The Short Answer
GDPR is EU/EEA law with no revenue or size threshold, applying to any organization processing the personal data of people there. CCPA is California law that applies mainly to larger businesses meeting specific revenue or data-volume thresholds. They share similar goals, protecting individuals' personal data, but differ meaningfully in scope, consent model, and enforcement.
The Fundamental Difference
| GDPR | CCPA (as amended by CPRA) | |
|---|---|---|
| Jurisdiction | EU / EEA | California, USA |
| Applies based on | Data subject's location, no size threshold | Business meeting revenue or data-volume thresholds |
| Consent model | Opt-in for many processing purposes | Opt-out of sale/sharing |
| Enforced by | National Data Protection Authorities | California Privacy Protection Agency |
| Maximum fines | €20M or 4% of global turnover | $2,500–$7,500 per violation |
| DPO required? | For certain large-scale processing | No formal DPO requirement |
See our GDPR compliance guide for the full picture of GDPR specifically.
Applicability: The Biggest Practical Difference
GDPR has no minimum size or revenue threshold. A five-person startup offering services to a handful of EU users is squarely subject to it. CCPA only applies once specific thresholds are crossed: over $25 million in annual gross revenue, or processing personal information of 100,000 or more California consumers or households annually, or deriving 50 percent or more of revenue from selling or sharing personal information. A small US startup can be fully subject to GDPR while being entirely exempt from CCPA, which surprises many founders who assume US-only companies can ignore EU privacy law.
Opt-In vs Opt-Out: Different Defaults
GDPR generally requires a lawful basis, often opt-in consent, before processing personal data for many purposes. The default is no collection without justification. CCPA takes the opposite starting point: businesses can generally process personal information by default, but must honor a consumer's right to opt out of its sale or sharing. This difference shapes how consent banners, privacy notices, and data collection flows need to be designed for each.
Not sure which of these applies to your business?
We'll check your actual user base and revenue against both frameworks' real thresholds.
Get a Free QuoteEnforcement and Penalties
GDPR fines can reach 20 million euros or 4 percent of global annual turnover, whichever is higher, enforced by national Data Protection Authorities. CCPA penalties are assessed per violation, generally up to $2,500 for unintentional violations and $7,500 for intentional ones or those involving minors, enforced by the California Privacy Protection Agency. The scale is fundamentally different, GDPR's percentage-of-revenue model can produce far larger absolute penalties for large organizations than CCPA's per-violation structure.
Does Complying With One Cover the Other?
Partially. Data mapping, security safeguards, and breach response processes built for GDPR carry over well to CCPA, since both frameworks care about similar underlying data governance discipline. But CCPA-specific mechanics, particularly the opt-out flow for sale and sharing of personal information and California's specific consumer request handling rules, don't exist under GDPR and need dedicated implementation on top of a GDPR programme if you're subject to both.
Subject to both GDPR and CCPA?
We build one coordinated compliance programme that satisfies both rather than two separate projects.
Talk to an Avantcert ExpertFrequently asked questions about GDPR vs CCPA
Does a small US startup need to worry about GDPR at all?
Yes, if you offer goods or services to individuals in the EU or monitor their behavior, regardless of company size or revenue. GDPR has no minimum threshold. CCPA, by contrast, only applies once a business crosses specific revenue or data-volume thresholds, so a small startup can be squarely subject to GDPR while being entirely exempt from CCPA.
What are the actual CCPA applicability thresholds?
A for-profit business doing business in California generally falls under CCPA if it has over $25 million in annual gross revenue, or buys, sells, or shares the personal information of 100,000 or more California consumers or households annually, or derives 50 percent or more of annual revenue from selling or sharing personal information.
What's the core difference between GDPR's and CCPA's consent models?
GDPR generally requires opt-in consent before processing personal data for many purposes, the default is no collection without a lawful basis. CCPA operates on an opt-out model, businesses can process personal information by default, but must honor a consumer's right to opt out of its sale or sharing.
Which has bigger fines, GDPR or CCPA?
GDPR, by a wide margin. GDPR fines can reach up to 20 million euros or 4 percent of global annual turnover, whichever is higher, for the most serious infringements. CCPA penalties are assessed per violation, generally up to $2,500 for unintentional violations and $7,500 for intentional ones, or violations involving minors, a fundamentally smaller scale even before accounting for GDPR's revenue-based ceiling.
Who enforces GDPR versus CCPA?
GDPR is enforced by national Data Protection Authorities across EU/EEA member states, coordinated through mechanisms like the European Data Protection Board. CCPA, as amended by the CPRA, is enforced by the California Privacy Protection Agency, a dedicated state regulator created specifically for this purpose.
If we're already GDPR compliant, does that cover CCPA too?
It covers a meaningful share but not all of it. Data mapping, security safeguards, and breach response processes built for GDPR carry over well. CCPA-specific requirements, particularly the opt-out mechanism for sale and sharing of personal information and California-specific consumer request handling, still need dedicated implementation on top of a GDPR programme.
About Avantcert. Avantcert is a compliance consultancy that has guided 3,000+ organisations across 40+ markets through GDPR and CCPA data mapping, remediation, and defensible compliance evidence. See our GDPR compliance service or request a free quote.