Loading

CCPA and CPRA

Knowledge Base | CCPA and CPRA | How is CCPA different from GDPR?

How is CCPA different from GDPR?

The CCPA and GDPR both protect personal information, but they use different compliance models. The CCPA focuses largely on transparency and consumers’ ability to control the sale or sharing of their information. The GDPR regulates personal data processing more broadly and requires a valid legal basis for each processing activity.

Comparison area

CCPA

GDPR

Legal framework

A California state privacy law, as amended by the CPRA.

A data protection regulation that applies across the EU and EEA.

Territorial scope

Protects California residents when their personal information is handled by a covered business.

Covers organisations in the EU or EEA and certain organisations outside the region that target or monitor people there.

Business coverage

Applies to certain for-profit businesses that meet one or more of the CCPA's applicability thresholds.

Has no general revenue or data-volume threshold. It applies when its territorial and processing conditions are met.

Protected information

Covers information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a consumer or household.

Covers information relating to an identified or identifiable living person.

Processing model

Focuses mainly on transparency, consumer rights, and opt-out choices. It does not require a legal basis for every processing activity.

Requires every processing activity to rely on a lawful basis, such as consent, contract, legal obligation, or legitimate interests.

Individual rights

Includes rights to know, access, correct, and delete information, opt out of sale or sharing, and limit certain uses of sensitive information.

Includes rights of access, correction, erasure, restriction, portability, objection, and protection regarding certain automated decisions.

Sale and sharing

Gives consumers a specific right to stop the sale or sharing of personal information.

Does not use the same sale-or-sharing model. Any disclosure must have a lawful basis and meet GDPR requirements.

Sensitive information

Allows consumers to limit certain uses and disclosures of sensitive personal information.

Processing special categories of personal data is generally prohibited unless an exception under Article 9 applies.

Cookie requirements

Does not generally require prior consent for all cookies. Notice and opt-out rights may apply when cookies or similar technologies are used to sell or share personal information.

Non-essential cookies generally require prior consent under EU ePrivacy rules, while strictly necessary cookies are generally exempt. The GDPR governs the processing of personal data collected through those cookies.

Request deadlines

Requests to know, correct or delete personal information must generally be answered within 45 calendar days, with a possible 45-day extension.

Requests must generally be answered within one month, with a possible extension of up to two additional months.

Enforcement

Enforced by the California Privacy Protection Agency and the California Attorney General.

Enforced by national data protection authorities, coordinated through the European Data Protection Board.

Penalties

Administrative fines can reach $2,663 per violation or $7,988 for intentional violations and violations involving the personal information of consumers the violator actually knows are under 16.

Fines can reach €20 million or 4% of worldwide annual turnover, whichever is higher, for the most serious violations.

The main difference is that the GDPR regulates whether and how personal data may be processed, while the CCPA gives California consumers specific rights over information collected by covered businesses, especially the right to prevent its sale or sharing. Compliance with one law does not automatically establish compliance with the other.