GDPR vs. CCPA: 2026 Compliance Guide for US Businesses
GDPR vs. CCPA compared for 2026: scope, consent models, penalties, and the vendor-contract gap most compliance guides miss. Know which law applies and what to fix.
Generate a data processing agreement in 60 seconds
Describe what you need in plain English. A panel of AI agents (Researcher, Drafter, Critic, Validator, Adversary) writes a review-ready draft you can edit, sign, and send.
GDPR vs. CCPA: Which Privacy Law Applies to Your Business?
The GDPR is an EU opt-in framework requiring a lawful basis before any personal data processing, and it applies to every organization — any size, any sector, any country — that handles personal data of EU/EEA residents. The CCPA/CPRA is a California opt-out law applying only to for-profit businesses meeting specific thresholds. Both laws can apply to the same company simultaneously, and the place most dual-compliance programs silently fail is not consent banners — it is vendor contracts.
Key takeaways
- GDPR covers any organization processing EU resident data with no size minimum; CCPA covers only for-profit California-facing businesses above defined thresholds.
- GDPR requires opt-in consent as a default; CCPA allows data collection by default but mandates a clear opt-out mechanism.
- GDPR requires a written Data Processing Agreement (DPA) under Article 28 with eight mandatory provisions; CCPA requires a differently structured service provider agreement — a GDPR DPA alone does not satisfy CCPA.
- As of 2025, CCPA intentional-violation fines are $7,988 per violation with no aggregate cap; GDPR fines reach up to €20 million or 4% of global annual revenue, whichever is higher.
- California's CPPA issued the largest-ever CCPA penalty in 2025: a $12.75 million settlement with General Motors for selling driver geolocation data without consent.
Who Does Each Law Cover?
GDPR scope is defined by Article 3 and requires no revenue minimum. Any organization that offers goods or services to people in the EU, or monitors the behavior of people in the EU, must comply — whether the company is in Berlin, Boston, or Bangalore. A Chicago SaaS company with EU customers is covered. A nonprofit with EU subscribers is covered.
CCPA/CPRA scope is narrower and threshold-based. The law applies to for-profit businesses doing business in California that meet at least one of three criteria:
| Threshold | Current figure (2025) |
|---|---|
| Annual gross revenue | Above $26.625 million (CPI-adjusted) |
| Data volume | Buying, selling, or sharing personal information of 100,000+ California residents or households |
| Revenue from data sales | 50% or more of annual revenue from selling or sharing personal information |
Sources: Cal. Civ. Code § 1798.140; California Privacy Protection Agency 2024 CPI adjustment announcement.
CCPA also exempts nonprofits and government agencies entirely. GDPR does not. That distinction matters for educational institutions, charities, and trade associations operating across both jurisdictions.
Consent: Opt-In vs. Opt-Out
This is the most operationally consequential difference between the two laws, and it affects every form, banner, and email flow you build.
GDPR requires a lawful basis before processing begins. Consent under GDPR Article 6 must be freely given, specific, informed, and unambiguous — a pre-ticked box does not qualify (confirmed by the Court of Justice of the EU in Planet49, C-673/17). If consent is not the chosen lawful basis, the organization must rely on one of the other five: contract, legal obligation, vital interests, public task, or legitimate interests. Processing without a documented lawful basis is the most common trigger for large fines: LinkedIn Ireland received a €310 million fine in October 2024 from Ireland's DPC for using an incorrect legal basis for targeted advertising.
CCPA/CPRA flips the default. Businesses may collect and use personal information without prior consent in most cases, as long as consumers have a clear, functional way to opt out of the sale or sharing of their data. The required mechanism — originally a "Do Not Sell My Personal Information" link, expanded under CPRA to cover "sharing" for cross-context behavioral advertising — must actually work. Tractor Supply Company paid $1.35 million in September 2025 after the CPPA found that its "Do Not Sell" link routed consumers to a web form that did not actually stop data sharing through third-party tracking technologies.
CPRA Section 1798.135 also requires businesses to honor browser-based opt-out preference signals such as Global Privacy Control (GPC). Ignoring GPC is no longer a minor oversight — it was a central violation in the Tractor Supply case and has appeared in multiple other CPPA enforcement actions.
One practical consequence: your cookie banner for EU visitors must collect affirmative consent before any non-essential cookies fire. Your California flow must allow users to opt out of data sales after the fact. These requirements are structurally incompatible in a single banner without conditional logic tied to user geography.
The Contract Gap: Where Dual Compliance Actually Breaks Down
Every GDPR vs. CCPA comparison covers consent and penalties. Almost none covers the layer where most dual-compliance programs quietly fail: vendor contracts.
Both laws require a written agreement with any third party that processes personal data on your behalf. They use different terminology, require different clauses, and are not interchangeable.
| Requirement | GDPR Article 28 DPA | CCPA/CPRA Service Provider Agreement |
|---|---|---|
| Document name | Data Processing Agreement | Service Provider Agreement (or Addendum) |
| Your role | Data Controller | Business |
| Their role | Data Processor | Service Provider |
| Processing scope | Must state subject matter, duration, nature, purpose, data types, and categories of data subjects | Must identify specific business purposes (reference to services alone is insufficient) |
| Documented instructions | Processor acts only on written instructions (Art. 28(3)(a)) | No equivalent — focus is on contractual purpose limitation |
| Confidentiality | Required for all authorized personnel (Art. 28(3)(b)) | Not expressly required but advisable |
| Security measures | Must reference Art. 32 technical/organizational measures | Must maintain reasonable security; security audit rights added by CPPA regs effective Jan. 1, 2026 |
| Sub-processor rules | Requires prior specific or general written authorization; sub-processors bound by same terms (Art. 28(2), 28(4)) | Must require service providers to impose same restrictions on subcontractors |
| Data subject rights | Must assist controller in responding to data subject rights (Art. 28(3)(e)) | Must assist business with CCPA consumer rights requests |
| Deletion/return | Processor must delete or return all data at end of services (Art. 28(3)(g)) | Must include prohibition on retaining data beyond contract purpose |
| Audit rights | Controller may audit; processor must cooperate (Art. 28(3)(h)) | CPPA 2026 regulations require cybersecurity audit provisions for qualifying businesses |
| No-sale certification | Not applicable | Service provider must certify it will not sell the personal information (Cal. Civ. Code § 1798.140(ag)) |
| Transfer mechanism | Must address international transfers (SCCs, adequacy decision, etc.) for non-EEA processors | No restrictions on international data transfers |
A GDPR-compliant DPA does not automatically satisfy CCPA, because it will not contain the no-sale certification, the CCPA-specific business purpose language, or the required CPRA-era prohibitions on sharing for cross-context behavioral advertising. A CCPA service provider agreement does not satisfy GDPR, because it typically lacks documented-instruction requirements, data deletion/return obligations, and sub-processor chain rules.
The fix is a combined vendor addendum — often called a "DPA++" — that includes both sets of requirements in a single document with jurisdiction-specific annexes. To see how a compliant data processing agreement is structured, explore Pactlio's DPA template, and read our deeper breakdown in the GDPR DPA guide.
A Worked Example: The US SaaS Company Caught Between Both Laws
Situation: A US-based B2B software company generates $40 million in annual revenue, has customers in Germany, France, and the Netherlands, and processes account data for approximately 150,000 California business users.
Which laws apply?
- GDPR applies because the company offers services to EU residents and processes their personal data (GDPR Article 3).
- CCPA/CPRA applies because the company (a) exceeds $26.625 million in annual revenue and (b) processes data of more than 100,000 California residents.
What the company must do differently for each law:
For EU users: Deploy a consent management platform that collects explicit opt-in consent for marketing cookies before they fire. Maintain records of processing activities (GDPR Article 30). Execute a GDPR Article 28 DPA with every third-party vendor — including the email platform, analytics tool, and cloud host. Appoint a Data Protection Officer if processing is systematic and large-scale (GDPR Article 37). Report breaches to the relevant supervisory authority within 72 hours.
For California users: Add a "Do Not Sell or Share My Personal Information" link in the website footer. Configure the site to honor GPC signals automatically. Respond to consumer rights requests — access, deletion, correction, portability — within 45 days (CPRA Section 1798.130(2)(A)). Execute CCPA-compliant service provider agreements with all vendors. Starting January 1, 2026, conduct mandatory cybersecurity audits and risk assessments for automated decision-making technology (CPPA regulations, September 2025).
What the company cannot recycle from its GDPR work: Its GDPR DPAs do not contain the CCPA no-sale certification. Its EU privacy notice does not include the "categories of third parties to whom personal information is disclosed" disclosure required by CCPA. Its 72-hour breach notification process is faster than California law requires, so it satisfies both — but the breach notification goes to the EU supervisory authority, not to affected California consumers directly.
For a compliant privacy policy that satisfies both frameworks, you'll need jurisdiction-specific disclosures rather than a single one-size-fits-all document.
Penalties: What Non-Compliance Actually Costs
GDPR fines have exceeded €7.1 billion since 2018, with approximately €1.2 billion issued in 2025 alone. The average fine across all enforcement actions is approximately €2.36 million, though outlier cases dominate the headlines: Meta received the largest single GDPR fine ever — €1.2 billion from Ireland's DPC in May 2023 — for unlawfully transferring EU user data to the United States without adequate safeguards.
CCPA/CPRA enforcement has escalated sharply. The five largest confirmed penalties:
| Enforcement action | Amount | Violation |
|---|---|---|
| General Motors (joint AG/CPPA, 2025) | $12.75 million | Selling geolocation and driving behavior data to brokers without consent |
| Tractor Supply Company (CPPA, Sept. 2025) | $1.35 million | Non-functional opt-out; failure to honor GPC signals |
| Sephora (California AG, 2022) | $1.2 million | Failure to disclose data sales; ignored GPC signals |
| PlayOn Sports (2024) | $1.1 million | Inadequate protection of student data; insufficient disclosure |
| American Honda (CPPA, March 2025) | $632,500 | Excessive identity verification requirements before consumer rights could be exercised |
The CPPA reported hundreds of active investigations in its 2025 annual report — most at a stage where the targeted business was not yet aware it was under scrutiny.
For a deeper look at jurisdiction-specific compliance obligations, see our GDPR compliance guide and our CCPA privacy policy guide for California businesses.
How to Build a Dual-Compliance Privacy Program
-
Map your data flows. Identify every category of personal data you collect, every jurisdiction where you have users, and every third-party vendor that touches that data. You cannot comply with either law without knowing what you have.
-
Determine applicability for each law separately. Apply the GDPR Article 3 test (do you offer goods/services to, or monitor behavior of, EU residents?). Apply the CCPA three-threshold test independently. Do not assume one implies the other.
-
Build jurisdiction-sensitive consent infrastructure. EU users need opt-in consent before non-essential data processing. California users need a functional opt-out mechanism and automatic GPC signal recognition. These are two separate technical configurations, not one.
-
Audit every vendor agreement. GDPR requires an Article 28 DPA with eight mandatory provisions. CCPA requires a service provider agreement with a no-sale certification and CPRA-specific purpose restrictions. Use a combined addendum with jurisdiction-specific annexes. Generate a compliant DPA and draft a privacy policy that addresses both frameworks before signing any vendor contract.
-
Set parallel breach notification workflows. GDPR: notify the supervisory authority within 72 hours of awareness; notify affected data subjects if the breach is likely to result in high risk. California: notify affected residents "in the most expedient time possible and without unreasonable delay" per Cal. Civ. Code § 1798.82.
-
Conduct the new CPPA-required audits. Effective January 1, 2026, CPPA regulations require cybersecurity audits for qualifying businesses and formal risk assessments for automated decision-making technology (ADMT) that makes significant decisions about consumers. GDPR has required Data Protection Impact Assessments (DPIAs) for high-risk processing under Article 35 since 2018.
-
Train your team on request response timelines. GDPR: respond to data subject access, deletion, correction, and portability requests within one month (Article 12), extendable by two months with notice. CCPA/CPRA: respond within 45 days (CPRA Section 1798.130(2)(A)), extendable by 45 more days with notice.
Common Mistakes to Avoid
- Running a single "global" privacy notice. GDPR and CCPA require different disclosures. A single document rarely satisfies both without jurisdiction-specific sections.
- Using a GDPR DPA as your CCPA service provider agreement. The GDPR DPA lacks the CCPA no-sale certification and the explicit purpose-limitation language California law requires. Both parties are exposed.
- Ignoring GPC signals. The CPPA treats failure to honor browser-based opt-out signals as a distinct violation. It was central to multiple 2024–2025 enforcement actions.
- Applying the same consent banner to all users. EU users require opt-in before non-essential cookies fire. California users require an opt-out link. Pre-checked boxes violate GDPR; an opt-in-only flow may be more restrictive than CCPA requires but satisfies both.
- Assuming GDPR compliance covers international transfers automatically. The CCPA places no restrictions on international data transfers. GDPR's Chapter V imposes strict requirements including Standard Contractual Clauses and Transfer Impact Assessments for data leaving the EEA.
- Missing the 2026 CPPA cybersecurity audit requirement. Effective January 1, 2026, qualifying California businesses must complete mandatory cybersecurity audits. This obligation has no direct GDPR equivalent but aligns with the spirit of GDPR Article 32.
Sources
- GDPR Article 3 (Territorial Scope): https://gdpr-info.eu/art-3-gdpr/
- GDPR Article 6 (Lawful Basis for Processing): https://gdpr-info.eu/art-6-gdpr/
- GDPR Article 12 (Response timelines): https://gdpr-info.eu/art-12-gdpr/
- GDPR Article 28 (Processor requirements): https://gdpr-info.eu/art-28-gdpr/
- GDPR Article 33 (Breach notification to supervisory authority): https://gdpr-info.eu/art-33-gdpr/
- GDPR Article 37 (Data Protection Officer): https://gdpr-info.eu/art-37-gdpr/
- GDPR Article 83 (Administrative fines): https://gdpr-info.eu/art-83-gdpr/
- California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq.: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.100
- CPRA Section 1798.130(2)(A) (45-day response window): https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.130
- Cal. Civ. Code § 1798.82 (California breach notification statute): https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.82
- CCPA Section 1798.135 (Global Privacy Control / opt-out mechanism): https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.135
- California Privacy Protection Agency — 2025 CPI Fine Adjustments: https://cppa.ca.gov/announcements/2024/20241217.html
- CPPA Final Order: Tractor Supply Company ($1.35M, September 2025): https://www.orrick.com/en/Insights/2025/10/CPPA-Imposes-the-Largest-Administrative-Fine-to-Date-What-Companies-Need-to-Know
- IAPP — GM $12.75M CCPA Settlement: https://iapp.org/news/a/california-authorities-announce-largest-ccpa-fine-to-date
- CPPA — September 2025 ADMT, Cybersecurity Audit, and Risk Assessment Regulations: https://www.privacyworld.blog/2025/10/california-privacy-agency-rolls-out-new-regulations-and-approves-1-35-million-penalty-in-latest-ccpa-enforcement-action/
- Irish DPC — Meta €1.2B Fine (May 2023, EU-US data transfers): https://www.dataprotection.ie/en/news-media/press-releases/data-protection-commission-announces-conclusion-of-inquiry-into-meta-ireland
- Irish DPC — LinkedIn €310M Fine (October 2024): https://www.dataprotection.ie/en/news-media/press-releases/data-protection-commission-announces-decision-in-linkedin-inquiry
- DLA Piper GDPR Fines Survey (January 2026) — €7.1B cumulative total: https://www.dlapiper.com/en/insights/publications/2026/01/dla-piper-gdpr-fines-and-data-breach-survey-2026
- CJEU Planet49, C-673/17 (pre-ticked consent boxes invalid): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A62017CJ0673
This article is general information, not legal advice. Laws vary by jurisdiction. Pactlio generates professional drafts for review — have a licensed attorney review anything important.
Frequently Asked Questions
What is the main difference between GDPR and CCPA?▾
The GDPR is an EU opt-in framework: businesses must have a lawful basis before processing personal data, and it applies to any organization of any size that handles EU/EEA residents' data. The CCPA/CPRA is a California opt-out law that applies only to for-profit businesses meeting specific revenue or data-volume thresholds.
Does GDPR apply to US companies?▾
Yes. GDPR Article 3 applies extraterritorially to any organization that offers goods or services to people in the EU, or monitors their behavior within the EU — regardless of where the company is incorporated or located. A US-based SaaS company with even one EU customer falls under GDPR.
Does CCPA apply to businesses outside California?▾
Yes. CCPA applies to any for-profit business that does business in California and meets at least one threshold: annual gross revenue above $26.625 million (2025 figure), buying/selling/sharing data of 100,000 or more California residents, or deriving 50% or more of annual revenue from selling personal information.
Can a business be subject to both GDPR and CCPA at the same time?▾
Yes. A US company that sells software to EU customers and has 100,000+ California users must comply with both simultaneously. The laws are not inherently incompatible, but they require different consent mechanisms, different vendor contracts, and different breach notification timelines running in parallel.
What are the penalties for GDPR violations vs. CCPA violations?▾
GDPR fines reach up to €20 million or 4% of global annual turnover, whichever is higher. CCPA/CPRA fines (as of 2025) are $2,663 per unintentional violation and $7,988 per intentional violation, with no aggregate cap — so a single breach affecting thousands of consumers can compound rapidly.
What is a GDPR Data Processing Agreement and do I need one for CCPA too?▾
A GDPR Data Processing Agreement (DPA) is a written contract required by GDPR Article 28 whenever you share personal data with a vendor. CCPA requires a different document — a service provider agreement — with partially overlapping but distinct terms. Running a GDPR DPA alone does not automatically satisfy CCPA.
What is the breach notification deadline under GDPR vs. CCPA?▾
GDPR requires notifying your supervisory authority within 72 hours of discovering a breach (GDPR Article 33). CCPA does not have its own breach notification rule; California relies on Cal. Civ. Code § 1798.82, which requires notification 'in the most expedient time possible and without unreasonable delay.'
Does GDPR compliance automatically mean CCPA compliance?▾
Not entirely. GDPR compliance is a strong foundation because its requirements generally exceed CCPA's, but the two laws differ on consent direction (opt-in vs. opt-out), vendor contract terminology, data transfer restrictions, and the 'Do Not Sell' mechanism, which exists only under California law.