---------------------------
Title: CCPA vs. GDPR: 10 Key Differences and How to Comply With Both
URL: https://www.cookiebot.com/us/ccpa-vs-gdpr/
---------------------------

# CCPA vs. GDPR: 10 Key Differences and How to Comply With Both

If your website reaches visitors in both California and the EU, the CCPA and GDPR set different rules for consent, data rights, and penalties, and meeting one doesn't mean you meet the other. This guide breaks down the ten differences that matter most for compliance.

## At a Glance

- The GDPR requires opt-in consent before collecting personal data; the CCPA/CPRA lets businesses collect first and requires an opt-out for sales and sharing instead.
- The GDPR applies to any organization processing EU residents' data, regardless of size; the CCPA/CPRA only applies to for-profit businesses meeting a revenue, volume, or revenue-share threshold.
- The GDPR's maximum fine is EUR 20 million or 4% of global turnover; the CCPA/CPRA's is USD 7,988 per intentional violation, with separate statutory damages for data breaches.
- Both laws give people rights to know, access, and delete their data, but GDPR's rights are broader, including data portability and objection to automated decision-making.
- A single consent management platform can typically handle both frameworks by adjusting the banner and disclosures shown by visitor location.

The California Consumer Privacy Act (CCPA) and the General Data Protection Regulation (GDPR) were created to give people greater power over their personal information. Both regulate how companies collect and use individuals' personal data.

While both laws focus on privacy rights and putting control over one's data back into consumers' hands, there are a few crucial differences between the two regulations beyond just their jurisdiction. The CCPA is also no longer the only U.S. option to know: nearly twenty states now have their own comprehensive privacy laws, and the same core distinctions covered here apply to most of them (see our [full regulations overview](https://www.cookiebot.com/us/regulations-and-frameworks/) for the complete picture).

Here is a comparison of the key differences between CCPA vs GDPR and an overview of how organizations can meet both.

## 10 Key Differences Between CCPA and GDPR at a Glance

AspectCCPA / CPRAGDPRJurisdictionFor-profit businesses meeting a CA-specific thresholdAny organization processing EU residents' data, worldwideConsent ModelOpt-out — collection allowed by default, with a right to opt out of sale/sharing (prior consent required for sensitive data and minors' data)Opt-in: consent required before collectionApplicability ThresholdsAt least one of:

- $26,625,000+ revenue
- 100,000+ CA residents' data,
- 50%+ revenue from data salesNoneLegal Basis for Data ProcessingNo prior legal basis required in most casesSix defined legal bases (one required):
- Consent
- Contract
- Legal Obligation
- Vital Interests
- Public Task
- Legitimate InterestsSensitive Data"Sensitive personal information" — right to limit use and disclosure"Special category data" — explicit consent typically requiredData Subject Rights- Right to know
- Right to delete
- Right to correct
- Right to opt out (sale/sharing)
- Right to limit use of sensitive personal information
- Right to non-discrimination
- Right to data portability- Right to be informed
- Right of access
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right to data portability
- Right to object
- Rights related to automated decision-makingBreach Notification- Without unreasonable delay
- CA AG notified if 500+ residents affectedWithin 72 hours to the supervisory authorityEnforcement BodyCalifornia Attorney General and CalPrivacyNational data protection authorities in each EU Member StateMaximum Penalty$7,988 per intentional violation, plus private right of action€20 million or 4% of global turnover, whichever is higherCure PeriodEnded under CPRA (previously 30 days)None

## GDPR Explained: What EU Data Protection Requires

The [General Data Protection Regulation (GDPR)](https://www.cookiebot.com/en/gdpr/) is a European Union-wide regulation that controls how companies and other organizations handle personal data. It's designed to give EU residents, regardless of their citizenship, more control over their personal data while simplifying rules for global businesses. It applies to companies that process the data of EU residents, even if the companies are not located in the EU, also known as extraterritoriality. The law went into effect on May 25, 2018.

Some key aspects of the GDPR include:

- Organizations must only gather personal data for a particular, explicitly stated reason (purpose), which they must record.
- In most cases, organizations must get clear, informed, voluntary consent from individuals for the stated purpose before collecting or using their data. If the purpose for collecting and processing data changes, organizations must get new consent from individuals.
- Data should be deleted, returned, or anonymized when it's no longer needed.
- Individuals have rights regarding their data, including access to it, having it corrected or deleted, and receiving a copy of it.
- Companies require a documented legal reason to handle personal data (legal basis) and should openly share with individuals what that reason is and how they handle collected data.

## CCPA Explained: California's Consumer Privacy Law

[The California Consumer Privacy Act (CCPA)](https://www.cookiebot.com/en/what-is-ccpa/) is a state-level data privacy law that regulates how organizations handle the personal information of California residents.

The CCPA was passed in 2018 and went into effect on January 1, 2020. It was the first of the modern and comprehensive data privacy laws passed in the United States. California has since expanded and amended the CCPA with the [California Privacy Rights Act (CPRA)](https://www.cookiebot.com/en/cpra/), fully in effect since January 1, 2023, and several other states have followed with laws of their own.

Some key aspects of the CCPA include:

- Giving California residents the right to know what personal information, including [data collected through cookies](https://www.cookiebot.com/en/ccpa-cookies/), a business has collected about them and how it is being used and shared
- Enabling consumers to opt out of the sale or sharing of their personal information with third parties
- Requiring companies to obtain consumers' consent to collect and use personal data if it is categorized as sensitive or belongs to a child
- Requiring businesses to delete a consumer's personal information upon request

## Who Needs to Comply With GDPR vs CCPA Privacy Regulations?

Both the CCPA and the GDPR can have global (extraterritorial) reach. The CCPA applies to businesses collecting data from California residents, regardless of the business's location, while the GDPR applies to any entity worldwide offering goods or services to and collecting and using the personal data of EU residents.

The GDPR protects any individual in the EU whenever their data is processed by a business that either operates within the EU or specifically targets people there. This reaches beyond direct collection and processing of personal data to include monitoring behavior, and it applies regardless of where the business itself is based. An EU-established controller is covered even when the individual whose data it processes is outside the EU, while a non-EU business is caught the moment it offers goods or services to, or monitors, people who are in the EU.

The CCPA, by contrast, specifically safeguards California residents who are not just temporarily in the state, so it does not apply to tourists, but there have been questions as to whether it applies to groups like college students who may not reside there year round.

### Who Has to Comply With the GDPR?

All organizations and their properties, including websites and mobile applications, that process data of people in the European Union must comply with the GDPR. The law doesn't have compliance thresholds, as the CCPA does.

This includes nonprofit organizations, community groups, e-commerce companies, and more. Compliance is also required if companies use third-party services (e.g., for advertising) to process personal data, though the initial company, the data controller, is ultimately responsible for privacy compliance by third-party processors.

### Who Has to Comply With the CCPA?

The CCPA defines the term "business" broadly. It applies to any for-profit organization, regardless of its location, that collects personal information from California consumers and meets at least one of the following thresholds:

- Has annual gross revenues above $26,625,000 (adjusted every two years for inflation; next adjustment due 2027)
- Buys, receives, sells, or shares the personal information of 100,000 or more California residents or households
- Earns 50 percent or more of its annual revenue from selling or sharing California residents' personal information

IP addresses count as personal information, so this can apply to any website with enough California visitors even without a direct revenue tie to their data.

### How Do GDPR and CCPA Differ in Their Consent Requirements?

Both CCPA and GDPR focus on obtaining [cookie consent](https://www.cookiebot.com/en/cookie-consent/) from visitors. But each law does this differently.

The GDPR emphasizes obtaining consent before the collection of any data, whereas the CCPA focuses on enabling consumers to opt out later, and in most cases does not require prior consent to collect and process individuals' personal data.

Additionally, the GDPR has wider coverage and stricter data protection rules than the CCPA.

#### Consent Requirements Under the GDPR

Under the GDPR, businesses must obtain clear, unambiguous consent from individuals before collecting and processing their personal data, an opt-in consent model. The consent must be an active affirmative action and cannot be assumed by an unrelated action or lack of one, like scrolling past a consent banner or closing it without making a selection. Individuals also have the right to change or withdraw consent at any time.

This requirement extends to [tracking cookies](https://www.cookiebot.com/en/tracking-cookies/), which are considered a form of personal data for processing under the GDPR.

#### Consent Requirements Under the CCPA

The CCPA does not require opt-in consent to collect personal data, except where the data is categorized as sensitive or belongs to a child.

Instead, it gives consumers the right to opt out of the sale or sharing of their personal information with third parties. Businesses can collect and use most personal data without consent but must provide a "[Do Not Sell or Share My Personal Information](https://usercentrics.com/guides/website-disclaimers/do-not-sell-my-personal-information/)" link on their website so consumers can exercise this opt-out right.

California businesses are also expected to recognize [Global Privacy Control (GPC)](https://www.cookiebot.com/en/global-privacy-control/), a browser-based signal that gives consumers a way to signal their opt-out preference automatically, without visiting the link on every site individually. This is an area where a consent management platform can help by detecting and honoring the signal without requiring manual configuration on your part. [Cookiebot™ CMP](https://www.cookiebot.com/us/cookie-consent-solution/) does this. An increasing number of states require honoring GPC or other universal opt-out mechanisms (UOOM).

### CIPA and How It Complicates Consent Under California Law

A growing wave of litigation under statutes like the [California Invasion of Privacy Act (CIPA)](https://www.cookiebot.com/us/cipa-california-invasion-of-privacy-act/) is complicating the CCPA's opt-out model in practice. Some courts have been treating trackers that fire before a visitor responds to a consent banner as unauthorized interception, pushing many companies toward the pre-consent blocking GDPR requires even though no California statute formally mandates it. Legislation to partially address this remains in progress, but nothing has been settled yet.

## What Data Is Protected Under the GDPR vs CCPA?

Both the CCPA and GDPR aim to protect people's personal information that could make them identifiable, either via individual data points or in aggregate. So their definitions of personal data are very similar apart from a few small differences.

### Definition of Personal Data Under the GDPR

Under the GDPR, personal data is defined very broadly as "any information relating to an identified or identifiable natural person." This includes direct identifiers like names and ID numbers, as well as indirect identifiers that can be used to recognize an individual, location data, or IP address. It also includes factors specific to a person's physical, psychological, or genetic identity, healthcare or financial information, political or religious beliefs, and other factors.

The GDPR's broad interpretation means even seemingly harmless information can be classified as "personal data" if it can be linked to an individual or used to identify them. This includes items like website cookies, media recordings, biometrics, and GPS data.

### Definition of Personal Data Under the CCPA

The CCPA has a similarly broad definition of [personal information](https://www.cookiebot.com/en/ccpa-personal-information-ccpa-compliance-with-cookiebot-cmp/), encompassing data that can directly or indirectly identify or describe a consumer or household.

This includes identifiers like names, email addresses, and Social Security numbers, as well as browsing history, purchasing data, or location information. Also similarly to the GDPR, the CCPA includes indirect identifying factors specific to a person's physical, physiological, or genetic identity.

The CPRA added a further category of sensitive personal information, which covers things like precise geolocation, government ID numbers, and health or biometric data. Unlike standard personal information, California residents have a specific right to limit how sensitive personal information is used and disclosed, closer in spirit to GDPR's special category data protections than anything in the original 2018 CCPA text.

The CCPA also has a few specific exemptions for certain types of personal data that are covered under other U.S. laws. For example, medical information is protected by the [Health Insurance Portability and Accountability Act (HIPAA)](https://www.cookiebot.com/us/hipaa-compliance-healthcare-websites/), and financial data is regulated by the [Gramm-Leach-Bliley Act (GLBA)](https://www.cookiebot.com/us/gramm-leach-bliley-act-glba/).

### When Can Companies Use Personal Data?

When comparing the GDPR to the CCPA, the laws have different approaches to regulating how companies use people's personal information. The GDPR outlines six legal bases, at least one of which companies must rely on. The CCPA is more flexible and focuses on giving consumers more rights and transparency, with fewer upfront requirements for companies.

#### Legal Bases for Data Processing Under the GDPR

Under the GDPR, companies can only process personal data if they have a legitimate reason to do so. The GDPR lists six legal bases from which companies can choose to enable compliant use of personal data. Companies must be able to justify which of these legal reasons they rely on for each personal data use. Where consent is the legal basis, organizations also need to be able to prove consent was obtained, and that it was freely given, specific, informed, and unambiguous.

## GDPR Legal Bases

- **Consent** — An individual must provide voluntary and informed consent prior to the collection and processing of their personal data (e.g., via a consent banner).
- **Contract** — The data processing is necessary to fulfill a contract (e.g., delivering a product or service) with the person, or to take steps before entering a contract.
- **Legal obligation** — A company needs to use the data to comply with a law or regulation.
- **Vital interests** — The processing is necessary to protect someone's life, safety, or well-being.
- **Public task** — An organization needs the data to perform a task with a clear legal basis that is in the public interest, e.g., by government or law enforcement.
- **Legitimate interest** — A company (or third party) has a legitimate business interest that requires processing personal data, e.g., an insurance company processing data to prevent fraud that may affect its customers.

#### Legal Exceptions for Processing Under the CCPA

The CCPA doesn't clearly define when or how companies can use personal data, and in most cases does not require a prior legal basis to collect it, as long as an opt-out is available. However, the law does include some exceptions that override the CCPA, including the following. The CCPA also allows companies to use personal information for "business purposes," which includes auditing, security, debugging, and short-term transactions.

## CCPA Legal Exceptions

- **Obeying federal, state, or local laws**
- **Cooperating with law enforcement or regulators**
- **Performing internal research for product development**
- **Conducting public interest research**

Automated decision-making — profiling, scoring, or algorithmic decisions based on personal data — is a newer and still-developing area under the CCPA/CPRA. CalPrivacy has introduced regulations covering automated decision-making technology and cybersecurity audits, but rulemaking in this area is ongoing, so businesses relying heavily on automated profiling of California consumers should check current guidance directly rather than treating it as settled.

## How Do Regulatory Requirements Impact a Company's Marketing Efforts?

The GDPR and CCPA can both have a significant impact on how companies conduct their digital marketing activities.

### GDPR Compliance and Marketing

The GDPR significantly impacts a marketer's ability to [track website visitors](https://www.cookiebot.com/en/website-tracking/), collect data about their browsing patterns and preferences, and tailor their marketing activities. Additionally, it grants individuals the "right to be forgotten," allowing them to request the deletion of their personal data. This makes it challenging for marketers to maintain complete visitor profiles and tailor campaigns accordingly.

To adapt, marketers need to take a more consent-based and transparent approach. This means obtaining clear consent for cookies and tracking, providing detailed privacy and [cookie policies](https://www.cookiebot.com/en/cookie-policy/), giving website visitors clear information about data processing and revocable consent options, and respecting data subject rights.

For email marketing, marketers can't rely on implied consent. Individuals must explicitly opt in to sign up for a company's email newsletter or allow cookie use. Marketers can't pre-check boxes or present a consent banner with only an "Accept" button. If a company has an email list for one purpose, it can't be used for another purpose without getting new, explicit consent for that new purpose.

### CCPA Compliance and Marketing

Similar to the GDPR, the CCPA creates more requirements for marketers to personalize marketing activities, because much of the data used for targeting and personalization is now subject to compliance rules. Under the CCPA and CPRA, consumers have greater rights to opt out of the use of their data for targeting and profiling.

The CCPA gives consumers the right to know about processing, access their data, have it deleted, and opt out of data sales or sharing with third parties. This can limit marketers' access to [third-party data sources](https://www.cookiebot.com/en/google-third-party-cookies/) previously used for audience expansion.

To stay compliant with the CCPA and maintain consumer trust, marketers should focus on first-party data strategies and consider collecting zero-party data directly from consumers, ideally combined with preference management, to build transparent relationships.

To get there, assess data usage through data mapping and inventory exercises, and keep your [privacy policy](https://www.cookiebot.com/en/how-to-write-a-privacy-policy/) and related disclosures updated to reflect current data practices.

For email marketing, the CCPA works differently from the GDPR. Automatically enrolling a visitor onto an email list is ordinary first-party collection and doesn't require prior opt-in consent under the CCPA, unlike the GDPR's consent-before-collection standard. Consent obligations arise only if that data is then sold or shared, for example, disclosed to a third party for cross-context behavioural advertising. At that point the consumer must be given the means to opt out.

If children are on the list, advance consent from a parent or guardian is still required before their personal information can be sold, regardless of the general opt-out framework. Companies must provide this opt-out option via a "Do Not Sell or Share My Personal Information" link, and a company can still process a consumer's personal data for other purposes after such an opt-out request.

Do you know what your website is collecting?
Scan your site for free and find all the active cookies and trackers. Get your custom report and privacy compliance risk level in minutes.

[Scart Scan](https://www.cookiebot.com/us/cookie-checker/)

## How Do Data Breach Notification Requirements Differ Between the CCPA and GDPR?

If something goes wrong, the two laws put very different clocks on how fast you need to act.

Under the GDPR, you must notify your supervisory authority within 72 hours of becoming aware of a [data breach](https://www.cookiebot.com/en/personal-data-breach/), unless it's unlikely to result in a risk to individuals' rights and freedoms. Miss the window, and you're expected to explain the delay. Breaches that pose a high risk also require direct notification to the individuals affected, covering what happened, the likely consequences, and what you're doing about it. Every breach needs to be documented, even ones that don't require notification, since regulators can request the records later.

The CCPA didn't originally set its own breach notification rules beyond California's general breach law, and the CPRA layered fines on top for breaches involving unencrypted personal information. In practice, that means notifying affected California residents without unreasonable delay, and, if more than 500 residents are affected, notifying the California Attorney General as well. There's no fixed hour count like GDPR's 72 hours, but "unreasonable delay" is still a standard regulators and courts will hold you to.

For a business handling data on both sides of the Atlantic, the practical takeaway is to build your incident response process around the stricter GDPR clock. Meeting a 72-hour internal target will comfortably clear the CCPA's looser bar as well.

## CCPA and GDPR Privacy Compliance

To meet relevant privacy laws, there are different steps you need to take depending on which regulation — or both — applies to your business.

### Supporting **GDPR Compliance**

GDPR compliance rests on four obligations: transparency, consent, respecting individual rights, and accountability.

## GDPR Compliance Requirements

- **1. Transparency** — Companies must maintain a clear, transparent privacy policy that openly states how data is collected and used. This policy should be:

Easily accessible to individuals (e.g., linked from the website)
Inclusive of a cookie policy covering that specific form of data collection and processing
- **2. Consent** — Before processing any personal data, companies must obtain consent from the individual. If that individual later withdraws consent, the company must stop collecting and processing their data going forward.
- **3. Individual rights** — Companies must respect several rights on request:

Access: Granting individuals access to their personal data
Erasure: Deleting data once it's no longer needed for its original purpose
Purpose limitation: Obtaining fresh consent before using data for any new purpose beyond the one originally disclosed
- **4. Accountability** — Companies must maintain thorough documentation of their data practices, including retention schedules that reflect the GDPR's storage limitation principle, keeping personal data only as long as necessary and disposing of or anonymizing it once that purpose is fulfilled. They must also undertake regular audits to support ongoing compliance.

#### **Where a CMP helps**

A [consent management platform (CMP)](https://www.cookiebot.com/en/cookie-consent-solution/) helps companies centralize the process of obtaining, signaling, and storing consent, and managing individual rights as required by the GDPR. A CMP also maintains consent records, which can support auditing and [data subject access requests (DSARs)](https://usercentrics.com/knowledge-hub/data-subject-access-requests/).

### **CCPA Compliance Requirements**

CCPA compliance rests on two obligations: informing consumers, and giving them control.

## CCPA/CPRA Compliance Requirements

- **1. Disclosure at the Point of Collection** — Before or at the point of collection, companies must tell consumers:

The categories of personal information collected
The purposes for which it will be used
Whether it will be sold or shared, and with which categories of third parties
How long each category of data will be retained (or the criteria used to determine that)

Meeting this obligation requires knowing every tracker and cookie actually running on your site. You can't disclose a third-party category you haven't identified.
- **2. Consumer Rights and Controls** — Companies must also enable consumers to:

Know what personal information has been collected about them
Access that information
Request its deletion
Limit or opt out of its sale or sharing, via a "Do Not Sell or Share My Personal Information" link

#### **Data Minimization**

As with the GDPR, the CCPA (via the CPRA amendments) restricts how long data can be kept: businesses must avoid retaining personal information longer than necessary for the disclosed purpose, and must state that retention period to consumers up front.

#### **Where a CMP helps**

A CMP supports CCPA compliance by identifying all tracking technologies in use, centralising the opt-out mechanism for data sales and sharing, and managing consumer rights requests end-to-end.

## **What Are the GPDR and CCPA Privacy Policy Requirements?**

The GDPR and CCPA both have specific requirements for the privacy policies companies must have in place on their website.

### **GDPR Privacy Policy Requirements**

Under the GDPR, companies must provide a clear, up-to-date, and easily accessible privacy policy that discloses:

- What personal data is being collected and processed
- The purposes for which the personal data is being used
- How long the personal data will be stored
- Who the personal data may be shared with
- The rights individuals have over their personal data and how to exercise them
- The legal basis for processing the personal data, such as consent or legitimate interest
- Whether the personal data will be transferred outside the EU and how it will be protected
- Contact information for the organization (e.g., data protection officer) and for submitting rights requests

The privacy policy must be easily accessible and written in plain, easy-to-understand language, with a cookie policy included where cookies are used. A [Privacy Policy Generator](https://www.cookiebot.com/en/privacy-policy-generator-gdpr/) can help you get started or update yours so it's customized for your business operations and data handling, plus the automated updates support ongoing compliance as your business, technologies in use, and regulatory requirements evolve.

### **CCPA Privacy Policy Requirements**

The CCPA has similar privacy policy requirements, though the specifics differ somewhat from the GDPR:

- Disclosure of the categories of personal information they collect, how they use it, and whether they sell or share that information
- A clear, up-to-date, and accessible privacy policy (and cookie policy) explaining data processing, consumers' rights, and how to exercise them
- Data handling and consent requirements for sensitive data or that of children
- Clear, understandable language, with no legal jargon
- An update to the privacy policy at least once every 12 months

The CCPA does not require companies to obtain consent before collecting personal information in most cases. The focus is more on clear notice and giving consumers the ability to opt out of data sales or sharing, alongside accessible options for exercising their other privacy rights.

## **How Are Privacy Laws Enforced?**

Passing a privacy law is one thing; giving it teeth is another. The GDPR and CCPA take markedly different approaches to enforcement, with different regulators, different investigative powers, and different consequences for the companies that fall short.

### **GDPR Enforcement**

The GDPR is enforced by national data protection authorities (DPAs) in each European Union member state, coordinated by the European Data Protection Board (EDPB) to help ensure consistent application across the EU. These DPAs have significant powers, including the ability to conduct audits, issue warnings, and impose fines.

Individuals who believe their rights under the GDPR have been violated can file complaints with their national DPA, which is then required to investigate and take appropriate action.

### **CCPA Enforcement**

The CCPA was originally enforced solely by the California Attorney General's Office, with no centralized enforcement body at the national level like the GDPR has. Since CPRA took effect, education, investigation, and enforcement now sit with the California Privacy Protection Agency, known publicly as CalPrivacy.

The CCPA's original 30-day cure period, which gave companies a chance to fix violations before enforcement action, ended under the CPRA, though authorities can still provide one at their discretion.

## **What Are the Fines and Penalties for GDPR and CCPA Non-Compliance?**

Both the GDPR and CCPA specify fines for companies that don't meet their requirements, tiered by severity. The GDPR carries much heavier potential penalties than the CCPA.

### **GDPR Penalties**

The GDPR has some of the highest fines of any data privacy law in the world. Companies found in serious or repeated violation of the GDPR can be fined up to four percent of their global annual revenue or EUR 20 million, whichever is greater.

Lower-tier fines can be up to two percent of global annual revenue or EUR 10 million. The GDPR also enables a private right of action, letting individuals sue companies for damages in the event of a data breach or other relevant violation.

### **CCPA Penalties**

If a business does not comply with the CCPA, the California Attorney General's Office and CalPrivacy can pursue civil penalties of up to USD 2,663 per unintentional violation, or up to USD 7,988 per intentional violation or one involving a minor under 16. Those figures are adjusted for inflation every two years, with the next adjustment due in 2027.

The CCPA also gives consumers a private right of action, for example if their personal information is exposed in a data breach due to a company's lack of reasonable security measures. Consumers can seek statutory damages between USD 107 and USD 799 per incident. Those figures are also periodically adjusted for inflation.

### Building a Privacy Compliance Strategy that Evolves with Your Business and the Law

The GDPR and CCPA both focus on protecting data and giving consumers control, but they take meaningfully different routes to get there. By now, both laws are well enough established that companies should have solid privacy compliance strategies and operations in place. If not, it's never too late to close the gap, and doing so pays off in consumer trust and brand reputation as much as in regulatory standing.

As more U.S. states pass their own privacy laws, and the litigation landscape makes issues more complicated, the practical move is to build data handling practices, compliance policies, and consent infrastructure that scale across jurisdictions rather than treating each law as a one-off project. It's also a good idea to consult a data privacy expert and qualified legal counsel for your specific situation, especially over time as your business grows and the laws change.

Stay ahead of privacy complexity
Whichever laws apply to your business, staying on top of it shouldn't mean starting from scratch every time a new one lands.
Try Cookiebot™ free for 14 days and see how it handles GDPR and CCPA requirements in one place.

[Start Free Trial](https://admin.cookiebot.com/signup?lang=en)

## Preamble

If your website reaches visitors in both California and the EU, the CCPA and GDPR set different rules for consent, data rights, and penalties, and meeting one doesn't mean you meet the other. This guide breaks down the ten differences that matter most for compliance.

## Summary

If your website reaches visitors in both California and the EU, the CCPA and GDPR set different rules for consent, data rights, and penalties, and meeting one doesn't mean you meet the other. This guide breaks down the ten differences that matter most for compliance.

---

## Footer

### Products
- [Cookiebot™ Consent Solution](https://www.cookiebot.com/us/cookie-consent-solution/)
- [Audience Survey](https://www.cookiebot.com/us/audience-survey-add-on/)
- [Usercentrics for Wix](https://www.cookiebot.com/us/cookiebot-for-wix-by-usercentrics-app/)
- [Usercentrics Cookiebot WordPress Plugin](https://www.cookiebot.com/us/new-wp-cookie-plugin/)
- [Cookiebot CMP for Shopify](https://www.cookiebot.com/us/cookiebot-cmp-for-shopify/)
- [Cookie checker](https://www.cookiebot.com/us/cookie-checker/)
- [Usercentrics products](https://usercentrics.com/us/)
- [Pricing](https://www.cookiebot.com/us/pricing/)

### Regulations
- [DMA (EU)](https://www.cookiebot.com/us/digital-markets-act-dma/)
- [GDPR (EU)](https://www.cookiebot.com/us/gdpr/)
- [CCPA (California)](https://www.cookiebot.com/us/what-is-ccpa/)
- [VCDPA (Virginia)](https://www.cookiebot.com/us/virginia-vcdpa/)
- [LGPD (Brazil)](https://www.cookiebot.com/us/lgpd/)
- [TCF v2.3 (IAB)](https://www.cookiebot.com/us/tcf/)
- [Google Consent Mode (EU)](https://www.cookiebot.com/us/cookiebot-cmp-google-consent-mode/)
- [Microsoft UET Consent Mode](https://www.cookiebot.com/us/microsoft-consent-mode-cmp/)
- [View all regulations](/us/regulations-and-frameworks/#united-states-state&united-states-federal)

### Partners
- [Become an affiliate](https://www.cookiebot.com/us/affiliates/)
- [Affiliate Login](https://app.impact.com/login.user)
- [Become a partner](https://www.cookiebot.com/us/resellers/)
- [Find a partner](https://www.cookiebot.com/us/cookiebot-reseller/)

### Resources
- [Blog](https://www.cookiebot.com/us/blog/)
- [Customer stories](https://www.cookiebot.com/us/customer-stories/)
- [Customer directory](https://www.cookiebot.com/us/cookiebot-customer-directory/)
- [Digital Markets Act Hub](https://www.cookiebot.com/us/digital-markets-act-dma-resources/)
- [Google Consent Mode Hub](https://www.cookiebot.com/us/google-consent-mode-resources/)
- [Google Consent Mode V2 certification](https://courses.usercentrics.com/course/google-consent-mode-v2)
- [Google Consent Audit Fixes](https://www.cookiebot.com/us/google-consent-audit-fixes/)
- [Cookie Banner Cost Calculator](https://www.cookiebot.com/us/cookie-banner-pricing-calculator/)

### Company
- [About us](https://www.cookiebot.com/us/about/)
- [Careers](https://usercentrics.com/career/)
- [Support](https://support.cookiebot.com/hc/en-us/)
- [Developer documentation](https://www.cookiebot.com/us/developer/)

©2026 Cookiebot. All rights reserved. Cookiebot is a trademark of     Usercentrics     A/S. Usercentrics A/S is registered in Denmark. Company reg. no.: 34624607. Do Not Sell or Share My Personal InformationData Subject RequestsManage Your Preferences

[Privacy Policy](https://www.cookiebot.com/us/privacy-policy/) · [Terms of Service](/en/terms-of-service/) · [Cookie Declaration](https://www.cookiebot.com/us/cookie-declaration/) · [Data Processing Agreement](/us/data-processing-agreement/) · [Legal Notice](https://www.cookiebot.com/us/legal-notice/) · [Accessibility Statement](/en/accessibility-statement-wcag-compliance/)