facebook-pixel

GDPR vs CCPA: Understanding Your Privacy Rights in 2026

L
Lunyb Security Team
··11 min read

Data privacy laws have reshaped how companies collect, store, and use your personal information. Two regulations stand at the forefront of this transformation: the European Union's General Data Protection Regulation (GDPR) and California's Consumer Privacy Act (CCPA). While both aim to give you more control over your data, they take dramatically different approaches. Understanding the differences between GDPR vs CCPA is essential whether you're a consumer wanting to protect your rights or a business navigating compliance.

This guide breaks down both laws in plain language, compares their protections side by side, and shows you how to exercise the rights each one gives you.

What Is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive European Union privacy law that took effect on May 25, 2018. It governs how organizations anywhere in the world handle personal data belonging to individuals located in the EU or European Economic Area (EEA).

GDPR replaced the outdated 1995 Data Protection Directive and introduced a unified set of rules across all EU member states. Its scope is intentionally broad: any company that offers goods or services to EU residents, or that monitors their behavior, must comply, regardless of where the company is based.

Core Principles of GDPR

GDPR is built on seven guiding principles that organizations must follow:

  1. Lawfulness, fairness, and transparency - Data must be processed legally and openly.
  2. Purpose limitation - Data can only be used for specified, legitimate purposes.
  3. Data minimization - Only collect what is necessary.
  4. Accuracy - Personal data must be kept accurate and up to date.
  5. Storage limitation - Data should not be kept longer than needed.
  6. Integrity and confidentiality - Data must be secured against unauthorized access.
  7. Accountability - Organizations must demonstrate compliance.

What Is CCPA?

The California Consumer Privacy Act (CCPA) is a state-level privacy law that went into effect on January 1, 2020. It grants California residents specific rights regarding how businesses collect, use, and share their personal information. In 2023, the California Privacy Rights Act (CPRA) expanded and amended the CCPA, adding new protections and creating the California Privacy Protection Agency to enforce the law.

Unlike GDPR, CCPA applies only to for-profit businesses that meet certain thresholds: annual gross revenue over $25 million, buying or selling personal information of 100,000 or more consumers, or deriving 50% or more of annual revenue from selling personal information.

Consumer Rights Under CCPA

CCPA established several key rights for California residents:

  • The right to know what personal information is collected
  • The right to delete personal information
  • The right to opt out of the sale or sharing of personal information
  • The right to correct inaccurate personal information (added by CPRA)
  • The right to limit the use of sensitive personal information (added by CPRA)
  • The right to non-discrimination for exercising these rights

GDPR vs CCPA: Key Differences at a Glance

While both laws share the goal of protecting personal information, they differ significantly in scope, approach, and enforcement. The table below highlights the most important distinctions.

Feature GDPR CCPA/CPRA
Jurisdiction EU/EEA residents California residents
Who must comply Any organization processing EU data For-profit businesses meeting thresholds
Legal basis required Yes (six lawful bases) No explicit basis needed
Consent model Opt-in (explicit) Opt-out (for data sales)
Right to be forgotten Yes Yes (with more exceptions)
Data portability Yes Limited
Maximum penalty €20 million or 4% of global revenue $7,500 per intentional violation
Data Protection Officer Required in many cases Not required
Breach notification Within 72 hours No specific timeline (state law separately)
Private right of action Yes, broadly Limited to certain data breaches

Scope and Territorial Reach

One of the most striking differences between the two laws is who they protect and where they apply. GDPR has a global footprint. If your business processes the personal data of anyone physically located in the EU, you must comply, even if your company operates entirely from another continent. This extraterritorial reach has forced companies worldwide to adopt GDPR-compliant practices.

CCPA, by contrast, applies only to California residents and only to businesses meeting specific size or revenue thresholds. Small businesses that don't collect large amounts of consumer data may fall outside its scope entirely. However, because California is the world's fifth-largest economy, CCPA has effectively become a national benchmark, prompting similar laws in Virginia, Colorado, Connecticut, Utah, Texas, and other states.

The Consent Question: Opt-In vs Opt-Out

Perhaps the most consequential philosophical difference between GDPR and CCPA is how they handle consent.

GDPR: Opt-In by Default

GDPR requires companies to obtain clear, affirmative consent before processing personal data in most cases. Pre-ticked boxes, silence, or inactivity do not count as consent. Users must actively agree, and they must be able to withdraw that consent as easily as they gave it. This is why you see cookie banners across European websites asking for explicit permission before tracking.

CCPA: Opt-Out by Default

CCPA takes the opposite approach. Businesses can generally collect and use personal information without prior consent, but consumers have the right to opt out of the sale or sharing of their data. The law requires businesses to provide a clear "Do Not Sell or Share My Personal Information" link on their websites. For sensitive personal information and minors under 16, CPRA introduced additional opt-in requirements.

How Personal Information Is Defined

Both laws define personal information broadly, but with slightly different framings.

GDPR defines "personal data" as any information relating to an identified or identifiable natural person. This includes obvious identifiers like names and email addresses, but also IP addresses, cookie IDs, location data, and biometric information. GDPR also identifies "special categories" of sensitive data, including race, religion, health information, and sexual orientation, which require heightened protection.

CCPA defines "personal information" as data that identifies, relates to, describes, or could reasonably be linked with a particular consumer or household. Notably, CCPA includes household-level data, which GDPR does not explicitly cover. CPRA added a category called "sensitive personal information" that gives consumers additional control over items like Social Security numbers, precise geolocation, and financial account details.

Penalties and Enforcement

The financial consequences of non-compliance differ dramatically between the two regimes.

Under GDPR, regulators can impose fines up to €20 million or 4% of a company's global annual revenue, whichever is higher. Major companies have faced multi-hundred-million-euro fines for violations involving inadequate consent, insufficient security, or improper cross-border data transfers.

CCPA penalties are more modest: $2,500 per unintentional violation and $7,500 per intentional violation or violation involving minors. However, these can add up quickly when violations affect thousands of consumers. CCPA also grants consumers a limited private right of action, meaning individuals can sue businesses directly for certain data breaches, potentially recovering $100 to $750 per incident.

Rights Comparison: What You Can Actually Do

Both laws empower individuals with specific rights, but the details vary.

Rights Available Under Both Laws

  • Right to access - Request a copy of the data collected about you
  • Right to deletion - Ask companies to erase your data
  • Right to correction - Fix inaccurate information
  • Right against discrimination - Not be penalized for exercising rights

Rights Unique to GDPR

  • Right to data portability - Receive data in a machine-readable format and transfer it to another service
  • Right to object - Refuse specific types of processing, including direct marketing
  • Right against automated decision-making - Not be subject to purely automated decisions with legal effects

Rights Unique to CCPA/CPRA

  • Right to opt out of sale or sharing - Prevent businesses from selling your data
  • Right to limit use of sensitive personal information - Restrict how sensitive data is used beyond necessary purposes

How to Exercise Your Privacy Rights

Knowing your rights is only half the battle. Here's a practical process for exercising them under either law:

  1. Identify the company - Determine which businesses hold your data. Check emails, account settings, and privacy policies.
  2. Find the privacy contact - Look for a "Privacy" link in the footer of the website, a dedicated privacy portal, or a Data Protection Officer's email.
  3. Submit a formal request - Most companies offer a webform for access, deletion, or opt-out requests. Include your identifying information and specify the right you're exercising.
  4. Verify your identity - Businesses will usually require identity verification to prevent fraud.
  5. Track the response - GDPR requires responses within 30 days (extendable to 90 in complex cases). CCPA requires 45 days (extendable to 90).
  6. Escalate if needed - If a company ignores your request, file a complaint with the relevant Data Protection Authority (in the EU) or the California Privacy Protection Agency.

Practical Steps to Protect Your Data

Beyond legal rights, you can take proactive measures to safeguard your privacy online:

  • Use privacy-focused tools - Choose browsers, search engines, and services that minimize data collection. For example, when sharing links, a privacy-conscious URL shortener like Lunyb avoids the invasive tracking practices found in some mainstream alternatives.
  • Review privacy settings regularly - Social media platforms, mobile apps, and cloud services frequently update their settings. Audit them at least twice a year.
  • Limit third-party cookies - Configure your browser to block or restrict cross-site tracking.
  • Use encrypted DNS - Services like DNS over HTTPS prevent your internet provider from easily logging every domain you visit.
  • Read privacy policies - At least skim them before signing up for new services. Look for what data is collected, how long it's kept, and who it's shared with.
  • Minimize account creation - Use guest checkout, disposable email addresses, and secondary accounts when possible.

If you frequently share links across social media or in professional communications, consider tools that respect your audience's privacy. Our comprehensive guide to the best URL shorteners covers which services minimize data collection and which ones treat your links as tracking opportunities.

The Convergence of Global Privacy Laws

GDPR and CCPA are only the two most well-known privacy regulations. A growing patchwork of similar laws is emerging worldwide: Brazil's LGPD, Canada's PIPEDA (currently being modernized), Japan's APPI, South Africa's POPIA, and India's Digital Personal Data Protection Act, among others. Most borrow heavily from the GDPR framework while adapting to local contexts.

For businesses, this means privacy compliance is becoming increasingly complex. Many organizations now aim to meet the strictest applicable standard (usually GDPR) across all their operations, creating a de facto global baseline. For consumers, it means your privacy rights are strengthening year over year, no matter where you live.

Which Law Protects You Better?

The honest answer is that GDPR provides stronger, broader protections. Its opt-in consent model, higher penalties, wider scope of rights, and stricter security requirements make it the gold standard for privacy law. CCPA has narrower thresholds, weaker penalties, and an opt-out model that places more burden on consumers.

That said, CCPA and its CPRA amendments represent a major step forward for privacy in the United States, and they continue to evolve. If you're a California resident, you enjoy protections that most Americans don't. If you're an EU resident, you have some of the strongest privacy rights in the world.

The best approach for anyone concerned about privacy is to understand and exercise the rights available to you, choose services that respect your data by default, and support the broader movement toward stronger privacy protections everywhere.

Frequently Asked Questions

Do businesses need to comply with both GDPR and CCPA?

Yes, if a business processes data from both EU and California residents and meets the applicable thresholds, it must comply with both laws. Most global companies implement a unified privacy program that meets the strictest requirements across all their operations, typically using GDPR as the baseline.

Can I request my data from a company under both laws?

Yes. Both GDPR and CCPA give you the right to access personal data a company holds about you. Under GDPR, companies must respond within 30 days. Under CCPA, they have 45 days. You typically submit these requests through a privacy portal on the company's website or by emailing their privacy team.

What is the biggest difference between GDPR and CCPA?

The most fundamental difference is the consent model. GDPR requires explicit opt-in consent before most data processing can begin, while CCPA allows data collection by default and gives consumers the right to opt out of data sales. This reflects different philosophical approaches to privacy: GDPR treats it as a fundamental right, while CCPA treats it as a consumer protection issue.

Does GDPR apply to US companies?

Yes. GDPR applies to any organization, anywhere in the world, that offers goods or services to people in the EU or monitors their behavior. A US company with even a small European customer base must comply. This extraterritorial reach is one of the reasons GDPR has had such a global impact on privacy practices.

How do I file a complaint if a company violates my privacy rights?

Under GDPR, you can file a complaint with the Data Protection Authority in your EU member state. Each country has its own regulator (for example, the CNIL in France or the ICO in the UK, which follows a similar framework post-Brexit). Under CCPA, you can file a complaint with the California Privacy Protection Agency or the California Attorney General's office. For certain data breaches, you may also have the right to sue directly.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles