Back to the hub

CCPA vs GDPR: what's the difference?

The CCPA is California's consumer privacy law; the GDPR is the EU's data protection regulation. The CCPA applies to for-profit businesses that meet a threshold like $25 million revenue or 100,000 consumers. The GDPR applies to almost anyone processing EU residents' data, with no size threshold and far larger fines.

Applies to: Businesses deciding whether the CCPA, the GDPR, or both apply, typically US companies with some EU users or EU companies with California users.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

People search for CCPA versus GDPR expecting one to be a lighter version of the other. They are not the same law with different labels. They start from different ideas about who is covered and what a business owes, and a company can easily fall under both at once. This page lines up the parts that matter when you are working out which rules apply to you.

Who each law covers

The CCPA, as amended by the CPRA, applies to for-profit businesses that handle California residents' personal information and meet at least one threshold: annual gross revenue over $25 million, buying, selling, or sharing the personal information of 100,000 or more California consumers or households in a year, or deriving 50 percent or more of revenue from selling or sharing that information, under Cal. Civ. Code Section 1798.140(d). If you sit under every threshold, the CCPA does not reach you. The GDPR has no size threshold at all. Under Article 3 it applies to an organization established in the EU, and to one outside the EU that offers goods or services to people in the EU or monitors their behavior. A two-person startup can be fully in scope.

What each law requires

The CCPA is built around transparency and opt-out. Covered businesses post a notice at collection and a privacy policy, offer a Do Not Sell or Share My Personal Information link, honor opt-out preference signals like Global Privacy Control, and answer verifiable consumer requests within 45 days. The GDPR is built around a lawful basis. Before you process personal data you must identify one of six grounds, such as consent, contract, or legitimate interests, and you owe a wider set of duties: records of processing, data-protection-by-design, breach notification within 72 hours, and in some cases a representative or a data protection officer. Both give people rights to access and delete, but the GDPR's set is broader.

What a violation costs

This is where the gap is widest. CCPA fines are up to $2,500 per violation, or $7,500 for an intentional violation or one involving a consumer under 16, and consumers can separately sue for $100 to $750 per person after certain data breaches. Detail sits on the CCPA fines and penalties page. GDPR fines are far larger and turnover-based: up to 20 million euros or 4% of total worldwide annual turnover, whichever is higher, for the most serious breaches, with a lower tier of 10 million euros or 2%. For a large group the percentage, not the euro figure, is the real exposure.

When both apply

The two run in parallel. A California-based SaaS company with users in Germany can owe CCPA duties for its California consumers and GDPR duties for its EU users at the same time, and neither analysis cancels the other. The practical move is not to pick one. Map where your users are, then meet the stricter requirement on each topic, since a GDPR-grade consent and records program will usually carry most of the CCPA load, but not the reverse. See does the CCPA apply to your business and does the GDPR apply to your SaaS for each test in full.

Next step

If you have users on both sides of the Atlantic and are not sure which law reaches you, the free 2-minute Obligation Scan checks the CCPA thresholds and the GDPR territorial test against your business and lists the duties that follow under each, so you can build one plan instead of guessing. The US state privacy laws hub shows how California fits with the other states.

Compliance checklist

  • Check CCPA scope: a for-profit business handling California residents' data that meets one threshold ($25 million revenue, 100,000 consumers, or 50% of revenue from selling data).
  • Check GDPR scope: offering goods or services to, or monitoring the behavior of, people in the EU, with no size threshold.
  • If only the CCPA applies, focus on notice at collection, a Do Not Sell or Share link, and honoring opt-out signals.
  • If the GDPR applies, identify a lawful basis for each activity before processing and support data-subject rights.
  • If both apply, build one program that meets the stricter rule on each topic rather than running two separate ones.

Sources

Last verified: 2026-07-30

Informational, not legal advice.