The GDPR is built on permission: you need a lawful basis before you process personal data at all. California is built on disclosure and refusal: you may process, but you must tell people and let them opt out. That structural difference drives nearly every other distinction between them.
Who they apply to
- GDPR - any organisation processing personal data of people in the EU or UK, regardless of establishment. No revenue or size threshold; a small company with EU customers is in scope.
- CCPA/CPRA - for-profit businesses doing business in California that meet defined thresholds relating to revenue, the volume of consumers' personal information handled, or deriving substantial revenue from selling or sharing it. Below the thresholds, you are generally out of scope.
That threshold difference matters strategically: many startups face the GDPR long before California applies to them.
The core structural difference
- GDPR requires a lawful basis for every processing activity - consent, contract, legal obligation, vital interests, public task or legitimate interests - documented in advance.
- CCPA/CPRA does not require a lawful basis. It requires notice at collection, and it gives consumers the right to opt out of the sale or sharing of their personal information, and to limit use of sensitive personal information.
"Sale" and "sharing" are defined broadly in California - broadly enough that common advertising and analytics arrangements can fall within them even where no money changes hands. That surprises organisations who assume they do not sell data.
Rights compared
- Access - both provide it. California is more prescriptive about a lookback period.
- Deletion - both, with exceptions. The GDPR's right to erasure is broader in framing.
- Correction - both, with CPRA adding it explicitly.
- Portability - both.
- Opt out of sale or sharing - California only. This has no direct GDPR equivalent, and it drives the "Do Not Sell or Share My Personal Information" link and universal opt-out signal handling.
- Limit use of sensitive personal information - California specific.
- Object to processing / withdraw consent - GDPR framing, without a direct California analogue.
- Non-discrimination for exercising rights - explicit in California.
One privacy programme, multiple regimes
GRC Copilot maps your privacy controls across the GDPR, CCPA/CPRA, the Saudi PDPL and ISO 27701 - reusing evidence and showing exactly what each regime still needs.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
What a GDPR programme still leaves undone
If you already run GDPR compliance, you have most of the foundations - data inventory, notices, rights processes, vendor terms, security. The California-specific gaps are usually:
- Opt-out mechanics - the link, the request flow, and honouring browser-level universal opt-out signals.
- Sale and sharing analysis - determining whether your advertising and analytics stack triggers the definitions.
- Sensitive personal information handling and the limit-use right.
- Notice at collection in the specific California format, including categories and retention.
- Contractual terms with service providers, contractors and third parties, which use California-specific definitions rather than GDPR controller/processor language.
- Non-discrimination and financial incentive disclosures.
Enforcement and consequences
The GDPR is enforced by supervisory authorities across member states with substantial maximum administrative fines. California is enforced by the state Attorney General and a dedicated privacy agency, with per-violation penalties and a limited private right of action tied to certain data breaches. Both regimes make documented accountability the practical defence.
The practical approach
Run one programme with jurisdictional overlays: a single data inventory, one rights-handling process with regime-specific rules, one vendor programme with the right contract language per relationship, and one security control set. Duplicating the whole programme per jurisdiction is how organisations end up giving inconsistent answers to the same question.
Note also that the US picture is fragmenting - several states have enacted comprehensive privacy laws with their own variations. Designing for "multi-regime" rather than "GDPR plus California" is the durable choice.
This is orientation, not legal advice. Confirm current requirements and thresholds with qualified counsel - both regimes have been amended since enactment.
Frequently asked questions
Does GDPR compliance make us CCPA compliant?
No, though it gets you most of the way. The opt-out mechanics, sale and sharing analysis, and California-specific notice and contract terms need direct work.
What is the difference between CCPA and CPRA?
CPRA amended and expanded CCPA - adding correction rights, the sensitive personal information category, "sharing" alongside "sale", and a dedicated enforcement agency. In practice people say CCPA to mean the amended regime.
Do we need consent banners for California?
The model is opt-out rather than opt-in, so a GDPR-style consent banner is not the mechanism. You need notice and an accessible opt-out, including honouring universal opt-out signals.
Are B2B contacts covered?
California's regime now covers business contacts and employees following the expiry of earlier exemptions - a point many organisations missed.
Key takeaways
- GDPR is opt-in with a lawful basis; California is notice plus opt-out.
- "Sale" and "sharing" are defined broadly enough to catch common ad tech.
- GDPR has no revenue threshold; California does.
- Build one programme with jurisdictional overlays, not parallel programmes.