Theme comparison · gdpr-vs-ccpa
GDPR vs CCPA/CPRA
Theme comparison of the EU GDPR and California CCPA/CPRA — territorial scope, consumer/data-subject rights, and what SaaS teams should not conflate.
Frameworks covered: GDPR
Key differences
| Dimension | GDPR | CCPA / CPRA |
|---|---|---|
| Legal instrument | GDPR — Regulation (EU) 2016/679, directly applicable across EU Member States with EDPB guidance | CCPA/CPRA — California state privacy law (Civil Code) with regulations and AG/CPPA enforcement — not an EU regulation |
| Primary protected party | Data subjects — natural persons in the EU/EEA (and extraterritorial cases) | California consumers — residents of California under CCPA/CPRA definitions |
| Who is regulated | Controllers and processors with GDPR territorial or targeting nexus | Businesses meeting CCPA thresholds (revenue, data volume, or data-selling criteria) and service providers/contractors under CPRA roles |
| Core duties | Lawful basis, transparency, DPIAs where required, security of processing (Art. 32), DPAs, international transfers | Notice at collection, consumer rights (access, delete, opt-out of sale/share, correct, limit sensitive use under CPRA), service-provider contracts |
| “Sale” / advertising | GDPR focuses on lawful basis and purpose limitation for processing — including ads tech; “sale” is not the central CCPA construct | CCPA/CPRA center consumer opt-out of sale/sharing and dark-pattern limits — critical for adtech and data brokers |
| Security expectations | Article 32 — appropriate technical and organisational measures; breach notification to authorities (Art. 33) and individuals (Art. 34) when required | Reasonable security procedures; California also has separate breach statutes — CCPA private right of action for certain breaches of unencrypted data |
| Transfer / cross-border | Chapter V transfer tools (SCCs, adequacy, etc.) when exporting personal data from the EEA | No GDPR-style Chapter V regime — still need contractual and security discipline for California personal information |
| Typical SaaS mistake | Assuming a SOC 2 report or CCPA page equals GDPR compliance | Assuming a GDPR DPA and RoPA automatically satisfy CCPA service-provider and notice requirements |
Control overlap
Transparency, access/deletion workflows, vendor contracts, and security baselines appear in both regimes with different legal tests. Product and eng teams can share identity verification for rights requests, retention tooling, and encryption — but lawful basis (GDPR) and sale/share opt-outs (CCPA/CPRA) need distinct product and legal design. This site’s primary framework ID remains GDPR; CCPA is discussed here as a US state-law counterpart without a separate FRAMEWORK_IDS entry.
Sequencing advice
If you target EU users or monitor EU behavior, stand up GDPR foundations (lawful basis, notices, DPAs, Art. 32 measures, transfer strategy). If you meet CCPA thresholds or process California personal information at scale, implement CCPA/CPRA notices, rights portals, and service-provider terms — often in parallel, not as a copy-paste of GDPR text. Use /frameworks/gdpr for EU depth and /controls/gdpr/article-6, article-28, article-32 for operational articles. Do not treat either law as “done” because the other checklist is green.