GDPR vs. CCPA: What Entrepreneurs Actually Need to Know
GDPR and CCPA share one core idea: people have rights over their data. Here is how the two laws differ in scope, rights, and penalties, and how to tell which applies to you.

GDPR and CCPA both give individuals enforceable rights over their personal data, but they differ in who they cover, which rights they grant, and how they are enforced. In short: GDPR is broader in principles and can reach almost any business serving people in the EU, while CCPA applies to for-profit businesses that meet specific California thresholds. For most entrepreneurs, the practical task is to work out which rules actually apply to your customers and data practices, then build the habits that satisfy both.
Two laws, one idea
GDPR, the General Data Protection Regulation, is the European Union's comprehensive privacy law. CCPA, the California Consumer Privacy Act, is California's privacy statute, significantly amended by the CPRA. They differ in drafting and enforcement, but they share a core idea: people have enforceable rights over the personal information organizations hold about them, and organizations must handle that information transparently and securely. If you build your practices around that core idea, adapting to either law becomes a matter of detail rather than reinvention.
Who each law applies to
GDPR's reach
GDPR applies to organizations established in the EU and, importantly for American businesses, to organizations anywhere in the world that offer goods or services to people in the EU or monitor their behavior. A US-based online store that ships to EU customers, or that markets in a way targeted at EU residents, can fall within GDPR's scope. There is no exemption based on headcount; the practical trigger is your relationship with people in the EU.
CCPA's thresholds
CCPA applies to for-profit businesses doing business in California that meet at least one of three thresholds: annual gross revenue above roughly twenty-five million dollars, buying or selling the personal information of one hundred thousand or more consumers or households, or deriving half or more of annual revenue from selling personal information. Most small businesses sit below these thresholds on every count. But thresholds move as your business grows, and other states have enacted their own laws with different lines, which is why many owners build toward the stricter standard rather than track each statute separately.
What rights people get
Under GDPR
GDPR grants rights of access, correction, deletion, portability, and objection to certain types of processing, and it requires a lawful basis for processing personal data in the first place. It also embeds principles that apply before any individual makes a request: purpose limitation, data minimization, storage limitation, and security. Requests generally must be answered within about a month.
Under CCPA
CCPA grants rights to know what personal information is collected and shared, to delete it, to correct inaccurate information, and to opt out of the sale or sharing of personal information, along with a right to limit the use of sensitive personal information. Businesses must provide required notices at or before collection and must honor valid opt-out requests. Response windows generally run forty-five days, extendable in defined circumstances.
How the laws treat selling data differently
One difference trips up many owners. GDPR does not use the phrase selling data the way American readers expect; it regulates disclosures broadly through its lawful basis and consent requirements. CCPA defines sale and sharing specifically, including sharing for cross-context behavioral advertising, and builds the opt-out right around those definitions. In practice, a US business running advertising integrations should review whether its setup counts as a sale or share under CCPA even though no money changes hands directly.
What it costs to get it wrong
GDPR enforcement can reach fines of up to twenty million euros or four percent of worldwide annual turnover, whichever is higher, along with supervisory orders that force changes in practice. CCPA provides civil penalties for violations and a private right of action in the specific case of breaches of unencrypted personal information caused by unreasonable security. The exact figures matter less than the shape of the risk: both regimes create consequences that scale with the size of the business, and both are enforced against ordinary failures, not exotic ones.
How to tell which rules apply to you
Work through three questions. First, where are your customers: do you deliberately serve people in the EU, or operate only below CCPA's thresholds in California? Second, what do you do with data: do you sell or share personal information, or only use it to fulfill orders? Third, what do your tools do: advertising pixels, analytics, and CRM integrations can change the analysis. Answering those three questions honestly tells most owners which regime, if either, currently applies, and whether the safer path is complying with one or simply adopting the stricter habits of both.
A practical path that covers both
The overlap between the two laws is large. Both reward minimized collection, clear notices, honored deletion and access requests, secure storage, and vendor oversight. A business that records what it collects, publishes an honest privacy notice, sets retention periods, enables strong authentication, and maintains a request-handling procedure is most of the way to satisfying either framework. Where the regimes diverge in detail, counsel can fill the gap quickly, because the foundation is already in place.
Consent, cookies, and children's data
A few specifics deserve their own attention. Under GDPR, consent must be freely given, specific, informed, and as easy to withdraw as it was to give, which is why pre-ticked boxes and consent walls that offer no real choice fail review. CCPA requires notices at or before collection and a clear path to opt out of sales and sharing. Children's data is protected more strictly under both regimes, so if your product could attract minors, age-appropriate handling is not optional. And website cookies, including analytics and advertising pixels, are where these duties become visible to every visitor, so your banner and your privacy notice should describe the same reality.
What to document along the way
Whatever regime applies, the record of your reasoning is itself protection. Keep a short written trail: which laws you checked and when, what you decided about your advertising tools, where your data-processing agreements with vendors live, and how you handle requests. Regulators and courts respond far better to a business that can show its decisions than to one that must reconstruct them from memory. The documentation need not be elaborate; a dated summary reviewed annually, kept with your policy pages, gives you a defensible answer to the question of what you knew and what you did about it.
If you want to go deeper on both frameworks, including exercises that test how each requirement applies to real business scenarios, our Data Privacy course covers GDPR, CCPA, and the wider privacy landscape in a structured, quiz-supported format.
About the author
David Walter
Founder of BrightPoint Consulting Solutions, with more than 35 years of experience across startups and senior executive consulting, including secure IoT networking, FDA-regulated product development, and blockchain and crypto platforms, and teaching. He writes about data privacy, cybersecurity, AI, and building businesses with the right tools.
Frequently Asked Questions
My business is outside the EU and California. Do these laws still apply to me?
Possibly. GDPR applies wherever a business offers goods or services to people in the EU or monitors their behavior, regardless of where the business is located. CCPA applies to for-profit businesses doing business in California that meet its revenue, volume, or revenue-share thresholds. If you sell online, check both against your actual customer base.
Is GDPR only about websites and cookies?
No. Cookies and online tracking are a visible part of GDPR enforcement, but the law covers all processing of personal data, including customer records, employee files, and marketing lists. Online tracking just happens to be where many businesses first encounter its consent requirements.
Which law is stricter?
They are strict in different ways. GDPR sets broader principles and heavier maximum fines, while CCPA is more specific about consumer rights such as opting out of data sales and sharing. Rather than choosing one, many small businesses adopt the shared basics of both and treat the stricter habit as the default.
Related Articles
View all
What Is Data Privacy? A Plain-English Guide for Small Business Owners
Data privacy is not just a big-company problem. This plain-English guide explains what counts as personal data, why the duties apply to you, and the first five steps to take.

Data Privacy as a Business Strategy, Not a Compliance Task
Organizations that treat privacy as a checkbox pay for it in breaches and lost trust. Those that treat it as strategy turn it into a competitive advantage.

