💼 This website is for sale — a proven, self-running tool + content asset. Serious inquiries: contact@sellyourinfo.com
SellYourInfo
Share this tool: in f X r 🌐

GDPR vs. CCPA vs. New State Privacy Laws: A Plain-English Comparison

Direct answer: GDPR (EU) is the broadest and strictest, requiring an affirmative legal basis for any data processing; CCPA/CPRA (California) gives consumers the right to know, delete, and opt out of sale but doesn't require opt-in consent for most processing; and the newer wave of 20-plus U.S. state laws generally follows a lighter version of the California model, with variation in thresholds and specific protections.

GDPR: consent-first, EU-wide

Under GDPR, companies need a valid legal basis — often explicit consent — before processing personal data at all, and violations can trigger fines up to a percentage of global revenue, making it the strictest framework most global companies have to comply with.

CCPA/CPRA: opt-out, not opt-in

California's model assumes data collection can happen by default but gives consumers rights to know what's collected, request deletion, and opt out of sale or sharing — a materially lighter standard than GDPR's opt-in requirement.

The new state law template

Most of the 20-plus state laws in effect by 2026 (Virginia's original model, now echoed in states like Kentucky, Indiana, and Rhode Island) follow a CCPA-like opt-out structure, with variation in which businesses are covered (based on revenue or data-volume thresholds) and which specific categories get extra protection.

What this patchwork means for consumers

Your specific rights depend heavily on which state you live in — some states have universal opt-out signal recognition and dedicated health-data protections; others have narrower coverage — which is why checking your specific state's law matters more than assuming a single national standard.

Frequently Asked Questions

Which law gives consumers the most control, GDPR or CCPA?

GDPR generally gives EU residents more control because it requires an affirmative legal basis (often consent) before processing, whereas CCPA/CPRA is primarily an opt-out model that assumes collection can happen by default.

Do all US states now have a privacy law like California's?

No — roughly 20 states have comprehensive privacy laws as of 2026, but coverage, thresholds, and specific protections vary significantly between them, and about 30 states still have no comprehensive law.

Does GDPR apply to a US company if it has no EU offices?

GDPR can still apply if a US company offers goods or services to, or monitors the behavior of, individuals in the EU, regardless of whether the company has a physical EU presence.