If you handle personal data on both sides of the Atlantic, you'll meet both GDPR and CCPA. Here's how they compare.
The core difference
GDPR is the EU's comprehensive data-protection regulation; CCPA/CPRA is California's privacy law (and a model many US states now follow). GDPR is broader and more prescriptive; CCPA focuses strongly on consumer rights and opt-outs.
| GDPR | CCPA / CPRA | |
|---|---|---|
| Scope | EU residents' personal data | California residents' personal information |
| Lawful basis | Required for processing | Notice + opt-out model |
| Core rights | Access, erasure, portability, more | Know, delete, opt-out of sale/share |
| Data transfers | Restricted out of the EU | Less prescriptive |
What they share
Both require you to know what personal data you hold, honor data-subject/consumer requests, secure the data, and contract carefully with vendors. Much of the underlying work — data mapping, request handling, security controls — is the same.
General guidance, not legal advice. Confirm your specific privacy obligations with your compliance and legal teams.