Home
ClikBy
ClikBy Knowledge Base
CCPA

CCPA vs GDPR: what's the difference

A full comparison for teams with traffic from the EU and California — without the illusion that one banner covers both regimes.

14–18 min Updated: July 2026
opt-outCCPA
opt-inGDPR
cookiesdifferent UX

Коротко

  • GDPR is an EU/EEA regulation with opt-in logic for many cookies; CCPA/CPRA is California law with opt-out of sale/share.
  • GDPR applies more broadly to data subjects (no revenue threshold); CCPA is for-profit + thresholds.
  • GDPR compliance ≠ automatic CCPA: you need DNSMPI/share disclosures and California notices.
  • For multilingual campaigns: banner geo-logic + aligned copy on the site and on the ClikBy redirect.

Not legal advice

A comparison for product and marketing decisions. Details sit with counsel in each jurisdiction.

A guide to structure and facts: www.cookieyes.com/… · www.cookieyes.com/…. Summary KB section: CookieYes → CCPA. This is not legal advice and not a verbatim translation of other articles.

Why compare

Both regimes give people control over data and require transparency. But the consent model, thresholds, data definition, response times, and fines differ. Companies with EU and California traffic often err by putting one «European» banner worldwide or one «US» Accept without Reject.

CPRA brings California closer to GDPR (SPI, correct, agency) but does not turn CCPA into a GDPR copy.

Summary table

ТемаCCPA / CPRAGDPR
ТипStatutory (+ regulations)Regulation EU
SubjectsCalifornia residentsEU/EEA data subjects
Who is obligatedFor-profit + thresholdsAlmost any controller/processor with nexus
ДанныеPI (+ household/device); SPI under CPRAPersonal data; special categories
Default collectionOpt-out (sale/share)A lawful basis is required; cookies are often opt-in
CookiesOpt-out for sale/share trackersConsent before non-essential
Response time~45 days (+45)~1 month (+2 if complex)
Штрафы$2.5k / $7.5k per violationup to €10M/2% or €20M/4%
RegulatorAG + CPPADPAs / EDPB / Commission

1. Type of law

CCPA — state statutory law: violations give a cause of action in California courts (with caveats on the private right of action).

GDPR — EU regulation: it applies directly, but enforcement and details go through national DPAs and national acts (plus ePrivacy for cookies).

2. Who it applies to

CCPA/CPRA: for-profit, PI of Californians, revenue / volume / share-of-income thresholds from sale/share. It can reach a business outside CA if it is «doing business» with state residents.

GDPR: processing of personal data of subjects in the EU/EEA (and monitoring of behavior), almost without a «$25M» threshold. Non-profit can fall in scope too.

Bottom line: a small EU landing page without CCPA thresholds can still be under GDPR; a large US brand without EU traffic — the reverse.

3. What data is covered

Definitions are close, but CCPA explicitly pulls in household and device, plus a broad category list. CPRA adds SPI, closer to GDPR special categories.

Exceptions differ: CCPA has HIPAA/CMIA, FCRA, GLBA, public records, and others; GDPR has deceased (mostly), purely household processing, anonymous data. Do not copy exceptions one-to-one.

4. User rights

CCPA baseline: know/access, delete, opt-out of sale, non-discrimination. CPRA+: correct, limit SPI, opt-out of share, elements of automated decision-making.

GDPR: access, rectification, erasure, restriction, portability, objection, objection to automated decision-making/profiling — plus transparency and lawful basis.

Timelines: CCPA is often 45+45 days; GDPR is about a month with a possible extension if complex.

8. Cookie control

CCPA/CPRA: no EU-style prior consent requirement for all non-essential cookies. You need transparency and opt-out for trackers that constitute sale/share. CPRA explicitly includes share.

GDPR + ePrivacy: non-essential cookies usually after informed consent; Reject must be equivalent to Accept.

A practical stack: geo-target — EU sees an opt-in CMP; CA — Do Not Sell/Share + GPC; the rest of the world — per your policy. Put ClikBy smart links on the same map: do not fire EU pixels before consent or CA pixels after opt-out.

9. Security

CCPA rests on a duty of reasonable security (and private action on breach). CPRA raises expectations on SPI protection, assessments, and audits for qualifying businesses.

GDPR expressly requires appropriate technical and organisational measures (encryption, pseudonymization, TOMs).

10. Fines

  • CCPA: до $2 500 / $7 500 за violation; consumer statutory damages $100–$750 в узких breach-сценариях; потолка «% globallyй выручки» как в GDPR нет — сумма растёт с числом нарушений.
  • GDPR: up to €10M/2% or €20M/4% of annual turnover — depending on the article.

11. Who enforces

CCPA: California Attorney General. CPRA: + California Privacy Protection Agency.

GDPR: national DPAs, EDPB coordination, the Commission framework.

What the ClikBy team should do

  • Split EU / CA / BY (99-3) audiences in the policy and banners;
  • For the EU: consent before marketing pixels; for CA: DNSMPI + a real category opt-out;
  • On redirects, enable pixel_notification and do not contradict the site copy;
  • Keep a DPA with ClikBy and contracts with ad vendors;
  • In-depth product breakdown: Personal data and cookies.

In ClikBy: roles Customer = controller / ClikBy = processor for clicks; the controls are Cookie Consent and pixel_notification on the redirect. A CCPA badge on the landing page does not replace your Do Not Sell or Share notice.

FAQ

Is CCPA like GDPR?

The goals are close; the mechanics are not: different scope, consent model, fines, and cookies.

Is GDPR stricter?

On coverage and «percentage» fines GDPR is often tougher; CCPA is dangerous in the number of per-violation fines and sale through the ads stack.

Do you need granular consent like GDPR?

For CCPA — generally no (see the CookieYes KB on granular consent). You need a working opt-out of sale/share. Source: Does CCPA require granular consent like GDPR?

What’s next?

Review your policy

Open the ClikBy product mapping of roles and consents.