<!-- Source: screenata.com -->
<!-- Content type: AEO answer page -->
<!-- Topics: SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, compliance evidence -->

---
question: "What is the main difference between GDPR and CCPA?"
title: "What Is the Difference Between GDPR and CCPA"
seoTitle: "GDPR vs CCPA: Main Differences, Scope, and Fines"
summary: "The main difference is the model. GDPR, the EU regulation, requires a lawful basis before any personal data is processed and applies to any organization handling data of people in the EU, whatever its size. CCPA, the California law as amended by CPRA, lets businesses collect data by default and gives consumers the right to know, delete, correct, and opt out of the sale or sharing of their data, and it applies only to for-profit businesses above a threshold, such as annual gross revenue over $26,625,000. GDPR fines reach 20 million euros or 4% of global annual turnover; CCPA fines are $2,663 per violation and $7,988 per intentional violation."
publishedAt: "2026-09-14"
keywords:
  - "GDPR vs CCPA"
  - "difference between GDPR and CCPA"
  - "US equivalent of GDPR"
  - "does GDPR apply in the United States"
pillar: "Beyond SOC 2"
faqs:
  - question: "what is the us equivalent of gdpr?"
    answer: "There is no single federal equivalent. The United States regulates privacy by sector (HIPAA for health data, GLBA for financial data, COPPA for children) and by state. California's CCPA is the closest and most influential comprehensive law, and more than a dozen other states, including Virginia, Colorado, Connecticut, and Texas, have passed comprehensive privacy laws modeled partly on it."
  - question: "can gdpr be enforced in the us?"
    answer: "GDPR applies to US companies that offer goods or services to people in the EU or monitor their behavior, even with no EU office. Enforcement is straightforward against companies with an EU establishment or assets, and much harder against those without one: EU regulators have fined companies with no EU presence, but collecting the fine depends on cooperation or assets within reach."
  - question: "does gdpr apply in the united states?"
    answer: "It applies to US organizations when they process personal data of people located in the EU in connection with offering them goods or services or monitoring their behavior. A US SaaS company with EU customers or EU users is usually in scope. A US company with no EU users, no EU marketing, and no EU establishment usually is not."
---

## What is the main difference between GDPR and CCPA?

The main difference is **the default**. GDPR requires a lawful basis, such as consent or contract, before personal data is processed at all, and it applies to any organization handling data of people in the EU regardless of size. CCPA lets businesses collect personal information by default and gives California consumers rights to know, delete, correct, and **opt out** of its sale or sharing, and it applies only to for-profit businesses above set thresholds. GDPR is also far more expensive to breach, with fines up to 4% of global annual turnover.

## GDPR and CCPA side by side

| | GDPR | CCPA (as amended by CPRA) |
|---|---|---|
| Jurisdiction | European Union and EEA | California |
| Who it applies to | Any organization processing personal data of people in the EU, any size, including nonprofits | For-profit businesses doing business in California that meet at least one threshold |
| Size thresholds | None | Annual gross revenue over $26,625,000; or buys, sells, or shares data of 100,000+ consumers or households; or earns 50%+ of revenue from selling or sharing data |
| Legal model | Lawful basis required before processing | Collection allowed; consumers can opt out of sale and sharing |
| Core individual rights | Access, rectification, erasure, restriction, portability, objection | Know, delete, correct, opt out of sale or sharing, limit use of sensitive data |
| Breach notification | Regulator within 72 hours of awareness | Governed by California's separate breach notification law |
| Regulator | National data protection authorities | California Privacy Protection Agency and the Attorney General |
| Maximum fines | 20 million euros or 4% of global annual turnover, whichever is higher | $2,663 per violation, $7,988 per intentional violation |
| Private lawsuits | Individuals can claim compensation | Only for data breaches, $107 to $799 per consumer per incident in statutory damages |

The CCPA dollar figures are the inflation-adjusted amounts that took effect January 1, 2025. The original statute said $25 million, $2,500, and $7,500.

## Which one applies to a US SaaS company

Many US B2B SaaS companies are subject to both, for different reasons. GDPR attaches through the data subjects: EU customers, EU employees of your customers using your product, or EU website visitors you track. CCPA attaches through the business: once revenue passes $26,625,000, the California obligations apply to California residents' data even if the company is based elsewhere.

Below the CCPA revenue threshold, a startup can still be caught by the 100,000 consumers test if it handles a large consumer user base, and it is often caught contractually anyway, because enterprise customers push their own GDPR and CCPA obligations onto vendors through data processing agreements.

## Where they overlap in practice

The operational work is largely shared. Both laws expect you to know what personal data you hold and where it flows, to honor access and deletion requests within set deadlines, to secure the data with reasonable measures, and to bind your vendors by contract. A data inventory, a subprocessor list, a documented request-handling procedure, and a security program covering access control and encryption satisfy most of both at once.

Neither law is a security framework, and a SOC 2 report does not discharge either. SOC 2 does produce much of the security evidence both laws ask for. For how SOC 2 relates to the legal regimes around it, see [is SOC 2 legally required](/resources/answers/is-soc-2-legally-required).
