Home  /  Insights  /  GDPR vs. CCPA

Regulatory & Compliance

GDPR vs. CCPA: A Practical Comparison

Law library shelves

Two of the world’s most influential privacy laws — the EU’s General Data Protection Regulation (GDPR) and California’s Consumer Privacy Act (CCPA, as amended by the CPRA) — are often discussed together, but they don’t work the same way. For companies operating on both sides of the Atlantic, the differences matter more than the similarities.

Who Each Law Actually Covers

GDPR applies to any organization that processes the personal data of individuals in the EU — regardless of where the organization itself is based. A U.S. company with no EU office can still fall squarely within its scope simply by having EU customers or website visitors.

CCPA is narrower and threshold-based. It applies to for-profit businesses that do business in California and meet at least one of several thresholds — annual revenue, the volume of consumer data processed, or the share of revenue derived from selling or sharing personal information.

Consent vs. Opt-Out: The Core Philosophical Difference

This is where the two laws diverge most. GDPR requires a valid legal basis before processing personal data in the first place — consent is one basis among several (including contractual necessity and legitimate interest), but it must generally be freely given, specific, and opt-in.

CCPA takes an opt-out approach: businesses can generally collect and use personal information by default, but must give consumers a clear way to opt out of having their data sold or shared, along with other specific rights described below.

What Rights Do Individuals Actually Get?

RightGDPRCCPA / CPRA
AccessRight to confirm processing and access a copy of personal dataRight to know what personal information is collected and how it’s used
DeletionRight to erasure (“right to be forgotten”), subject to exceptionsRight to delete, subject to exceptions
PortabilityRight to receive data in a structured, machine-readable formatLimited portability right for data provided directly by the consumer
Opt-OutRight to object to processing, including for direct marketingRight to opt out of sale/sharing of personal information
CorrectionRight to rectification of inaccurate dataRight to correct inaccurate personal information

Enforcement

GDPR is enforced by national Data Protection Authorities across the EU, with fines that can reach up to 4% of a company’s global annual revenue for the most serious violations — among the highest maximum penalties of any privacy regime in the world.

CCPA is enforced primarily by the California Privacy Protection Agency, with civil penalties assessed per violation, plus a limited private right of action for consumers affected by certain data breaches.

Practical Takeaways for Growing Companies

  • Map your data flows first. You can’t determine which law applies until you know whose data you actually process, and where they’re located.
  • Don’t assume a US-only company is automatically exempt from GDPR — EU website visitors alone can trigger it.
  • Build your consent and opt-out mechanisms to the stricter standard where your obligations overlap — it’s usually cheaper than maintaining two systems.
  • Revisit your privacy program annually. Both regimes continue to evolve through regulatory guidance and enforcement actions.

The Bottom Line

Neither law is simply a “checkbox” exercise, and treating them as interchangeable is one of the most common compliance mistakes we see. The right program starts with understanding exactly which regime applies to your business today — and building in enough flexibility to adapt as both laws continue to change.

This article is provided for general informational purposes and does not constitute legal advice. Privacy law changes frequently and its application depends on your specific facts — speak with counsel before relying on it for a compliance decision.

PN
Priya Nandan

Partner, Data Privacy & Regulatory Compliance

Priya advises technology and financial services clients on privacy compliance and data governance across U.S., Canadian, and E.U. jurisdictions.

Related Insights

Keep reading.

City skyline
Expansion·Jun 2026
Structuring Your First E.U. Market Entry
Read More →
Federal courthouse
Employment·Apr 2026
Employment Law Basics for Your First International Hire
Read More →
Law library shelves
Technology & AI Law·Jun 2026
AI Governance: What “Compliant” Actually Means in 2026
Read More →

Get Started

Schedule Your Strategy Consultation

Begin with a conversation about your business, your risks, and your goals. Most clients receive initial legal guidance within 24–48 hours.

Schedule Your Strategy Consultation

No obligation. Confidential. Response within 24–48 hours.