For the complete documentation index, see llms.txt. This page is also available as Markdown.

GDPR vs. CCPA

Contents

Key differences

  • The GDPR also applies to individuals who process data, whereas the CCPA only applies to for-profit businesses.

  • The GDPR is stricter and has far greater penalties for non-compliance

  • The GDPR requires consumers to consent to their personal data being used at the time, whereas the CCPA informs consumers how their personal data has been used for business purposes retroactively.

Comparison table

GDPR
CCPA

Primary regulator

European Data Protection Board (EDPB)

California Privacy Protection Agency (CPPA)

Data subjects

EU residents

California Residents

Who must comply?

Any business or individual handling the data of EU residents.

The business may be incorporated outside the EU.

For-profit businesses trading in California which either:

  • Have gross annual revenue in excess of $25 million; OR

  • Buy, sell, or share the PI of 100,000 or more California residents/ households; OR

  • Derive 50% or more of their annual revenue from selling California residents’ PI.

The business may be incorporated outside California.

How is ‘personal data’/ ‘personal information’ defined?

Personal data:

“Any information relating to an identified or identifiable natural person (‘data subject’)” (GDPR)

Personal information:

“Information that identifies, relates to, or could reasonably be linked with you or your household.” (CCPA)

It does not include publicly available information.

How is ‘sensitive’ personal data/ information’ defined?

Full list in legislation

Includes genetic, biometric and health data, as well as personal data revealing racial and ethnic origin, political opinions, religious or ideological convictions or trade union membership.

Full list in legislation.

Includes certain government identifiers (such as social security numbers)’ and contents of mail, email, and text messages.

Approach to consent

Opt-in system

Opt-out system

Penalties

Up to €20 million or 4% of global annual turnover

Up to $2,500 per violation; and $7,500 per ‘intentional’ violation.

private rights of action for consumers with damages $100-$750 per incident

Enforcement agencies

National data protection authorities (DPAs) in each EU member state

California Privacy Protection Agency (CPPA) and California Attorney General (CAG)

Last updated