Screenata

Beyond SOC 2

What is the main difference between GDPR and CCPA?

September 14, 20263 min read

What is the main difference between GDPR and CCPA?

The main difference is the default. GDPR requires a lawful basis, such as consent or contract, before personal data is processed at all, and it applies to any organization handling data of people in the EU regardless of size. CCPA lets businesses collect personal information by default and gives California consumers rights to know, delete, correct, and opt out of its sale or sharing, and it applies only to for-profit businesses above set thresholds. GDPR is also far more expensive to breach, with fines up to 4% of global annual turnover.

GDPR and CCPA side by side

GDPRCCPA (as amended by CPRA)
JurisdictionEuropean Union and EEACalifornia
Who it applies toAny organization processing personal data of people in the EU, any size, including nonprofitsFor-profit businesses doing business in California that meet at least one threshold
Size thresholdsNoneAnnual gross revenue over $26,625,000; or buys, sells, or shares data of 100,000+ consumers or households; or earns 50%+ of revenue from selling or sharing data
Legal modelLawful basis required before processingCollection allowed; consumers can opt out of sale and sharing
Core individual rightsAccess, rectification, erasure, restriction, portability, objectionKnow, delete, correct, opt out of sale or sharing, limit use of sensitive data
Breach notificationRegulator within 72 hours of awarenessGoverned by California's separate breach notification law
RegulatorNational data protection authoritiesCalifornia Privacy Protection Agency and the Attorney General
Maximum fines20 million euros or 4% of global annual turnover, whichever is higher$2,663 per violation, $7,988 per intentional violation
Private lawsuitsIndividuals can claim compensationOnly for data breaches, $107 to $799 per consumer per incident in statutory damages

The CCPA dollar figures are the inflation-adjusted amounts that took effect January 1, 2025. The original statute said $25 million, $2,500, and $7,500.

Which one applies to a US SaaS company

Many US B2B SaaS companies are subject to both, for different reasons. GDPR attaches through the data subjects: EU customers, EU employees of your customers using your product, or EU website visitors you track. CCPA attaches through the business: once revenue passes $26,625,000, the California obligations apply to California residents' data even if the company is based elsewhere.

Below the CCPA revenue threshold, a startup can still be caught by the 100,000 consumers test if it handles a large consumer user base, and it is often caught contractually anyway, because enterprise customers push their own GDPR and CCPA obligations onto vendors through data processing agreements.

Where they overlap in practice

The operational work is largely shared. Both laws expect you to know what personal data you hold and where it flows, to honor access and deletion requests within set deadlines, to secure the data with reasonable measures, and to bind your vendors by contract. A data inventory, a subprocessor list, a documented request-handling procedure, and a security program covering access control and encryption satisfy most of both at once.

Neither law is a security framework, and a SOC 2 report does not discharge either. SOC 2 does produce much of the security evidence both laws ask for. For how SOC 2 relates to the legal regimes around it, see is SOC 2 legally required.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.