Home / GDPR vs CCPA
GDPR vs CCPA
The short answer: GDPR is opt-in and covers almost anyone who targets people in the EU. The CCPA is opt-out and covers only larger businesses (or data-heavy ones) with Californian customers. The chart below compares them point by point, with the article or section each answer comes from.
Figures are the 2025 CPI adjustments announced by the California Privacy Protection Agency; the agency adjusts them every other year. Sources: official texts and regulator guidance.
Which sections each law adds to your privacy policy
Turn GDPR and CCPA on together to see the combined list, or one at a time to see what each demands.
With GDPR + CalOPPA, your policy needs 18 of 19 sections.
GDPR: Art. 13(1)(a)CCPA: 11 CCR § 7011(e)PIPEDA: Sch. 1, Principle 4.8 (openness)
Next steps
Not sure either applies? Run the law finder. If they do, generate a policy with both sections: GDPR privacy policy generator or CCPA privacy policy generator. Smaller US sites are usually covered by CalOPPA even when the CCPA doesn't apply.
Frequently asked questions
What is the main difference between GDPR and CCPA?
GDPR is opt-in: you need a legal basis before processing anyone's personal data, and it applies to organisations of any size that target people in the EU. The CCPA is opt-out: businesses may collect and use data but must disclose it and let Californians opt out of sale and sharing, and it only applies to businesses above its thresholds.
If I comply with GDPR, am I compliant with CCPA?
Not automatically. Much overlaps (notices, access and deletion rights), but the CCPA has its own requirements, such as the "Do Not Sell or Share" link, honouring Global Privacy Control, the 12-month categories disclosure and specific request-verification rules.
Can one privacy policy cover both?
Yes. Most businesses publish a single policy with a general section and separate sections for EEA/UK and California rights. Our generator does this when you switch both laws on.
Which is stricter?
GDPR is broader and stricter on the basics (legal basis, no size threshold, higher maximum fines). The CCPA is more prescriptive on some mechanics, such as opt-out links, preference signals and the exact contents of the privacy policy.