Back to Blog
CCPA

CCPA vs GDPR Compliance: Key Differences Every Global Privacy Team Should Know

GDPR is a rights-based, opt-in framework; CCPA is a transparency and opt-out one. That philosophical gap shapes almost every operational difference — from lawful basis and breach timelines to sale/share opt-outs and DPO obligations. A side-by-side breakdown of scope, consumer rights, cross-border transfers, and enforcement, plus how to build one unified programme that satisfies both.

Ananya KrishnanAugust 7, 202612 min read
CCPA vs GDPR Compliance: Key Differences Every Global Privacy Team Should Know

Two Laws, Two Philosophies

The EU's General Data Protection Regulation (GDPR) and California's Consumer Privacy Act (CCPA, as amended by the CPRA) are the two most consequential privacy laws in the world, and almost every global company touches both. But treating them as broadly similar is a mistake that quietly bakes compliance gaps into a programme.

GDPR is a rights-based, opt-in framework grounded in the idea that personal data processing is unlawful unless a specific legal basis applies. CCPA is a transparency-and-opt-out framework grounded in consumer choice: businesses may generally collect and use personal information, provided they disclose it and honour opt-out and deletion requests. That philosophical gap shapes almost every operational difference that follows.

Territorial Scope: Who Each Law Covers

GDPR applies to any organisation established in the EU/EEA, and to non-EU organisations that offer goods or services to individuals in the EU or monitor their behaviour. There is no revenue threshold — a two-person startup with a single EU customer is technically in scope. The 'establishment' principle also means an EU office pulls the whole organisation into scope, regardless of where processing occurs.

CCPA takes a threshold-based approach. It applies to for-profit businesses that do business in California and meet one of three tests: annual gross revenue over $25 million, buying or selling the personal information of 100,000 or more California consumers or households, or deriving 50% or more of annual revenue from selling or sharing personal information. Smaller businesses are simply out of scope — a structural distinction that does not exist under GDPR.

Personal Data vs Personal Information: Definitions Diverge

Both laws define their protected data category broadly, but not identically. GDPR's 'personal data' means any information relating to an identified or identifiable natural person. It includes online identifiers, location data, and any data that could indirectly identify someone — cookie IDs, IP addresses, and device fingerprints are all in scope.

CCPA defines 'personal information' broadly too, but it is scoped to California consumers and explicitly excludes deidentified or aggregate consumer information, publicly available government records, and personal information collected in a B2B or employment context under narrower rules. The CPRA amendment also introduced 'sensitive personal information' — a category (government IDs, precise geolocation, health, race, biometrics, financial credentials, communications content) that triggers a separate 'Limit the Use of My Sensitive Personal Information' right. GDPR's parallel concept, 'special category data' under Article 9, is stricter still: processing is generally prohibited unless one of ten specific conditions applies.

Legal Basis: Opt-In vs Opt-Out

This is the deepest structural difference between the two laws. GDPR requires a lawful basis before any processing begins — consent, contract, legal obligation, vital interests, public task, or legitimate interests. Consent must be freely given, specific, informed, and unambiguous, and it must be as easy to withdraw as to give. For cookies and tracking, ePrivacy overlays this with a hard opt-in requirement for anything beyond strictly necessary.

CCPA does not require a lawful basis or prior consent to collect personal information from adults. Businesses may collect and use it after disclosure, subject to consumer rights to opt out of sale/sharing, limit sensitive personal information use, and request deletion. Prior opt-in consent is required only in narrow cases: minors under 16 (opt-in), minors under 13 (verifiable parental consent), and financial incentive programmes. In practical terms, a GDPR-compliant cookie banner asks for permission before firing analytics; a CCPA-only banner discloses tracking and offers an opt-out link. The two look nothing alike.

Consumer and Data Subject Rights: Overlap and Gaps

Both regimes give individuals rights over their data, but the shape of those rights differs. GDPR provides eight: access, rectification, erasure, restriction of processing, portability, objection, rights related to automated decision-making, and the right not to be subject to profiling. Response is due within one calendar month, extendable by two months for complex requests.

CCPA (post-CPRA) provides seven: the right to know, the right to delete, the right to correct, the right to opt out of sale or sharing, the right to limit use of sensitive personal information, the right to data portability, and the right to non-discrimination for exercising these rights. Response is due within 45 calendar days, extendable by another 45. Notable gaps in CCPA: no general right to object to processing, no restriction right, and narrower automated-decision-making protections (though the CPPA's ADMT regulations are closing that gap). GDPR requires you to prove identity proportionate to the risk; CCPA is more prescriptive about verification tiers and non-account-holder requests.

Sale, Share, and the Opt-Out Signal

CCPA carves out a set of activities — 'selling' and 'sharing' personal information — that has no direct GDPR parallel. 'Selling' means disclosing personal information for monetary or other valuable consideration; 'sharing' means disclosing it for cross-context behavioural advertising, regardless of whether money changes hands. Both trigger a mandatory 'Do Not Sell or Share My Personal Information' link and an obligation to honour opt-out preference signals like Global Privacy Control (GPC) at the browser level.

GDPR does not use the sale/share vocabulary. Instead, cross-context behavioural advertising is governed through the consent and legitimate-interests analysis, ePrivacy's cookie consent rules, and increasingly through Digital Services Act and Digital Markets Act obligations. In practice, the same underlying activity — passing user data to an ad-tech partner for retargeting — must clear a prior opt-in bar under GDPR/ePrivacy and an opt-out plus GPC-honouring bar under CCPA. A single implementation can satisfy both if you default to opt-in for EU visitors and expose a GPC-aware opt-out for California visitors.

Breach Notification: 72 Hours vs No Fixed Deadline

GDPR imposes a strict 72-hour clock: notify the competent supervisory authority within 72 hours of becoming aware of a personal data breach that poses a risk to individuals; notify affected data subjects 'without undue delay' if the risk is high. The 72 hours run from awareness, not from the intrusion itself, and 'aware' is interpreted narrowly.

CCPA itself does not include an omnibus breach notification requirement — that sits in California's separate breach notification statute (Cal. Civ. Code §§ 1798.29 and 1798.82). Notification to affected residents is required 'in the most expedient time possible and without unreasonable delay', with no fixed hour count, and to the California Attorney General only if more than 500 residents are affected. What CCPA does add is a private right of action for certain data breaches — a statutory-damages lever ($100–$750 per consumer per incident) that has driven most of the meaningful CCPA litigation to date.

Governance Obligations: DPO, RoPA, DPIA

GDPR mandates specific governance artefacts. A Data Protection Officer is required for public authorities, for organisations whose core activities involve large-scale systematic monitoring, and for those processing special category data at scale. Records of Processing Activities (RoPA) under Article 30 are mandatory for most controllers and processors. Data Protection Impact Assessments (DPIAs) are required whenever processing is likely to result in a high risk to individuals.

CCPA does not require a DPO or a RoPA. Instead, it introduces two CPRA-era obligations for high-risk processors: annual cybersecurity audits and regular risk assessments for processing that presents a significant risk to consumers' privacy or security — the exact scope and format are set by ongoing CPPA rulemaking. In practice, a company running a GDPR-grade RoPA and DPIA programme is already 80% of the way to satisfying the CPPA's risk-assessment expectations; running only a CCPA programme leaves a significant gap when EU exposure appears.

Cross-Border Data Transfers

GDPR restricts transfers of personal data outside the EU/EEA unless the destination has an adequacy decision, or the transfer is protected by an approved mechanism — Standard Contractual Clauses (SCCs), Binding Corporate Rules, or a limited set of derogations. Post-Schrems II, controllers must also run a Transfer Impact Assessment to evaluate destination-country surveillance risk, and often layer supplementary technical measures on top. See the Schrems II transfer guide for the practical mechanics.

CCPA imposes no equivalent transfer restriction. Personal information can flow freely across borders subject to the same disclosure, opt-out, and contractual obligations that apply to any recipient. The operational implication: a GDPR-first architecture already handles CCPA transfers by default, but a CCPA-first architecture usually needs re-engineering — DPAs, SCCs, sub-processor registries, TIAs, and often data residency choices — before it can lawfully serve EU customers.

Enforcement and Penalties

GDPR enforcement is decentralised through national Data Protection Authorities, coordinated through the European Data Protection Board and the one-stop-shop lead supervisory authority mechanism for cross-border processing. Maximum administrative fines are €20 million or 4% of global annual turnover — whichever is higher — for the most serious infringements, and €10 million or 2% for lesser ones. Enforcement has been assertive and creative: fines against Meta, TikTok, Amazon, and Google now exceed €4 billion cumulatively.

CCPA enforcement sits with the California Attorney General and the California Privacy Protection Agency (CPPA), the first dedicated privacy enforcement body in the United States. Administrative penalties are $2,500 per violation and $7,500 per intentional violation or violation involving minors. There is no percentage-of-revenue cap, but each affected consumer's data can constitute a separate violation, so aggregate exposure at scale is meaningful. The private right of action for data breaches ($100–$750 per consumer per incident) is a distinct and increasingly active enforcement channel that has no direct GDPR equivalent.

Building a Unified Compliance Programme

For organisations covered by both laws, the most efficient posture is to build the programme to the stricter standard by function, then layer jurisdiction-specific mechanics on top. GDPR usually sets the higher bar for lawful basis, consent, records, DPIAs, cross-border transfers, and breach notification timing. CCPA sets the higher bar for opt-out signal handling (GPC), the 'Limit the Use of Sensitive Personal Information' flow, contractor/service-provider paperwork, and the specific text of consumer notices.

Operationally this means one data inventory that tags every asset with jurisdictional flags, one DSR intake that branches by residency, one consent engine that switches between opt-in and opt-out defaults based on geolocation, and one contract library with modular DPA/SCC/Service Provider Addendum blocks. The DSR automation guide covers the request-handling side; the privacy verification guide covers identity verification tiers that satisfy both frameworks. Building to one law and bolting the other on later almost always produces a more expensive, gap-prone programme than designing for both from the start.

Automate your privacy compliance

See how TruePrivacy can handle DSRs, consent, and breach response — all in one platform.

Free 14-day trial · No credit card required · Setup in minutes