Коротко
- GDPR is an EU/EEA regulation with opt-in logic for many cookies; CCPA/CPRA is California law with opt-out of sale/share.
- GDPR applies more broadly to data subjects (no revenue threshold); CCPA is for-profit + thresholds.
- GDPR compliance ≠ automatic CCPA: you need DNSMPI/share disclosures and California notices.
- For multilingual campaigns: banner geo-logic + aligned copy on the site and on the ClikBy redirect.
Not legal advice
A comparison for product and marketing decisions. Details sit with counsel in each jurisdiction.
A guide to structure and facts: www.cookieyes.com/… · www.cookieyes.com/…. Summary KB section: CookieYes → CCPA. This is not legal advice and not a verbatim translation of other articles.
Why compare
Both regimes give people control over data and require transparency. But the consent model, thresholds, data definition, response times, and fines differ. Companies with EU and California traffic often err by putting one «European» banner worldwide or one «US» Accept without Reject.
CPRA brings California closer to GDPR (SPI, correct, agency) but does not turn CCPA into a GDPR copy.
Summary table
| Тема | CCPA / CPRA | GDPR |
|---|---|---|
| Тип | Statutory (+ regulations) | Regulation EU |
| Subjects | California residents | EU/EEA data subjects |
| Who is obligated | For-profit + thresholds | Almost any controller/processor with nexus |
| Данные | PI (+ household/device); SPI under CPRA | Personal data; special categories |
| Default collection | Opt-out (sale/share) | A lawful basis is required; cookies are often opt-in |
| Cookies | Opt-out for sale/share trackers | Consent before non-essential |
| Response time | ~45 days (+45) | ~1 month (+2 if complex) |
| Штрафы | $2.5k / $7.5k per violation | up to €10M/2% or €20M/4% |
| Regulator | AG + CPPA | DPAs / EDPB / Commission |
1. Type of law
CCPA — state statutory law: violations give a cause of action in California courts (with caveats on the private right of action).
GDPR — EU regulation: it applies directly, but enforcement and details go through national DPAs and national acts (plus ePrivacy for cookies).
2. Who it applies to
CCPA/CPRA: for-profit, PI of Californians, revenue / volume / share-of-income thresholds from sale/share. It can reach a business outside CA if it is «doing business» with state residents.
GDPR: processing of personal data of subjects in the EU/EEA (and monitoring of behavior), almost without a «$25M» threshold. Non-profit can fall in scope too.
Bottom line: a small EU landing page without CCPA thresholds can still be under GDPR; a large US brand without EU traffic — the reverse.
3. What data is covered
Definitions are close, but CCPA explicitly pulls in household and device, plus a broad category list. CPRA adds SPI, closer to GDPR special categories.
Exceptions differ: CCPA has HIPAA/CMIA, FCRA, GLBA, public records, and others; GDPR has deceased (mostly), purely household processing, anonymous data. Do not copy exceptions one-to-one.
4. User rights
CCPA baseline: know/access, delete, opt-out of sale, non-discrimination. CPRA+: correct, limit SPI, opt-out of share, elements of automated decision-making.
GDPR: access, rectification, erasure, restriction, portability, objection, objection to automated decision-making/profiling — plus transparency and lawful basis.
Timelines: CCPA is often 45+45 days; GDPR is about a month with a possible extension if complex.
5–7. Opt-in, opt-out, and age
- CCPA: collection of adult PI usually without prior opt-in; opt-out of sale/share is required; opt-in for minors (13–16 / <13).
- GDPR: many purposes need consent or another lawful basis; withdrawing consent must be as easy as giving it.
- Age: CCPA — 16 (parental <13); GDPR — 16 by default, государство-член может снизить до 13.
«We have a GDPR banner, so CCPA is covered» — no. You need California disclosures and DNSMPI/share if there is sale/share.
9. Security
CCPA rests on a duty of reasonable security (and private action on breach). CPRA raises expectations on SPI protection, assessments, and audits for qualifying businesses.
GDPR expressly requires appropriate technical and organisational measures (encryption, pseudonymization, TOMs).
10. Fines
- CCPA: до $2 500 / $7 500 за violation; consumer statutory damages $100–$750 в узких breach-сценариях; потолка «% globallyй выручки» как в GDPR нет — сумма растёт с числом нарушений.
- GDPR: up to €10M/2% or €20M/4% of annual turnover — depending on the article.
What the ClikBy team should do
- Split EU / CA / BY (99-3) audiences in the policy and banners;
- For the EU: consent before marketing pixels; for CA: DNSMPI + a real category opt-out;
- On redirects, enable pixel_notification and do not contradict the site copy;
- Keep a DPA with ClikBy and contracts with ad vendors;
- In-depth product breakdown: Personal data and cookies.
In ClikBy: roles Customer = controller / ClikBy = processor for clicks; the controls are Cookie Consent and pixel_notification on the redirect. A CCPA badge on the landing page does not replace your Do Not Sell or Share notice.
FAQ
Is CCPA like GDPR?
The goals are close; the mechanics are not: different scope, consent model, fines, and cookies.
Is GDPR stricter?
On coverage and «percentage» fines GDPR is often tougher; CCPA is dangerous in the number of per-violation fines and sale through the ads stack.
Do you need granular consent like GDPR?
For CCPA — generally no (see the CookieYes KB on granular consent). You need a working opt-out of sale/share. Source: Does CCPA require granular consent like GDPR?