GDPR vs. CCPA: What You Need to Know Now
Why Counsel Can No Longer Treat GDPR and CCPA as Interchangeable
Data privacy law has matured from a niche compliance concern into a core area of legal practice. Yet many lawyers still approach the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), as if they are essentially the same framework wearing different flags. They are not. Understanding where these regimes align—and where they diverge sharply—is now a fundamental competency for any counsel advising businesses that collect personal data.
Foundational Differences Every Lawyer Should Understand
Jurisdictional Reach and Threshold Triggers
GDPR applies to any organization, regardless of where it is established, that processes personal data of individuals located in the European Economic Area (EEA). There is no minimum revenue or data-volume threshold; a single EU resident's data can trigger applicability.
CCPA/CPRA applies to for-profit businesses that do business in California and meet at least one of three thresholds:
- Annual gross revenues exceeding $25 million
- Annually buys, sells, or shares for commercial purposes the personal information of 100,000 or more consumers or households
- Derives 50% or more of annual revenues from selling or sharing consumers' personal information
Practical takeaway: A mid-size SaaS company with EU users but modest California-facing revenue may face full GDPR obligations while falling entirely outside CCPA's scope—or vice versa. Counsel must conduct threshold analysis before advising on compliance posture.
Legal Bases for Processing vs. Opt-Out Rights
One of the most operationally significant distinctions is the concept of lawful basis. GDPR requires organizations to identify and document a specific legal basis—consent, legitimate interests, contractual necessity, legal obligation, vital interests, or public task—before processing personal data. This is a prerequisite, not an afterthought.
CCPA/CPRA takes a fundamentally different approach: processing is generally permitted, but consumers have the right to opt out of the sale or sharing of their personal information. The burden shifts from pre-justification to honoring consumer choices after the fact.
For counsel drafting privacy notices or advising on data flows, this distinction has immediate drafting consequences. A GDPR-compliant notice that lists legitimate interests as a legal basis does not satisfy CCPA's requirement to disclose opt-out rights—and a CCPA opt-out mechanism does not substitute for GDPR's lawful basis documentation.
Sensitive Data Categories
Both frameworks elevate protection for certain categories of data, but the lists differ:
- GDPR identifies special categories including racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data used for identification, health data, and sex life or sexual orientation.
- CPRA (the CCPA amendment) adds its own sensitive personal information (SPI) category, which includes Social Security numbers, financial account credentials, precise geolocation, genetic data, and the contents of private communications.
Counsel advising clients who process health or biometric data should ensure compliance mapping covers both frameworks' heightened requirements, which may include explicit consent under GDPR and a separate opt-out right for SPI use under CPRA.
Where the Frameworks Overlap: Building an Efficient Compliance Program
Despite their differences, GDPR and CCPA/CPRA share several core obligations that allow counsel to build layered compliance programs rather than duplicating effort entirely.
Consumer and Data Subject Rights
Both regimes recognize:
- Right of access – individuals may request to know what personal data is held about them
- Right to deletion – subject to exceptions, individuals may request erasure
- Right to data portability – individuals can request their data in a portable format
- Non-discrimination – businesses cannot penalize individuals for exercising their privacy rights
Building a unified Data Subject Request (DSR) / Consumer Request workflow that satisfies both regimes' response timelines (30 days extendable under GDPR; 45 days extendable under CCPA) is a practical starting point for most organizations.
Contracts with Third Parties
Both frameworks require written agreements with vendors and processors that handle personal data. GDPR mandates Data Processing Agreements (DPAs) with specific mandatory clauses. CCPA/CPRA requires service provider contracts that prohibit the service provider from selling or using the data outside the business purpose. Counsel should audit vendor contracts to ensure they satisfy both sets of requirements where applicable, rather than maintaining two parallel contract libraries unnecessarily.
Enforcement Landscape: Understanding the Stakes
GDPR Enforcement
GDPR enforcement authority rests with supervisory authorities in each EU member state, with cross-border cases coordinated through the lead supervisory authority mechanism. Penalties can reach €20 million or 4% of global annual turnover, whichever is higher. Enforcement has been active, with regulators scrutinizing cookie consent, data transfer mechanisms, and AI-related processing.
CCPA/CPRA Enforcement
The California Privacy Protection Agency (CPPA) assumed rulemaking and enforcement authority under CPRA. The California Attorney General retains enforcement authority as well. Fines reach $2,500 per unintentional violation and $7,500 per intentional violation, with a private right of action available to consumers for certain data breaches. The CPPA has signaled aggressive enforcement priorities, particularly around dark patterns in consent interfaces.
Counsel should advise clients not to treat CCPA penalties as immaterial. At scale, per-violation fines can accumulate rapidly.
Immediate Action Items for Legal Counsel
- Map your client's data flows before any compliance advice—jurisdiction, data types, and vendor relationships all affect which obligations apply.
- Audit privacy notices to ensure they satisfy both frameworks' distinct disclosure requirements.
- Review lawful basis documentation for GDPR and opt-out mechanisms for CCPA/CPRA as separate compliance tracks.
- Update vendor contracts to include both DPA and service provider agreement language where cross-border data sharing occurs.
- Train client personnel on DSR/consumer request handling, including verification procedures that balance identity confirmation with privacy.
- Monitor regulatory guidance—both the EDPB and the CPPA regularly issue updated guidance that can shift compliance obligations without legislative change.
The Bottom Line
GDPR and CCPA/CPRA are complementary but distinct legal regimes. Counsel who conflate them risk leaving clients exposed on one side while over-engineering compliance on the other. A structured, jurisdiction-specific analysis—followed by a unified operational program where possible—is the mark of sophisticated privacy counsel in today's regulatory environment. The investment in getting this right now is far less costly than responding to a regulatory investigation or class action later.