CCPA vs GDPR Explained: California’s Data Privacy Law vs EU Regulation

CCPA vs GDPR

Written by

in

A major difference between the CCPA and GDPR is becoming clearer in 2026: privacy compliance is moving beyond privacy policies and into the technology businesses use to collect, share, delete, and profile personal data. California’s rules now include stronger requirements around opt-out signals, automated decision-making, risk assessments, cybersecurity audits, and data brokers. At the same time, the GDPR continues to apply to businesses outside Europe when they offer services to people in the EU or monitor their behaviour. That means a business can no longer assume that having a privacy policy and cookie banner is enough. The practical question is whether its systems actually respect a person’s privacy choice.

CCPA vs GDPR: The Core Difference

The CCPA, formally the California Consumer Privacy Act as amended by the California Privacy Rights Act, is California’s broad consumer privacy law. The CPRA did not create a separate law. It changed the CCPA and added new rights and obligations.  The GDPR is an EU regulation that applies across the European Economic Area and can also reach organisations outside Europe.

The biggest difference is how each law approaches scope.

AreaCCPAGDPR
Main focusConsumer privacy and control over personal informationProtection of personal data and individual rights
Geographic reachCalifornia-focused, with rules that can affect businesses outside CaliforniaCan apply to organisations outside the EU
Opt-outStrong rights to opt out of sale and sharingDifferent legal bases and consent rules apply
Sensitive dataRight to limit certain usesStronger special-category data rules
Automated decisionsNew requirements are being phased inExisting rules cover certain automated decision-making
Maximum administrative fineGenerally up to $2,663 per violation, or $7,988 for intentional violations under current California amountsUp to €20 million or 4% of the company’s total annual global turnover, depending on the type of violation.

California’s monetary thresholds were adjusted for inflation in 2025. 

Who Does the CCPA Apply To?

The CCPA does not apply to every business simply because someone from California visits its website. Coverage depends on factors such as the business’s activities and statutory thresholds. One threshold tied to annual gross revenue was adjusted to $26.625 million from January 1, 2025. Other CCPA tests can apply based on the amount of personal information handled or the business’s role in selling or sharing personal information. This differs from the GDPR.

The GDPR can apply to a small business outside the EU if it offers goods or services to people in the EU or monitors their behaviour there. Company size alone does not remove a business from GDPR coverage.  For example, a small Australian software company that specifically sells subscriptions to customers in Germany may need to assess GDPR obligations even though it has no European office. A business targeting California customers may instead need to determine whether it meets the CCPA definition of a covered business.

The Rights Consumers Get Under CCPA and GDPR

The laws overlap, but they give people different forms of control.

Under the CCPA, California consumers are entitled to several privacy rights, including:

  • Know what personal information a business collects, uses, and shares.
  • Delete personal information, subject to exceptions
  • Correct inaccurate information
  • Opt out of the sale or sharing of personal information
  • Limit certain uses and disclosures of sensitive personal information
  • Receive equal treatment when exercising privacy rights 

The GDPR provides a different rights framework. Depending on the circumstances, individuals can request access, correction, deletion, restriction of processing, data portability, and objection to certain processing. Consent can also be withdrawn where consent is the legal basis. This creates an important practical difference: CCPA often gives consumers a direct opt-out from certain commercial data uses, while GDPR compliance depends heavily on why the organisation is processing the data in the first place.

The Overlooked CCPA Detail: Your Privacy Choice Must Reach the Technology

One of the most important CCPA developments is not simply another consumer right. It is the growing requirement for businesses to make privacy choices work across their technical systems. California already requires covered businesses to honour qualifying opt-out preference signals, such as Global Privacy Control, for sale and sharing. In September 2025, California, Colorado, and Connecticut announced a joint investigation into businesses that may have failed to honour these signals.

California then went further. In October 2025, the Governor signed the California Opt Me Out Act, requiring browsers operating in California to offer users a simple built-in way to send opt-out preference signals. For businesses, this changes the technical question.

It is not enough to place a “Your Privacy Choices” link in a footer. The signal must affect what happens behind the page. If a visitor sends an opt-out signal, businesses need to consider whether their advertising tools, analytics systems, customer databases, and third-party vendors actually stop the relevant sale or sharing. That makes privacy engineering part of CCPA compliance, not just legal drafting.

CCPA Data Brokers Are Facing a New Practical Test

Another major 2026 development is California’s Delete Request and Opt-Out Platform, or DROP. Beginning January 1, 2026, California residents can use DROP to submit a single request to participating data brokers. Starting August 1, 2026, data brokers must access the mechanism at least once every 45 days and process qualifying deletion requests. The system matters because it changes deletion from a company-by-company process into a centralized request. California is also actively enforcing data broker rules.

In January 2026, CalPrivacy announced a $45,000 fine against Datamasters for failing to register as a data broker and ordered it to stop selling Californians’ personal information. The same announcement described a separate $62,600 fine against S&P Global for a registration failure.

These cases show why businesses should examine whether their marketing, audience-building, enrichment, or data-resale activities could make them subject to California’s data broker rules.

How the GDPR Differs on International Reach

The GDPR’s reach is broader than many businesses expect. An organisation outside the EU can fall under the GDPR if it offers goods or services to individuals in the EU or monitors their behaviour there. Simply having a website that happens to be accessible from Europe does not automatically establish GDPR coverage. The business’s actual activities matter. The GDPR also has a strong focus on the legal basis for processing.

A business generally needs a lawful reason to process personal data. Depending on the activity, that can include consent, contract, legal obligation, legitimate interests, or other recognised grounds. This is different from treating privacy mainly as a consumer opt-out system. For businesses operating internationally, CCPA and GDPR should therefore be assessed separately, even when the same customer data is involved.

New CCPA Rules Matter for AI and Automated Decisions

California’s privacy rules are also moving into artificial intelligence and automated decision-making. Regulations adopted in 2025 became effective January 1, 2026. They introduced requirements covering risk assessments, cybersecurity audits, and automated decision-making technology. Some automated decision-making requirements begin in 2027, while certain cybersecurity audit reporting deadlines extend into 2028, 2029, and 2030 depending on business revenue.

This is an important difference from older CCPA comparisons.

A privacy review should now ask more than, “What information do we collect?”

It should also ask:

What decisions does our technology make using personal information, and can a consumer exercise the rights that California provides?

Businesses using profiling, recommendation systems, advertising technology, or automated eligibility decisions should map those systems before assuming their existing CCPA controls are sufficient.

CCPA vs GDPR: What Businesses Should Do

Businesses dealing with both California and EU users should build a single data map first, then test it against each law.

We should identify:

  1. What personal information is collected
  2. Where it comes from
  3. Why it is processed
  4. Which vendors receive it
  5. Whether it is sold or shared
  6. How deletion and correction requests move through systems
  7. How opt-out signals are detected
  8. Whether sensitive information receives additional controls
  9. Whether profiling or automated decisions are involved
  10. How privacy choices are recorded and enforced

The goal should not be to copy one law’s policy wording into another jurisdiction. The stronger approach is to make the underlying data systems capable of enforcing each person’s applicable rights.

Conclusion

CCPA vs GDPR is not simply a comparison between two privacy policies. The more useful distinction is how each law makes businesses give people control over personal data. The CCPA has developed into a system where opt-out signals, data brokers, automated decision-making, risk assessments, and technical controls matter alongside traditional privacy notices. The GDPR remains broader in its territorial reach and places strong emphasis on the legal basis and conditions for processing personal data. For organisations operating across California and Europe, the practical lesson is clear: map the data, map the technology, and then test each processing activity against the law that applies to the people involved.

CCPA vs GDPR FAQs

Does GDPR automatically apply to every business with European visitors?

No. A business outside the EU can fall under the GDPR when it offers goods or services to people in the EU or monitors their behaviour there. Mere accessibility from Europe does not automatically establish coverage. 

Does CCPA apply to small businesses?

Not necessarily. CCPA coverage depends on the statutory tests, rather than simply whether a company is large or small. A business should check its revenue, data-processing activities, and other applicable criteria.

Is CCPA compliance the same as having a privacy policy?

No. A privacy policy is only one part of compliance. CCPA obligations can affect website controls, opt-out signals, advertising systems, vendor contracts, data deletion processes, and automated technologies. 

What is the biggest practical CCPA change in 2026?

For many businesses, the important shift is that privacy choices increasingly need to work through technology rather than remain on paper. Opt-out signals, centralized data-broker deletion through DROP, risk assessments, and new automated decision-making rules all reinforce this direction.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *