GDPR vs CCPA vs the US State Laws: One Comparison Table
GDPR, CCPA/CPRA, and the growing set of US state privacy laws share a lot of DNA but differ in real, practical ways. Here's a single table comparing scope, rights, and enforcement.
If you’re trying to figure out which privacy laws actually apply to your business, it helps to see them side by side rather than read four separate explainers. GDPR, CCPA/CPRA, and the broader wave of US state privacy laws share a common ancestry but differ in scope, consent model, and enforcement in ways that actually change what you need to do.
The comparison
| GDPR (EU/EEA) | CCPA/CPRA (California) | Other US state laws | |
|---|---|---|---|
| Applies based on | Where the individual is located, regardless of your business location | Doing business and meeting CA-specific thresholds, and CA resident data | Similar resident-based scope, varies by state |
| Default consent model | Opt-in for non-essential processing | Opt-out (right to opt out of sale/sharing) | Mostly opt-out, some opt-in elements for sensitive data |
| Core individual rights | Access, rectification, erasure, portability, restriction, objection | Know, delete, opt-out, correct, limit use of sensitive data | Broadly similar, specifics vary by state |
| Enforcement | National data protection authorities, fines up to €20M / 4% of revenue | California Privacy Protection Agency + AG | State AGs, mostly, with varying penalty structures |
| Private right of action | Very limited | Narrow, mainly for certain data breaches | Varies; generally limited |
The distinction that trips people up most: opt-in vs. opt-out
This is the single biggest practical difference. GDPR requires affirmative opt-in consent before non-essential tracking begins, the default state is “off” until a visitor says yes. CCPA and most US state laws instead give visitors a right to opt out of having their data sold/shared, the default state is “on” until a visitor says no. A banner built correctly for one model isn’t automatically correct for the other; see our piece on what GDPR consent actually requires for the opt-in side specifically.
Usercentrics
Managing both consent models correctly, opt-in by default for EU visitors, opt-out mechanisms for US visitors, is exactly the kind of geo-aware configuration Usercentrics is built around.
Why “we’re CCPA compliant” doesn’t mean “we’re GDPR compliant”
Because the underlying consent models are different, a banner tuned for CCPA’s opt-out model (tracking runs by default, with a “Do Not Sell” link) doesn’t satisfy GDPR’s opt-in requirement for EU visitors, and vice versa. If your traffic spans both regions, your consent tool needs to detect visitor location and apply the correct model, not use one configuration everywhere.
How to figure out which of these actually applies to you
Rather than reading every state’s statute individually, our free privacy law checker takes your business location and customer locations and tells you which frameworks from this table are actually in scope for your specific situation.
This comparison is educational and not legal advice, and doesn’t cover every jurisdiction or exemption. For your specific situation, consult a privacy attorney.