Comparison

GDPR vs CCPA vs the US State Laws: One Comparison Table

GDPR, CCPA/CPRA, and the growing set of US state privacy laws share a lot of DNA but differ in real, practical ways. Here's a single table comparing scope, rights, and enforcement.

Published June 15, 2026·Last updated August 18, 2026

If you’re trying to figure out which privacy laws actually apply to your business, it helps to see them side by side rather than read four separate explainers. GDPR, CCPA/CPRA, and the broader wave of US state privacy laws share a common ancestry but differ in scope, consent model, and enforcement in ways that actually change what you need to do.

The comparison

GDPR (EU/EEA) CCPA/CPRA (California) Other US state laws
Applies based on Where the individual is located, regardless of your business location Doing business and meeting CA-specific thresholds, and CA resident data Similar resident-based scope, varies by state
Default consent model Opt-in for non-essential processing Opt-out (right to opt out of sale/sharing) Mostly opt-out, some opt-in elements for sensitive data
Core individual rights Access, rectification, erasure, portability, restriction, objection Know, delete, opt-out, correct, limit use of sensitive data Broadly similar, specifics vary by state
Enforcement National data protection authorities, fines up to €20M / 4% of revenue California Privacy Protection Agency + AG State AGs, mostly, with varying penalty structures
Private right of action Very limited Narrow, mainly for certain data breaches Varies; generally limited

The distinction that trips people up most: opt-in vs. opt-out

This is the single biggest practical difference. GDPR requires affirmative opt-in consent before non-essential tracking begins, the default state is “off” until a visitor says yes. CCPA and most US state laws instead give visitors a right to opt out of having their data sold/shared, the default state is “on” until a visitor says no. A banner built correctly for one model isn’t automatically correct for the other; see our piece on what GDPR consent actually requires for the opt-in side specifically.

Our recommendation

Usercentrics

Managing both consent models correctly, opt-in by default for EU visitors, opt-out mechanisms for US visitors, is exactly the kind of geo-aware configuration Usercentrics is built around.

Try Usercentrics

Why “we’re CCPA compliant” doesn’t mean “we’re GDPR compliant”

Because the underlying consent models are different, a banner tuned for CCPA’s opt-out model (tracking runs by default, with a “Do Not Sell” link) doesn’t satisfy GDPR’s opt-in requirement for EU visitors, and vice versa. If your traffic spans both regions, your consent tool needs to detect visitor location and apply the correct model, not use one configuration everywhere.

How to figure out which of these actually applies to you

Rather than reading every state’s statute individually, our free privacy law checker takes your business location and customer locations and tells you which frameworks from this table are actually in scope for your specific situation.

This comparison is educational and not legal advice, and doesn’t cover every jurisdiction or exemption. For your specific situation, consult a privacy attorney.