facebook-pixel

GDPR vs CCPA: Understanding Your Privacy Rights in 2026

L
Lunyb Security Team
··10 min read

Data privacy has evolved from a niche legal concern into one of the defining issues of the digital age. Two laws sit at the center of that transformation: the European Union's General Data Protection Regulation (GDPR) and California's Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). Although they share a goal — giving people more control over their personal information — they take noticeably different approaches.

This guide breaks down GDPR vs CCPA in plain language, so you can understand your rights as a consumer and your obligations as a business owner, marketer, or developer.

What Is the GDPR?

The General Data Protection Regulation (GDPR) is a European Union privacy law that took effect on May 25, 2018. It governs how organizations collect, store, process, and share the personal data of individuals located in the EU and the European Economic Area (EEA), regardless of where the organization itself is based.

GDPR is widely considered the world's most comprehensive privacy framework. It introduced the concepts of "data controllers" and "data processors," established lawful bases for processing, and set strict rules on consent and cross-border data transfers. Penalties can reach €20 million or 4% of a company's global annual revenue — whichever is higher.

Core principles of the GDPR

  • Lawfulness, fairness, and transparency — data must be processed with a clear legal basis.
  • Purpose limitation — collected only for specified, explicit purposes.
  • Data minimization — limited to what is necessary.
  • Accuracy — kept up to date and corrected when needed.
  • Storage limitation — retained only as long as required.
  • Integrity and confidentiality — protected with appropriate security measures.
  • Accountability — controllers must demonstrate compliance.

What Is the CCPA (and CPRA)?

The California Consumer Privacy Act (CCPA) is a U.S. state law that took effect on January 1, 2020. It was significantly expanded by the California Privacy Rights Act (CPRA), which became fully enforceable on July 1, 2023, and created the California Privacy Protection Agency (CPPA) to oversee enforcement.

The CCPA applies to for-profit businesses that collect personal information from California residents and meet at least one of these thresholds: annual gross revenue over $25 million, buy or sell the personal information of 100,000+ consumers or households, or derive 50% or more of annual revenue from selling or sharing personal information.

Rather than requiring opt-in consent for every type of processing, the CCPA focuses on transparency and opt-out rights, particularly around the sale or sharing of personal information for cross-context behavioral advertising.

GDPR vs CCPA: Side-by-Side Comparison

The clearest way to understand the two laws is to compare them directly across the attributes that matter most.

AttributeGDPR (EU)CCPA/CPRA (California)
Effective DateMay 25, 2018Jan 1, 2020 (CPRA: Jan 1, 2023)
Who It ProtectsAny person in the EU/EEACalifornia residents
Who Must ComplyAny organization processing EU personal dataFor-profit businesses meeting revenue/data thresholds
Consent ModelOpt-in (explicit, freely given)Opt-out (for sale/sharing of data)
Scope of DataAny information relating to an identifiable personPersonal information linkable to a consumer or household
Sensitive DataSpecial category — stricter rules, usually requires explicit consentSeparate category under CPRA with right to limit use
Right to DeleteYes (right to erasure)Yes, with exceptions
Right to AccessYes, including purposes, recipients, retentionYes, including specific pieces collected
Right to CorrectYesAdded under CPRA
Right to PortabilityYesYes
Non-DiscriminationImplicit through fairness principleExplicitly protected
Max Penalty€20M or 4% of global revenue$7,500 per intentional violation; $2,500 per unintentional
RegulatorNational Data Protection AuthoritiesCalifornia Privacy Protection Agency (CPPA) & AG

Who Each Law Protects

The GDPR protects data subjects — any natural person physically present in the EU or EEA when their data is collected. Citizenship doesn't matter. If a U.S. tourist in Berlin signs up for a service, GDPR applies to that interaction.

The CCPA protects California consumers, defined as natural persons who are California residents. Importantly, since January 2023, the CCPA also covers employees, job applicants, and business-to-business contacts — categories that were previously exempt.

Key Rights Granted to Individuals

Both laws give individuals meaningful control, but the specifics differ.

Rights under the GDPR

  1. Right to be informed — know what data is collected and why.
  2. Right of access — obtain a copy of your personal data.
  3. Right to rectification — correct inaccurate data.
  4. Right to erasure ("right to be forgotten") — request deletion.
  5. Right to restrict processing — pause how data is used.
  6. Right to data portability — receive data in a machine-readable format.
  7. Right to object — opt out of certain processing, especially marketing.
  8. Rights related to automated decision-making — including profiling.

Rights under the CCPA/CPRA

  1. Right to know what personal information is collected, used, shared, or sold.
  2. Right to delete personal information held by the business.
  3. Right to correct inaccurate personal information (added by CPRA).
  4. Right to opt out of the sale or sharing of personal information.
  5. Right to limit use of sensitive personal information.
  6. Right to data portability.
  7. Right to non-discrimination for exercising privacy rights.

Consent: Opt-In vs Opt-Out

This is the single biggest philosophical difference between the two laws.

GDPR requires opt-in consent for most processing of personal data that isn't justified by another lawful basis (contract, legal obligation, vital interests, public task, or legitimate interests). Consent must be freely given, specific, informed, and unambiguous — typically through a clear affirmative action like ticking an unchecked box.

CCPA follows an opt-out model. Businesses can collect and use personal information by default, but they must offer consumers a clear way to opt out of the sale or sharing of that information. The familiar "Do Not Sell or Share My Personal Information" link stems directly from this requirement. For sensitive data and consumers under 16, however, opt-in applies.

Enforcement and Penalties

GDPR fines have grabbed headlines. Companies like Meta, Amazon, and Google have faced penalties in the hundreds of millions — in some cases over a billion euros. Enforcement is handled by national Data Protection Authorities (DPAs), coordinated through the European Data Protection Board.

CCPA fines are smaller per violation but can accumulate quickly: $2,500 for each unintentional violation and $7,500 for intentional ones or violations involving minors. The CPRA removed the previous 30-day cure period for most violations, giving regulators more immediate leverage. The California Privacy Protection Agency can also conduct audits and issue administrative penalties.

Both laws also allow for private rights of action in specific scenarios — most notably, CCPA permits individuals to sue after certain data breaches involving unencrypted personal information.

Practical Compliance Steps for Businesses

If your organization touches data from either jurisdiction, a hybrid compliance program is usually more efficient than treating each law in isolation.

  1. Map your data. Document what personal information you collect, where it comes from, where it's stored, who you share it with, and why.
  2. Update privacy notices. Clearly explain categories of data, purposes, retention periods, and consumer rights. Include jurisdiction-specific sections.
  3. Implement a consent management platform (CMP). Capture opt-ins for EU visitors and offer opt-outs for California residents, including Global Privacy Control (GPC) signals.
  4. Create rights-request workflows. Verify identity, respond within statutory deadlines (one month under GDPR, 45 days under CCPA), and keep an audit trail.
  5. Review vendors and processors. Sign Data Processing Agreements under GDPR and service provider contracts under CCPA.
  6. Harden security. Encryption, access controls, logging, and incident response plans reduce both breach risk and liability.
  7. Train your team. Marketing, engineering, and support staff all handle personal data in different ways.

Where Marketing Tools and Link Tracking Fit In

Marketing stacks are a common blind spot. Analytics scripts, pixels, retargeting tags, and even URL shorteners can collect IP addresses, device identifiers, or referrer data that qualify as personal information under both laws.

When choosing a link management or shortener platform, look for providers that are transparent about data retention, allow you to disable or anonymize IP logging, and give you control over which third-party scripts fire. A privacy-respecting shortener like Lunyb makes it easier to publish branded, trackable links without pulling in heavy third-party tracking you may not have disclosed in your privacy notice. If you're evaluating options, our 2026 buyer's guide to URL shorteners and our honest review of Lunyb walk through what to look for from a compliance standpoint.

How GDPR and CCPA Influenced Other Laws

Both frameworks have inspired a wave of similar legislation worldwide. Brazil's LGPD mirrors much of the GDPR. In the U.S., states including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others have enacted their own comprehensive privacy laws, each borrowing elements from the CCPA while adding unique provisions. Globally, Canada's upcoming CPPA, the UK GDPR, India's DPDP Act, and Australia's reformed Privacy Act all pull from the same conceptual well.

For businesses, this means privacy compliance is no longer a one-time project. It's an ongoing program that must adapt as new laws take effect, often with overlapping but not identical requirements.

Common Myths About GDPR and CCPA

"GDPR only applies to European companies."

False. Any organization offering goods or services to people in the EU — or monitoring their behavior — must comply, regardless of location.

"CCPA is just for California-based companies."

Also false. The CCPA applies to businesses anywhere in the world that meet the thresholds and process California residents' personal information.

"If I'm GDPR-compliant, I'm automatically CCPA-compliant."Not quite. GDPR compliance gets you most of the way, but CCPA has unique requirements like the "Do Not Sell or Share" link, specific disclosure categories, and recognition of GPC browser signals.

"Small businesses don't need to worry."

Small businesses may fall outside CCPA thresholds, but GDPR has no revenue minimum. Even a one-person startup selling to EU customers must comply.

The Future of Privacy Regulation

Expect the trend lines to continue: more jurisdictions, stricter rules on sensitive data (especially biometric, health, geolocation, and children's data), and greater scrutiny of AI and automated decision-making. The EU AI Act, growing enforcement around dark patterns, and the rise of universal opt-out mechanisms like GPC all point toward a future where privacy by design isn't optional — it's the baseline expectation.

For individuals, the practical takeaway is to exercise your rights: request copies of your data, delete accounts you no longer use, and opt out of tracking where you can. For businesses, treat privacy as a product feature, not a legal checkbox. The companies that build trust now will have a durable competitive advantage as regulation keeps tightening.

Frequently Asked Questions

Is GDPR stricter than CCPA?

In most respects, yes. GDPR requires opt-in consent, has broader territorial scope, applies to organizations of any size, and carries larger maximum fines. CCPA is narrower but has evolved significantly under the CPRA and continues to add protections similar to GDPR.

Do I need to comply with both laws?

If you collect personal information from both EU residents and California residents and meet the applicable thresholds, then yes. Many organizations build a unified privacy program that satisfies the stricter requirements of each law in parallel.

What counts as "personal information" under each law?

GDPR defines personal data very broadly — any information relating to an identified or identifiable natural person, including IP addresses and cookie IDs. CCPA uses a similar broad definition that includes identifiers, commercial information, internet activity, geolocation, inferences, and more, as long as it's linkable to a consumer or household.

How quickly must businesses respond to privacy requests?

Under GDPR, you generally have one month to respond, extendable by two more months for complex requests. Under CCPA, you must confirm receipt within 10 business days and respond substantively within 45 days, with a possible 45-day extension.

Can I be fined for a single violation?

Yes. GDPR fines are assessed per infringement and can scale with severity and company revenue. CCPA fines are typically assessed per violation, per consumer — so a single flawed practice affecting thousands of consumers can produce substantial cumulative penalties.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles