Guide
CCPA vs GDPR: Understanding the Key Differences
The two most important privacy regulations in the world take fundamentally different approaches to protecting consumer data. Here is what you need to know about each — and how to comply with both.
The General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), are the two most influential privacy laws in the world today. GDPR took effect across the European Union in May 2018, establishing a rigorous standard for data protection that applies to any organization that processes the personal data of EU and EEA residents. The CCPA followed in January 2020, giving California residents new rights over their personal information, and was significantly strengthened by the CPRA, which took effect in January 2023.
If your website serves visitors from both the European Union and California — and most websites with any meaningful traffic do — you likely need to comply with both regulations. While the two laws share the same underlying goal of giving individuals more control over their personal data, they differ substantially in how they define personal data, how they approach consent, what rights they grant consumers, how they are enforced, and how they handle cookies and online tracking.
This guide breaks down the difference between CCPA and GDPR in plain language, with a detailed side-by-side comparison table followed by in-depth analysis of the most consequential distinctions. Whether you are a website owner trying to understand your obligations, a developer implementing compliance features, or a privacy professional advising clients, this comparison will help you understand exactly where these two laws align and where they diverge.
Side-by-Side
CCPA vs GDPR comparison table
A comprehensive look at how these two privacy regulations compare across every major dimension.
| Category | GDPR | CCPA / CPRA |
|---|---|---|
| Full name | General Data Protection Regulation (Regulation (EU) 2016/679) | California Consumer Privacy Act / California Privacy Rights Act (Cal. Civ. Code §1798.100–1798.199.100) |
| Effective date | May 25, 2018 | January 1, 2020 (CCPA) / January 1, 2023 (CPRA amendments) |
| Geographic scope | Protects EU/EEA residents. Applies to any organization worldwide that processes their personal data, regardless of where the organization is based. | Protects California residents. Applies to for-profit businesses that collect personal information of California consumers and meet specific revenue or data-volume thresholds. |
| Applicability threshold | No minimum threshold. Any organization processing personal data of EU residents must comply, regardless of size, revenue, or data volume. | Applies to for-profit businesses that meet any one of: annual gross revenue exceeding $25 million; buying, selling, or sharing personal information of 100,000+ consumers or households per year; or deriving 50% or more of annual revenue from selling or sharing personal information. |
| Definition of personal data / information | “Personal data” — any information relating to an identified or identifiable natural person. Includes names, email addresses, IP addresses, cookie identifiers, location data, biometric data, and any data that can directly or indirectly identify someone. | “Personal information” — information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to a particular consumer or household. Includes names, IP addresses, browsing history, purchasing history, geolocation, and inferences drawn from other data. |
| Consent model | Opt-in. Organizations must obtain explicit, affirmative consent before processing personal data for non-essential purposes. Consent must be freely given, specific, informed, and unambiguous. Pre-checked boxes and implied consent are not valid. | Opt-out. Businesses may collect and process personal information by default, but must give consumers the right to opt out of the sale or sharing of their data. Opt-in consent is only required for minors (under 16, or under 13 with parental consent). |
| Consumer / data subject rights | Right to access, rectification, erasure, restriction of processing, data portability, objection, and rights related to automated decision-making and profiling. | Right to know, delete, correct, opt out of sale/sharing, limit use of sensitive personal information, and non-discrimination. CPRA added the right to correct and the right to limit use of sensitive data. |
| Right to delete | Yes — the “right to erasure” or “right to be forgotten.” Data controllers must erase personal data upon request unless a legal exception applies (e.g., legal obligation, public interest, exercise of legal claims). | Yes. Businesses must delete a consumer’s personal information upon request and direct service providers and contractors to do the same. Exceptions include completing transactions, detecting security incidents, legal obligations, and internal uses consistent with the consumer’s relationship with the business. |
| Right to access | Yes. Data subjects can request confirmation of whether their data is being processed, a copy of that data, and information about the purposes and recipients of processing. Response required within one month. | Yes. Consumers can request the categories and specific pieces of personal information collected about them, the sources, the business purposes for collecting or selling, and the third parties with whom data is shared. Response required within 45 days. |
| Right to data portability | Yes. Data subjects have the right to receive their personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller. | Limited. CPRA added a right to access personal information in a portable and readily usable format, but the scope is narrower than GDPR’s portability provisions and applies primarily to the data a business has collected directly from the consumer. |
| Right to opt out of sale | Not a standalone right. GDPR grants a broader right to object to processing. The concept of “selling” data is not separately addressed because the opt-in consent model already prevents processing without consent. | Yes — a core CCPA right. Consumers can opt out of the “sale” or “sharing” of their personal information. Businesses must provide a clear “Do Not Sell or Share My Personal Information” link on their website. |
| Right to non-discrimination | Not explicitly named. GDPR includes general principles of fairness and non-discrimination in automated decision-making, but there is no standalone non-discrimination right tied to exercising privacy rights. | Yes, explicitly stated. Businesses cannot discriminate against consumers who exercise their CCPA rights — for example, by denying goods or services, charging different prices, providing a different quality of service, or suggesting they will receive different treatment. |
| Cookie requirements | Prior consent required. Under GDPR and the ePrivacy Directive, non-essential cookies (analytics, advertising, tracking) cannot be set until the user has given explicit consent. A cookie consent banner must be presented before any tracking begins. | Disclosure and opt-out. Cookies that collect personal information for sale or sharing require disclosure. If cookies are used to “sell” or “share” personal information (e.g., third-party advertising cookies), consumers must be able to opt out. No prior consent is needed to set cookies, but their use must be disclosed. |
| Enforcement body | National Data Protection Authorities (DPAs) in each EU/EEA member state. The European Data Protection Board (EDPB) coordinates cross-border enforcement. Lead supervisory authority model for cross-border cases. | California Attorney General and the California Privacy Protection Agency (CPPA), established by CPRA. The CPPA is the first dedicated state privacy enforcement agency in the United States. |
| Maximum penalties | Up to €20 million or 4% of global annual turnover, whichever is higher. Lower-tier fines of up to €10 million or 2% of global turnover for less severe violations. Fines have exceeded €1 billion in individual cases (Meta, 2023). | Up to $2,500 per unintentional violation and $7,500 per intentional violation. While the per-violation amounts are small, they are assessed per consumer per incident, which can add up quickly for businesses that handle large volumes of personal information. |
| Private right of action | Limited. GDPR allows individuals to lodge complaints with DPAs and seek judicial remedies, but private class-action lawsuits are not a primary enforcement mechanism in most EU jurisdictions. Some member states allow representative actions through consumer organizations. | Yes, for data breaches. Consumers have a private right of action if their nonencrypted or nonredacted personal information is exposed in a data breach resulting from a business’s failure to maintain reasonable security measures. Statutory damages of $100–$750 per consumer per incident, or actual damages, whichever is greater. |
Analysis
Key differences between CCPA and GDPR in detail
Consent model: opt-in vs opt-out
The most fundamental difference between CCPA and GDPR is how they approach consent. GDPR operates on an opt-in model: organizations must obtain clear, affirmative consent from individuals before processing their personal data for non-essential purposes. This means that before you can set analytics cookies, fire advertising pixels, or send marketing emails, the user must actively agree. Silence, pre-checked boxes, or continued browsing do not constitute valid consent under GDPR.
The CCPA takes the opposite approach. Under California law, businesses are allowed to collect and process personal information by default. The consumer’s right is to opt out of the sale or sharing of that information after the fact. This is why CCPA-compliant websites display a “Do Not Sell or Share My Personal Information” link, rather than an upfront consent banner. The business can start collecting data immediately, but it must honor opt-out requests promptly.
There is one important exception to the CCPA’s opt-out model: minors. For consumers under 16 years of age, businesses must obtain opt-in consent before selling their personal information. For children under 13, that consent must come from a parent or guardian. This mirrors GDPR’s approach to children’s data, though the age thresholds differ slightly.
In practice, this difference in consent models has significant implications for website design and user experience. GDPR-compliant sites must present a consent banner before any non-essential tracking begins, and they must provide granular options for different categories of cookies and data processing. CCPA-compliant sites need a clearly visible opt-out link but do not need to interrupt the user’s experience with a consent gate before loading the page.
Scope and applicability
GDPR casts a remarkably wide net. It applies to any organization in the world that processes the personal data of individuals located in the EU or EEA, regardless of the organization’s size, revenue, location, or the volume of data it processes. A sole proprietor running a blog from Argentina that collects email addresses from EU subscribers is technically subject to GDPR. There are no revenue thresholds, no minimum number of data subjects, and no exemption for small businesses.
The CCPA is more targeted in its applicability. It applies only to for-profit businesses that collect the personal information of California residents and that meet at least one of three thresholds: annual gross revenue exceeding $25 million; buying, receiving, selling, or sharing the personal information of 100,000 or more consumers, households, or devices per year; or deriving 50 percent or more of annual revenue from selling or sharing personal information. Nonprofit organizations and government agencies are exempt, and small businesses that fall below all three thresholds are not covered.
This difference in scope means that many small and medium-sized businesses that must comply with GDPR if they have any EU visitors may not need to comply with the CCPA at all. Conversely, large businesses that do not target European consumers may only need to worry about CCPA. For businesses that operate globally with significant traffic from both regions, both laws apply simultaneously and the question becomes how to satisfy both sets of requirements efficiently.
Definition of personal data
Both regulations define the concept of protected data broadly, but they use different terminology and slightly different boundaries. GDPR protects “personal data,” defined as any information relating to an identified or identifiable natural person. This includes obvious identifiers like names and email addresses, but also extends to IP addresses, cookie identifiers, device fingerprints, location data, genetic data, biometric data, and even pseudonymized data if it can be re-identified.
The CCPA protects “personal information,” defined as information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. The CCPA’s definition is notable for explicitly including household-level data, browsing history, search history, purchasing history, and inferences drawn from other data points to create consumer profiles.
In practice, both definitions are broad enough to cover most types of data that modern websites collect. The key practical difference is that GDPR’s definition is centered on the individual, while CCPA’s definition extends to the household level. Both laws clearly cover online identifiers like cookies and IP addresses, which is why both have significant implications for how websites handle tracking technologies.
Cookie requirements
Cookie compliance is where the day-to-day difference between CCPA and GDPR is most visible to website visitors. Under GDPR, combined with the ePrivacy Directive, non-essential cookies simply cannot be placed on a user’s device until they have provided informed, affirmative consent. This is why GDPR-compliant websites display a cookie consent banner before loading any analytics, advertising, or social media tracking scripts. The banner must describe the categories of cookies used, the purposes of each category, and provide a way to accept or reject each category individually. Essential cookies for basic functionality (like session management and security) are exempt.
The CCPA does not require prior consent for cookies. Instead, it requires transparency and opt-out capability. If cookies are used to collect personal information that is then “sold” or “shared” with third parties — which includes most advertising cookies and many analytics configurations — the business must disclose this practice and provide consumers with the ability to opt out. This is typically implemented through a “Do Not Sell or Share My Personal Information” link in the website footer, along with a mechanism to honor the Global Privacy Control (GPC) browser signal.
The practical consequence for website owners is that GDPR-compliant cookie handling is significantly more restrictive. If you implement GDPR-compliant consent management first, you will already satisfy most CCPA cookie requirements by extension, since blocking cookies until consent is given is more restrictive than simply allowing opt-out. The additional CCPA-specific element you need is the “Do Not Sell or Share” link and the ability to detect and honor the GPC signal.
Enforcement and penalties
The enforcement models of these two laws differ in both structure and scale. GDPR enforcement is handled by independent Data Protection Authorities (DPAs) in each EU/EEA member state, coordinated by the European Data Protection Board. Fines under GDPR can reach up to 20 million euros or 4 percent of global annual turnover, whichever is higher. These are not theoretical maximums — DPAs have imposed fines exceeding 1 billion euros in a single case, and total GDPR fines have surpassed 7 billion euros since 2018.
CCPA enforcement is handled by the California Attorney General and, since the CPRA amendments took effect, the California Privacy Protection Agency (CPPA). The maximum penalties under CCPA are $2,500 per unintentional violation and $7,500 per intentional violation. While these per-violation amounts are modest compared to GDPR fines, they are assessed per consumer per incident. A data practice that affects millions of California consumers can therefore result in substantial aggregate liability.
A critical distinction is the private right of action. Under CCPA, individual consumers can sue businesses directly if their nonencrypted or nonredacted personal information is compromised in a data breach that results from the business’s failure to maintain reasonable security measures. Statutory damages range from $100 to $750 per consumer per incident. In a large-scale data breach affecting millions of consumers, this creates exposure that can rival or exceed the largest GDPR fines. GDPR, by contrast, relies primarily on regulatory enforcement through DPAs, though individuals can seek judicial remedies and some member states allow representative actions.
Practical Guidance
When you need to comply with both CCPA and GDPR
If your business has customers, visitors, or users from both the European Union and California — and most businesses with any online presence do — you need to comply with both regulations. This is not an edge case. Any website that receives traffic from both regions and meets the CCPA’s applicability thresholds is subject to both laws simultaneously.
The good news is that the two laws are not contradictory. Because GDPR is generally the stricter of the two, the most practical approach is to build your privacy compliance program around GDPR first, then layer on CCPA-specific requirements. Here is a practical framework for dual compliance:
- Implement GDPR-compliant consent management. Set up a cookie consent banner that blocks non-essential cookies until the user actively consents. This satisfies GDPR’s opt-in requirement and, by extension, exceeds CCPA’s opt-out requirement for most cookie use cases.
- Add a “Do Not Sell or Share My Personal Information” link. This is a CCPA-specific requirement that GDPR does not address. Place this link in your website footer so it is accessible from every page. When clicked, it should allow the consumer to opt out of any sale or sharing of their personal information with third parties.
- Honor the Global Privacy Control (GPC) signal. Under CCPA/CPRA, businesses are required to treat the GPC browser signal as a valid opt-out request. Configure your consent management tool to detect GPC and automatically suppress the sale or sharing of personal information for those visitors.
- Update your privacy policy. Your privacy policy needs to address both sets of requirements. For GDPR, it must describe your lawful basis for processing, data retention periods, international transfers, and data subject rights. For CCPA, it must disclose the categories of personal information collected, the purposes of collection, the categories of third parties with whom data is shared, and the consumer rights available under California law.
- Use geo-targeting to show the right experience. Rather than showing all users the same consent experience, use geo-targeting to present the appropriate interface based on the visitor’s location. EU visitors should see a GDPR opt-in consent banner. California visitors should see a CCPA-compliant notice with an opt-out option. Visitors from other regions can be shown a simplified notice or no banner at all, depending on applicable local laws.
- Build processes for handling rights requests. Both laws give consumers the right to access, delete, and correct their data. Establish a single intake process — typically a web form or dedicated email address — that can handle requests under either regulation, with internal workflows to verify identity, retrieve data, and respond within the required timeframes (one month for GDPR, 45 days for CCPA).
The key insight for dual compliance is that GDPR and CCPA are complementary rather than conflicting. If you satisfy the stricter GDPR requirements, you are most of the way toward CCPA compliance. The remaining gap is primarily the CCPA-specific elements: the “Do Not Sell” link, GPC signal handling, the privacy notice at collection, and the non-discrimination provisions.
Solution
How FixGDPR covers both CCPA and GDPR
FixGDPR’s consent banner is designed to handle both the opt-in model required by GDPR and the opt-out model required by CCPA, all within a single tool. Rather than installing separate consent solutions for each regulation, you configure one banner that adapts its behavior based on the visitor’s location.
For visitors from EU/EEA countries, FixGDPR displays a full opt-in consent banner that blocks non-essential cookies and tracking scripts until the user provides affirmative consent. The banner supports granular consent categories — necessary, analytics, marketing, and preferences — and records proof of consent for your compliance records. This satisfies GDPR’s requirements under the ePrivacy Directive.
For visitors from California, FixGDPR adjusts the experience to match CCPA/CPRA requirements. The banner can be configured to display a notice-style banner with an opt-out option rather than a consent gate, and FixGDPR automatically detects and honors the Global Privacy Control (GPC) signal. Combined with the “Do Not Sell or Share My Personal Information” link that FixGDPR can add to your site, this covers the core CCPA consent requirements.
Beyond the consent banner, FixGDPR’s compliance scanner audits your site against both regulatory frameworks, identifying issues such as:
- Cookies loading before consent is obtained (GDPR violation)
- Missing or incomplete privacy policy disclosures (GDPR and CCPA)
- Third-party tracking scripts that constitute “sharing” of personal information (CCPA)
- Missing “Do Not Sell or Share” link (CCPA)
- Inadequate data subject rights information (GDPR)
- Non-compliant cookie consent implementation (GDPR)
One tool, both regulations, with geo-targeted consent experiences that match the legal requirements of each visitor’s jurisdiction. That is the FixGDPR approach to privacy compliance.
Get Started
Comply with CCPA and GDPR in minutes
Scan your website for compliance issues, deploy a geo-targeted consent banner, and cover both regulations with a single tool. No credit card required to start.
Related Resources
More privacy compliance guides
A complete guide to cookie consent laws and what your website needs to comply with GDPR, CCPA, and other regulations.
Everything you need to know about implementing cookie consent that meets GDPR and ePrivacy Directive requirements.
A plain-language explanation of the General Data Protection Regulation, who it applies to, and what it requires.
A step-by-step checklist for making your website fully GDPR compliant, from consent banners to privacy policies.