facebook-pixel

GDPR vs CCPA: Understanding Your Privacy Rights in 2026

L
Lunyb Security Team
··9 min read

Data privacy laws have reshaped how businesses handle personal information and how individuals control their own data. Two frameworks dominate the global conversation: the European Union's General Data Protection Regulation (GDPR) and California's Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). While both aim to protect consumers, they differ significantly in scope, definitions, and enforcement.

This guide breaks down GDPR vs CCPA in plain language so you can understand your rights, whether you're a consumer wanting to control your data or a business owner navigating compliance.

What Is the GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive European Union privacy law that took effect on May 25, 2018. It governs how organizations collect, store, process, and share the personal data of individuals located in the European Economic Area (EEA), regardless of where the organization itself is based.

The GDPR is considered the gold standard of global privacy legislation. It replaced the outdated 1995 Data Protection Directive and introduced sweeping new rights for individuals along with strict obligations for data controllers and processors.

Core Principles of the GDPR

  1. Lawfulness, fairness, and transparency — Data must be processed lawfully and openly.
  2. Purpose limitation — Data collected for one purpose cannot be reused for unrelated purposes.
  3. Data minimization — Only collect what is strictly necessary.
  4. Accuracy — Personal data must be kept accurate and up to date.
  5. Storage limitation — Data should not be kept longer than needed.
  6. Integrity and confidentiality — Data must be secured against unauthorized access.
  7. Accountability — Organizations must be able to demonstrate compliance.

What Is the CCPA (and CPRA)?

The California Consumer Privacy Act (CCPA) is a state-level privacy law that took effect on January 1, 2020. It grants California residents specific rights over their personal information held by qualifying businesses. In 2023, the California Privacy Rights Act (CPRA) expanded those rights and created a dedicated enforcement agency, the California Privacy Protection Agency (CPPA).

Unlike the GDPR, the CCPA is not an all-encompassing framework. Instead, it focuses on giving consumers transparency and choice — particularly around the "sale" and "sharing" of personal information.

Who Must Comply with the CCPA?

A for-profit business must comply if it does business in California and meets at least one of the following thresholds:

  • Has annual gross revenue over $25 million
  • Buys, sells, or shares personal data of 100,000+ California consumers or households
  • Derives 50% or more of its annual revenue from selling or sharing personal information

GDPR vs CCPA: Side-by-Side Comparison

Understanding the differences between these two laws helps clarify what protections apply to you and what obligations apply to businesses handling your data.

FeatureGDPR (EU)CCPA/CPRA (California)
Effective DateMay 25, 2018January 1, 2020 (CPRA: Jan 1, 2023)
Who It ProtectsAnyone in the EEACalifornia residents
Who Must ComplyAny organization processing EEA residents' dataFor-profit businesses meeting thresholds
Legal Basis RequiredYes — 6 lawful basesNo explicit legal basis required
Opt-in vs Opt-outOpt-in consent requiredOpt-out model (opt-in for minors)
Right to DeleteYes (Right to Erasure)Yes, with exceptions
Right to AccessYesYes (12-month lookback, expanded under CPRA)
Right to PortabilityYesYes
Right to CorrectionYesYes (added by CPRA)
Data Protection OfficerRequired in many casesNot required
Maximum Fine€20 million or 4% of global revenue$7,500 per intentional violation
Private Right of ActionYesLimited to data breaches

Key Differences Explained

1. Scope of "Personal Data"

Both laws define personal data broadly, but the GDPR is arguably wider. It covers any information relating to an identified or identifiable natural person — including IP addresses, cookie identifiers, and location data. The CCPA covers similar categories but explicitly ties personal information to consumers, households, or devices in California.

2. Consent Model

The GDPR generally requires opt-in consent: users must actively agree before their data is processed for many purposes, particularly marketing. Consent must be freely given, specific, informed, and unambiguous.

The CCPA takes an opt-out approach. Businesses can collect and sell data by default, but consumers must be given a clear "Do Not Sell or Share My Personal Information" link. Opt-in consent is only required for minors under 16.

3. Legal Basis for Processing

Under the GDPR, businesses must identify one of six lawful bases before processing data: consent, contract, legal obligation, vital interests, public task, or legitimate interests. The CCPA has no equivalent requirement — businesses need only disclose what they collect and why.

4. Enforcement and Penalties

GDPR penalties are notoriously severe: up to €20 million or 4% of global annual turnover, whichever is higher. Enforcement is handled by Data Protection Authorities in each EU member state.

CCPA fines are lower per incident — $2,500 per unintentional violation and $7,500 per intentional one — but can accumulate quickly across large datasets. The CPPA and California Attorney General share enforcement authority.

Consumer Rights Under Both Laws

Despite their differences, GDPR and CCPA give individuals a comparable toolkit for controlling their personal information.

Rights Common to Both

  • Right to know what data is being collected and why
  • Right to access a copy of your personal data
  • Right to delete your data (with certain exceptions)
  • Right to correct inaccurate information
  • Right to data portability — receive your data in a machine-readable format
  • Right to non-discrimination — you cannot be penalized for exercising your rights

GDPR-Only Rights

  • Right to restrict processing — pause how your data is used
  • Right to object to processing based on legitimate interests
  • Rights related to automated decision-making, including profiling

CCPA-Specific Rights

  • Right to opt out of the sale or sharing of personal information
  • Right to limit use of sensitive personal information (added by CPRA)

Business Compliance Obligations

If you run a business that collects user data — even something as simple as email signups or link-click analytics — you may fall under one or both frameworks. Here's what you generally need to do.

Steps to Comply with the GDPR

  1. Map all personal data you collect, store, and share.
  2. Identify a lawful basis for each processing activity.
  3. Update your privacy policy to be clear and specific.
  4. Implement consent management for cookies and marketing.
  5. Enable users to exercise their rights (access, deletion, portability).
  6. Appoint a Data Protection Officer if required.
  7. Report data breaches within 72 hours.

Steps to Comply with the CCPA/CPRA

  1. Determine whether you meet the applicability thresholds.
  2. Publish a compliant privacy notice, updated annually.
  3. Add a "Do Not Sell or Share My Personal Information" link on your homepage.
  4. Honor Global Privacy Control (GPC) browser signals.
  5. Provide two or more methods for consumers to submit rights requests.
  6. Train staff who handle consumer inquiries.
  7. Enter into compliant contracts with service providers.

How to Protect Your Privacy as a Consumer

Regardless of where you live, you can take meaningful steps to reduce your data exposure online. Privacy laws are helpful, but personal habits and tools carry equal weight.

Practical Privacy Steps

  • Use privacy-respecting browsers like Firefox or Brave with tracker blocking enabled.
  • Enable encrypted DNS (DNS-over-HTTPS or DNS-over-TLS) to hide your browsing lookups from your network provider.
  • Review app permissions regularly on your phone and revoke anything unnecessary.
  • Use unique, strong passwords managed by a reputable password manager.
  • Turn on two-factor authentication everywhere it's offered.
  • Limit what you share on social media — assume anything posted is permanent.
  • Use privacy-first tools when sharing content online. For example, a URL shortener like Lunyb lets you share links without exposing your full destination URL or leaking referrer data unnecessarily.

Exercising Your Rights

Most large platforms now offer a dedicated privacy dashboard. To submit a data request:

  1. Locate the company's privacy policy — usually linked in the footer.
  2. Look for a "Your Privacy Choices" or "Data Requests" section.
  3. Submit a verified request specifying what you want (access, deletion, correction).
  4. Track the response — GDPR requires a reply within one month; CCPA allows 45 days.

The Growing Patchwork of Privacy Laws

GDPR and CCPA are the most influential, but they're no longer alone. As of 2026, over 20 U.S. states have passed comprehensive privacy laws, including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and others. Internationally, Brazil (LGPD), Canada (PIPEDA and the incoming CPPA), the UK (UK GDPR), and India (DPDPA) have their own frameworks.

Most of these laws borrow heavily from either the GDPR or CCPA model. Businesses operating globally increasingly adopt GDPR-level practices as a baseline, since compliance with the strictest law usually satisfies the weaker ones.

Which Law Applies to You?

Determining which law applies depends on two things: where you live and where the business operates.

  • If you live in the EEA, the GDPR protects you no matter where the business is located.
  • If you live in California, the CCPA/CPRA protects you when interacting with qualifying businesses.
  • If a business serves both markets, it typically must comply with both.
  • Businesses often extend GDPR protections globally as a practical matter — meaning users in other regions benefit indirectly.

Related Reading

If you're interested in privacy-conscious tools for everyday online tasks, check out our other guides:

Frequently Asked Questions

Is the GDPR stricter than the CCPA?

Yes, generally. The GDPR requires a lawful basis for processing, opt-in consent for most activities, and comes with far higher potential fines. The CCPA is narrower in scope, focusing on transparency and the ability to opt out of data sales.

Do I need to comply with the GDPR if my business is based in the U.S.?

Yes, if you process personal data of individuals located in the EEA — for example, by selling products to European customers or tracking European website visitors. The GDPR applies based on where the data subject is, not where your business is headquartered.

Can I request my data from any company?

You can submit a request to any company, but they are only legally obligated to respond if a privacy law applies to them. Under GDPR, virtually all businesses handling EEA data must comply. Under CCPA, only businesses meeting the size thresholds must respond.

What happens if a business ignores my privacy request?

You can file a complaint with the relevant regulator — a Data Protection Authority in the EU, or the California Privacy Protection Agency or Attorney General in California. In some cases, particularly under CCPA data-breach provisions, you may also have a private right of action.

How can I tell if a website is respecting my privacy?

Look for a clear, readable privacy policy, granular cookie consent options (not a single "Accept All" button), and easy-to-find data request tools. Reputable services also honor Global Privacy Control browser signals and minimize the data they collect in the first place.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles