Video Hub / GDPR vs CCPA: What's Different and Which Applies to You

GDPR vs CCPA: What's Different and Which Applies to You

Please accept marketing cookies to view this video

Accept cookies

Frequently asked questions

Yes, and many businesses are. GDPR applies to processing data from people in the EU or EEA regardless of where your company sits, while CCPA and CPRA cover California residents. A site with visitors from both places falls under both frameworks simultaneously, which is the normal situation for anyone selling online.

GDPR requires opt-in and CCPA operates on opt-out. Under GDPR someone has to actively agree before you collect or use their data. Under CCPA you may collect, but people can step out of the sale or sharing of their information and of its use for targeted advertising or profiling.

If CCPA applies to you, yes. It is an explicit requirement rather than a best practice, and it has to be genuinely findable rather than buried. This is one of the clearest structural differences between the two regimes, since GDPR has no direct equivalent.

Only if it adapts to the visitor. The two regimes require opposite defaults, so a single static banner will be wrong for one audience or the other. Consent platforms handle this by detecting jurisdiction and serving the appropriate flow, opt-in for European visitors and opt-out for Californian ones.

GDPR allows up to 20 million or 4% of global annual turnover, whichever is higher. California's framework works per violation rather than as a single ceiling, at up to $7,988 for an intentional violation. Because that figure applies per affected consumer, exposure scales with the number of people involved rather than being capped.

Categories such as health information, religion, sexual orientation and biometric identifiers. Both frameworks apply stricter handling here, with GDPR limiting how it can be processed at all and CCPA restricting its use and disclosure. The general rule is that the more personal the data, the higher the standard applied to it.

No. Privacy laws generally protect people where they live rather than where your business is registered, so a company with no European presence still falls under GDPR if it has European visitors. Assuming geography offers protection is one of the more common and expensive misreadings.

Close, but not automatically. GDPR is generally the stricter standard on consent, so the technical foundation transfers well. What does not transfer are the CCPA-specific obligations, including the opt-out link, the required disclosures and the handling of consumer requests, all of which have to be implemented separately.