Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

CCPA vs GDPR: Key Differences and How to Comply With Both

Side-by-side comparison of CCPA and GDPR data privacy law requirements

Quick answer: The CCPA, as amended and expanded by the CPRA, and the GDPR are the two most influential data privacy laws affecting organizations that handle US and EU personal data. CCPA/CPRA governs California consumers’ personal information; GDPR governs personal data of anyone in the EU/EEA, regardless of company size or location. Most organizations serving both markets should build one overlapping program: data mapping, a unified consent/opt-out layer, encryption or pseudonymization, and a single workflow for handling data subject requests and breach notifications under both laws at once.

Key takeaways:

  • CCPA/CPRA applies to for-profit businesses that meet revenue, data-volume, or data-sale thresholds and process California residents’ personal information. GDPR applies to any organization, anywhere in the world, that processes personal data of people located in the EU or EEA.
  • The CPRA (Proposition 24) took effect January 1, 2023, expanded CCPA’s rights and obligations, and created the California Privacy Protection Agency (CPPA), which assumed rulemaking and enforcement authority on July 1, 2023.
  • GDPR fines can reach the greater of 20 million euros or 4% of a company’s total global annual turnover for the most serious violations. CCPA administrative fines are adjusted for inflation and currently reach up to $7,988 per intentional violation, and California also allows consumers a private right of action for certain data breaches.
  • As of January 1, 2026, California requires notification to affected residents within 30 calendar days of discovering a breach, narrowing the gap with GDPR’s 72 hour regulator notification requirement.
  • Encryption, pseudonymization, tokenization, and documented access controls reduce breach-notification exposure and regulatory risk under both laws simultaneously.

Published: January 10, 2019. Updated: August 2026. Reviewed by Encryption Consulting’s Compliance Advisory team.

What Is the CCPA and CPRA?

The California Consumer Privacy Act (CCPA) is a state law that gives California residents rights over the personal information that businesses collect about them. California voted to sign the CCPA into law in June 2018, and it took effect on January 1, 2020. The CCPA defines “personal information” broadly as information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with a particular consumer or household.

In November 2020, California voters approved Proposition 24, the California Privacy Rights Act (CPRA). The CPRA amended and significantly expanded the CCPA, and its provisions took effect on January 1, 2023. The CPRA created the California Privacy Protection Agency (CPPA), a dedicated regulator that took over rulemaking authority and, as of July 1, 2023, primary enforcement authority for the law (the California Attorney General retains concurrent enforcement authority). In practice, “CCPA” today generally refers to the law as amended by the CPRA.

A business must comply with the CCPA/CPRA if it does business in California and meets at least one of these thresholds:

  1. Had annual gross revenue over $25 million in the prior calendar year, or
  2. Buys, sells, or shares the personal information of 100,000 or more California consumers or households annually, or
  3. Derives 50% or more of its annual revenue from selling or sharing California consumers’ personal information.

What Rights Does the CCPA Give Consumers?

The CCPA, as expanded by the CPRA, gives California consumers the following rights over their personal information:

  • Right to Know

    Consumers can request what personal information a business has collected, used, sold, or disclosed about them, and for what purpose.

  • Right to Delete

    Consumers can request that a business delete personal information it has collected from them, subject to certain exceptions.

  • Right to Opt-Out

    Consumers can direct a business to stop selling or sharing their personal information.

  • Right to Correct

    Added by the CPRA, this lets consumers request correction of inaccurate personal information a business holds about them.

  • Right to Limit Use of Sensitive Personal Information

    Added by the CPRA, this lets consumers restrict a business’s use of sensitive categories of data, such as precise geolocation, government identifiers, or health information, to what is necessary to provide the requested goods or services.

  • Right to Non-Discrimination

    Businesses cannot charge different prices or provide a different level of service to consumers who exercise their CCPA rights.

What Is the GDPR?

The General Data Protection Regulation (GDPR), formally Regulation (EU) 2016/679, is the European Union’s comprehensive data protection law. It has applied directly in all EU member states since May 25, 2018. Unlike the CCPA, GDPR is not limited by a company’s revenue or headcount: it applies to any organization, anywhere in the world, that processes the personal data of individuals located in the EU or European Economic Area (EEA), whether that organization is established in the EU or simply offers goods or services to, or monitors the behavior of, people there.

GDPR is enforced by independent national Data Protection Authorities (DPAs) in each EU member state, coordinated through the European Data Protection Board. Under GDPR, an individual whose data is processed is called a “data subject,” and a formal request from that person to access, correct, delete, or restrict their data is commonly referred to as a Data Subject Access Request (DSAR).

What Rights Does the GDPR Give Data Subjects?

  • Right of Access

    Data subjects can request confirmation of whether their personal data is being processed and obtain a copy of that data.

  • Right to Erasure

    Similar to CCPA’s right to delete, data subjects can request that their personal data be erased under certain conditions.

  • Right to Rectification

    Data subjects can request correction of inaccurate or incomplete personal data.

  • Right to Restrict Processing

    Data subjects can request that processing of their data be limited under certain conditions.

  • Right to Object

    Data subjects can object to processing carried out for direct marketing or based on legitimate interests.

  • Right to Data Portability

    Data subjects can request their data in a structured, commonly used format so it can be transferred to another provider. GDPR has no direct CCPA equivalent for this right.

Tailored Encryption Services

We assess, strategize & implement encryption strategies and solutions.

CCPA vs GDPR: Side-by-Side Comparison

The table below compares the CCPA (as amended by the CPRA) and the GDPR across the criteria that most affect a compliance program: who each law covers, how consent works, what happens after a breach, and how large the penalties can be.

Requirement CCPA / CPRA (California) GDPR (European Union)
Territorial scope California residents’ personal information, regardless of where the business is headquartered Personal data of individuals located in the EU/EEA, regardless of where the processing organization is located
Who must comply For-profit businesses meeting a revenue, data-volume, or data-sale threshold Any organization, of any size, that processes in-scope personal data (no revenue or size threshold)
Consent / opt-out model Opt-out model: businesses may process and sell/share data by default, and consumers can opt out Opt-in model: processing generally requires a valid legal basis, such as freely given, informed consent
Core individual rights Right to know, delete, correct, opt-out of sale/sharing, limit use of sensitive data, non-discrimination Right of access, erasure, rectification, restriction, objection, and data portability
Privacy by design Not an explicit statutory requirement Required under Article 25 (data protection by design and by default)
Breach notification to regulator No single fixed statutory deadline for regulator notification under the CCPA itself; separate California breach law (Civil Code 1798.82) requires notice to affected residents within 30 calendar days as of January 1, 2026, and notice to the Attorney General within 15 calendar days of notifying individuals when more than 500 California residents are affected Notification to the relevant supervisory authority within 72 hours of becoming aware of a qualifying breach (Article 33), and notification to affected individuals without undue delay when the breach poses a high risk (Article 34)
Maximum penalties Inflation-adjusted administrative fines, currently up to $2,663 per violation and up to $7,988 per intentional violation or violation involving a minor’s data; consumers also have a private right of action for certain data breaches, with statutory damages of $100 to $750 per consumer per incident Up to the greater of 20 million euros or 4% of total global annual turnover for the most serious violations; up to the greater of 10 million euros or 2% of turnover for less severe violations
Enforcement authority California Privacy Protection Agency (CPPA) and the California Attorney General National Data Protection Authorities (DPAs) in each EU member state

How to Comply With Both CCPA and GDPR at the Same Time

Organizations that handle both California residents’ data and EU/EEA residents’ data do not need two separate compliance programs. Building to the stricter requirement in each category generally satisfies both laws at once:

  1. Map your data flows. Inventory what personal information and personal data you collect, where it is stored, who processes it, and which regulations apply to each data set.
  2. Confirm applicability under each law. Check CCPA/CPRA’s revenue, data-volume, and data-sale thresholds and GDPR’s territorial-scope test separately; a company can be in scope for one law and out of scope for the other.
  3. Build one privacy notice and consent layer that satisfies both models. Design your consent banners and preference center to support GDPR’s opt-in requirement for EU/EEA visitors and CCPA’s “Do Not Sell or Share My Personal Information” opt-out for California visitors.
  4. Stand up a single DSAR/consumer-request workflow. Use one intake process, identity-verification step, and response tracker for CCPA consumer requests and GDPR data subject access requests, and honor the shorter of the two response deadlines.
  5. Apply encryption, pseudonymization, and tokenization to reduce the personal data actually exposed in the event of a breach and to limit regulatory and breach-notification exposure under both laws.
  6. Enforce role-based access controls and least privilege so that only staff and systems with a documented need can access personal information or personal data.
  7. Maintain records of processing activities. GDPR Article 30 requires a formal record of processing; keeping an equivalent CCPA data inventory current makes both audits faster.
  8. Build and rehearse a breach-notification runbook that meets the strictest applicable deadline, which today is GDPR’s 72-hour regulator notification window, with California’s 30-day individual-notification requirement running in parallel.
  9. Review vendor and processor contracts for the data protection clauses each law requires, such as GDPR Article 28 processor obligations and CCPA’s service-provider and contractor restrictions on using personal information outside the contracted purpose.
  10. Reassess annually. Both regulations continue to evolve through new regulations, guidance, and enforcement actions, so a program built for today’s rules needs a scheduled review, not a one-time setup.

Which Technical and Organizational Controls Satisfy Both CCPA and GDPR?

Neither law mandates a specific algorithm or product, but both explicitly reward organizations that reduce risk through technical and organizational measures. The following controls consistently satisfy both regimes:

  • Encryption at rest and in transit

    Encrypting personal information and personal data reduces breach severity under both laws, and CCPA specifically calls out unencrypted, nonredacted personal information as the trigger for its private right of action. Encrypted data that is exfiltrated in unusable form generally falls outside that exposure. See What Is Encryption? for the underlying mechanics.

  • Pseudonymization and tokenization

    GDPR names pseudonymization directly as a risk-reduction measure in Articles 25 and 32. Tokenization, which replaces sensitive values with non-sensitive tokens, achieves a similar effect for CCPA-regulated personal information. See What Is Tokenization? How Does It Work?

  • Data masking for non-production environments

    Masking production data before it reaches development, testing, or analytics environments limits the personal information and personal data exposed to internal misuse or accidental disclosure. See What Is Data Masking and Why Is It Important?

  • Role-based access controls and least privilege

    Restricting access to personal data by role, with multi-factor authentication for privileged access, satisfies GDPR’s data-protection-by-design expectation and reduces the CCPA breach exposure tied to internal access sprawl.

  • A documented DSAR / consumer-request handling workflow

    A repeatable process for verifying requester identity, locating relevant records, and responding within the applicable deadline is required in substance by both laws, even though CCPA and GDPR use different terminology for the request.

  • A tested breach-notification procedure

    A documented, rehearsed runbook that identifies the breach, assesses scope and risk, and notifies regulators and individuals within the applicable deadlines keeps an organization from improvising under both GDPR’s 72-hour window and California’s 30-day window.

For a broader view of how these controls map to other regulations beyond CCPA and GDPR, see Regulatory Compliance 101: Laws, Requirements & Best Practices and Guide to Your Data Protection Evaluation Checklist.

Limitations

This article is a comparison overview, not a legal compliance determination. It does not cover every CCPA/CPRA regulation, every GDPR provision, or every sector-specific overlay (such as HIPAA, GLBA, or COPPA) that may also apply to your organization. Both laws are actively evolving through new regulations, guidance, and enforcement actions, and applicability depends on facts specific to each business, such as revenue, data volumes, and where data subjects are located. Consult qualified privacy counsel to confirm how CCPA/CPRA and GDPR apply to your specific organization before making compliance decisions.

What Would Encryption Consulting Recommend?

Encryption Consulting recommends starting with a data inventory that separates California-regulated personal information from EU/EEA-regulated personal data, then applying encryption, tokenization, and masking to the highest-risk data sets before layering on process controls. Our Compliance Advisory Services help organizations map CCPA/CPRA and GDPR obligations to concrete technical controls, and our Encryption Audit Service evaluates whether your current encryption practices are strong enough to limit breach-notification exposure under both laws. We also help design and refine encryption strategies so that data protection controls stay aligned with regulatory requirements as they change.

Tailored Cloud Key Management Services

We assess, strategize & implement data protection strategies and solutions customized to your requirements.

Frequently Asked Questions

Does the CCPA apply to my business if it is not based in California? Yes. The CCPA/CPRA applies based on whether you do business in California and process California residents’ personal information, not on where your company is headquartered. If you meet the revenue, data-volume, or data-sale threshold and handle California residents’ data, the law applies regardless of your physical location.

Does the GDPR apply to companies in the United States? Yes, if the company processes the personal data of individuals located in the EU or EEA, whether by offering goods or services to them or by monitoring their behavior. GDPR has no revenue or headcount threshold, so a small US company with EU customers can be fully in scope.

Can encryption reduce our breach-notification obligations? Encryption can significantly reduce practical and legal exposure. Under the CCPA, the private right of action for data breaches is specifically tied to unencrypted, nonredacted personal information, so strong encryption can remove that exposure. Under GDPR, encryption is named as a risk-mitigating measure and can affect whether individual notification is required after a breach, though notification to the supervisory authority may still be necessary.

What is the difference between CCPA’s opt-out model and GDPR’s consent requirement? CCPA generally allows businesses to collect and sell or share personal information by default, and requires them to honor a consumer’s request to opt out. GDPR generally requires a valid legal basis, most commonly freely given, informed, opt-in consent, or another recognized basis such as contractual necessity, before processing can begin at all.

Do we need two separate compliance programs for CCPA and GDPR? Not usually. Most organizations build one privacy program that maps each control, such as consent management, DSAR handling, encryption, and breach response, to the stricter of the two laws’ requirements, then documents which specific CCPA/CPRA and GDPR obligations each control satisfies.

Conclusion

CCPA and GDPR are both data privacy regulations designed to give individuals more control over their personal information while holding businesses accountable for how they collect, use, and protect it. The CCPA, now amended and expanded by the CPRA, protects California residents and is enforced by the CPPA and the California Attorney General. GDPR protects individuals in the EU and EEA and is enforced by national Data Protection Authorities, with substantially higher maximum fines. Rather than treating these as two unrelated compliance obligations, organizations that operate in both markets get the most value from one overlapping program: a single data inventory, one consent and request-handling workflow built to the stricter standard, and technical controls, including encryption, pseudonymization, tokenization, and access controls, that reduce risk under both laws at once.

References