CCPA and GDPR can govern the same data flow, but neither law is a substitute for the other.
Test California and EU scope separately, assign each legal role, and compare purpose, rights, contracts, transfers, security, deadlines, and evidence before reusing a control.
The CCPA protects California residents and regulates qualifying businesses and specified recipients of personal information. The regulates processing of personal data within its territorial scope and assigns duties mainly to controllers and processors. A California business can also be a GDPR controller, but the labels, scope tests, rights, deadlines, and legal mechanisms do not automatically match. Run both analyses when the same product, person, or data flow connects to California and the European Union.
Side-by-side comparison
CCPA vs GDPR implementation map
Apply each row to the same entity and data flow. Reuse evidence only after both legal tests are documented.
The CCPA protects natural persons who are California residents, including employees, applicants, and business contacts. It generally applies to a for-profit business doing business in California that meets a current revenue, data-volume, or sale-or-sharing revenue threshold, plus specified related entities, joint ventures, and voluntary participants. It also imposes duties on service providers, contractors, and third parties.
The applies to processing in the context of an EU controller or processor establishment, regardless of where processing occurs. It can also reach a non-EU controller or processor that offers goods or services to people in the EU or monitors their behavior there. Article 3 does not use revenue or record-count thresholds.
Document both tests. A company below CCPA thresholds can still be subject to , and a company outside the EU can still be subject to GDPR because of its establishment, offering, or monitoring facts.
Personal information is information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a particular consumer or household. Statutory exclusions include deidentified, aggregate consumer, and publicly available information when their conditions are met.
Personal data is information relating to an identified or identifiable natural person. Pseudonymized data remains personal data when it can be attributed to a person using additional information; anonymous information falls outside only when the person is not or is no longer identifiable.
Do not copy a CCPA exclusion into the inventory. Record the person-or-household link, identifiability, public-source facts, and deidentification controls under the applicable definition.
A business determines the purposes and means of processing and meets the CCPA's other scope elements. Service providers and contractors process information for a business under qualifying written contracts. Third parties are recipients that do not fit the business, service-provider, or contractor definitions for the transaction.
A controller determines purposes and means; a processor processes personal data on a controller's behalf; joint controllers determine purposes and means together. The contract label does not control if the parties' actual functions show a different role.
Create a role finding for each processing activity and recipient. One organization can be a business or third party under CCPA and a controller or processor under in different contexts.
The CCPA requires notice, disclosed or compatible purposes, and collection, use, retention, and sharing that are reasonably necessary and proportionate. It gives consumers choices for sale, sharing, and specified sensitive-information uses. It does not use 's six-lawful-basis framework for all processing.
A controller must identify an Article 6 lawful basis for each purpose. Processing special categories of personal data also needs an Article 9 condition unless an exception applies. Consent is only one possible basis and must meet requirements when used.
Maintain separate fields: CCPA purpose, necessity, sale, sharing, and sensitive-information findings; purpose, Article 6 basis, Article 9 condition, and consent evidence where applicable.
CCPA rights include notice, know/access, delete, correct, opt out of sale or sharing, limit specified sensitive-information uses, and equal treatment, subject to verification rules and exceptions. Delete, correct, and know requests generally require confirmation within 10 business days and a substantive response within 45 calendar days, extendable once by 45 days with notice.
rights include access, rectification, erasure, restriction, portability, objection, and protections concerning certain solely automated decisions, each subject to its own conditions and exceptions. A controller generally must respond without undue delay and within one month, with a possible two-month extension for complexity or request volume if the person is informed within the first month.
Route the request under each applicable law, calculate both clocks, and document verification, identity concerns, exceptions, extensions, response format, and downstream action. Apply the rule that produces the required timely result; do not average the deadlines.
A business must classify disclosures as sale, sharing for cross-context behavioral advertising, business-purpose disclosures to service providers or contractors, consumer-directed disclosures, or another exception. Covered sale or sharing requires an opt-out route and processing of qualifying opt-out preference signals.
has no direct equivalent to CCPA 'sale' or 'sharing.' A disclosure needs a lawful basis, transparency, proper controller or processor allocation, and any required Article 28 terms. A transfer of personal data to a third country or international organization also needs a Chapter V transfer basis.
Do not use one 'data sharing' checkbox. Preserve the CCPA transfer classification and opt-out result beside the lawful basis, roles, recipients, transparency, processor terms, and international-transfer mechanism.
The CCPA requires reasonable security, documented purpose and proportionality limits, and applicable contract and recordkeeping controls. Current regulations add risk-assessment, cybersecurity-audit, and automated-decisionmaking duties for businesses that meet their specific triggers and phased compliance dates.
requires controllers to demonstrate compliance, maintain records where Article 30 applies, implement data protection by design and by default, use appropriate security, conduct a DPIA where processing is likely to create high risk, and appoint a DPO when Article 37's conditions are met.
A DPIA does not automatically satisfy a California risk assessment, and a California cybersecurity audit does not replace GDPR accountability. Reuse the system facts and test results, then add each law's trigger, required content, approval, submission, and timing.
The CCPA requires reasonable security and permits a private action for certain breaches of specified nonencrypted and nonredacted personal information caused by failure to maintain reasonable security. The CPPA and California Attorney General can enforce the CCPA; consumers cannot sue for most other CCPA violations.
A controller must notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours after awareness unless the breach is unlikely to risk individuals' rights and freedoms. High-risk breaches generally require notice to affected people. Supervisory authorities can use Article 58 powers and Article 83 fines, and Article 82 provides compensation for qualifying damage.
Run California breach-law and breach tests separately. The CCPA comparison does not replace California's separate breach-notification statutes, and a GDPR notification decision does not determine CCPA private-action exposure.
The CCPA protects natural persons who are California residents, including employees, applicants, and business contacts. It generally applies to a for-profit business doing business in California that meets a current revenue, data-volume, or sale-or-sharing revenue threshold, plus specified related entities, joint ventures, and voluntary participants. It also imposes duties on service providers, contractors, and third parties.
The applies to processing in the context of an EU controller or processor establishment, regardless of where processing occurs. It can also reach a non-EU controller or processor that offers goods or services to people in the EU or monitors their behavior there. Article 3 does not use revenue or record-count thresholds.
Document both tests. A company below CCPA thresholds can still be subject to , and a company outside the EU can still be subject to GDPR because of its establishment, offering, or monitoring facts.
Personal information is information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a particular consumer or household. Statutory exclusions include deidentified, aggregate consumer, and publicly available information when their conditions are met.
Personal data is information relating to an identified or identifiable natural person. Pseudonymized data remains personal data when it can be attributed to a person using additional information; anonymous information falls outside only when the person is not or is no longer identifiable.
Do not copy a CCPA exclusion into the inventory. Record the person-or-household link, identifiability, public-source facts, and deidentification controls under the applicable definition.
A business determines the purposes and means of processing and meets the CCPA's other scope elements. Service providers and contractors process information for a business under qualifying written contracts. Third parties are recipients that do not fit the business, service-provider, or contractor definitions for the transaction.
A controller determines purposes and means; a processor processes personal data on a controller's behalf; joint controllers determine purposes and means together. The contract label does not control if the parties' actual functions show a different role.
Create a role finding for each processing activity and recipient. One organization can be a business or third party under CCPA and a controller or processor under in different contexts.
The CCPA requires notice, disclosed or compatible purposes, and collection, use, retention, and sharing that are reasonably necessary and proportionate. It gives consumers choices for sale, sharing, and specified sensitive-information uses. It does not use 's six-lawful-basis framework for all processing.
A controller must identify an Article 6 lawful basis for each purpose. Processing special categories of personal data also needs an Article 9 condition unless an exception applies. Consent is only one possible basis and must meet requirements when used.
Maintain separate fields: CCPA purpose, necessity, sale, sharing, and sensitive-information findings; purpose, Article 6 basis, Article 9 condition, and consent evidence where applicable.
CCPA rights include notice, know/access, delete, correct, opt out of sale or sharing, limit specified sensitive-information uses, and equal treatment, subject to verification rules and exceptions. Delete, correct, and know requests generally require confirmation within 10 business days and a substantive response within 45 calendar days, extendable once by 45 days with notice.
rights include access, rectification, erasure, restriction, portability, objection, and protections concerning certain solely automated decisions, each subject to its own conditions and exceptions. A controller generally must respond without undue delay and within one month, with a possible two-month extension for complexity or request volume if the person is informed within the first month.
Route the request under each applicable law, calculate both clocks, and document verification, identity concerns, exceptions, extensions, response format, and downstream action. Apply the rule that produces the required timely result; do not average the deadlines.
Advertising disclosures and international transfers
CCPA
A business must classify disclosures as sale, sharing for cross-context behavioral advertising, business-purpose disclosures to service providers or contractors, consumer-directed disclosures, or another exception. Covered sale or sharing requires an opt-out route and processing of qualifying opt-out preference signals.
has no direct equivalent to CCPA 'sale' or 'sharing.' A disclosure needs a lawful basis, transparency, proper controller or processor allocation, and any required Article 28 terms. A transfer of personal data to a third country or international organization also needs a Chapter V transfer basis.
Do not use one 'data sharing' checkbox. Preserve the CCPA transfer classification and opt-out result beside the lawful basis, roles, recipients, transparency, processor terms, and international-transfer mechanism.
The CCPA requires reasonable security, documented purpose and proportionality limits, and applicable contract and recordkeeping controls. Current regulations add risk-assessment, cybersecurity-audit, and automated-decisionmaking duties for businesses that meet their specific triggers and phased compliance dates.
requires controllers to demonstrate compliance, maintain records where Article 30 applies, implement data protection by design and by default, use appropriate security, conduct a DPIA where processing is likely to create high risk, and appoint a DPO when Article 37's conditions are met.
A DPIA does not automatically satisfy a California risk assessment, and a California cybersecurity audit does not replace GDPR accountability. Reuse the system facts and test results, then add each law's trigger, required content, approval, submission, and timing.
The CCPA requires reasonable security and permits a private action for certain breaches of specified nonencrypted and nonredacted personal information caused by failure to maintain reasonable security. The CPPA and California Attorney General can enforce the CCPA; consumers cannot sue for most other CCPA violations.
A controller must notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours after awareness unless the breach is unlikely to risk individuals' rights and freedoms. High-risk breaches generally require notice to affected people. Supervisory authorities can use Article 58 powers and Article 83 fines, and Article 82 provides compensation for qualifying damage.
Run California breach-law and breach tests separately. The CCPA comparison does not replace California's separate breach-notification statutes, and a GDPR notification decision does not determine CCPA private-action exposure.
Apply CCPA when its California resident, business, role, data, and activity requirements are met.
Apply when its material and territorial scope tests are met, even if the organization does not meet a CCPA business threshold.
When both apply, satisfy each law independently. Reuse inventories, technical controls, request tooling, contracts, and tests only where the saved evidence proves both requirements.
What is the practical difference between CCPA and GDPR?
CCPA scope starts with California residency, the statutory definition of a business, current thresholds, and the roles of service provider, contractor, and third party. scope starts with personal-data processing by an EU establishment or, for a non-EU organization, offering goods or services to people in the EU or monitoring their behavior there. GDPR applies to controllers and processors without a CCPA-style revenue or data-volume threshold.
The CCPA does not impose a general requirement to select an Article 6-style lawful basis for every processing purpose. It instead combines notice, purpose and proportionality limits, consumer rights, sale-and-sharing choices, sensitive-information limits, contracts, and security duties. requires a lawful basis for each processing purpose and adds separate conditions for special-category data.
Do not map 'business' automatically to 'controller' or 'service provider' automatically to 'processor'; classify the actual decision-making and processing under each law.
Do not treat a CCPA sale-or-sharing opt-out as consent, or GDPR consent as proof that a California sale, sharing, or sensitive-information rule is satisfied.
Keep separate response clocks and exception analyses for CCPA consumer requests and data-subject requests.
For every external disclosure, record the CCPA recipient role and sale-or-sharing result, then separately record the controller or processor role, lawful basis, transparency, contract, and any Chapter V transfer mechanism.
Build the shared layer from facts: systems, data categories, people, purposes, recipients, locations, retention, security, and request history. Then attach separate legal findings. The same inventory or deletion workflow may support both laws, but the evidence must still show that each law's trigger, actor, deadline, exception, and downstream duty was met.
Assign implementation to the team that controls the relevant system or process, with privacy or legal review for role, scope, exemption, lawful-basis, and transfer questions. This comparison cannot determine whether either law applies to a specific organization without its entity, establishment, targeting, monitoring, revenue, volume, data, and relationship facts.
Record one scope memo per legal entity and law, including the factual date and any exemption relied on.
Map every purpose to CCPA notice, necessity, retention, sale, sharing, and sensitive-information findings, and to the lawful basis and Article 9 condition where needed.
Keep request logs that identify the governing law, identity-verification steps, receipt date, extension notice, outcome, exception, and downstream instructions.
Test live notices, consent or opt-out interfaces, preference signals, vendor behavior, deletion, correction, access exports, and restriction flags; a policy alone does not prove the control works.