation (GDPR). Art 4 GDPR Definitions The CCPA protects “personal information” that identifies, relates to, or could reasonably be linked to a particular consumer or household.4State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA) That household-level coverage has no GDPR counterpart; data tied to a household device, like a smart TV’s viewing history, can be personal information under California law even when no individual is named.
Consent: Opt-In Versus Opt-Out
This is the split that shapes almost every other difference. The GDPR runs on opt-in. Consent must be freely given, specific, informed, and demonstrated by a clear affirmative action before any processing begins.3General Data Protection Regulation (GDPR). Art 4 GDPR Definitions Pre-checked boxes and buried terms don’t count. The regulation recognizes five other legal bases for processing beyond consent, such as contractual necessity or legitimate interest, but the consent bar itself is high.
The CCPA runs on opt-out. Businesses can collect and use personal information without asking first, but they have to let consumers say stop. Any business that sells or shares personal information must display a “Do Not Sell or Share My Personal Information” link on its website.4State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA) Consumers can also use browser-level global privacy controls to broadcast an opt-out signal automatically. Once received, the business must stop selling or sharing that consumer’s data unless the consumer later reauthorizes it.5California Privacy Protection Agency. California Consumer Privacy Act of 2018
Both laws reject interfaces designed to trick users. Under the CPRA amendments, consent obtained through dark patterns — user interfaces designed to subvert or impair user autonomy — is legally void.6California Privacy Protection Agency. Enforcement Advisory No 2024-02 The GDPR reaches the same result through its consent standard: if consent isn’t freely given and unambiguous, it isn’t valid regardless of what the interface looks like.
Consumer Rights and Response Deadlines
Both frameworks give people rights over their information, though the details differ.
Deletion
The GDPR’s right to erasure lets individuals request deletion when the data is no longer necessary for its original purpose or when they withdraw consent.7General Data Protection Regulation. Art 17 GDPR Right to Erasure The CCPA gives a similar right to delete, subject to exceptions for completing transactions, detecting security incidents, and complying with legal obligations.4State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA) California’s exceptions are more explicitly enumerated, which can make it easier for businesses to justify denying a request.
Access and Portability
Both laws require companies to disclose what personal information they hold and provide a copy on request. The GDPR’s portability right goes further: individuals can demand their data in a structured, machine-readable format and have it transmitted directly to another service provider where technically feasible.8General Data Protection Regulation (GDPR). Art 20 GDPR Right to Data Portability The CCPA guarantees access to specific pieces and categories of information but its portability requirements stop short of that direct-transfer mechanism.
Correction
The GDPR has always required businesses to correct inaccurate data and complete incomplete records without undue delay.9General Data Protection Regulation. Art 16 GDPR Right to Rectification The original CCPA didn’t include an equivalent, but the CPRA amendments added a formal right to correct.4State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act (CCPA)
Response Deadlines
Under the GDPR, a business must act on a data subject request within one month of receiving it, with the possibility of a two-month extension for complex or high-volume requests.10General Data Protection Regulation (GDPR). Art 12 GDPR Transparent Information, Communication and Modalities The CCPA gives businesses 45 calendar days to respond, extendable by another 45 days (for a maximum of 90) if the business notifies the consumer and explains the delay. Opt-out requests specifically must be honored within 15 business days.
Sensitive Data and Children
Both laws single out certain categories for stronger protection, and both tighten the rules for minors, but the mechanics differ.
The GDPR flatly prohibits processing “special category” data unless one of ten specific exceptions applies. Special categories include racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data used for identification, health data, and information about sex life or sexual orientation.11Information Commissioner’s Office. What Are the Rules on Special Category Data The most common exceptions are explicit consent and necessity for employment or legal claims. The default is a hard no.
The CCPA defines “sensitive personal information” to include Social Security numbers, financial account credentials, precise geolocation, racial or ethnic origin, religious beliefs, genetic and biometric data, health information, the contents of private messages, and neural data.12California Privacy Protection Agency. What Is Personal Information Rather than blocking processing, it gives consumers the right to limit how businesses use and disclose it, and requires a link letting consumers restrict secondary uses. Processing starts by default; the consumer holds the lever.
For minors, the CCPA is stricter in one specific respect. Businesses can’t sell or share personal information of anyone they know to be under 16 without affirmative opt-in consent. Children between 13 and 15 can give that consent directly; for children under 13, a parent or guardian must authorize it.5California Privacy Protection Agency. California Consumer Privacy Act of 2018 The GDPR sets a default age of 16 for consenting to data processing by online services, though individual EU member states can lower that threshold to as young as 13. Below the applicable age, parental consent is required, and the requirement applies to data processing generally, not only to sales or sharing.
Cross-Border Data Transfers
This is where the GDPR imposes obligations the CCPA largely ignores. The GDPR restricts transfers of personal data to countries outside the EU and European Economic Area unless a legal mechanism is in place. The European Commission can issue an adequacy decision declaring that a country provides sufficient protection. For the United States, the EU-U.S. Data Privacy Framework took effect in July 2023, letting certified U.S. organizations receive EU personal data.13EU-U.S. Data Privacy Framework. Program Overview Companies not certified under the framework must rely on standard contractual clauses or binding corporate rules. Fines for improper transfers fall under the GDPR’s highest penalty tier.
The CCPA has no comparable restriction. A California business can send consumer data to servers anywhere in the world without a special legal mechanism. Consumer rights still apply regardless of where the data sits, but the law doesn’t treat cross-border movement as an independent compliance event. For companies subject to both laws, GDPR transfer rules effectively set the constraint.
Breach Notification
The GDPR requires a controller to notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to individuals. If notification runs past 72 hours, the controller must explain why.14GDPR-Text.com. Article 33 Notification of a Personal Data Breach to the Supervisory Authority When the breach poses a high risk to individuals, they must be notified directly as well.
California’s breach notification duty comes from a separate state statute, not from the CCPA itself. Businesses must notify any California resident whose unencrypted personal information was acquired or reasonably believed to have been acquired by an unauthorized person. Breaches affecting more than 500 residents also require submitting a sample notification to the Attorney General.15State of California – Department of Justice – Office of the Attorney General. Data Security Breach Reporting California law requires notification “in the most expedient time possible” without specifying an hour count. The CCPA’s role in breaches runs mainly through its private right of action, which lets consumers sue when a breach results from inadequate security.
Vendor and Processor Contracts
Handing personal data to a vendor doesn’t hand off legal responsibility. Both laws require written agreements with specific terms.
Under the GDPR, a data processing agreement must state that the processor will act only on the controller’s written instructions, keep data confidential, implement appropriate security, assist with data subject requests, delete or return all data when the contract ends, and allow audits by the controller.16GDPR.eu. What Is a GDPR Data Processing Agreement Sub-processors can’t be engaged without prior written authorization.
The CCPA requires contracts with service providers and contractors that restrict them from selling or sharing received personal information, using it for purposes beyond the contract, or combining it with data from other sources. Contractors must certify in writing that they understand and will follow these restrictions.5California Privacy Protection Agency. California Consumer Privacy Act of 2018 A service provider that determines it can no longer meet its CCPA obligations must notify the business.
Penalties and Private Lawsuits
The GDPR’s fines are designed to matter to large companies. Less severe violations carry fines up to €10 million or 2% of worldwide annual revenue, whichever is higher. More serious violations, including ignoring data subject rights or making unauthorized cross-border transfers, can reach €20 million or 4% of global revenue.17GDPR-Text. GDPR Article 83 General Conditions for Imposing Administrative Fines Each EU member state’s supervisory authority can bring enforcement actions, with the European Data Protection Board coordinating cross-border cases.
California enforcement comes from two directions. The California Privacy Protection Agency can bring administrative actions with fines up to $2,500 per unintentional violation and $7,500 per intentional violation or per violation involving a minor’s data.18California Legislative Information. California Code CIV 1798.155 Those per-violation numbers look modest next to GDPR figures, but they compound; mishandling opt-out requests from tens of thousands of consumers can produce exposure in the millions.
The CCPA also includes a private right of action for data breaches caused by a failure to maintain reasonable security. Consumers can sue for statutory damages between $100 and $750 per person per incident, or actual damages if higher.19California Legislative Information. California Code CIV 1798.150 Personal Information Security Breaches In a breach affecting millions of users, class-action math gets enormous. The GDPR doesn’t include a comparable statutory damages mechanism for private lawsuits, though individuals can seek compensation through national courts for material or non-material damage caused by a violation.
If Both Laws Apply
A company serving both EU residents and California consumers has to satisfy both frameworks, and the more restrictive rule usually wins. In practice the GDPR’s opt-in consent, strict transfer rules, and Data Protection Officer requirements tend to set the floor. The CCPA then adds obligations the GDPR doesn’t have: the “Do Not Sell or Share” link, household-level data coverage, and the private right of action for security breaches.
The GDPR requires certain organizations to appoint a Data Protection Officer: public authorities, companies whose core activities involve large-scale systematic monitoring, and companies that process special category data at scale. The CCPA has no equivalent DPO mandate, but businesses subject to both often need one anyway. Some EU member states add their own rules; Germany requires a DPO for any organization with 20 or more employees regularly processing personal data.
Treating GDPR compliance as a superset that automatically covers the CCPA is a common mistake. The two laws diverge enough in definitions, enforcement mechanisms, and consumer-facing requirements that a business genuinely needs to map both against its operations. The companies that struggle most assume a single privacy policy handles everything without tracking which obligations come from which law.