Your Privacy Rights

GDPR vs CCPA: What They Mean for Your Data

By the RedactZero Team · August 3, 2026 · 8 min read

The short version

GDPR is Europe's privacy law: a company needs a legal basis, often your opt-in consent, before it touches your data, and fines run to 4 percent of worldwide revenue. The CCPA is California's: collection is allowed by default, but you get enforceable rights to know, delete, correct, and opt out of the sale of your data. GDPR protects people located in Europe; the CCPA protects California residents. If you are Californian, the most practical wins are the Global Privacy Control browser signal, which businesses must honor, and the state's free DROP platform for deleting your data from registered data brokers.

Two privacy laws, one big idea

GDPR is the European Union's General Data Protection Regulation, in force since May 25, 2018. The CCPA is the California Consumer Privacy Act, in effect since January 1, 2020. Both start from the same idea: companies hold enormous amounts of personal data, and the people that data describes deserve enforceable rights over it.

They answer that idea very differently, and the differences decide what you can actually do. One more piece of history matters: California voters strengthened the CCPA in November 2020 by passing Proposition 24, the CPRA. Its added protections took effect on January 1, 2023 and gave the state a dedicated privacy regulator, the California Privacy Protection Agency. When people say "CCPA" today they usually mean this amended version, and that is how we use it here.

Who each law actually protects

GDPR protects people physically located in the EU and the wider European Economic Area, whatever their citizenship. The CCPA protects California residents, even while they are temporarily out of state. Neither law cares much where the company sits - what matters is who you are, where you are, and the law's coverage thresholds.

That produces results that surprise people. An American living in Berlin has full GDPR rights. A French citizen living in Ohio has neither law's protection. A Texan visiting Los Angeles does not gain CCPA rights, because those belong to residents, not visitors.

Coverage differs on the business side too. The CCPA only applies to for-profit businesses that clear at least one threshold: more than $25 million in annual gross revenue, or buying, selling, or sharing the personal information of 100,000 or more consumers or households, or earning half their revenue from selling or sharing personal data. GDPR has no revenue floor - a tiny web shop in Lisbon carries the same core duties as a tech giant.

Opt-in vs opt-out: the difference that matters most

GDPR works before collection: a company needs one of six lawful bases, such as your consent, before it may process your personal data at all. The CCPA works after: collection is legal by default, and the law hands you rights to see, delete, and stop the sale of what was collected.

You have felt this difference in your browser. European-style consent screens ask permission up front because, without a lawful basis, processing simply is not allowed. California sites instead carry "Do Not Sell or Share My Personal Information" links, because the burden sits on you to object. Neither model is painless, but the default is the whole game: in Europe the company must justify itself; in California you must speak up.

What GDPR lets you do

GDPR gives people in Europe a bundle of individual rights: access to the data an organization holds about you, correction of inaccurate data, erasure - the famous "right to be forgotten" - restriction of processing, a portable machine-readable copy of your data, and the right to object to certain uses, including direct marketing.

It also puts duties on companies rather than on you. The one you are most likely to notice: when a company suffers a personal data breach, GDPR requires it to notify its regulator without undue delay and, where feasible, within 72 hours of becoming aware of it. High-risk breaches must also be disclosed to the affected people, which is why European breach letters tend to arrive faster than American ones.

What the CCPA lets you do

The CCPA gives California residents six practical rights: to know what a business collects about you, to delete it, to correct it (added in the 2023 update), to opt out of its sale or sharing, to limit the use of sensitive personal information, and to face no discrimination - no worse prices or service - for exercising any of them.

The sleeper feature is Global Privacy Control. GPC is a signal your browser sends to every site you visit saying "do not sell or share my information," and under the CCPA covered businesses are legally required to honor it as a valid opt-out request. Turn it on once and you have objected everywhere, automatically, without hunting for footer links.

GDPR vs CCPA at a glance

The comparison below compresses both laws into the parts that touch you directly: who is covered, what the default is, what the penalties look like, and what happens after a breach. It simplifies - both laws run to hundreds of pages - but it is accurate on every line.

GDPRCCPA (as amended)
ProtectsPeople located in the EU/EEA, any citizenshipCalifornia residents
In force sinceMay 25, 2018January 1, 2020; CPRA updates January 1, 2023
Default modelOpt-in: lawful basis required before processingOpt-out: collection allowed, you object to sale/sharing
Top penaltiesUp to EUR 20 million or 4% of worldwide revenue$2,500 per violation; $7,500 if intentional or involving under-16s
Breach rulesRegulator notified within 72 hours where feasibleConsumers can sue for $100 to $750 per incident
Who enforcesEach country's data protection authorityCalifornia Attorney General and the CPPA

Sources: gdpr.eu (Articles 6, 33, 83); California Civil Code sections 1798.140, 1798.150, 1798.155; oag.ca.gov/privacy/ccpa.

What enforcement looks like in real money

Both laws have teeth, but different sizes. GDPR fines reach EUR 20 million or 4 percent of a company's total worldwide annual revenue, whichever is higher. CCPA penalties are $2,500 per violation and $7,500 when intentional or involving consumers under 16 - and because violations can count per consumer, they stack quickly.

The GDPR record is enormous: in May 2023, Ireland's Data Protection Commission fined Meta EUR 1.2 billion over transfers of European users' data to US servers - the largest GDPR fine issued to date.

California's numbers are smaller but increasingly steady. Sephora paid $1.2 million in August 2022, the first public CCPA settlement, largely for ignoring Global Privacy Control opt-out signals. The state's privacy agency then fined Honda $632,500 in March 2025 in its first enforcement order, and Tractor Supply $1.35 million in September 2025, its largest penalty so far. Separately, if a business's poor security exposes your data in a breach, the CCPA lets you sue for $100 to $750 per incident without proving actual losses.

How to actually use these rights today

If you live in California, start with the state's free DROP platform, created by the Delete Act. One request reaches more than 500 registered data brokers, and from August 1, 2026 those brokers are legally required to process the requests. Our California DROP guide walks through signing up step by step.

Next, turn on Global Privacy Control in your browser, and send deletion or correction requests directly to companies via the privacy links in their footers. For the wider legal picture, see our explainers on the Delete Act and your deletion rights state by state.

If you live elsewhere in the US, you are not out of options. Per the IAPP, 19 states have now enacted comprehensive privacy laws, many copying California's model - our guide to privacy options outside California covers what to do. And data-broker opt-outs are free in every state; our step-by-step opt-out guides show exactly how each one works.

Not sure where to begin? RedactZero's free exposure scan shows any breaches tied to your email and the data brokers most likely to list you, and nothing you scan is stored.

See what is out there about you

Rights only help once you know where your data is. Run a free exposure scan to see which brokers likely list you and whether your email has appeared in a breach - no account, nothing stored.

Run a free exposure scan

Frequently asked questions

Does GDPR protect Americans?

Only while they are physically in the EU or EEA. GDPR covers people located in Europe regardless of citizenship, so an American living in Berlin is protected, but an American at home in Ohio is not. At home, your protections come from state laws like the CCPA.

Do I get CCPA rights if I do not live in California?

No. Only California residents have rights under the CCPA. But 19 states have now enacted comprehensive privacy laws of their own, many modeled on California's, so check what applies where you live. Data-broker opt-outs, meanwhile, are free to everyone regardless of state.

What is the difference between opt-in and opt-out?

Under an opt-in model like GDPR's consent basis, a company needs a legal justification, often your permission, before processing your data. Under the CCPA's opt-out model, collection is allowed by default and it is on you to say no to the sale or sharing of your information.

What is Global Privacy Control?

Global Privacy Control (GPC) is a browser signal that tells every site you visit not to sell or share your personal information. Under the CCPA, covered businesses are legally required to honor it as a valid opt-out request. It ships in some browsers and is available as an extension in others.

How big can GDPR fines get?

The most serious GDPR violations carry fines up to EUR 20 million or 4 percent of a company's total worldwide annual revenue, whichever is higher. The record so far is the EUR 1.2 billion fine Ireland's regulator issued to Meta in May 2023 over EU-to-US data transfers.

Has anyone actually been fined under the CCPA?

Yes. Sephora paid $1.2 million in 2022 for ignoring Global Privacy Control opt-outs, Honda was fined $632,500 in March 2025, and Tractor Supply was fined $1.35 million in September 2025 - the California privacy agency's largest penalty to date.

How do I delete my data under the CCPA?

Send a deletion request to the business directly - look for a 'Your Privacy Choices' or CCPA link in its footer. For data brokers, California residents can file one request through the state's free DROP platform and reach more than 500 registered brokers at once.

Which law is stronger, GDPR or CCPA?

They are strong in different ways. GDPR covers more organizations, demands a legal basis before any processing happens, and carries far larger fines. The CCPA gives Californians unusually practical tools, like the legally binding Global Privacy Control signal and the state-run DROP deletion platform for data brokers.

Sources: gdpr.eu (the GDPR text and Articles 6, 33, and 83); the California Attorney General (oag.ca.gov/privacy/ccpa, including the Sephora settlement); California Civil Code sections 1798.140, 1798.150, and 1798.155; the Irish Data Protection Commission (Meta fine, May 2023); the California Privacy Protection Agency (Honda and Tractor Supply orders, and the DROP platform); the IAPP state privacy legislation tracker.