facebook-pixel

GDPR vs CCPA: Understanding Your Privacy Rights in 2026

L
Lunyb Security Team
··9 min read

Data privacy is no longer a niche legal topic — it's a global business imperative. Two laws dominate the conversation: the European Union's General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), now expanded by the California Privacy Rights Act (CPRA). If you run a website, market to customers online, or simply want to understand what rights you have over your personal data, knowing the difference between GDPR and CCPA is essential.

This guide breaks down both laws, compares them side by side, explains your rights as a consumer, and outlines what businesses must do to stay compliant.

What Is the GDPR?

The General Data Protection Regulation (GDPR) is a European Union law that took effect on May 25, 2018. It governs how organizations collect, store, process, and share the personal data of individuals located in the EU and European Economic Area (EEA).

GDPR is widely considered the most comprehensive privacy law in the world. It applies to any organization — regardless of where it's based — that processes the personal data of EU residents. That extraterritorial reach means a small e-commerce shop in Brazil selling to French customers must comply, just as a Silicon Valley tech giant must.

Core Principles of GDPR

  • Lawfulness, fairness, and transparency — data must be processed legally and openly.
  • Purpose limitation — data collected for one reason can't be repurposed without consent.
  • Data minimization — only collect what you actually need.
  • Accuracy — data must be kept up to date.
  • Storage limitation — don't keep data longer than necessary.
  • Integrity and confidentiality — protect data with appropriate security.
  • Accountability — organizations must demonstrate compliance.

What Is the CCPA (and CPRA)?

The California Consumer Privacy Act (CCPA) took effect on January 1, 2020, and was significantly strengthened by the California Privacy Rights Act (CPRA), which became fully enforceable on July 1, 2023. Together, they form the strongest state-level privacy law in the United States.

The CCPA gives California residents specific rights over their personal information and requires businesses to disclose what data they collect and how it's used. Unlike GDPR, it's not a nationwide U.S. law — it applies only to California residents — but its influence has been enormous, inspiring similar laws in Virginia, Colorado, Connecticut, Utah, Texas, and beyond.

Who Must Comply With CCPA?

The CCPA applies to for-profit businesses that do business in California and meet at least one of these thresholds:

  1. Have annual gross revenue over $25 million.
  2. Buy, sell, or share the personal information of 100,000 or more California consumers or households.
  3. Derive 50% or more of annual revenue from selling or sharing consumers' personal information.

GDPR vs CCPA: Side-by-Side Comparison

While both laws aim to protect personal data, they differ significantly in scope, definitions, and enforcement. Here's a direct comparison:

FeatureGDPRCCPA / CPRA
JurisdictionEU / EEA residentsCalifornia residents
Effective DateMay 25, 2018Jan 1, 2020 (CPRA: July 1, 2023)
Who It Applies ToAny organization processing EU personal dataBusinesses meeting revenue/data thresholds
Legal Basis RequiredYes — six lawful bases (consent, contract, etc.)No — notice-based model
Opt-in vs Opt-outOpt-in for most processingOpt-out of sale/sharing
Right to AccessYesYes
Right to DeleteYes (right to erasure)Yes
Right to PortabilityYesYes
Right to CorrectYesYes (added by CPRA)
Data Protection OfficerRequired in many casesNot required
Maximum Penalty€20M or 4% of global revenue$7,500 per intentional violation
Private Right of ActionYes (limited)Yes (for data breaches only)

Key Differences Explained

1. Consent Model: Opt-In vs Opt-Out

The most fundamental difference is philosophical. GDPR is an opt-in regime — companies generally can't process personal data unless they have a valid legal basis, most commonly explicit consent. Pre-ticked boxes and vague terms don't cut it.

The CCPA takes an opt-out approach. Businesses can collect and even sell your personal information by default, but they must give you a clear way to say "no." That's why you see "Do Not Sell or Share My Personal Information" links on many U.S. websites.

2. Definition of Personal Data

Both laws define personal data broadly, but with different nuances. GDPR defines it as "any information relating to an identified or identifiable natural person." This covers names, email addresses, IP addresses, cookie IDs, location data, and even inferences drawn about you.

CCPA's definition is similarly broad and explicitly includes household-level information, browsing history, purchase records, and inferred characteristics. The CPRA also introduced a new category: sensitive personal information, which includes precise geolocation, race, religion, health data, and financial account details.

3. Enforcement and Penalties

GDPR fines can be enormous. Regulators can impose penalties up to €20 million or 4% of a company's global annual turnover — whichever is higher. Amazon, Meta, and Google have all faced fines in the hundreds of millions of euros.

CCPA penalties are lower per violation ($2,500 for unintentional, $7,500 for intentional), but they can add up quickly when a violation affects thousands of consumers. The California Privacy Protection Agency (CPPA), established by CPRA, actively enforces the law.

4. Data Breach Notification

Under GDPR, organizations must notify the relevant supervisory authority within 72 hours of becoming aware of a breach that risks individuals' rights. Affected individuals must also be informed if the risk is high.

CCPA doesn't impose a strict 72-hour rule, but California's separate breach notification law requires notice "in the most expedient time possible and without unreasonable delay." The CCPA also gives consumers a private right of action to sue for statutory damages ($100–$750 per incident) after certain breaches.

Your Rights Under GDPR

If you're in the EU or EEA, GDPR grants you eight explicit rights:

  1. Right to be informed — know what data is collected and why.
  2. Right of access — request a copy of your data.
  3. Right to rectification — correct inaccurate data.
  4. Right to erasure — the "right to be forgotten."
  5. Right to restrict processing — pause how your data is used.
  6. Right to data portability — receive your data in a usable format.
  7. Right to object — refuse certain uses like direct marketing.
  8. Rights related to automated decision-making — including profiling.

Your Rights Under CCPA/CPRA

California residents have the following rights:

  1. Right to know — what personal information is collected, used, shared, or sold.
  2. Right to delete — request deletion of personal information.
  3. Right to correct — fix inaccurate information (added by CPRA).
  4. Right to opt out of sale or sharing — including for targeted advertising.
  5. Right to limit use of sensitive personal information — a CPRA addition.
  6. Right to non-discrimination — businesses can't punish you for exercising these rights.
  7. Right to data portability — receive your data in a portable format.

How to Exercise Your Privacy Rights

Whether you're covered by GDPR, CCPA, or both, exercising your rights follows a similar process:

  1. Identify the company holding your data (data controller under GDPR, business under CCPA).
  2. Locate their privacy contact — usually in the privacy policy or a dedicated privacy portal.
  3. Submit a verifiable request — you may need to prove your identity.
  4. Wait for a response — GDPR requires a reply within one month; CCPA within 45 days.
  5. Escalate if needed — file a complaint with the relevant supervisory authority (EU DPA or CPPA).

Compliance Checklist for Businesses

If you operate a website or online service that reaches EU or California users, use this checklist:

  • Publish a clear, plain-language privacy policy.
  • Implement a compliant cookie consent banner (opt-in for GDPR).
  • Provide a "Do Not Sell or Share My Personal Information" link for California users.
  • Establish a process for handling data subject requests.
  • Maintain records of processing activities (GDPR Article 30).
  • Appoint a Data Protection Officer if required.
  • Use data processing agreements with vendors.
  • Encrypt sensitive data in transit and at rest.
  • Train employees on privacy fundamentals.
  • Conduct Data Protection Impact Assessments (DPIAs) for high-risk processing.

Privacy-First Tools and Practices

Compliance isn't just about paperwork — it's about the tools you use. When choosing services for analytics, email marketing, or link management, look for providers that support privacy by design. For example, when sharing links across channels, using a privacy-conscious URL shortener like Lunyb helps you avoid unnecessary tracking pixels and third-party data leakage. You can read our honest review of Lunyb or compare options in our 2026 buyer's guide to URL shorteners.

For enterprise teams weighing branded link platforms, our Rebrandly review also covers compliance-relevant features like custom domains and data residency.

The Global Trend: More Privacy Laws Are Coming

GDPR and CCPA are just the beginning. Brazil's LGPD, Canada's PIPEDA (and forthcoming CPPA), the UK GDPR, China's PIPL, India's DPDP Act, and a growing wave of U.S. state laws all reflect the same reality: consumers expect control over their data, and regulators are responding.

The smart approach for businesses is to build to the highest common standard — usually GDPR — and layer regional adjustments on top. For consumers, understanding your rights under both frameworks helps you push back when companies overstep.

Frequently Asked Questions

Does GDPR apply to U.S. companies?

Yes, if a U.S. company offers goods or services to EU residents or monitors their behavior (for example, through cookies and analytics), it must comply with GDPR — regardless of where the company is headquartered.

Is CCPA stricter than GDPR?

No. GDPR is generally considered stricter because it requires a lawful basis for processing, uses an opt-in consent model, and carries much higher potential fines. CCPA is more permissive but still substantial, especially with CPRA additions.

Can I be fined under both GDPR and CCPA at the same time?

Yes. If your business collects data from both EU residents and California consumers and violates both laws, you can face parallel enforcement actions from EU data protection authorities and the California Privacy Protection Agency.

What is the difference between a data controller and a data processor?

Under GDPR, a controller decides why and how personal data is processed, while a processor handles data on the controller's behalf (like a cloud vendor). CCPA uses "business" and "service provider" for roughly equivalent roles, with slightly different obligations.

Do I need cookie consent under CCPA?

CCPA doesn't require opt-in cookie consent the way GDPR does. However, if cookies are used to "sell" or "share" personal information (including for targeted advertising), you must give California users a clear opt-out mechanism, typically via a "Do Not Sell or Share" link and honoring the Global Privacy Control signal.

Final Thoughts

GDPR and CCPA represent two different philosophies of privacy protection — one built on affirmative consent, the other on transparency and opt-out. Both give individuals meaningful power over their personal data, and both impose real obligations on businesses.

Whether you're a consumer wanting to reclaim your data or a business trying to stay compliant, the fundamentals are the same: know what data is being collected, understand why, and make sure the people it belongs to have real control. In a world where data breaches and surveillance are daily news, that's not just a legal requirement — it's the foundation of digital trust.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles