Guide · Privacy

GDPR vs CCPA

If you handle personal data on both sides of the Atlantic, you'll meet both GDPR and CCPA. Here's how they compare.

The core difference

GDPR is the EU's comprehensive data-protection regulation; CCPA/CPRA is California's privacy law (and a model many US states now follow). GDPR is broader and more prescriptive; CCPA focuses strongly on consumer rights and opt-outs.

 GDPRCCPA / CPRA
ScopeEU residents' personal dataCalifornia residents' personal information
Lawful basisRequired for processingNotice + opt-out model
Core rightsAccess, erasure, portability, moreKnow, delete, opt-out of sale/share
Data transfersRestricted out of the EULess prescriptive

What they share

Both require you to know what personal data you hold, honor data-subject/consumer requests, secure the data, and contract carefully with vendors. Much of the underlying work — data mapping, request handling, security controls — is the same.

One program, both lawsMap your data and controls once and apply them across GDPR and US state privacy laws. A self-hosted, region-locked deployment also solves GDPR's transfer restrictions. GDPR · US Data Privacy.

General guidance, not legal advice. Confirm your specific privacy obligations with your compliance and legal teams.

See Vallorix on your own infrastructure

Continuous evidence, auditor-ready reports, and controls that stay in your boundary.

Get a demo →
V
Vallorix AssistantAI · answers about compliance & the product
AI assistant · not a human · answers may be imperfect