Two of the world’s most influential privacy laws — the EU’s General Data Protection Regulation (GDPR) and California’s Consumer Privacy Act (CCPA, as amended by the CPRA) — are often discussed together, but they don’t work the same way. For companies operating on both sides of the Atlantic, the differences matter more than the similarities.
Who Each Law Actually Covers
GDPR applies to any organization that processes the personal data of individuals in the EU — regardless of where the organization itself is based. A U.S. company with no EU office can still fall squarely within its scope simply by having EU customers or website visitors.
CCPA is narrower and threshold-based. It applies to for-profit businesses that do business in California and meet at least one of several thresholds — annual revenue, the volume of consumer data processed, or the share of revenue derived from selling or sharing personal information.
Consent vs. Opt-Out: The Core Philosophical Difference
This is where the two laws diverge most. GDPR requires a valid legal basis before processing personal data in the first place — consent is one basis among several (including contractual necessity and legitimate interest), but it must generally be freely given, specific, and opt-in.
CCPA takes an opt-out approach: businesses can generally collect and use personal information by default, but must give consumers a clear way to opt out of having their data sold or shared, along with other specific rights described below.
What Rights Do Individuals Actually Get?
| Right | GDPR | CCPA / CPRA |
|---|---|---|
| Access | Right to confirm processing and access a copy of personal data | Right to know what personal information is collected and how it’s used |
| Deletion | Right to erasure (“right to be forgotten”), subject to exceptions | Right to delete, subject to exceptions |
| Portability | Right to receive data in a structured, machine-readable format | Limited portability right for data provided directly by the consumer |
| Opt-Out | Right to object to processing, including for direct marketing | Right to opt out of sale/sharing of personal information |
| Correction | Right to rectification of inaccurate data | Right to correct inaccurate personal information |
Enforcement
GDPR is enforced by national Data Protection Authorities across the EU, with fines that can reach up to 4% of a company’s global annual revenue for the most serious violations — among the highest maximum penalties of any privacy regime in the world.
CCPA is enforced primarily by the California Privacy Protection Agency, with civil penalties assessed per violation, plus a limited private right of action for consumers affected by certain data breaches.
Practical Takeaways for Growing Companies
- Map your data flows first. You can’t determine which law applies until you know whose data you actually process, and where they’re located.
- Don’t assume a US-only company is automatically exempt from GDPR — EU website visitors alone can trigger it.
- Build your consent and opt-out mechanisms to the stricter standard where your obligations overlap — it’s usually cheaper than maintaining two systems.
- Revisit your privacy program annually. Both regimes continue to evolve through regulatory guidance and enforcement actions.
The Bottom Line
Neither law is simply a “checkbox” exercise, and treating them as interchangeable is one of the most common compliance mistakes we see. The right program starts with understanding exactly which regime applies to your business today — and building in enough flexibility to adapt as both laws continue to change.
This article is provided for general informational purposes and does not constitute legal advice. Privacy law changes frequently and its application depends on your specific facts — speak with counsel before relying on it for a compliance decision.
Priya Nandan
Partner, Data Privacy & Regulatory Compliance
Priya advises technology and financial services clients on privacy compliance and data governance across U.S., Canadian, and E.U. jurisdictions.
Related Insights
Keep reading.
Employment Law Basics for Your First International Hire
Read More →
AI Governance: What “Compliant” Actually Means in 2026
Read More →Get Started
Schedule Your Strategy Consultation
Begin with a conversation about your business, your risks, and your goals. Most clients receive initial legal guidance within 24–48 hours.
Schedule Your Strategy ConsultationNo obligation. Confidential. Response within 24–48 hours.