facebook-pixel

GDPR vs CCPA: Understanding Your Privacy Rights in 2026

L
Lunyb Security Team
··10 min read

Data privacy has moved from a niche legal topic to a boardroom priority — and for good reason. Two regulations dominate the global conversation: the European Union's General Data Protection Regulation (GDPR) and California's Consumer Privacy Act (CCPA), as amended by the CPRA. Both give individuals meaningful control over their personal information, but they take very different approaches to how, when, and why that control applies.

This guide breaks down GDPR vs CCPA in plain English, compares your rights side-by-side, and explains what businesses must do to stay compliant. Whether you're a consumer wanting to protect your data or an organization navigating dual compliance, you'll leave with a clear map of the privacy landscape in 2026.

What Is the GDPR?

The General Data Protection Regulation is a comprehensive European Union privacy law that took effect on May 25, 2018. It governs how any organization — inside or outside the EU — collects, stores, processes, and shares the personal data of individuals located in the European Economic Area (EEA).

GDPR is built on a principle of data protection by default and by design. Companies must have a lawful basis before processing personal data, be transparent about what they collect, and honor a broad set of individual rights. The regulation applies extraterritorially, meaning a small business in Brazil or the U.S. targeting European users must still comply.

Key GDPR Principles

  • Lawfulness, fairness, and transparency — data processing must have a legal basis and be clearly disclosed.
  • Purpose limitation — data collected for one reason cannot be repurposed without consent.
  • Data minimization — only collect what is strictly necessary.
  • Accuracy — personal data must be kept up to date.
  • Storage limitation — data cannot be kept longer than needed.
  • Integrity and confidentiality — appropriate security measures are mandatory.
  • Accountability — organizations must be able to demonstrate compliance.

What Is the CCPA (and CPRA)?

The California Consumer Privacy Act took effect on January 1, 2020, and was significantly expanded by the California Privacy Rights Act (CPRA), which became fully enforceable in 2023. Together, they form the strongest state-level privacy law in the United States and are often referred to collectively as "CCPA" in industry conversation.

The CCPA gives California residents specific rights over personal information that businesses collect about them. Unlike GDPR's opt-in default, the CCPA generally operates on an opt-out model: businesses can collect and sell data unless a consumer tells them to stop.

Who Must Comply With the CCPA?

A for-profit business must comply if it does business in California and meets at least one of these thresholds:

  1. Has annual gross revenue exceeding $25 million.
  2. Buys, sells, or shares the personal information of 100,000 or more California consumers or households.
  3. Derives 50% or more of annual revenue from selling or sharing California consumers' personal information.

GDPR vs CCPA: The Core Differences

While both laws aim to protect personal data, they differ in scope, definitions, consent models, and enforcement. The table below highlights the most important contrasts.

Aspect GDPR CCPA / CPRA
Jurisdiction EU/EEA residents (extraterritorial) California residents
Who It Applies To Any organization processing EU personal data For-profit businesses meeting revenue/data thresholds
Consent Model Opt-in (explicit consent required) Opt-out (with opt-in for minors under 16)
Definition of Personal Data Any info relating to an identified/identifiable person Info that identifies, relates to, or could be linked to a consumer or household
Right to Delete Yes (right to erasure) Yes, with exceptions
Right to Portability Yes Yes
Right to Correct Yes Yes (added by CPRA)
Data Protection Officer Required in many cases Not required
Maximum Fines €20M or 4% of global annual turnover $7,500 per intentional violation; $2,500 per unintentional
Private Right of Action Yes, individuals can sue Limited (data breach cases only)

Your Privacy Rights Under GDPR

GDPR grants eight fundamental rights to data subjects. Understanding them helps you assert control over your personal information.

1. Right to Be Informed

You must be told what data is being collected, why, how long it will be kept, and with whom it will be shared — typically through a clear privacy notice at the point of collection.

2. Right of Access

You can request a copy of the personal data an organization holds about you, usually free of charge, within one month.

3. Right to Rectification

Inaccurate or incomplete data must be corrected without undue delay upon your request.

4. Right to Erasure ("Right to Be Forgotten")

You can request deletion when data is no longer necessary, consent is withdrawn, or processing was unlawful — subject to certain exemptions like legal obligations.

5. Right to Restrict Processing

You can pause data processing in specific circumstances, such as while contesting the accuracy of your data.

6. Right to Data Portability

You can obtain your data in a structured, machine-readable format and transfer it to another provider.

7. Right to Object

You can object to processing based on legitimate interests, direct marketing, or automated profiling.

8. Rights Related to Automated Decision-Making

You have the right not to be subject to purely automated decisions — including profiling — that produce legal or similarly significant effects.

Your Privacy Rights Under the CCPA

The CCPA/CPRA grants California residents six primary rights that echo — but don't perfectly mirror — GDPR protections.

1. Right to Know

You can request the categories and specific pieces of personal information a business has collected about you over the past 12 months (and, under CPRA, beyond that in some cases).

2. Right to Delete

You can ask a business to delete personal information it has collected from you, subject to legal exceptions (like completing a transaction or complying with a legal obligation).

3. Right to Correct

Added by CPRA, you can request correction of inaccurate personal information.

4. Right to Opt Out of Sale or Sharing

Businesses must offer a clear "Do Not Sell or Share My Personal Information" link. "Sharing" specifically covers cross-context behavioral advertising.

5. Right to Limit Use of Sensitive Personal Information

You can restrict how businesses use sensitive categories like precise geolocation, biometric data, health data, or racial/ethnic origin.

6. Right to Non-Discrimination

A business cannot deny service, charge higher prices, or provide lower quality to consumers who exercise their privacy rights.

Consent: Opt-In vs Opt-Out

Perhaps the most philosophical difference between the two laws is the default position on consent.

GDPR uses an opt-in model. Before processing personal data for most purposes — especially marketing or tracking cookies — a business must obtain freely given, specific, informed, and unambiguous consent. Pre-ticked boxes and cookie walls that force acceptance are illegal.

CCPA uses an opt-out model for adults. Businesses can collect and even sell your data by default, but they must give you a straightforward way to say "stop." For consumers under 16, an opt-in is required (and for children under 13, parental consent).

This distinction has practical implications for anyone building websites or marketing funnels. If your audience includes EU users, you'll need a consent management platform. If you're targeting Californians, you'll need visible opt-out mechanisms and honor the Global Privacy Control (GPC) signal, which browsers can send automatically.

Enforcement and Penalties

Both laws come with real financial teeth, but the mechanisms differ.

GDPR Enforcement

Enforcement is handled by Data Protection Authorities (DPAs) in each EU member state. Fines are tiered:

  • Up to €10 million or 2% of global annual turnover for lower-tier violations (record-keeping, security).
  • Up to €20 million or 4% of global annual turnover for higher-tier violations (violating core principles, ignoring consent rules).

Major enforcement actions against tech giants have resulted in fines exceeding €1 billion, making GDPR one of the most consequential privacy laws globally.

CCPA Enforcement

The California Privacy Protection Agency (CPPA) and the state Attorney General enforce the CCPA. Fines are:

  • $2,500 per unintentional violation.
  • $7,500 per intentional violation or violations involving minors' data.

While per-violation figures seem modest, they can multiply quickly when hundreds of thousands of consumer records are involved. Additionally, consumers have a limited private right of action for data breaches caused by inadequate security.

Practical Steps for Businesses

If your organization touches personal data from either jurisdiction, dual compliance is often the smart path. Here's a streamlined roadmap:

  1. Map your data. Know what you collect, where it lives, who accesses it, and how long you keep it.
  2. Update privacy notices. Ensure disclosures satisfy both GDPR transparency requirements and CCPA "Notice at Collection" rules.
  3. Deploy consent and opt-out tools. Use a consent management platform for EU users and a visible "Do Not Sell or Share" link for Californians.
  4. Build a rights-request workflow. Create a documented process for verifying identity and responding within legal timelines (30 days for GDPR, 45 days for CCPA).
  5. Vet vendors. Data processors must be bound by contracts (DPAs) that mirror your obligations.
  6. Secure your data. Encryption, access controls, and breach response plans are non-negotiable.
  7. Train your team. Human error is the leading cause of breaches — recurring privacy training pays for itself.

Practical Steps for Individuals

Whether or not a specific law protects you, everyone can take steps to safeguard personal data online.

  • Read privacy notices before signing up for services — especially free ones.
  • Use privacy-respecting browsers and enable Global Privacy Control if available.
  • Turn on encrypted DNS (DNS-over-HTTPS) to prevent network operators from logging your browsing.
  • Exercise your rights. If a company holds data about you, ask for it, correct it, or delete it. Both GDPR and CCPA make this a legal obligation.
  • Choose privacy-first tools. When shortening or sharing links, pick a service that respects your data. For example, Lunyb offers a privacy-focused URL shortener that avoids invasive tracking — you can read our honest review of Lunyb for details, or compare it against alternatives in our 2026 buyer's guide.

The Global Trend Beyond GDPR and CCPA

GDPR and CCPA set the template, but they're no longer alone. Brazil's LGPD, the UK's Data Protection Act, Canada's PIPEDA (with modernization on the way), Japan's APPI, and a growing patchwork of U.S. state laws — Virginia's VCDPA, Colorado's CPA, Connecticut's CTDPA, Texas's TDPSA, and many more — all draw from the same core rights framework.

For businesses, this means privacy compliance is no longer about picking one law to follow. A rights-based, data-minimization mindset is the only sustainable strategy. For consumers, it means privacy expectations are becoming a global baseline — and companies that ignore that trend risk both fines and reputational damage.

Frequently Asked Questions

Which is stricter, GDPR or CCPA?

GDPR is generally considered stricter. It requires opt-in consent, applies to all organizations regardless of size, and carries significantly higher potential fines (up to 4% of global turnover). CCPA is opt-out by default and only applies to businesses meeting specific revenue or data thresholds.

Do I need to comply with both GDPR and CCPA?

If your business collects personal data from both EU residents and California consumers, yes. Many companies build a unified privacy program that satisfies the stricter GDPR requirements, then layer on CCPA-specific elements like the "Do Not Sell or Share" link and category-based disclosures.

How do I file a GDPR or CCPA request?

Visit the company's privacy policy page, which is legally required to include contact information and a request mechanism. Most large organizations offer a web form. You'll need to verify your identity, and the business must respond within 30 days (GDPR) or 45 days (CCPA).

Does CCPA apply to non-U.S. companies?

Yes. If a business meets the CCPA's thresholds and processes personal information of California residents, it must comply regardless of where the business is headquartered. This mirrors GDPR's extraterritorial reach.

What counts as "selling" data under CCPA?

The CCPA defines "sale" broadly as any exchange of personal information for monetary or other valuable consideration. This can include sharing data with advertising partners in exchange for services. The CPRA added "sharing" for cross-context behavioral advertising, meaning even non-monetary data exchanges for targeted ads trigger opt-out obligations.

Final Thoughts

GDPR and CCPA are more than legal checkboxes — they represent a fundamental shift in how personal data is treated worldwide. For individuals, they provide real tools to reclaim control over your digital footprint. For businesses, they set a rising bar for transparency, security, and respect for user choice.

The best approach in 2026 isn't to view privacy as a compliance burden, but as a competitive advantage. Users increasingly choose products and services that treat their data with care. Whether you're picking a link shortener, an analytics platform, or a cloud provider, ask the same question regulators ask: "What are you doing with my data, and why?"

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles