Back to Blog
Compliance4 min read

GDPR vs. CCPA: A Quick Reference Guide

Two privacy laws, different requirements, overlapping obligations. Here's what you need to know about GDPR and CCPA compliance.

If your business collects data on EU residents or California customers — even through a website contact form — GDPR and CCPA are probably in play. They overlap more than they differ, but the gaps matter. Here's the quick reference.

Data Protection Law Cheat Sheet: GDPR and CCPA


General Data Protection Regulation (GDPR)

Scope:

  • Applies to all organizations processing personal data of EU residents, regardless of the organization's location.

Key Principles:

  • Lawfulness, Fairness, and Transparency: Data must be processed lawfully, fairly, and transparently.
  • Purpose Limitation: Data must be collected for specified, explicit, and legitimate purposes.
  • Data Minimization: Data must be adequate, relevant, and limited to what is necessary.
  • Accuracy: Data must be accurate and kept up-to-date.
  • Storage Limitation: Data must be kept in a form which permits identification of data subjects for no longer than necessary.
  • Integrity and Confidentiality: Data must be processed securely to ensure protection against unauthorized access.
  • Accountability: Organizations must demonstrate compliance with GDPR principles.

Rights of Data Subjects:

  • Right to Access: Individuals can access their personal data.
  • Right to Rectification: Individuals can correct inaccurate or incomplete data.
  • Right to Erasure (Right to be Forgotten): Individuals can request deletion of their data.
  • Right to Restrict Processing: Individuals can limit the processing of their data.
  • Right to Data Portability: Individuals can transfer their data to another organization.
  • Right to Object: Individuals can object to data processing.
  • Rights Related to Automated Decision Making and Profiling: Individuals have rights concerning automated processing and profiling.

Compliance Requirements:

  • Data Protection Officer (DPO): Appoint a DPO for large-scale monitoring or processing of sensitive data.
  • Data Protection Impact Assessments (DPIAs): Conduct DPIAs for high-risk processing.
  • Breach Notification: Notify supervisory authorities within 72 hours of a data breach.
  • Consent: Obtain explicit consent for data processing where required.

Penalties:

  • Fines up to €20 million or 4% of the annual global turnover, whichever is higher.

California Consumer Privacy Act (CCPA)

Scope:

  • Applies to for-profit businesses that collect personal data of California residents and meet certain criteria, such as revenue thresholds or data volume.

Key Principles:

  • Transparency: Businesses must disclose data collection practices and purposes.
  • Control: Individuals have more control over their personal data.

Rights of Consumers:

  • Right to Know: Consumers can request information about the categories and specific pieces of personal data collected.
  • Right to Delete: Consumers can request deletion of their personal data.
  • Right to Opt-Out: Consumers can opt-out of the sale or sharing of their personal data (including sharing for cross-context behavioral advertising).
  • Right to Correct: Consumers can request correction of inaccurate personal data.
  • Right to Limit Use of Sensitive Personal Information: Consumers can restrict how businesses use sensitive data to only what is necessary for the transaction.
  • Right to Non-Discrimination: Consumers must not be discriminated against for exercising their privacy rights.

Compliance Requirements:

  • Privacy Policy: Update privacy policies to reflect CCPA rights and practices.
  • Verification: Implement methods for verifying consumer requests.
  • Training: Train employees on CCPA compliance and handling consumer requests.
  • Data Security: Implement reasonable security measures to protect personal data.

Penalties:

  • Fines up to $7,500 per intentional violation and $2,500 per unintentional violation.
  • Private right of action for data breaches, with statutory damages between $100 and $750 per incident.

Where to Go From Here

For primary sources, start with the California AG's CCPA page and the European Commission's GDPR portal. If you need to build a privacy program, the IAPP (iapp.org) is the professional standard — their CIPP/E and CIPM certifications cover GDPR and privacy program management respectively.

Jonathan Carpenter
Jonathan Carpenter
Founder, Anchor Cyber Security
Share:

Want to discuss this topic?

Let's talk about how these insights apply to your organization.

Get in Touch