facebook-pixel

GDPR vs CCPA: Understanding Your Privacy Rights in 2026

L
Lunyb Security Team
··10 min read

Data privacy laws now shape how nearly every online business collects, stores, and shares personal information. Two frameworks stand at the center of this shift: the European Union's General Data Protection Regulation (GDPR) and California's Consumer Privacy Act (CCPA), as expanded by the CPRA. Although both aim to give individuals more control over their data, they take very different approaches.

This guide breaks down GDPR vs CCPA in plain language, so you understand your rights as a consumer and your obligations as a business, no matter where you operate.

What Is the GDPR?

The General Data Protection Regulation is a European Union law that took effect on May 25, 2018. It governs how any organization, worldwide, handles the personal data of people located in the EU or European Economic Area.

The GDPR is built on seven core principles: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability. In practice, this means a business must have a legal reason to process data, collect only what it needs, keep it accurate, and delete it when it is no longer required.

Who Must Comply With the GDPR?

The GDPR applies to any organization that:

  1. Is established in the EU, regardless of where processing occurs.
  2. Offers goods or services to individuals in the EU, even for free.
  3. Monitors the behavior of people located in the EU (for example, through analytics or targeted advertising).

A small ecommerce site in Brazil that ships to customers in Germany, or a mobile app in Singapore that tracks users in France, both fall under the GDPR's reach.

What Is the CCPA (and CPRA)?

The California Consumer Privacy Act took effect on January 1, 2020, and was substantially expanded by the California Privacy Rights Act (CPRA) in 2023. Together they form the strongest state-level privacy law in the United States, giving California residents clear rights over how businesses collect and share their personal information.

The CCPA focuses on transparency and choice. It requires businesses to disclose what personal information they collect, why they collect it, and with whom they share it. Consumers can then ask to see the data, delete it, correct it, or opt out of its sale or sharing.

Who Must Comply With the CCPA?

The CCPA applies to for-profit businesses that do business in California and meet at least one of these thresholds:

  1. Annual gross revenue over $25 million.
  2. Buy, sell, or share personal information of 100,000 or more California consumers or households per year.
  3. Derive 50% or more of annual revenue from selling or sharing personal information.

GDPR vs CCPA: Side-by-Side Comparison

The clearest way to see the differences is to place the two frameworks side by side.

FeatureGDPRCCPA / CPRA
Region protectedEU and EEA residentsCalifornia residents
Who must complyAny organization processing EU personal dataFor-profit businesses meeting revenue or data thresholds
Legal basis requiredYes (six lawful bases, including consent)No prior legal basis required; opt-out model
Consent modelOpt-in (explicit, freely given)Opt-out (right to say no to sale/sharing)
Definition of personal dataVery broad; any identifiable infoBroad; tied to consumer or household
Right to accessYesYes
Right to deleteYes (right to erasure)Yes, with exceptions
Right to correctYesYes (added by CPRA)
Right to portabilityYesYes
Data Protection OfficerRequired in many casesNot required
Maximum fines€20 million or 4% of global revenue$7,500 per intentional violation
Private right of actionYes (broad)Limited (data breaches only)

Key Consumer Rights Under Each Law

Both laws give individuals a set of enforceable rights, but the scope and mechanics differ.

Rights Under the GDPR

  • Right to be informed: Clear notice about what data is collected and why.
  • Right of access: A copy of your personal data on request.
  • Right to rectification: Correction of inaccurate data.
  • Right to erasure ("right to be forgotten"): Deletion when data is no longer needed or consent is withdrawn.
  • Right to restrict processing: Pause processing in certain cases.
  • Right to data portability: Receive your data in a machine-readable format.
  • Right to object: Stop processing based on legitimate interests or direct marketing.
  • Rights around automated decisions: Human review of significant automated decisions, including profiling.

Rights Under the CCPA/CPRA

  • Right to know: What personal information is collected, used, shared, or sold.
  • Right to delete: Request deletion of personal information.
  • Right to correct: Fix inaccurate personal information.
  • Right to opt out: Say no to the sale or sharing of personal information.
  • Right to limit use of sensitive personal information: Restrict how data like geolocation, health, or biometric data is used.
  • Right to non-discrimination: Businesses cannot penalize you for exercising these rights.
  • Right to data portability: Receive data in a readily usable format.

The Biggest Practical Differences

Beyond the legal text, five practical distinctions matter most for businesses and consumers alike.

1. Opt-In vs Opt-Out

The GDPR generally requires opt-in consent before non-essential processing, especially for marketing cookies and profiling. The CCPA relies on an opt-out model: businesses can collect and share data by default, but consumers can tell them to stop.

2. Scope of "Personal Data"

The GDPR treats almost any information that can identify a person, directly or indirectly, as personal data, including IP addresses and cookie identifiers. The CCPA's definition is also broad but is tied to a "consumer" or "household," and excludes publicly available government records.

3. Legal Basis for Processing

Under the GDPR, every act of processing needs one of six legal bases: consent, contract, legal obligation, vital interests, public task, or legitimate interests. The CCPA does not require a specific legal basis; it focuses on transparency and honoring consumer requests.

4. Penalties and Enforcement

GDPR fines can reach €20 million or 4% of global annual turnover, whichever is higher. Regulators have already issued penalties in the hundreds of millions of euros. CCPA fines are capped at $2,500 per unintentional violation and $7,500 per intentional violation, plus statutory damages of $100 to $750 per consumer per incident for certain data breaches.

5. Data Protection Officers and Documentation

The GDPR often requires a Data Protection Officer, formal Records of Processing Activities, and Data Protection Impact Assessments for high-risk processing. The CCPA does not mandate a DPO but requires clear privacy notices, training for staff who handle consumer requests, and risk assessments under CPRA regulations.

How Businesses Can Comply With Both

Most organizations that must follow either law choose to build a single privacy program that satisfies the stricter requirements of both. Here is a practical roadmap.

  1. Map your data. Document what personal information you collect, where it comes from, where it flows, and how long you keep it.
  2. Update privacy notices. Publish a clear, layered privacy policy with all disclosures required by both laws, including categories of data, purposes, third parties, and consumer rights.
  3. Implement consent and opt-out tools. Use a compliant consent banner for EU visitors and a "Do Not Sell or Share My Personal Information" link for California residents, plus support for Global Privacy Control signals.
  4. Build a rights request workflow. Provide accessible channels (web form, email, toll-free number where required), verify identities, and respond within legal timelines (one month under the GDPR; 45 days under the CCPA).
  5. Sign proper contracts. Use Data Processing Agreements with vendors under the GDPR and Service Provider or Contractor agreements under the CCPA.
  6. Secure the data. Encrypt in transit and at rest, restrict access, and monitor for breaches. Have an incident response plan that meets the GDPR's 72-hour notification rule.
  7. Train your team. Privacy is only as strong as the humans handling data. Regular training reduces the risk of mistakes and fines.

Everyday Privacy: What Consumers Can Do

Understanding your legal rights is only half the story. You can also reduce how much data companies collect about you in the first place.

  • Read privacy notices before you sign up. Look for the sections on what is collected, who it is shared with, and how to opt out.
  • Turn on Global Privacy Control in browsers like Firefox, Brave, and DuckDuckGo. Many CCPA-covered businesses must honor this signal automatically.
  • Use encrypted DNS and privacy-focused browsers to limit tracking at the network and browser level.
  • Be careful with links. Malicious or over-tracked links are a common way personal data is harvested. When sharing links, use a trustworthy shortener such as Lunyb, which focuses on privacy-respecting redirects rather than aggressive tracking. You can read more in our honest review of Lunyb or compare options in our 2026 buyer's guide to URL shorteners.
  • Exercise your rights. Submit access and deletion requests to companies that hold your data. If you are an EU resident, you can also file complaints with your national data protection authority.

URL Shorteners, Marketing Links, and Privacy Law

Short links are a small but underestimated part of the compliance picture. Every click on a shortened link typically generates data: IP address, user agent, referrer, sometimes geolocation. Under the GDPR, that data is personal data. Under the CCPA, it can be personal information tied to a consumer.

If you run marketing campaigns, choose a link management platform that:

  • Discloses exactly what it logs and for how long.
  • Offers regional data storage where possible.
  • Signs a Data Processing Agreement.
  • Supports minimal or anonymized analytics.

For a deeper look at how commercial link platforms stack up on features and cost, see our 2026 Rebrandly review.

Other Privacy Laws to Watch

The GDPR and CCPA are the most influential, but they are far from alone. In the United States, states such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others have passed their own comprehensive privacy laws, most modeled loosely on the CCPA with some GDPR-style elements. Globally, Brazil's LGPD, the UK GDPR, Canada's PIPEDA (and the forthcoming CPPA), Japan's APPI, and India's DPDP Act all move in a similar direction.

The trend is clear: consent, transparency, minimization, and accountability are becoming the global default. Building your privacy program around the strictest requirements you face is the most future-proof approach.

Frequently Asked Questions

Is the GDPR stricter than the CCPA?

In most respects, yes. The GDPR requires an opt-in legal basis for most processing, mandates Data Protection Officers in many cases, imposes higher fines, and gives regulators broad enforcement powers. The CCPA is more consumer-notice and opt-out driven, though the CPRA has closed some of the gap.

Do small businesses have to comply with the GDPR or CCPA?

Small businesses processing EU personal data must comply with the GDPR regardless of size, although some obligations scale with risk and volume. The CCPA generally applies only to businesses meeting revenue or data thresholds, so many small US businesses fall outside its direct scope, but they may still be affected as service providers.

Can I be fined under both laws for the same incident?

Yes. If a data breach affects both EU and California residents, regulators in the EU and the California Privacy Protection Agency (or state attorney general) can pursue separate enforcement actions. Coordinated privacy programs and prompt notification reduce this risk.

What is Global Privacy Control and does it matter?

Global Privacy Control (GPC) is a browser signal that tells websites you opt out of the sale and sharing of your personal information. Under the CCPA, many businesses are required to honor it automatically. Turning it on in supported browsers is one of the easiest ways to exercise your rights at scale.

Do I need cookie banners under both laws?

Under the GDPR (combined with the ePrivacy Directive), you generally need an opt-in cookie banner for non-essential cookies. Under the CCPA, you need to offer an opt-out from the sale or sharing of personal information, which often takes the form of a "Do Not Sell or Share" link and a preference tool. Many businesses use a single consent management platform that handles both.

Final Thoughts

The GDPR and CCPA start from different philosophies, opt-in versus opt-out, comprehensive versus consumer-focused, but they arrive at similar destinations: giving individuals meaningful control over their personal data and forcing businesses to earn trust through transparency and good security practices.

Whether you are a consumer exercising your rights or a business building a compliance program, the practical answer is the same: adopt the strictest reasonable standard, minimize the data you collect, and treat privacy as a feature rather than a formality. In 2026 and beyond, that mindset is what will keep you both compliant and trusted.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles