Beyond SOC 2
What is the main difference between GDPR and CCPA?
What is the main difference between GDPR and CCPA?
The main difference is the default. GDPR requires a lawful basis, such as consent or contract, before personal data is processed at all, and it applies to any organization handling data of people in the EU regardless of size. CCPA lets businesses collect personal information by default and gives California consumers rights to know, delete, correct, and opt out of its sale or sharing, and it applies only to for-profit businesses above set thresholds. GDPR is also far more expensive to breach, with fines up to 4% of global annual turnover.
GDPR and CCPA side by side
| GDPR | CCPA (as amended by CPRA) | |
|---|---|---|
| Jurisdiction | European Union and EEA | California |
| Who it applies to | Any organization processing personal data of people in the EU, any size, including nonprofits | For-profit businesses doing business in California that meet at least one threshold |
| Size thresholds | None | Annual gross revenue over $26,625,000; or buys, sells, or shares data of 100,000+ consumers or households; or earns 50%+ of revenue from selling or sharing data |
| Legal model | Lawful basis required before processing | Collection allowed; consumers can opt out of sale and sharing |
| Core individual rights | Access, rectification, erasure, restriction, portability, objection | Know, delete, correct, opt out of sale or sharing, limit use of sensitive data |
| Breach notification | Regulator within 72 hours of awareness | Governed by California's separate breach notification law |
| Regulator | National data protection authorities | California Privacy Protection Agency and the Attorney General |
| Maximum fines | 20 million euros or 4% of global annual turnover, whichever is higher | $2,663 per violation, $7,988 per intentional violation |
| Private lawsuits | Individuals can claim compensation | Only for data breaches, $107 to $799 per consumer per incident in statutory damages |
The CCPA dollar figures are the inflation-adjusted amounts that took effect January 1, 2025. The original statute said $25 million, $2,500, and $7,500.
Which one applies to a US SaaS company
Many US B2B SaaS companies are subject to both, for different reasons. GDPR attaches through the data subjects: EU customers, EU employees of your customers using your product, or EU website visitors you track. CCPA attaches through the business: once revenue passes $26,625,000, the California obligations apply to California residents' data even if the company is based elsewhere.
Below the CCPA revenue threshold, a startup can still be caught by the 100,000 consumers test if it handles a large consumer user base, and it is often caught contractually anyway, because enterprise customers push their own GDPR and CCPA obligations onto vendors through data processing agreements.
Where they overlap in practice
The operational work is largely shared. Both laws expect you to know what personal data you hold and where it flows, to honor access and deletion requests within set deadlines, to secure the data with reasonable measures, and to bind your vendors by contract. A data inventory, a subprocessor list, a documented request-handling procedure, and a security program covering access control and encryption satisfy most of both at once.
Neither law is a security framework, and a SOC 2 report does not discharge either. SOC 2 does produce much of the security evidence both laws ask for. For how SOC 2 relates to the legal regimes around it, see is SOC 2 legally required.