GDPR gives people broader privacy rights, while CCPA gives California residents strong consumer rights focused on access, deletion, correction, and opting out of sale or sharing. A company that handles personal data across the EU and California should treat GDPR as the stricter baseline, then add CCPA-specific notices and opt-out controls.
TLDR: GDPR usually offers more control over how personal data is collected, used, stored, and challenged. CCPA, updated by CPRA, is narrower but more direct for California consumers, especially when data is sold or shared for advertising. For example, if a retailer receives 1,000 privacy requests in a quarter, it may need to answer EU requests within one month under GDPR and California requests within 45 days under CCPA. The practical fix is simple: clear request forms, identity checks, and a reliable data map.
GDPR vs CCPA: The Core Difference
The General Data Protection Regulation, or GDPR, applies to personal data linked to people in the European Union and European Economic Area. It focuses on lawful processing, transparency, data minimization, security, and individual control.
The California Consumer Privacy Act, or CCPA, as amended by the California Privacy Rights Act, applies to many for-profit businesses that handle personal information of California residents. It focuses on consumer notice, access, deletion, correction, and the right to opt out of sale or sharing.
The catch is that both laws sound similar on a website privacy page. In practice, they are not the same. GDPR asks, “What legal basis allows this use of data?” CCPA often asks, “Was the consumer told, and can the consumer stop certain uses?”
Who Is Protected?
Under GDPR, the protected person is called a data subject. This may include customers, employees, job applicants, website visitors, and users of apps or platforms. GDPR can apply even when a business is outside Europe, if it offers goods or services to people in the EU or monitors their behavior.
Under CCPA, the protected person is a California consumer. This includes California residents acting as customers, employees, applicants, or business contacts. CCPA usually applies to for-profit businesses that meet certain thresholds, such as annual gross revenue over $25 million, handling personal information of 100,000 or more consumers or households, or earning at least 50% of revenue from selling or sharing personal information.
Main GDPR Data Subject Rights
GDPR rights are broad and detailed. They include:
- Right to be informed: The person must receive clear details about data collection and use.
- Right of access: The person can ask for a copy of personal data and processing details.
- Right to rectification: Incorrect or incomplete data must be corrected.
- Right to erasure: Also called the right to be forgotten, this allows deletion in certain cases.
- Right to restrict processing: The person can ask an organization to pause certain data use.
- Right to data portability: The person can receive data in a usable format and move it elsewhere.
- Right to object: The person can object to direct marketing or certain processing based on legitimate interests.
- Rights over automated decisions: The person can challenge certain decisions made only by automated processing.
Main CCPA Privacy Rights
CCPA rights are also strong, but they are framed around consumer control. They include:
- Right to know: A consumer can ask what personal information is collected, used, sold, shared, or disclosed.
- Right to access: A consumer can request specific pieces of personal information held by the business.
- Right to delete: A consumer can ask a business to delete personal information, subject to exceptions.
- Right to correct: A consumer can ask for inaccurate personal information to be fixed.
- Right to opt out: A consumer can opt out of the sale or sharing of personal information.
- Right to limit sensitive data use: A consumer can restrict certain uses of sensitive personal information.
- Right against retaliation: A business cannot punish a consumer for using CCPA rights.
It drives privacy teams crazy that one broken data inventory can add days to a basic request. If customer data sits in five systems, and one export takes 20 seconds longer than expected each time, bulk requests become slow, messy, and risky.
Response Deadlines and Process
GDPR requires a response without undue delay and usually within one month. That period can be extended by two more months for complex or numerous requests. The organization must tell the person about the delay and explain why.
CCPA gives businesses 45 days to respond to a verifiable consumer request. A business may take another 45 days when needed, but it must notify the consumer. CCPA also requires specific methods for submitting requests, often including a web form and another contact method.
Both laws allow identity verification. That sounds simple, but poor verification creates trouble. Too little checking may expose data to the wrong person. Too much checking may block valid requests and annoy people who only want a copy of their account history.
Legal Basis vs Opt Out
One of the biggest GDPR differences is the need for a legal basis. A company must identify why it is allowed to process personal data. Common legal bases include consent, contract, legal obligation, vital interests, public task, and legitimate interests.
CCPA does not require the same legal basis structure. It relies more on notice and consumer choice. The business must explain categories of personal information, purposes of use, retention details, and whether information is sold or shared.
This means GDPR may stop a data use before it starts if no valid legal basis exists. CCPA may allow the use, but require notice and a working opt-out for sale or sharing.
Sensitive Data Rules
GDPR uses the term special categories of personal data. This includes health data, biometric data, political opinions, religion, trade union membership, genetic data, and data about sex life or sexual orientation. Processing this data is generally restricted unless a specific exception applies.
CCPA uses sensitive personal information. This may include precise geolocation, Social Security numbers, financial account details, union membership, health information, biometric information, and certain communications. Consumers can limit some uses and disclosures of this data.
Business Impact
For global businesses, GDPR often sets the stricter internal standard. It demands privacy by design, records of processing, processor contracts, data protection impact assessments in higher-risk cases, and tighter rules on international transfers.
CCPA adds its own operational duties. Businesses need clear “Do Not Sell or Share My Personal Information” links when required. They also need updated privacy notices, vendor terms, and tracking technology reviews. Advertising cookies and pixels can trigger CCPA sharing issues, which many teams miss until a scan flags them.
Practical Comparison
| Issue | GDPR | CCPA |
|---|---|---|
| Protected person | EU or EEA data subject | California resident |
| Main focus | Lawful processing and individual rights | Consumer notice, access, deletion, and opt out |
| Response time | Usually one month | Usually 45 days |
| Opt out | Strong objection rights, especially for marketing | Specific opt out for sale or sharing |
| Deletion | Available in several cases | Available, with business exceptions |
Best Practice for Organizations
A sound privacy rights program should not treat GDPR and CCPA as copy-and-paste laws. The better approach is to create one intake process, then apply region-specific rules behind the scenes.
- Map personal data by system, purpose, owner, and retention period.
- Use plain request forms for access, deletion, correction, and opt-outs.
- Track deadlines from the day the request arrives.
- Train support teams to spot privacy requests in emails and chats.
- Review vendors that store, analyze, sell, or share personal information.
- Keep proof of responses, verification steps, and exceptions used.
FAQ
Is GDPR stricter than CCPA?
Usually, yes. GDPR has broader rules on lawful processing, consent, international transfers, and individual rights. CCPA is still serious, especially for sale, sharing, sensitive data, and consumer requests.
Can one privacy form cover both GDPR and CCPA?
Yes, if it is built well. The form can collect the request type and location, then route the request under the correct law.
Does CCPA have a right to be forgotten?
CCPA has a right to delete, but it is not identical to GDPR’s right to erasure. Both laws include exceptions that may allow a business to keep some data.
Does GDPR apply to a United States company?
Yes, if the company offers goods or services to people in the EU or monitors their behavior. Physical location is not the only factor.
What is the safest starting point for compliance?
The safest start is a data inventory. If a business cannot find personal data, it cannot answer access, deletion, correction, or opt-out requests on time.
