Home / GDPR vs CCPA

GDPR vs CCPA

The short answer: GDPR is opt-in and covers almost anyone who targets people in the EU. The CCPA is opt-out and covers only larger businesses (or data-heavy ones) with Californian customers. The chart below compares them point by point, with the article or section each answer comes from.

TopicGDPR (EU)CCPA / CPRA (California)
Where it appliesGDPROrganisations established in the EU, and those outside it that offer goods or services to, or monitor, people in the EU (Art. 3).CCPAFor-profit businesses doing business in California that meet a threshold in Civ. Code § 1798.140(d).
Size thresholdGDPRNone. A one-person business is covered.CCPAGross revenue above $26,625,000 (2025 CPI-adjusted figure), or buying/selling/sharing data of 100,000+ consumers or households, or 50%+ of revenue from selling/sharing it.
Who is protectedGDPR"Data subjects": any identifiable person whose data is processed, wherever they are from.CCPA"Consumers": natural persons who are California residents (including employees and B2B contacts since 2023).
Basic modelGDPROpt-in: every processing activity needs one of six legal bases (Art. 6), such as consent, contract or legitimate interests.CCPAOpt-out: no legal basis needed, but consumers can opt out of the sale and sharing of their data (§ 1798.120).
Privacy noticeGDPRArticles 13 and 14 list the required content; Article 12 requires clear and plain language.CCPA11 CCR § 7011 lists the required content, including categories collected in the past 12 months; update at least every 12 months.
Individual rightsGDPRAccess, rectification, erasure, restriction, portability, objection, and rights around automated decisions (Arts. 15–22).CCPAKnow, delete, correct, opt out of sale/sharing, limit use of sensitive personal information, and non-discrimination.
Response deadlineGDPROne month, extendable by two further months for complex requests (Art. 12(3)).CCPA45 days, extendable once by a further 45 days with notice (§ 1798.130(a)(2)).
Sensitive dataGDPR"Special categories" (health, religion, biometrics, etc.) may not be processed unless an Art. 9 exception applies.CCPA"Sensitive personal information" may be used, but consumers can limit its use to what is necessary (§ 1798.121).
ChildrenGDPRConsent for online services needs parental authorisation under 16; member states may lower this to 13 (Art. 8).CCPASelling or sharing data of consumers under 16 needs opt-in consent; under 13, a parent's consent (§ 1798.120(c)).
Browser signalsGDPRNo specific rule; consent for non-essential cookies comes from the ePrivacy Directive.CCPAOpt-out preference signals such as Global Privacy Control must be honoured (11 CCR § 7025).
RegulatorGDPRA national data protection authority in each member state.CCPACalifornia Privacy Protection Agency and the California Attorney General.
Maximum finesGDPRUp to €20 million or 4% of worldwide annual turnover, whichever is higher (Art. 83(5)).CCPAAdministrative fines of up to $2,663 per violation, or $7,988 for intentional violations or those involving minors (2025 adjusted figures).
Private lawsuitsGDPRPeople can claim compensation for material or non-material damage (Art. 82).CCPAOnly for certain data breaches: $107 to $799 per consumer per incident, or actual damages (§ 1798.150, 2025 figures).

Figures are the 2025 CPI adjustments announced by the California Privacy Protection Agency; the agency adjusts them every other year. Sources: official texts and regulator guidance.

Which sections each law adds to your privacy policy

Turn GDPR and CCPA on together to see the combined list, or one at a time to see what each demands.

With GDPR + CalOPPA, your policy needs 18 of 19 sections.

Section (tap for the source)GDPRCCPACalOPPAPIPEDA
Who you are and how to contact you
GDPR: Art. 13(1)(a)CCPA: 11 CCR § 7011(e)PIPEDA: Sch. 1, Principle 4.8 (openness)

Next steps

Not sure either applies? Run the law finder. If they do, generate a policy with both sections: GDPR privacy policy generator or CCPA privacy policy generator. Smaller US sites are usually covered by CalOPPA even when the CCPA doesn't apply.

Frequently asked questions

What is the main difference between GDPR and CCPA?

GDPR is opt-in: you need a legal basis before processing anyone's personal data, and it applies to organisations of any size that target people in the EU. The CCPA is opt-out: businesses may collect and use data but must disclose it and let Californians opt out of sale and sharing, and it only applies to businesses above its thresholds.

If I comply with GDPR, am I compliant with CCPA?

Not automatically. Much overlaps (notices, access and deletion rights), but the CCPA has its own requirements, such as the "Do Not Sell or Share" link, honouring Global Privacy Control, the 12-month categories disclosure and specific request-verification rules.

Can one privacy policy cover both?

Yes. Most businesses publish a single policy with a general section and separate sections for EEA/UK and California rights. Our generator does this when you switch both laws on.

Which is stricter?

GDPR is broader and stricter on the basics (legal basis, no size threshold, higher maximum fines). The CCPA is more prescriptive on some mechanics, such as opt-out links, preference signals and the exact contents of the privacy policy.