Artifact GuideUSCCPA vs GDPR

US CCPA CCPA vs GDPR

CCPA and GDPR can govern the same data flow, but neither law is a substitute for the other.

Test California and EU scope separately, assign each legal role, and compare purpose, rights, contracts, transfers, security, deadlines, and evidence before reusing a control.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 27, 2026
Sections
2

Structured answer sets in this page tree.

Primary sources
19

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 27, 2026
Overview

The CCPA protects California residents and regulates qualifying businesses and specified recipients of personal information. The regulates processing of personal data within its territorial scope and assigns duties mainly to controllers and processors. A California business can also be a GDPR controller, but the labels, scope tests, rights, deadlines, and legal mechanisms do not automatically match. Run both analyses when the same product, person, or data flow connects to California and the European Union.

Side-by-side comparison

CCPA vs GDPR implementation map

Apply each row to the same entity and data flow. Reuse evidence only after both legal tests are documented.

Review all sources
First framework
CCPA

California law for qualifying businesses and specified recipients of California residents' personal information.

Second framework
GDPR

EU regulation for controllers and processors handling personal data within Article 3's territorial scope.

Comparison row 1

Territorial and organizational scope

CCPA

The CCPA protects natural persons who are California residents, including employees, applicants, and business contacts. It generally applies to a for-profit business doing business in California that meets a current revenue, data-volume, or sale-or-sharing revenue threshold, plus specified related entities, joint ventures, and voluntary participants. It also imposes duties on service providers, contractors, and third parties.

GDPR

The applies to processing in the context of an EU controller or processor establishment, regardless of where processing occurs. It can also reach a non-EU controller or processor that offers goods or services to people in the EU or monitors their behavior there. Article 3 does not use revenue or record-count thresholds.

Operational implication

Document both tests. A company below CCPA thresholds can still be subject to , and a company outside the EU can still be subject to GDPR because of its establishment, offering, or monitoring facts.

Comparison row 2

Protected data

CCPA

Personal information is information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a particular consumer or household. Statutory exclusions include deidentified, aggregate consumer, and publicly available information when their conditions are met.

GDPR

Personal data is information relating to an identified or identifiable natural person. Pseudonymized data remains personal data when it can be attributed to a person using additional information; anonymous information falls outside only when the person is not or is no longer identifiable.

Operational implication

Do not copy a CCPA exclusion into the inventory. Record the person-or-household link, identifiability, public-source facts, and deidentification controls under the applicable definition.

Comparison row 3

Regulated roles

CCPA

A business determines the purposes and means of processing and meets the CCPA's other scope elements. Service providers and contractors process information for a business under qualifying written contracts. Third parties are recipients that do not fit the business, service-provider, or contractor definitions for the transaction.

GDPR

A controller determines purposes and means; a processor processes personal data on a controller's behalf; joint controllers determine purposes and means together. The contract label does not control if the parties' actual functions show a different role.

Operational implication

Create a role finding for each processing activity and recipient. One organization can be a business or third party under CCPA and a controller or processor under in different contexts.

Comparison row 4

Purpose and authority to process

CCPA

The CCPA requires notice, disclosed or compatible purposes, and collection, use, retention, and sharing that are reasonably necessary and proportionate. It gives consumers choices for sale, sharing, and specified sensitive-information uses. It does not use 's six-lawful-basis framework for all processing.

GDPR

A controller must identify an Article 6 lawful basis for each purpose. Processing special categories of personal data also needs an Article 9 condition unless an exception applies. Consent is only one possible basis and must meet requirements when used.

Operational implication

Maintain separate fields: CCPA purpose, necessity, sale, sharing, and sensitive-information findings; purpose, Article 6 basis, Article 9 condition, and consent evidence where applicable.

Comparison row 5

Individual rights and response time

CCPA

CCPA rights include notice, know/access, delete, correct, opt out of sale or sharing, limit specified sensitive-information uses, and equal treatment, subject to verification rules and exceptions. Delete, correct, and know requests generally require confirmation within 10 business days and a substantive response within 45 calendar days, extendable once by 45 days with notice.

GDPR

rights include access, rectification, erasure, restriction, portability, objection, and protections concerning certain solely automated decisions, each subject to its own conditions and exceptions. A controller generally must respond without undue delay and within one month, with a possible two-month extension for complexity or request volume if the person is informed within the first month.

Operational implication

Route the request under each applicable law, calculate both clocks, and document verification, identity concerns, exceptions, extensions, response format, and downstream action. Apply the rule that produces the required timely result; do not average the deadlines.

Comparison row 6

Advertising disclosures and international transfers

CCPA

A business must classify disclosures as sale, sharing for cross-context behavioral advertising, business-purpose disclosures to service providers or contractors, consumer-directed disclosures, or another exception. Covered sale or sharing requires an opt-out route and processing of qualifying opt-out preference signals.

GDPR

has no direct equivalent to CCPA 'sale' or 'sharing.' A disclosure needs a lawful basis, transparency, proper controller or processor allocation, and any required Article 28 terms. A transfer of personal data to a third country or international organization also needs a Chapter V transfer basis.

Operational implication

Do not use one 'data sharing' checkbox. Preserve the CCPA transfer classification and opt-out result beside the lawful basis, roles, recipients, transparency, processor terms, and international-transfer mechanism.

Comparison row 7

Accountability, assessments, and security

CCPA

The CCPA requires reasonable security, documented purpose and proportionality limits, and applicable contract and recordkeeping controls. Current regulations add risk-assessment, cybersecurity-audit, and automated-decisionmaking duties for businesses that meet their specific triggers and phased compliance dates.

GDPR

requires controllers to demonstrate compliance, maintain records where Article 30 applies, implement data protection by design and by default, use appropriate security, conduct a DPIA where processing is likely to create high risk, and appoint a DPO when Article 37's conditions are met.

Operational implication

A DPIA does not automatically satisfy a California risk assessment, and a California cybersecurity audit does not replace GDPR accountability. Reuse the system facts and test results, then add each law's trigger, required content, approval, submission, and timing.

Comparison row 8

Breach response and enforcement

CCPA

The CCPA requires reasonable security and permits a private action for certain breaches of specified nonencrypted and nonredacted personal information caused by failure to maintain reasonable security. The CPPA and California Attorney General can enforce the CCPA; consumers cannot sue for most other CCPA violations.

GDPR

A controller must notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours after awareness unless the breach is unlikely to risk individuals' rights and freedoms. High-risk breaches generally require notice to affected people. Supervisory authorities can use Article 58 powers and Article 83 fines, and Article 82 provides compensation for qualifying damage.

Operational implication

Run California breach-law and breach tests separately. The CCPA comparison does not replace California's separate breach-notification statutes, and a GDPR notification decision does not determine CCPA private-action exposure.

Practical decision rule

Which regime controls a shared data flow?

  • Apply CCPA when its California resident, business, role, data, and activity requirements are met.
  • Apply when its material and territorial scope tests are met, even if the organization does not meet a CCPA business threshold.
  • When both apply, satisfy each law independently. Reuse inventories, technical controls, request tooling, contracts, and tests only where the saved evidence proves both requirements.
Section 1

What is the practical difference between CCPA and GDPR?

CCPA scope starts with California residency, the statutory definition of a business, current thresholds, and the roles of service provider, contractor, and third party. scope starts with personal-data processing by an EU establishment or, for a non-EU organization, offering goods or services to people in the EU or monitoring their behavior there. GDPR applies to controllers and processors without a CCPA-style revenue or data-volume threshold.

The CCPA does not impose a general requirement to select an Article 6-style lawful basis for every processing purpose. It instead combines notice, purpose and proportionality limits, consumer rights, sale-and-sharing choices, sensitive-information limits, contracts, and security duties. requires a lawful basis for each processing purpose and adds separate conditions for special-category data.

  • Do not map 'business' automatically to 'controller' or 'service provider' automatically to 'processor'; classify the actual decision-making and processing under each law.
  • Do not treat a CCPA sale-or-sharing opt-out as consent, or GDPR consent as proof that a California sale, sharing, or sensitive-information rule is satisfied.
  • Keep separate response clocks and exception analyses for CCPA consumer requests and data-subject requests.
  • For every external disclosure, record the CCPA recipient role and sale-or-sharing result, then separately record the controller or processor role, lawful basis, transparency, contract, and any Chapter V transfer mechanism.
Section 2

How should one control set support both laws?

Build the shared layer from facts: systems, data categories, people, purposes, recipients, locations, retention, security, and request history. Then attach separate legal findings. The same inventory or deletion workflow may support both laws, but the evidence must still show that each law's trigger, actor, deadline, exception, and downstream duty was met.

Assign implementation to the team that controls the relevant system or process, with privacy or legal review for role, scope, exemption, lawful-basis, and transfer questions. This comparison cannot determine whether either law applies to a specific organization without its entity, establishment, targeting, monitoring, revenue, volume, data, and relationship facts.

  • Record one scope memo per legal entity and law, including the factual date and any exemption relied on.
  • Map every purpose to CCPA notice, necessity, retention, sale, sharing, and sensitive-information findings, and to the lawful basis and Article 9 condition where needed.
  • Keep request logs that identify the governing law, identity-verification steps, receipt date, extension notice, outcome, exception, and downstream instructions.
  • Test live notices, consent or opt-out interfaces, preference signals, vendor behavior, deletion, correction, access exports, and restriction flags; a policy alone does not prove the control works.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Supports a separate GDPR identifiability analysis rather than relying on a CCPA data-category result.
eur-lex.europa.eu
Referenced sections
  • Sets data-subject rights, conditions, response timing, and extension rules.
eur-lex.europa.eu
Referenced sections
  • Provides the GDPR material and territorial scope tests.
eur-lex.europa.eu
Referenced sections
  • Sets the role definitions and the consequences for joint-controller arrangements and processor contracts.
eur-lex.europa.eu
Referenced sections
  • Sets processing principles, lawful bases, consent conditions, and special-category conditions.
Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.