GDPR vs CCPA: Consent, Rights, and Penalties Compared

The GDPR and the CCPA are the two most influential data privacy laws in force today, and they solve the same problem in opposite ways. The EU’s General Data Protection Regulation requires organizations to have a legal justification before they touch anyone’s personal data. California’s Consumer Privacy Act, significantly overhauled by the California Privacy Rights Act, lets businesses collect and use data by default and gives consumers the right to opt out afterward. That philosophical gap shapes nearly every practical difference between the two, from who must comply to how violations are punished.

Consent Up Front Versus Opt-Out After

Under the GDPR, an organization cannot process personal data unless it can point to one of six lawful bases: the individual’s consent, performance of a contract, a legal obligation, protection of vital interests, a public interest task, or a legitimate interest that doesn’t override the individual’s rights.1General Data Protection Regulation (GDPR). Art. 6 GDPR – Lawfulness of Processing When consent is the basis, it must be freely given, specific, informed, and unambiguous. Pre-checked boxes and buried terms don’t count, and withdrawing consent must be as easy as giving it.

The CCPA works the other way around. Businesses can collect and process personal information without asking permission first. The law instead gives consumers the power to say “stop” after the fact through opt-out rights covering the sale and sharing of their data.2California Office of the Attorney General. California Consumer Privacy Act (CCPA) The main exception is age-based. Businesses need opt-in consent before selling data belonging to anyone under 16, and for children under 13, a parent or guardian must provide that consent.

The difference shows up early in product decisions. A European company building a new app must decide its lawful basis for every type of processing before launch. A California company building the same app can launch first and focus on making sure the opt-out mechanism works.

Who Has to Comply

The GDPR casts an extremely wide net. It applies to any organization that processes the data of people located in the EU, regardless of where the organization is based.3General Data Protection Regulation (GDPR). Art. 3 GDPR – Territorial Scope A startup in Austin that sells software to customers in Berlin must comply. A mobile game developer in Tokyo that tracks European users’ behavior must comply. There is no revenue minimum, no employee count threshold, and no exemption for small businesses.

The CCPA is narrower. It covers for-profit businesses that collect the personal information of California residents and meet at least one of three thresholds:4California Legislative Information. California Code, Civil Code CIV 1798.140

  • Annual gross revenue over $26,625,000, adjusted for inflation from the original $25 million, with the next adjustment scheduled for 2027.5California Privacy Protection Agency. California Privacy Protection Agency Announces 2025 Increases
  • Annually buying, selling, or sharing the personal information of 100,000 or more consumers or households.
  • Deriving 50 percent or more of annual revenue from selling or sharing consumers’ personal information.

Nonprofits are generally outside the CCPA because the law only reaches for-profit entities. The CPRA also ended the temporary exemptions for employee data and business-to-business contacts, so if your company has employees working in California and you meet the thresholds, their personal information is now fully covered.

What Data Is Covered

The GDPR protects “personal data,” meaning any information relating to an identified or identifiable natural person. An identifiable person can be recognized directly or indirectly through identifiers like a name, an ID number, location data, an online identifier, or factors tied to their physical, genetic, mental, economic, cultural, or social identity.6UK Legislation. Regulation (EU) 2016/679, Article 4 The unit of protection is always the individual person.

The CCPA uses “personal information,” which covers data that identifies, relates to, or could reasonably be linked with a particular consumer or household.4California Legislative Information. California Code, Civil Code CIV 1798.140 That household inclusion is a real difference. A smart-home device collecting data tied to a family’s address falls within scope even if no individual family member is identified. The same data might not qualify as personal data under the GDPR unless it could be tied to a specific person.

Sensitive Categories

Both laws single out categories of information that carry more risk. The GDPR calls these “special categories” and generally prohibits processing them unless a specific exception applies, such as explicit consent or a substantial public interest.1General Data Protection Regulation (GDPR). Art. 6 GDPR – Lawfulness of Processing The protected categories include data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic and biometric data used for identification, health information, and data about sex life or sexual orientation.

The CCPA’s “sensitive personal information” category overlaps but adds items the GDPR doesn’t call out separately. California’s list includes Social Security and passport numbers, financial account credentials, precise geolocation (locating someone within a circle of roughly 1,850-foot radius), contents of private messages, and neural data.7California Office of Privacy Protection. What is Personal Information? Rather than banning the processing of sensitive information outright, California gives consumers the right to limit how businesses use and disclose it. A business must provide a link labeled “Limit the Use of My Sensitive Personal Information” that lets consumers restrict use of this data to what’s necessary to provide the goods or services they requested.

What Individuals Can Ask For

Both laws give people a toolkit for controlling their data, but the GDPR’s set is broader.

Access, Correction, and Deletion

Under both laws, individuals can request a copy of the data an organization holds about them. The GDPR requires this in a clear, commonly used electronic format.8General Data Protection Regulation (GDPR). GDPR Right of Access The CCPA requires businesses to disclose both the categories and specific pieces of data collected.2California Office of the Attorney General. California Consumer Privacy Act (CCPA)

Both include a right to correction. The GDPR has always allowed data subjects to demand that inaccurate records be fixed. The CCPA originally lacked this, but the CPRA added a right to correct inaccurate personal information, requiring businesses to use commercially reasonable efforts to fix the data as directed by the consumer.9California Office of the Attorney General. CPRA Ballot Initiative Text – Section 1798.106

Deletion rights exist in both frameworks but work differently. The GDPR’s right to erasure applies when data is no longer needed for its original purpose, the individual withdraws consent, the data was processed unlawfully, or other specific grounds are met.10General Data Protection Regulation (GDPR). Art. 17 GDPR – Right to Erasure The CCPA grants a deletion right but carves out broad exceptions: a business can refuse if the data is needed to complete a transaction, detect security incidents, exercise free speech, comply with a legal obligation, or support certain research purposes, among others.11California Legislative Information. California Code, Civil Code CIV 1798.105

Objecting and Opting Out

The GDPR gives data subjects an absolute right to stop any processing of their data for direct marketing purposes.12General Data Protection Regulation (GDPR). Art. 21 GDPR – Right to Object For other types of processing, individuals can object based on their particular situation, and the organization must stop unless it can demonstrate compelling legitimate grounds that override the individual’s interests.

The CCPA’s signature right is the opt-out of data sales and sharing. The CPRA expanded this beyond selling to also cover sharing for cross-context behavioral advertising, meaning ad targeting based on a consumer’s activity across multiple websites.2California Office of the Attorney General. California Consumer Privacy Act (CCPA) Businesses must provide a “Do Not Sell or Share My Personal Information” link on their website. Since January 2026, businesses must also honor Global Privacy Control signals sent automatically by a user’s browser as a valid opt-out request.

Portability

Both laws include the right to receive your data in a format that lets you transfer it to another service. The GDPR is more prescriptive, requiring a “structured, commonly used, and machine-readable format.” In practice the two rights function similarly.

How Fast Businesses Must Respond

Under the GDPR, organizations must respond to data subject requests within one month of receiving them. If a request is unusually complex or the organization is handling a high volume, it can extend the deadline by two additional months, but it must notify the individual within the original one-month window and explain the delay.13General Data Protection Regulation (GDPR). Art. 12 GDPR – Transparent Information, Communication and Modalities

The CCPA gives businesses 45 calendar days to verify the consumer’s identity and fulfill the request. If more time is needed, the business can take an additional 45 days (90 days total), but it must notify the consumer of the extension and the reason before the initial 45-day period expires. No request can take longer than 90 days.

Cross-Border Data Transfers

The GDPR is far more restrictive here. Transferring personal data outside the EU is only permitted if the destination country provides an adequate level of data protection, or if the organization uses approved safeguards like standard contractual clauses or binding corporate rules.14General Data Protection Regulation (GDPR). Art. 44 GDPR – General Principle for Transfers For transfers to the United States, the EU-U.S. Data Privacy Framework took effect in July 2023, and U.S. organizations that self-certify through the Department of Commerce can receive EU personal data without additional transfer mechanisms.15Data Privacy Framework. Data Privacy Framework (DPF) Overview Similar arrangements now cover transfers from the UK (effective October 2023) and Switzerland (effective September 2024).

The CCPA has no comparable restriction. California’s law governs how businesses handle residents’ data regardless of where that data is stored or processed. A company can send a California consumer’s information to a server in Singapore without triggering any special transfer mechanism, as long as it continues meeting its disclosure and opt-out obligations.

Penalties and Who Can Sue

The GDPR is enforced by independent Data Protection Authorities in each EU member state. Fines run on a two-tier scale:16General Data Protection Regulation (GDPR). Art. 83 GDPR – General Conditions for Imposing Administrative Fines

  • Lower tier: up to €10 million or 2 percent of worldwide annual revenue, whichever is higher, for violations of obligations like data protection impact assessments, record-keeping, and Data Protection Officer requirements.
  • Upper tier: up to €20 million or 4 percent of worldwide annual revenue, whichever is higher, for violations of core principles, data subject rights, and cross-border transfer rules.

Those percentages apply to global revenue, not just EU revenue. For a company with $50 billion in worldwide sales, the upper tier means a theoretical maximum of $2 billion.

The CCPA is enforced by both the California Attorney General and the California Privacy Protection Agency. Starting in 2025, penalty amounts were adjusted for inflation:5California Privacy Protection Agency. California Privacy Protection Agency Announces 2025 Increases

  • Unintentional violations: up to $2,663 per violation.
  • Intentional violations, including violations involving data of consumers the business knows are under 16: up to $7,988 per violation.

These per-violation figures add up. An intentional violation affecting 100,000 consumers reaches nearly $800 million in potential exposure.

The CCPA also includes a private right of action, but a narrow one. Consumers can only sue when their nonencrypted and nonredacted personal information is exposed in a data breach caused by the business’s failure to maintain reasonable security.17California Legislative Information. California Code, Civil Code CIV 1798.150 Statutory damages range from $100 to $750 per consumer per incident, or actual damages if higher. Consumers cannot sue for other violations like failure to honor opt-out requests or inadequate privacy disclosures; only the Attorney General and the CPPA can pursue those.

The Differences at a Glance

  • Default stance: GDPR requires a lawful basis before processing. CCPA allows processing unless the consumer opts out.
  • Who’s covered: GDPR applies to any organization handling EU data, with no revenue or size threshold. CCPA applies to for-profit businesses meeting specific revenue, data volume, or data-sale revenue thresholds.
  • Data scope: GDPR protects data linked to an identifiable individual. CCPA also covers household-level data.
  • Sensitive data: GDPR generally prohibits processing special categories. CCPA allows it but gives consumers a right to limit it.
  • Response deadlines: GDPR gives one month, extendable to three. CCPA gives 45 days, extendable to 90.
  • Cross-border transfers: GDPR restricts transfers outside the EU. CCPA imposes no transfer restrictions.
  • Maximum penalties: GDPR fines can reach 4 percent of global revenue. CCPA penalties are assessed per violation with no revenue-based cap.
  • Private lawsuits: The GDPR allows individuals to seek compensation through courts for any violation. The CCPA limits private lawsuits to data breaches caused by inadequate security.

Companies that operate in both markets need to satisfy both laws, and in most cases the GDPR’s stricter requirements set the floor. Building data practices to meet the GDPR first, then layering on the CCPA’s specific opt-out mechanisms and disclosure rules, is generally more efficient than treating each law as a separate project.