Two laws, two consent models. What counts as your data under each, who actually has to comply, and the practical checklist for protecting it either way.
| GDPR | CCPA / CPRA | |
|---|---|---|
| Trigger | Processing personal data of someone in the EU/EEA, when offering them goods or services or monitoring their behavior (Art. 3) | Doing business in California and meeting one of three thresholds below (Civ. Code §1798.140(d)) |
| Size/revenue floor | None — no revenue or headcount exemption. A 3-person company selling to EU customers online is in scope. | Any one of: $25M+ annual gross revenue, or buys/sells/shares personal info of 100,000+ consumers or households/year, or derives 50%+ of revenue from selling/sharing personal info |
| Who's covered | Any organization worldwide meeting the territorial test — location of the business is irrelevant | For-profit businesses only; most nonprofits are exempt regardless of size |
| GDPR | CCPA / CPRA | |
|---|---|---|
| Core term | "Personal data" (Art. 4(1)) — any info relating to an identified or identifiable natural person | "Personal information" (§1798.140(v)(1)) — identifies, relates to, or could reasonably be linked to a consumer or household |
| Common examples | Name, ID number, location data, online identifiers (IP address, cookie ID), and physical/genetic/economic/social identity factors | Identifiers (name, email, SSN, IP), purchase history, biometric info, browsing/search history, geolocation, employment & education info, and inferences drawn into a profile |
| Elevated category | Special categories (Art. 9) — race/ethnicity, political opinions, religious belief, union membership, genetic data, biometric ID data, health data, sex life/orientation. Processing is banned by default unless an Art. 9(2) exception applies. | Sensitive personal information (§1798.140(ae)) — government ID numbers, login credentials, precise geolocation (~1,850 ft radius), race/ethnicity, religion, union membership, mail/email/text contents, genetic data, biometric ID data, health data, sex life/orientation. Consumers can limit its use (§1798.121). |
| Notably excluded | — | Lawfully obtained publicly available information (narrowed by CPRA — can't reuse it for an incompatible purpose) and properly de-identified or aggregate data |
Consent is one of six legal bases for processing (Art. 6) — not the only one. When it's the basis actually used, it has to be freely given, specific, informed, unambiguous, and an affirmative act (Art. 4(11), Art. 7).
Pre-checked boxes don't count. Withdrawing consent has to be as easy as giving it.
Not a consent law in the GDPR sense. Businesses collect and use personal information by default; consumers have to affirmatively opt out of sale or sharing (§1798.120) or limit use of sensitive personal information (§1798.121).
Opt-in consent is the exception here — mainly for consumers under 16 (§1798.120(c)-(d)) and for sensitive-data use after an opt-out.
| GDPR | CCPA / CPRA | |
|---|---|---|
| Rights | Access (15), rectification (16), erasure (17), restrict processing (18), portability (20), object (21), rights re: automated decision-making (22) | Know/access (100, 110), delete (105), correct (106), opt out of sale/sharing (120), limit sensitive PI use (121), non-discrimination for exercising any right (125) |