Skip to content
compliancebase

Theme comparison · gdpr-vs-ccpa

GDPR vs CCPA/CPRA

Theme comparison of the EU GDPR and California CCPA/CPRA — territorial scope, consumer/data-subject rights, and what SaaS teams should not conflate.

Frameworks covered: GDPR

Key differences

DimensionGDPRCCPA / CPRA
Legal instrumentGDPR — Regulation (EU) 2016/679, directly applicable across EU Member States with EDPB guidanceCCPA/CPRA — California state privacy law (Civil Code) with regulations and AG/CPPA enforcement — not an EU regulation
Primary protected partyData subjects — natural persons in the EU/EEA (and extraterritorial cases)California consumers — residents of California under CCPA/CPRA definitions
Who is regulatedControllers and processors with GDPR territorial or targeting nexusBusinesses meeting CCPA thresholds (revenue, data volume, or data-selling criteria) and service providers/contractors under CPRA roles
Core dutiesLawful basis, transparency, DPIAs where required, security of processing (Art. 32), DPAs, international transfersNotice at collection, consumer rights (access, delete, opt-out of sale/share, correct, limit sensitive use under CPRA), service-provider contracts
“Sale” / advertisingGDPR focuses on lawful basis and purpose limitation for processing — including ads tech; “sale” is not the central CCPA constructCCPA/CPRA center consumer opt-out of sale/sharing and dark-pattern limits — critical for adtech and data brokers
Security expectationsArticle 32 — appropriate technical and organisational measures; breach notification to authorities (Art. 33) and individuals (Art. 34) when requiredReasonable security procedures; California also has separate breach statutes — CCPA private right of action for certain breaches of unencrypted data
Transfer / cross-borderChapter V transfer tools (SCCs, adequacy, etc.) when exporting personal data from the EEANo GDPR-style Chapter V regime — still need contractual and security discipline for California personal information
Typical SaaS mistakeAssuming a SOC 2 report or CCPA page equals GDPR complianceAssuming a GDPR DPA and RoPA automatically satisfy CCPA service-provider and notice requirements

Control overlap

Transparency, access/deletion workflows, vendor contracts, and security baselines appear in both regimes with different legal tests. Product and eng teams can share identity verification for rights requests, retention tooling, and encryption — but lawful basis (GDPR) and sale/share opt-outs (CCPA/CPRA) need distinct product and legal design. This site’s primary framework ID remains GDPR; CCPA is discussed here as a US state-law counterpart without a separate FRAMEWORK_IDS entry.

Sequencing advice

If you target EU users or monitor EU behavior, stand up GDPR foundations (lawful basis, notices, DPAs, Art. 32 measures, transfer strategy). If you meet CCPA thresholds or process California personal information at scale, implement CCPA/CPRA notices, rights portals, and service-provider terms — often in parallel, not as a copy-paste of GDPR text. Use /frameworks/gdpr for EU depth and /controls/gdpr/article-6, article-28, article-32 for operational articles. Do not treat either law as “done” because the other checklist is green.

Frequently Asked Questions

No. Overlap exists in rights and security themes, but CCPA/CPRA has distinct sale/share opt-outs, threshold tests, and California-specific definitions. Map shared tooling; do not assume equivalence.

No. If GDPR applies (establishment or targeting), California law does not displace it. Many US SaaS companies must comply with both for different populations.

CCPA/CPRA is covered comparatively in this theme page. Primary programmatic hubs today are SOC 2, ISO 27001, GDPR, and HIPAA. Expand secondary privacy laws carefully without diluting primary-source hubs.

Verified data-subject/consumer request workflows, retention deletion, vendor inventory, and encryption/access logging help both — then layer GDPR lawful-basis UX and CCPA opt-out/sale signals separately.

See /controls/gdpr/article-32 for security of processing and /controls/gdpr/article-33 for breach notification to supervisory authorities, plus the /frameworks/gdpr hub.

Framework versions referenced in this page:

  • GDPRRegulation (EU) 2016/679
  • CCPA / CPRACalifornia Civil Code (theme comparison)

Last verified: July 2026 · Primary sources linked above