GDPR vs CCPA: Understanding Your Privacy Rights in 2026
Data privacy is no longer a niche concern for lawyers and compliance officers—it affects every person who browses the web, clicks a link, or fills out an online form. Two laws stand at the center of the modern privacy landscape: the European Union's General Data Protection Regulation (GDPR) and California's Consumer Privacy Act (CCPA), as amended by the CPRA. Together, they shape how businesses worldwide handle personal information.
This guide breaks down the differences between GDPR and CCPA, explains the rights each grants you, and shows how to exercise them. Whether you're a consumer wanting to know what companies can do with your data, or a business trying to stay compliant, understanding these two frameworks is essential.
What Is GDPR?
The General Data Protection Regulation is a European Union law that took effect on May 25, 2018. It replaced the 1995 Data Protection Directive and established one of the world's strictest and most comprehensive privacy frameworks. GDPR applies to any organization—regardless of location—that processes the personal data of individuals in the EU or European Economic Area (EEA).
The regulation is built around a simple but powerful idea: personal data belongs to the individual, and organizations that handle it must do so lawfully, transparently, and with a legitimate purpose. Non-compliance can trigger fines of up to €20 million or 4% of a company's global annual turnover, whichever is higher.
Key Principles of GDPR
- Lawfulness, fairness, and transparency — data must be processed on a legal basis and communicated clearly.
- Purpose limitation — data collected for one purpose cannot be repurposed without consent.
- Data minimization — only the data strictly necessary should be collected.
- Accuracy — personal data must be kept up to date.
- Storage limitation — data should be kept only as long as needed.
- Integrity and confidentiality — data must be protected against unauthorized access.
- Accountability — organizations must be able to demonstrate compliance.
What Is CCPA (and CPRA)?
The California Consumer Privacy Act became effective on January 1, 2020, and was significantly expanded by the California Privacy Rights Act (CPRA), which took full effect on January 1, 2023. Together, these laws form the strongest state-level privacy framework in the United States and have influenced similar legislation in Virginia, Colorado, Connecticut, Utah, Texas, and beyond.
The CCPA gives California residents specific rights over the personal information that businesses collect about them. Unlike GDPR, which applies broadly to all organizations processing personal data, CCPA targets for-profit businesses that meet specific size or revenue thresholds.
Who Must Comply with CCPA?
A business is subject to CCPA if it does business in California and meets at least one of the following criteria:
- Has annual gross revenues over $25 million.
- Buys, sells, or shares the personal information of 100,000 or more California consumers or households.
- Derives 50% or more of its annual revenue from selling or sharing personal information.
GDPR vs CCPA: Side-by-Side Comparison
While both laws aim to protect personal data, they differ substantially in scope, definitions, and enforcement. The table below highlights the most important distinctions.
| Feature | GDPR | CCPA / CPRA |
|---|---|---|
| Jurisdiction | EU/EEA residents (global reach) | California residents |
| Who it protects | All natural persons in the EU | California consumers and households |
| Legal basis for processing | Required (consent, contract, legal obligation, etc.) | Not required; opt-out model |
| Consent model | Opt-in (explicit consent) | Opt-out (with opt-in for minors under 16) |
| Definition of personal data | Any info relating to an identified/identifiable person | Info that identifies, relates to, or could reasonably be linked to a consumer or household |
| Right to delete | Yes (right to erasure) | Yes, with more exceptions |
| Right to portability | Yes | Yes (limited) |
| Maximum penalties | €20 million or 4% of global turnover | $7,500 per intentional violation; $2,500 per unintentional |
| Enforcement authority | National Data Protection Authorities | California Privacy Protection Agency (CPPA) |
| Private right of action | Yes (broad) | Limited (data breaches only) |
Your Rights Under GDPR
GDPR grants eight fundamental rights to individuals, often referred to as "data subjects." These rights give people meaningful control over how their information is collected, used, and shared.
The Eight GDPR Rights
- Right to be informed — you must be told what data is collected and why.
- Right of access — you can request a copy of the data an organization holds about you.
- Right to rectification — you can have inaccurate data corrected.
- Right to erasure — also called the "right to be forgotten," letting you request deletion.
- Right to restrict processing — you can limit how your data is used.
- Right to data portability — you can receive your data in a machine-readable format.
- Right to object — you can object to certain uses like direct marketing.
- Rights related to automated decision-making — you can challenge decisions made solely by algorithms.
Your Rights Under CCPA/CPRA
The CCPA, expanded by CPRA, gives California residents a similar but narrower set of rights. The framework focuses on transparency and choice, rather than requiring a legal basis for every act of processing.
Core CCPA Rights
- Right to know — what personal information is collected, used, shared, or sold.
- Right to delete — request deletion of personal information a business has collected.
- Right to correct — introduced by CPRA, allows correction of inaccurate data.
- Right to opt out — of the sale or sharing of your personal information.
- Right to limit — the use and disclosure of "sensitive personal information."
- Right to non-discrimination — businesses cannot penalize you for exercising your rights.
- Right to data portability — receive your data in a usable format.
Consent: The Biggest Philosophical Difference
The most important distinction between GDPR and CCPA lies in how they treat consent. GDPR follows an opt-in model: organizations must obtain clear, affirmative permission before processing personal data (with some limited exceptions like contractual necessity or legal obligation). Pre-ticked boxes, silence, or inactivity do not count as consent.
CCPA takes the opposite approach, using an opt-out model. Businesses can collect and even sell personal information by default, but consumers have the right to say "do not sell my personal information." The only major exception involves minors under 16, who must opt in (or have a parent opt in for those under 13).
This distinction matters for both users and businesses. Europeans are asked to click through consent banners on nearly every website, while Californians typically need to actively seek out a "Do Not Sell" link—which the CPRA has made more prominent and standardized through the Global Privacy Control (GPC) signal.
What Counts as Personal Data?
Both laws define personal data broadly, but with important nuances.
GDPR Definition
GDPR defines personal data as "any information relating to an identified or identifiable natural person." This includes obvious identifiers like names and email addresses, but also IP addresses, cookie IDs, location data, biometric information, and even opinions. Special categories—such as health data, religious beliefs, and sexual orientation—receive heightened protection.
CCPA Definition
CCPA covers information that "identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household." Notably, it includes household data, which GDPR does not explicitly address. CPRA added a new category called "sensitive personal information" that includes Social Security numbers, precise geolocation, race, religion, and account credentials.
Penalties and Enforcement
The financial stakes for non-compliance are substantial under both regimes, but GDPR fines have historically been far larger.
GDPR Penalties
GDPR fines come in two tiers:
- Lower tier: up to €10 million or 2% of global annual turnover.
- Upper tier: up to €20 million or 4% of global annual turnover.
Major enforcement actions have included fines exceeding €1 billion against large technology companies for consent and data transfer violations.
CCPA Penalties
CCPA penalties are calculated per violation:
- $2,500 per unintentional violation.
- $7,500 per intentional violation or violation involving a minor.
While these numbers seem small, they multiply quickly when applied across thousands or millions of consumers. Additionally, consumers can sue directly following certain data breaches, with statutory damages of $100 to $750 per incident.
How to Exercise Your Privacy Rights
Whether you're covered by GDPR, CCPA, or both, the process for exercising your rights follows a similar pattern.
- Locate the privacy policy. Look for a link—usually in the website footer—titled "Privacy Policy," "Privacy Notice," or "Your Privacy Choices."
- Identify the request mechanism. Businesses must offer at least two methods, commonly a web form and an email address (e.g., privacy@company.com).
- Submit your request. Specify which right you're exercising: access, deletion, correction, opt-out, or portability.
- Verify your identity. Expect the business to ask for enough information to confirm you are who you claim to be.
- Wait for a response. GDPR requires a response within one month (extendable to three). CCPA allows 45 days (extendable to 90).
- Escalate if needed. File a complaint with your local Data Protection Authority (GDPR) or the California Privacy Protection Agency (CCPA) if the business fails to respond.
Practical Privacy Steps Beyond the Law
Legal rights are powerful, but proactive habits give you day-to-day protection. Consider the following:
- Use privacy-respecting tools. Choose browsers, search engines, and messaging apps that minimize data collection.
- Enable encrypted DNS. Services like DNS-over-HTTPS reduce network-level tracking.
- Audit app permissions regularly. Revoke access to your camera, microphone, and location for apps that don't need it.
- Be careful with links. Shortened URLs can hide malicious destinations. Use a trusted, transparent shortener like Lunyb that respects user privacy and offers link analytics without extensive tracking.
- Review third-party data brokers. Many services will delete your profile on request, and CCPA gives you the right to demand it.
If you frequently share links for work or content marketing, understanding how your shortener handles data matters just as much as the destination site. Our honest review of Lunyb and our 2026 URL shortener buyer's guide break down which providers take privacy seriously.
What Businesses Should Do
Companies operating internationally often adopt GDPR as their baseline standard because it is the strictest of the major frameworks. Meeting GDPR usually means you're most of the way to meeting CCPA. Key steps include:
- Map your data. Know exactly what personal information you collect, where it's stored, and who has access.
- Publish a clear privacy policy. Use plain language and cover all required disclosures.
- Implement consent and opt-out mechanisms. Support the Global Privacy Control signal and honor Do Not Sell requests.
- Establish a rights-request workflow. Assign a team or Data Protection Officer to handle access, deletion, and portability requests within legal deadlines.
- Vet your vendors. Third-party processors must offer equivalent protections.
- Prepare for breach response. GDPR requires notification within 72 hours of discovery.
The Growing Global Privacy Patchwork
GDPR and CCPA are the most influential privacy laws, but they're far from alone. Brazil's LGPD, the UK's post-Brexit DPA and UK GDPR, Canada's PIPEDA, and rapidly expanding state laws across the United States all draw inspiration from these two frameworks. The trend is unmistakable: consumer privacy rights are becoming the global norm, not the exception.
For individuals, this means more control than ever before. For businesses, it means privacy-by-design is no longer optional—it's a competitive necessity and a legal obligation.
Frequently Asked Questions
Does GDPR apply to U.S. companies?
Yes. GDPR applies to any organization anywhere in the world that offers goods or services to people in the EU/EEA or monitors their behavior. A U.S.-based e-commerce site that ships to Germany, or a SaaS product with European users, must comply.
Is CCPA stronger than GDPR?
No. GDPR is generally considered the stricter and more comprehensive of the two. It requires a lawful basis for all processing, uses an opt-in consent model, and carries larger potential fines. CCPA is narrower in scope and relies primarily on transparency and opt-out mechanisms.
Can I request deletion of my data from any company?
If you're a resident of the EU/EEA or California, yes—with some exceptions. Businesses can refuse deletion if the data is needed to complete a transaction, comply with a legal obligation, detect fraud, or exercise free speech. You must submit the request through the company's designated channels.
What happens if a company ignores my privacy request?
Under GDPR, you can file a complaint with your national Data Protection Authority, which has the power to investigate and impose fines. Under CCPA, you can report the violation to the California Privacy Protection Agency or the state Attorney General. In both cases, regulators take non-response seriously.
Do these laws protect me from data breaches?
They require companies to implement reasonable security measures and to notify you (and regulators) when breaches occur. Under CCPA, you can sue directly for statutory damages if a breach exposes your unencrypted personal information due to a company's failure to maintain reasonable security. GDPR mandates breach notification within 72 hours and can impose heavy fines for security failures.
Conclusion
GDPR and CCPA represent two different philosophies pointing toward the same goal: giving individuals meaningful control over their personal data. GDPR takes a rights-first, opt-in approach that applies broadly across the EU. CCPA takes a transparency-first, opt-out approach focused on California consumers. Understanding both frameworks helps you exercise your rights confidently—and helps businesses build the kind of trust that today's privacy-aware customers demand.
The best defense is a combination of legal knowledge and everyday privacy hygiene: know your rights, use tools that respect them, and don't hesitate to submit an access or deletion request when a company holds data you'd rather they didn't.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Do a Personal Data Audit: A Step-by-Step Guide for 2026
A personal data audit helps you find, control, and minimize the personal information scattered across the services you use. This 7-step guide shows you exactly how to run one in 2026, from inventorying accounts to opting out of data brokers.
Children's Online Privacy: A Parent's Guide for 2026
A practical children's online privacy guide for parents in 2026. Learn the laws, threats, tools, and age-appropriate strategies to protect kids across every device and platform they use — from smart toys to social media.
How Much Is Your Personal Data Worth in 2026? The Real Price Tag
Your personal data is worth pennies to advertisers but hundreds of dollars to criminals—and thousands per year in aggregate. Here's a breakdown of real 2026 prices on both legal and illegal markets, plus practical steps to reduce your exposure.
Cookie Consent Banners: Do They Actually Protect You?
Cookie consent banners promise privacy protection, but do they actually deliver? We explore how they work, the dark patterns that undermine them, and practical steps you can take in 2026 to genuinely control your online data.