CCPA and CPRA
How is CCPA different from GDPR?
The CCPA and GDPR both protect personal information, but they use different compliance models. The CCPA focuses largely on transparency and consumers’ ability to control the sale or sharing of their information. The GDPR regulates personal data processing more broadly and requires a valid legal basis for each processing activity.
Comparison area | CCPA | GDPR |
|---|---|---|
Legal framework | A California state privacy law, as amended by the CPRA. | A data protection regulation that applies across the EU and EEA. |
Territorial scope | Protects California residents when their personal information is handled by a covered business. | Covers organisations in the EU or EEA and certain organisations outside the region that target or monitor people there. |
Business coverage | Applies to certain for-profit businesses that meet one or more of the CCPA's applicability thresholds. | Has no general revenue or data-volume threshold. It applies when its territorial and processing conditions are met. |
Protected information | Covers information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a consumer or household. | Covers information relating to an identified or identifiable living person. |
Processing model | Focuses mainly on transparency, consumer rights, and opt-out choices. It does not require a legal basis for every processing activity. | Requires every processing activity to rely on a lawful basis, such as consent, contract, legal obligation, or legitimate interests. |
Individual rights | Includes rights to know, access, correct, and delete information, opt out of sale or sharing, and limit certain uses of sensitive information. | Includes rights of access, correction, erasure, restriction, portability, objection, and protection regarding certain automated decisions. |
Sale and sharing | Gives consumers a specific right to stop the sale or sharing of personal information. | Does not use the same sale-or-sharing model. Any disclosure must have a lawful basis and meet GDPR requirements. |
Sensitive information | Allows consumers to limit certain uses and disclosures of sensitive personal information. | Processing special categories of personal data is generally prohibited unless an exception under Article 9 applies. |
Cookie requirements | Does not generally require prior consent for all cookies. Notice and opt-out rights may apply when cookies or similar technologies are used to sell or share personal information. | Non-essential cookies generally require prior consent under EU ePrivacy rules, while strictly necessary cookies are generally exempt. The GDPR governs the processing of personal data collected through those cookies. |
Request deadlines | Requests to know, correct or delete personal information must generally be answered within 45 calendar days, with a possible 45-day extension. | Requests must generally be answered within one month, with a possible extension of up to two additional months. |
Enforcement | Enforced by the California Privacy Protection Agency and the California Attorney General. | Enforced by national data protection authorities, coordinated through the European Data Protection Board. |
Penalties | Administrative fines can reach $2,663 per violation or $7,988 for intentional violations and violations involving the personal information of consumers the violator actually knows are under 16. | Fines can reach €20 million or 4% of worldwide annual turnover, whichever is higher, for the most serious violations. |
The main difference is that the GDPR regulates whether and how personal data may be processed, while the CCPA gives California consumers specific rights over information collected by covered businesses, especially the right to prevent its sale or sharing. Compliance with one law does not automatically establish compliance with the other.
Türkçe
English