GDPR vs CCPA: Key Differences Explained (2026)

By Recording Law Editorial TeamReviewed May 20, 202619 min read
GDPR vs CCPA: Key Differences Explained (2026)

Frequently Asked Questions

Does the CCPA/CPRA apply to businesses outside California?

Yes. The CCPA/CPRA applies to any for-profit business that collects personal information from California residents and meets at least one of the three thresholds (revenue over $25 million, data on 100,000+ consumers per year, or 50%+ of revenue from selling or sharing data) regardless of where the business is located. A company with no physical presence in California but with California customers and a qualifying website can be covered.

Can a business be subject to both GDPR and CCPA/CPRA?

Yes. Any business that processes personal data of EU/EEA individuals and collects personal information from California residents meeting CCPA thresholds must comply with both laws. Many multinational companies build unified privacy programs anchored in GDPR requirements, then layer CCPA/CPRA-specific obligations on top.

Which law has stricter penalties?

The GDPR has far higher maximum penalties: EUR 20 million or 4% of global annual revenue, whichever is higher. CCPA/CPRA penalties cap at $7,500 per intentional violation. However, class-action litigation under the CCPA's private right of action can produce substantial aggregate damages, and the CPPA's active enforcement has resulted in seven-figure settlements.

Does GDPR require opt-in consent for all data processing?

No. Consent is one of six lawful bases under GDPR Article 6. Businesses can also rely on contract performance, legal obligation, vital interests, public task, or legitimate interests. However, where consent is the chosen basis it must be freely given, specific, informed, and unambiguous. For special-category data, explicit consent is required unless another Article 9 condition applies.

What is the CPPA's ADMT regulation and when does it take effect?

The CPPA finalized automated decision-making technology (ADMT) regulations on September 22, 2025, with a general effective date of January 1, 2026. Businesses using ADMT to make significant decisions affecting consumers (such as employment eligibility, credit approvals, housing, and healthcare decisions) must comply with consumer opt-out and access rights beginning January 1, 2027. Businesses using ADMT for advertising targeting have a separate compliance timeline.

What is the biggest practical difference between GDPR and CCPA/CPRA compliance?

The consent model. GDPR requires a documented lawful basis before data processing begins, which often means obtaining opt-in consent upfront. The CCPA/CPRA allows data collection by default but requires businesses to honor opt-out requests, post a 'Do Not Sell or Share My Personal Information' link, and (under the 2025 regulations) provide ADMT opt-out and access notices. This fundamental difference shapes website design, cookie banners, privacy notices, and internal data governance.

Does GDPR compliance satisfy CCPA/CPRA requirements?

Mostly, but not entirely. A GDPR-compliant program satisfies most CCPA/CPRA baseline requirements because GDPR is generally the stricter framework. However, several CCPA/CPRA-specific obligations have no GDPR equivalent: the 'Do Not Sell or Share' link, financial incentive disclosures, the ADMT opt-out right, risk assessment and cybersecurity audit requirements under the 2025 regulations, and CCPA-specific service provider contract language.

Updates

Expanded to cover CPRA amendments in full; added CPPA 2025 ADMT, cybersecurity audit, and risk assessment regulations (effective Jan 1, 2026 / Jan 1, 2027); updated enforcement section with Honda, Tractor Supply, Todd Snyder settlements; added US state privacy law landscape context; refreshed FAQ and SourcesList.

Sources and References

  1. GDPR - Regulation (EU) 2016/679 Full Text (EUR-Lex)(eur-lex.europa.eu).gov
  2. GDPR Article 3 - Territorial Scope(gdpr-info.eu)
  3. GDPR Article 6 - Lawfulness of Processing(gdpr-info.eu)
  4. GDPR Article 9 - Special Categories of Personal Data(gdpr-info.eu)
  5. GDPR Article 17 - Right to Erasure(gdpr-info.eu)
  6. GDPR Article 22 - Automated Individual Decision-Making(gdpr-info.eu)
  7. GDPR Article 37 - Designation of the Data Protection Officer(gdpr-info.eu)
  8. GDPR Article 83 - General Conditions for Imposing Fines(gdpr-info.eu)
  9. European Commission - Data Protection in the EU(commission.europa.eu).gov
  10. European Data Protection Board - Guidelines(edpb.europa.eu).gov
  11. California Consumer Privacy Act - Full Text (Cal. Civ. Code 1798.100 et seq.)(leginfo.legislature.ca.gov).gov
  12. Cal. Civ. Code 1798.150 - Private Right of Action(leginfo.legislature.ca.gov).gov
  13. California Attorney General - CCPA/CPRA Information(oag.ca.gov).gov
  14. CPPA - CCPA Updates, Cybersecurity Audits, Risk Assessments, ADMT Regulations(cppa.ca.gov).gov
  15. CPPA Announcement: California Finalizes Regulations to Strengthen Consumers Privacy (Sept. 22, 2025)(cppa.ca.gov).gov
  16. CPPA: Honda Settles Over Privacy Violations - $632,500 Fine(cppa.ca.gov).gov
  17. CPPA Orders Todd Snyder to Pay $345,178 Fine, Overhaul Privacy Practices(cppa.ca.gov).gov
Share: