facebook-pixel

GDPR vs CCPA: Understanding Your Privacy Rights in 2026

L
Lunyb Security Team
··9 min read

Data privacy laws have reshaped how businesses collect, store, and use personal information. Two of the most influential regulations in the world are the European Union's General Data Protection Regulation (GDPR) and California's Consumer Privacy Act (CCPA). While both aim to give individuals more control over their personal data, they take different approaches, cover different populations, and impose different obligations on businesses.

This guide breaks down GDPR vs CCPA in plain language, so you understand your rights as a consumer and your responsibilities as a business owner or developer.

What Is the GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive European Union privacy law that took effect on May 25, 2018. It governs how any organization—regardless of location—collects, processes, and stores personal data belonging to individuals in the EU and European Economic Area.

The GDPR replaced the older 1995 Data Protection Directive and is widely considered the strictest data privacy framework in the world. It applies extraterritorially: a small e-commerce store in Brazil that ships to customers in Germany must comply, just as much as a Fortune 500 company headquartered in Paris.

Core Principles of GDPR

  • Lawfulness, fairness, and transparency — data must be processed legally and openly.
  • Purpose limitation — data can only be collected for specified, explicit purposes.
  • Data minimization — only collect what is necessary.
  • Accuracy — keep personal data up to date.
  • Storage limitation — don't keep data longer than needed.
  • Integrity and confidentiality — secure the data properly.
  • Accountability — organizations must demonstrate compliance.

What Is the CCPA?

The California Consumer Privacy Act (CCPA) is a state-level privacy law that took effect on January 1, 2020, and was significantly expanded by the California Privacy Rights Act (CPRA) in 2023. It gives California residents specific rights over their personal information and applies to for-profit businesses that meet certain thresholds.

Unlike the GDPR, the CCPA is narrower in geographic scope (only California residents), but it introduced landmark consumer rights in the United States and has inspired similar laws in Virginia, Colorado, Connecticut, Utah, and beyond.

Who Must Comply with CCPA?

A business is subject to the CCPA if it does business in California and meets at least one of the following:

  1. Has annual gross revenue over $25 million.
  2. Buys, sells, or shares personal information of 100,000 or more California consumers or households.
  3. Derives 50% or more of annual revenue from selling or sharing personal information.

GDPR vs CCPA: Side-by-Side Comparison

The clearest way to understand the differences is to look at the two laws head-to-head across key dimensions.

FeatureGDPRCCPA/CPRA
JurisdictionEU/EEA residents (global reach)California residents only
Effective dateMay 25, 2018Jan 1, 2020 (CPRA amendments 2023)
Who it applies toAny organization processing EU personal dataFor-profit businesses meeting revenue/data thresholds
Legal basis for processingRequired (consent, contract, legal obligation, etc.)Not required; opt-out model
Consent modelOpt-in (explicit)Opt-out (except for minors)
Right to deleteYes (right to erasure)Yes, with exceptions
Right to accessYesYes
Right to portabilityYesYes
Right to correctYesYes (added by CPRA)
Data Protection OfficerRequired in many casesNot required
Maximum fine€20 million or 4% of global revenue$7,500 per intentional violation
Private right of actionYes (broad)Limited (data breach only)

Key Differences Explained

1. Opt-In vs Opt-Out Consent

This is arguably the most important philosophical difference. The GDPR requires businesses to obtain explicit, informed opt-in consent before processing most personal data. Pre-ticked boxes and passive acceptance don't count.

The CCPA takes an opt-out approach: businesses can collect and even sell data by default, but they must offer consumers a clear "Do Not Sell or Share My Personal Information" link and honor that request.

2. Definition of Personal Data

Both laws define personal information broadly, but the GDPR's definition is considered wider. GDPR covers any information relating to an identified or identifiable natural person—including online identifiers like IP addresses, cookies, and device IDs.

The CCPA also includes household-level data and inferences drawn from personal information to create consumer profiles, which is a distinctive feature.

3. Penalties and Enforcement

GDPR fines can be enormous—up to €20 million or 4% of a company's worldwide annual revenue, whichever is higher. Meta, Amazon, and Google have all been hit with fines exceeding hundreds of millions of euros.

CCPA fines are calculated per violation: $2,500 per unintentional violation and $7,500 per intentional violation or violation involving minors. While smaller per incident, they can add up quickly across millions of affected consumers.

4. Private Right of Action

Under the CCPA, consumers can only sue businesses directly in the event of a data breach caused by inadequate security. Under the GDPR, individuals have broader rights to seek compensation for material and non-material damages, including emotional distress.

Your Rights as a Consumer

Whether you live in the EU or California, you have meaningful control over your personal data. Here's what you can request from any covered business.

Rights Under GDPR

  1. Right to be informed — know what data is collected and why.
  2. Right of access — get a copy of your personal data.
  3. Right to rectification — correct inaccurate data.
  4. Right to erasure — request deletion ("right to be forgotten").
  5. Right to restrict processing — limit how your data is used.
  6. Right to data portability — receive your data in a machine-readable format.
  7. Right to object — opt out of marketing and certain processing.
  8. Rights related to automated decision-making — including profiling.

Rights Under CCPA/CPRA

  1. Right to know what personal information is collected, used, shared, or sold.
  2. Right to delete personal information held by a business.
  3. Right to correct inaccurate personal information.
  4. Right to opt out of the sale or sharing of personal information.
  5. Right to limit use of sensitive personal information (e.g., health, precise geolocation).
  6. Right to non-discrimination for exercising these rights.

How to Exercise Your Privacy Rights

Requesting your data or asking a company to delete it is easier than most people think. Here's a general process that works under both laws:

  1. Find the privacy policy — every covered business must publish one with contact information.
  2. Look for a privacy request form — most large companies have a self-service portal.
  3. Submit your request in writing — email, form, or postal mail. Specify which right you're exercising.
  4. Verify your identity — the business will usually confirm you are who you claim to be.
  5. Wait for a response — GDPR requires a response within 30 days; CCPA within 45 days (extendable).
  6. Escalate if ignored — file a complaint with the relevant data protection authority (your EU country's regulator, or the California Privacy Protection Agency).

What Businesses Need to Do

If you run an online business, blog, or even a personal project that collects visitor data, you may fall under one or both laws. Here's a practical checklist.

Compliance Checklist

  • Publish a clear, accessible privacy policy.
  • Map all the personal data you collect and where it flows.
  • Implement consent banners for cookies and tracking (opt-in for GDPR, opt-out for CCPA).
  • Provide a "Do Not Sell or Share" link if you sell or share data.
  • Set up a process for handling data subject requests within legal deadlines.
  • Sign Data Processing Agreements (DPAs) with all third-party vendors.
  • Encrypt data in transit and at rest.
  • Train your team on privacy and breach response.
  • Appoint a Data Protection Officer if required.

Privacy Beyond Compliance: Everyday Protections

Laws like GDPR and CCPA give you legal recourse, but proactive privacy hygiene matters just as much. A few practical habits go a long way:

  • Use a privacy-respecting browser and enable encrypted DNS (DoH or DoT).
  • Review and revoke permissions on apps you no longer use.
  • Prefer tools and services with clear, minimal data collection.
  • Use link shorteners that don't sell click data or build shadow profiles on your audience. Privacy-first services like Lunyb focus on giving you analytics without exploiting the visitors clicking your links—see our honest review of Lunyb for details.
  • Regularly audit which companies hold your data and submit deletion requests where possible.

The Growing Global Privacy Landscape

GDPR and CCPA are the two most well-known laws, but the privacy landscape is expanding rapidly. Brazil (LGPD), Canada (PIPEDA and Quebec's Law 25), the UK (UK GDPR), Japan (APPI), India (DPDP Act), and more than 15 U.S. states have their own frameworks. Many borrow heavily from GDPR's structure, meaning organizations that comply with GDPR are often well-positioned for global compliance.

If you're choosing tools for your business—like a link shortener, email platform, or analytics service—it's worth checking their compliance posture. See our 2026 buyer's guide to URL shorteners and our Rebrandly review for privacy-aware comparisons.

GDPR vs CCPA: Which Is Stricter?

The GDPR is generally considered the stricter of the two laws for four reasons:

  1. It requires affirmative opt-in consent rather than opt-out.
  2. It applies to all organizations processing EU data, regardless of size.
  3. It requires a lawful basis for every processing activity.
  4. Its potential fines are significantly higher and more frequently enforced.

That said, the CCPA (as amended by CPRA) is catching up—especially with the new California Privacy Protection Agency actively issuing enforcement actions since 2023.

Frequently Asked Questions

Does GDPR apply to U.S. companies?

Yes. GDPR applies to any organization worldwide that offers goods or services to individuals in the EU or monitors their behavior—regardless of where the company is based. A U.S. company with EU customers or website visitors from Europe likely has GDPR obligations.

Can I request my data from a company under both laws?

If you qualify under both jurisdictions (rare, since GDPR covers EU residents and CCPA covers California residents), yes. Most people fall under one or the other. Businesses often build a unified privacy request portal that handles either type of request.

What's the difference between CCPA and CPRA?

The CPRA (California Privacy Rights Act) is an amendment that expanded and strengthened the CCPA starting in 2023. It added new rights (like the right to correct and to limit sensitive information use), created the California Privacy Protection Agency, and introduced stricter rules for sensitive personal data.

Do small businesses need to comply with GDPR?

Yes, if they process the personal data of individuals in the EU. GDPR has no revenue or size threshold. However, some obligations (like appointing a Data Protection Officer) depend on the scale and nature of processing. Small businesses processing minimal data have lighter obligations but still need a privacy policy and a lawful basis for processing.

What happens if a company ignores my privacy request?

Under GDPR, you can file a complaint with your national data protection authority, which can investigate and fine the company. Under CCPA, you can report the business to the California Privacy Protection Agency or the state Attorney General. Both regulators have shown willingness to act on consumer complaints.

Final Thoughts

GDPR and CCPA represent two different philosophies for protecting privacy—one built on affirmative consent and comprehensive rights, the other on transparency and the ability to opt out. Both have fundamentally changed how businesses handle personal data, and together they've pushed privacy into the mainstream of digital policy.

As a consumer, you have more power than ever to see, correct, delete, and control your personal information. As a business, embracing privacy isn't just about avoiding fines—it's about earning the trust of your customers. Choose tools, partners, and platforms that share that value, and the compliance side of the equation becomes much easier.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles