GDPR vs. CCPA
Contents
Key differences
The GDPR is stricter and has far greater penalties for non-compliance
Comparison table
Primary regulator
European Data Protection Board (EDPB)
California Privacy Protection Agency (CPPA)
Data subjects
EU residents
California Residents
Who must comply?
Any business or individual handling the data of EU residents.
The business may be incorporated outside the EU.
For-profit businesses trading in California which either:
Have gross annual revenue in excess of $25 million; OR
Buy, sell, or share the PI of 100,000 or more California residents/ households; OR
Derive 50% or more of their annual revenue from selling California residents’ PI.
The business may be incorporated outside California.
How is ‘personal data’/ ‘personal information’ defined?
Personal data:
“Any information relating to an identified or identifiable natural person (‘data subject’)” (GDPR)
Personal information:
“Information that identifies, relates to, or could reasonably be linked with you or your household.” (CCPA)
It does not include publicly available information.
How is ‘sensitive’ personal data/ information’ defined?
Full list in legislation
Includes genetic, biometric and health data, as well as personal data revealing racial and ethnic origin, political opinions, religious or ideological convictions or trade union membership.
Full list in legislation.
Includes certain government identifiers (such as social security numbers)’ and contents of mail, email, and text messages.
Approach to consent
Opt-in system
Opt-out system
Penalties
Up to €20 million or 4% of global annual turnover
Up to $2,500 per violation; and $7,500 per ‘intentional’ violation.
private rights of action for consumers with damages $100-$750 per incident
Enforcement agencies
National data protection authorities (DPAs) in each EU member state
California Privacy Protection Agency (CPPA) and California Attorney General (CAG)
Last updated

