TL;DR
GDPR and CCPA compliance usually breaks in 10 operational gaps inside your systems, and one US company can owe duties under both laws. Regulators have fined opt-outs that ignored Global Privacy Control, stopped at one device, or demanded identity checks first. They also fined missing vendor contracts, forgotten job-applicant data and collecting more data than the purpose needed. The other gaps are consent walls, automated decisions without safeguards, deletions that miss copies, and programs that cannot show evidence. GDPR fines reach EUR 20 million or 4% of worldwide turnover, and CCPA fines are now $2,663 or $7,988 per violation. Close all 10 with one data map, one rights workflow, tested vendor and signal controls, and kept evidence.
Key Takeaways GDPR reaches US companies that target or monitor people in the EU, while the CCPA applies above $26,625,000 in revenue, at 100,000 California consumers or households whose data is bought, sold or shared, or when half of revenue comes from selling or sharing data. GDPR needs a legal basis before processing starts, while the CCPA lets processing run until a California consumer opts out. California fines in 2025 and 2026 targeted plumbing, such as Global Privacy Control, cross-device opt-outs, verification friction, vendor contracts and data minimization. California’s 2026 regulations add risk assessments from January 1, 2026, then automated decision-making rules from January 1, 2027 and cybersecurity audit certifications from April 2028. EU regulators fined Google EUR 403,000,000 over location data in September 2026, and the EDPB reported a EUR 824,990,000 Uber fine, now under appeal, on October 8, 2026. One program can serve both laws when each legal duty maps to a system control, a named owner and saved evidence. Watch on YouTube
Building an AI-Powered Compliance Platform That Scales Across Jurisdictions
A walkthrough of how Kanerika built one compliance platform that maps regulatory requirements to controls across several jurisdictions, the same pattern a two-law privacy program needs.
The Shopper Who Switched On Global Privacy Control Picture a shopper in Sacramento who switches on Global Privacy Control in her browser before she orders a pair of work boots. The retailer’s website reads the signal, so it stops passing her browsing data to ad partners. Her phone app has never heard of that setting, so it keeps sharing.
Then there is the loyalty program. It runs on a third system, and it sends her purchase history to a marketing vendor under a contract nobody has checked for privacy terms. Within a week, that vendor is also using her boot purchase to target her with ads on other sites she visits.
On paper, this retailer looks compliant because it has a privacy policy and a cookie banner. It also shows a “Do Not Sell or Share” link in the footer. In its systems, it repeats three failures that California regulators have fined since 2025. The policy says one thing, and the plumbing does another.
None of this shows up when a lawyer reads the policy. It shows up when a regulator tests the website, the app and the vendor list with a real browser and a real request.
That distance between the written program and the running systems is the subject of this article. You will see when each law applies, what changed after 2018, and the 10 gaps behind recent fines. Each gap comes with the enforcement action that exposed it and the control that closes it.
Do GDPR and CCPA Both Apply to Your Business? Scope comes first, because a company that misreads it builds controls for the wrong law. Both laws reach well beyond their home region, so a single US company can fall under each one for different reasons.
When GDPR Reaches a US Company Under Article 3(2) , a company with no office in Europe is still covered when it offers goods or services to people in the EU. It is also covered when it monitors their behaviour there, such as profiling site visitors for ad targeting. Signs of offering include prices in euros, EU shipping options and checkout pages in EU languages.
The law protects people who are in the EU, whatever their passport says. An American tourist browsing from Paris is in scope, while an EU citizen living in Ohio usually is not. That is why data privacy teams map where a person is, not their nationality.
When the CCPA Applies in 2026 The CCPA covers a for-profit business that handles California residents’ personal information when it meets at least one of three tests. The California Privacy Protection Agency adjusts the revenue figure for inflation , so the old $25 million number no longer holds.
Annual gross revenue above $26,625,000. Buying, selling or sharing the personal information of 100,000 or more California consumers or households. Earning 50% or more of annual revenue from selling or sharing personal information. Employee and business-to-business data are covered too. Those two exemptions expired on December 31, 2022 , so HR files and B2B contact lists now carry the same rights as customer records.
California Is Not the Only US State New state laws keep arriving, and each adds its own notice and opt-out details. Indiana, Kentucky and Rhode Island all brought broad consumer privacy laws into force on January 1, 2026 . Indiana and Kentucky allow fines up to $7,500 per violation with a 30-day cure period. Rhode Island, by comparison, allows up to $10,000 and gives no cure period.
Counts of state laws differ by source, so track them with the IAPP US State Privacy Legislation Tracker instead of a fixed number. A control built for California usually covers most of these laws with small changes.
Your situation Law that applies What it means in practice You offer goods or services to people in the EU, or monitor their behaviour GDPR A legal basis for every use, a one-month rights clock, 72-hour breach notice You meet one CCPA test and hold California residents’ data CCPA Notices, opt-out of sale and sharing (including Global Privacy Control), a 45-day rights clock You meet both GDPR and CCPA One program, with the stricter control applied system by system
A company in the third row still does not need two privacy teams. It needs one inventory of personal data, tagged by where each person is, so every system knows which rules to apply.
GDPR vs CCPA: The Differences That Change Your Controls Both laws give people rights over their personal data, and both expect a business to know where that data lives. The real difference, however, is the default setting.
GDPR starts from “no,” so a company needs a lawful basis such as consent, a contract or a legitimate interest before it processes anything. The CCPA starts from “yes,” which lets a business collect and share data until a consumer tells it to stop. That single difference decides whether your controls gate data at collection or switch it off on request.
The Control Each Difference Forces The table below turns each difference into the control it forces. Read the last column as a build list for your data processing systems.
Requirement GDPR CCPA Control it forces Model Lawful basis needed before processing Processing allowed until the consumer opts out Consent and basis records at collection; opt-out flags downstream Scope People in the EU, including non-EU firms that target or monitor them (Art. 3(2)) California residents’ data held by a business over one threshold A jurisdiction tag on every personal record Rights Access, rectification, erasure, restriction, portability, objection Know, delete, correct, opt out of sale or sharing, limit sensitive data use One rights-request workflow with law-specific steps Response clock One month, extendable by two more (Art. 12(3)) 45 calendar days, extendable by 45 more with notice A tracker that runs both clocks Breach Notify the supervisory authority within 72 hours where feasible (Art. 33) Consumers can sue for $107 to $799 per consumer per incident An incident runbook with timed steps Sensitive data Special categories need an extra legal condition Right to limit use of sensitive personal information Classification labels on sensitive fields Automated decisions Art. 22 limits solely automated decisions with significant effects Automated decision-making rules for significant decisions from January 1, 2027 A model inventory with human review points Vendors Art. 28 processor contracts Service provider and contractor contracts A contract register tied to each data flow Penalties and regulator Up to EUR 20 million or 4% of turnover; national data protection authorities Up to $2,663 or $7,988 per violation; CalPrivacy and the Attorney General An evidence file per control
What the Two Laws Share Because the overlap is large, both laws can share most of the plumbing. A data map, a classification scheme and a request workflow serve both laws, while only the rules on top differ. Teams that build twice also end up with two inventories that disagree, which is a gap in itself.
Security sits underneath every row. Encryption, access control and monitoring are the controls both regulators look for after a breach. Our guide to data security best practices also covers them in depth.
Kanerika Service
Data Governance Services
Kanerika maps personal data, classifies sensitive fields and builds the lineage, access and retention controls that GDPR and CCPA duties depend on.
Explore Data Governance What Changed Since 2018: CPRA, CalPrivacy and the 2026 Rules Many compliance programs were designed in 2018, when GDPR took effect and the CCPA was signed. California’s law has changed several times since then, and the new duties land on data teams rather than on the legal page.
The CPRA and the California Privacy Protection Agency California voters passed Proposition 24, the California Privacy Rights Act, in November 2020. It amended the CCPA instead of replacing it, so the law is still called the CCPA. Its text took effect on January 1, 2023.
Proposition 24 also created a dedicated regulator, the California Privacy Protection Agency , which now calls itself CalPrivacy. It writes regulations and also brings enforcement cases, alongside the Attorney General. The result is two active enforcers in one state.
The 2026 Regulations: Risk Assessments, Audits and Automated Decisions CalPrivacy finalized a new set of regulations on September 23, 2025 , and they took effect on January 1, 2026. The obligations then arrive in stages.
January 1, 2026. Risk assessments start for processing that presents significant risk to consumers’ privacy.January 1, 2027. Rules for automated decision-making technology apply to significant decisions about consumers.April 1, 2028. Risk-assessment attestations and summaries are due, and businesses above $100 million in revenue submit cybersecurity audit certifications.April 1, 2029. Cybersecurity audit certifications are due from businesses with $50 million to $100 million in revenue.April 1, 2030. Businesses under $50 million in revenue submit their first cybersecurity audit certifications.The legislature added one more change on September 27, 2026, when SB 923 was signed. From January 1, 2027, the right to delete also covers personal information a business obtained from third parties . Bought lists and enrichment feeds now need a deletion path too.
Current Penalties on Both Sides GDPR fines come in two tiers under Article 83 , and the higher of the fixed amount or the turnover share applies. CCPA amounts started at $2,500 and $7,500 per violation, and CalPrivacy raised them for inflation from January 1, 2025.
Law Maximum fine GDPR, lower tier EUR 10 million or 2% of total worldwide annual turnover GDPR, upper tier EUR 20 million or 4% of total worldwide annual turnover CCPA, per violation $2,663 CCPA, intentional or involving minors under 16 $7,988 CCPA, consumer breach lawsuits $107 to $799 per consumer per incident
California adjusts these figures every odd-numbered year, so expect new amounts in January 2027. Per-violation math adds up fast, because each affected consumer or each ignored request can count separately.
10 GDPR and CCPA Compliance Gaps Most Businesses Miss Nine of the 10 gaps below have already drawn a regulator’s fine. The remaining one, deletions that miss copies, becomes a wider California duty in January 2027. All of them live in systems rather than in policy text, which is why a legal review misses them. Read them as a test plan. For each gap you get what goes wrong, the case or rule that exposed it, and the control that closes it.
1. Opt-Outs That Ignore Global Privacy Control Global Privacy Control is a browser setting that sends an opt-out signal to every site a person visits. Under the CCPA, a user-enabled global privacy control counts as a valid request to opt out of sale and sharing. A business that honours it must also wait 12 months before asking that person to opt back in.
Tractor Supply, for example, learned this the expensive way. In September 2025, CalPrivacy fined the retailer $1,350,000 , partly because its site offered no effective opt-out, including for GPC signals. The control is simple to state and harder to wire, since the tag manager must read the signal before any ad or analytics tag fires.
2. Opt-Outs That Stop at One Device or One Brand A person who opts out once expects the choice to stick everywhere they are known, such as every app and brand. Many companies apply the choice only to the browser or app where it was made, because their identity data sits in separate systems.
California’s Attorney General announced a settlement with Disney of $2.75 million in February 2026 over exactly this. An opt-out made through Disney’s toggle applied only to the streaming service, and often only the device, the person was using at that moment. It did not reach everything tied to their Disney account. The fix is an account-level preference record that every brand and device reads from.
3. Identity Checks and Friction Before an Opt-Out Requests to access or delete data need identity checks, but opt-outs do not. Asking for an email confirmation or an ID before someone can stop the sale of their data adds friction that regulators treat as a violation.
Ford paid $375,703 in March 2026 because it would not process an opt-out until the person confirmed an email address. The regulator called that step unnecessary friction. By then the lesson was a year old. Todd Snyder paid $345,178 in May 2025 for demanding identity checks before opt-outs, and its misconfigured privacy portal left opt-out requests unprocessed for 40 days. Honda’s $632,500 order from March 2025 cited the same excess verification, plus hurdles for authorized agents acting for consumers. Keep the opt-out to one or two steps, and save identity checks for access, deletion and correction.
4. Consent Walls and Lopsided Cookie Banners A banner that makes “Accept all” one click and “Reject” a buried settings page steers people toward sharing. Regulators read that imbalance as a choice that was never really free.
Honda’s order also cited asymmetrical privacy choices. PlayOn Sports went further. It paid $1.10 million in March 2026 after forcing people to click “agree” to tracking before they could use their tickets or view its websites. People had no sufficient way to opt out. It was also CalPrivacy’s first case involving students and schools. Give “Accept” and “Reject” the same size, colour and number of clicks, and never gate a purchase on tracking consent.
5. Forgetting Employee, Job Applicant and B2B Data Privacy programs built in 2020 often stop at customer data, because the CCPA once exempted workforce and business contacts. Those exemptions ended on December 31, 2022, so applicant tracking systems, HR platforms and sales CRMs now hold data with full CCPA rights.
The Tractor Supply order was CalPrivacy’s first action to address job applicants, who received no privacy notice. Find these stores with the same discovery and data classification scans you run on customer systems. Then give each group its own notice and request path.
Watch on YouTube
Empower Your Business with Kanerika’s Data Governance Solutions | Microsoft Purview Integration
How Kanerika uses Microsoft Purview to discover, classify and govern data across an estate, the groundwork for finding forgotten HR, applicant and B2B records.
6. Vendor and Ad-Tech Sharing Without the Right Contracts Every pixel, SDK and data feed is a disclosure to another company. Under the CCPA, sharing personal information without a service-provider or contractor contract can turn that flow into a sale or share in the regulator’s eyes. GDPR asks for the same discipline through Article 28 processor terms .
Both Tractor Supply and Honda were cited for disclosures to ad-tech companies without the required contracts. Build a register that lists each vendor, the data it receives, the contract terms and the system that sends the data. Then test it, because marketing teams add tags faster than legal teams sign paper.
7. Collecting More Data Than the Purpose Needs Data minimization means collecting only what a stated purpose requires and keeping it no longer than needed. It is a core GDPR principle under Article 5 , and California now enforces it too.
In May 2026, California authorities announced a $12.75 million penalty against General Motors over the sale of driving and location data. The Attorney General called it the largest CCPA penalty in California history to date and the first data-minimization case. Tie every collected field to a purpose, then mask or drop what no purpose needs with data anonymization techniques or data masking tools .
8. Automated Decisions and Profiling Without Safeguards Scoring, ranking and pricing models make decisions about people at a scale no review team can match, so errors spread fast. GDPR Article 22 limits decisions based solely on automated processing when they have legal or similarly significant effects. It also requires clear information about how the logic works.
The Dutch data protection authority fined Uber EUR 824,990,000 , as the European Data Protection Board reported on October 8, 2026. Uber had automatically deactivated drivers’ accounts, cutting off their income, when it suspected fraud or ratings fell too low. It did not tell drivers enough about how those decisions were made. Uber has appealed the fine. California’s automated decision-making rules for significant decisions apply from January 1, 2027.
Keep an inventory of every model that touches personal data, with its purpose, inputs and human review point. An AI auditing framework then tests those review points on a schedule. Our guides on AI compliance and AI regulation also cover the wider rulebook for these systems.
On-Demand Webinar
Data Security Risks in AI: How Microsoft Purview Protects You
An on-demand session on how Microsoft Purview finds and protects sensitive data that flows into AI tools , the same data that profiling and automated decisions rely on.
Watch the Webinar → 9. Deleting in One System While Copies Live On A deletion request usually lands first in the CRM or the customer database. Copies of the same record also sit in the warehouse, BI extracts, marketing exports, backups and AI training sets. None of them hears about the request, so the person’s data lives on.
Under GDPR and the CCPA, a request applies to the data, not to one application. SB 923 widens the duty from January 1, 2027, when deletion also covers personal information bought or received from third parties. Data lineage shows where each record travelled, so a single request can trigger deletes everywhere downstream. For training data and model outputs, see our guide to AI privacy .
10. Two Paper Programs and No Evidence Some companies run a GDPR program and a separate CCPA program, each with its own policy binder, and neither can show that its controls actually work.
GDPR Article 5(2) makes the controller responsible for compliance and able to demonstrate it, and regulators now fine the failure to prove it. In September 2026 the Irish Data Protection Commission fined Google EUR 403,000,000 over location data. One finding was that Google could not demonstrate its Location Accuracy processing was lawful, fair and transparent. California asks for the same proof through risk-assessment attestations and summaries due by April 1, 2028. Evidence means test results, request logs, signal checks and contract records, kept per control and refreshed on a schedule.
All 10 Gaps at a Glance The summary below pairs each gap with the action or rule that exposed it and the control that closes it.
Gap Example action or rule Control 1. GPC ignored Tractor Supply, $1,350,000 (Sept 2025) Tag manager reads GPC before any tag fires 2. Opt-out on one device Disney, $2.75 million (Feb 2026) Account-level preference record 3. Friction before opt-out Ford, $375,703 (Mar 2026) Opt-out without identity checks 4. Consent walls PlayOn Sports, $1.10 million (Mar 2026) Equal accept and reject choices 5. Workforce and B2B data Tractor Supply job-applicant notice Discovery scans across HR and CRM 6. Vendors without contracts Honda, $632,500 (Mar 2025) Vendor register tied to data flows 7. Over-collection General Motors, $12.75 million (May 2026) Purpose for every field 8. Automated decisions Uber, EUR 824,990,000 (Oct 2026, under appeal) Model inventory with human review 9. Copies survive deletion SB 923 duty from Jan 2027 Lineage-driven deletes 10. No evidence Google, EUR 403 million, Irish DPC (Sept 2026) Evidence file per control
Notice how few of these gaps need a new policy. Nearly all of them need a data engineer, a tag manager or a contract register.
Talk to Kanerika
Find Your Privacy Gaps Before a Regulator Does
Kanerika reviews where your personal data lives, how signals and deletes travel between systems, and which of the 10 gaps your stack still carries.
Schedule a Demo → How to Run One Program for Both Laws The 10 gaps share a root cause, which is legal duties that never became system controls. One GDPR and CCPA compliance program fixes that by running the same five steps for both laws, with the law-specific rules layered on top.
The sequence matters, because each step feeds the next. You cannot honour a deletion request across systems you have not mapped, and you cannot prove a control works until you have tested it.
Step 1: Find and Map Personal Data First, build an inventory of every system that holds personal data, including HR, marketing, analytics and backups. Then classify sensitive fields with sensitive data discovery scans and tag each record with the jurisdictions it falls under. A data governance framework gives the inventory owners and update rules, so it does not decay after the first audit.
Step 2: Map Each Legal Duty to a System Control Take every obligation, from GPC handling to the 72-hour breach clock, and name the system that enforces it. A duty with no system behind it is a gap waiting for a regulator. This register then becomes the spine of your wider data governance program.
Step 3: Run One Rights-Request Workflow With Both Clocks Route GDPR and CCPA requests through one intake, then branch by law. The tracker should run the one-month GDPR clock and the 45-day CCPA clock side by side. It should also push deletes and opt-outs to every downstream copy found in Step 1.
Step 4: Test Vendors and Signals Check monthly that GPC signals stop the right tags, that opt-outs reach every brand and device, and that each vendor flow has a contract. Treat a new pixel like a new vendor, because to a regulator it is one.
Step 5: Test Controls and Keep the Evidence Run each control against a test case and then save the result with a date. Request logs, scan reports and contract records also belong in the same evidence file. That file answers GDPR’s accountability principle and California’s attestation duty with one set of records.
Manual, Platform-Native or Dedicated Privacy Tools? Tooling follows scale. A small company can start with spreadsheets. A company with dozens of data stores, however, needs scanning and workflow automation, as our guide to compliance automation explains.
Approach Fits Watch out for Manual (spreadsheets and email) Few systems, low request volume Inventories go stale; no audit trail Platform-native (for example Microsoft Purview) Data already in one cloud ecosystem Needs classification rules and owners to be useful Dedicated privacy tools (consent and request platforms) High request volume, many brands and sites Must still connect to the data platform for deletes
Many teams also combine the second and third rows, and our comparison of data governance tools covers the platform options. A consent platform handles the front end, while the data platform carries deletes and opt-outs to the warehouse and beyond.
Checklist
Enterprise Data Governance Checklist
A step-by-step checklist for data inventory, classification, ownership and policy controls, the base layer of one program for both laws.
Get the Checklist → Who Owns GDPR and CCPA Compliance? Every privacy control needs a named owner, because an unowned control drifts. The legal team owns interpretation, but the controls themselves live with the teams that run the systems.
The split below keeps legal from owning tag managers it cannot change, and keeps engineers from guessing at legal duties. Each owner also produces evidence, which is what turns the program into something you can prove.
Role Owns Evidence it produces Legal and privacy Interpreting duties, notices, risk assessments, DPO where Art. 37 requires one Duty register, assessment records Data owners Purpose and retention for each dataset Approved purposes per field Platform and data engineering Inventory, lineage, deletes and opt-out propagation Scan reports, deletion logs Security Access control, encryption, breach response Incident timelines, access reviews Marketing and web Banners, GPC handling, tags and pixels Signal test results, tag inventory AI and ML team Model inventory, profiling notices, human review Model cards, review logs
A data protection officer is mandatory under GDPR Article 37 for public bodies and for large-scale monitoring or large-scale special-category data. The CCPA has no DPO requirement, though someone still has to own the program. AI systems also add their own duties, which our AI compliance guide maps role by role.
How Kanerika Builds GDPR and CCPA Controls Into the Data Platform Kanerika works on the layer where most of these gaps live, which is the data platform under the privacy policy. Our data governance services turn legal duties into controls that run inside cloud, SQL and SaaS systems.
Discover and classify. Microsoft Purview scans and sensitive-information classification across cloud storage, SQL databases and SaaS sources, covering HR and B2B data as well as customers.Trace every copy. Lineage from source systems to warehouses, reports and AI pipelines, so deletes and opt-outs reach downstream data.Enforce access and retention. Access governance and retention policies tied to each dataset’s purpose, which supports minimization.Prove it. Power BI dashboards over the control register, showing request status, scan coverage and test results for auditors.Microsoft Purview is often the starting point when the estate already runs on Microsoft. Our Microsoft Purview guide explains how its data catalog , classification and policies fit together.
Case Study: 60% Less Manual Compliance Work With AI A leading provider of AI-powered regulatory compliance solutions for financial institutions faced fragmented workflows across multiple jurisdictions. Manual interpretation and controls mapping caused inconsistencies and audit-readiness gaps, while disconnected systems hid compliance coverage.
Kanerika built a centralized compliance platform that automated requirement mapping, controls monitoring and audit traceability. The published results show 40% faster regulatory response, 60% less manual compliance work and 5X better audit traceability. The project covered regulatory compliance oversight rather than a GDPR or CCPA program, yet it tackles the same problems as Step 2 and gap 10. Duties map to controls once, and the evidence stays ready.
Case Study
60% Less Manual Compliance Work with AI
A regulatory compliance solutions provider serving financial institutions reached 40% faster regulatory response, 60% less manual compliance work and 5X better audit traceability on a centralized platform Kanerika built.
Read the Case Study → Wrapping Up GDPR and CCPA compliance rarely fails because a policy is missing. It fails where systems ignore the policy, as recent fines against Tractor Supply, Disney, General Motors, Google and Uber show.
A first test takes an afternoon. Switch on Global Privacy Control and check which tags still fire. Opt out in the app and see whether the website honours it. Then send a test deletion and search the warehouse for the record. Each failed test points to one of the 10 gaps and the control that closes it.
The 10 gaps most businesses miss sit where policy meets plumbing, in signals, devices, vendors, copies and automated decisions, so closing them is a data-platform job.
Frequently Asked Questions
What are the 7 main principles of GDPR? GDPR Article 5 sets seven principles for handling personal data. They are lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. Accountability means the controller must be able to demonstrate compliance with the other six, so companies keep records, test results and policies that show each principle working in their systems.
What is the difference between GDPR and CCPA compliance? GDPR requires a lawful basis, such as consent or a contract, before a company processes personal data of people in the EU. The CCPA lets a business collect and share California residents’ data until they opt out. GDPR answers rights requests in one month, the CCPA in 45 days, and GDPR fines can reach 4% of worldwide turnover.
How is GDPR enforced? Each EU country has a data protection authority that investigates complaints, audits organizations and issues fines. Cross-border cases are led by the authority in the company’s main EU establishment, coordinated by the European Data Protection Board. In September 2026 the Irish authority fined Google EUR 403,000,000, and in October the EDPB reported a Dutch fine against Uber, now under appeal.
What rights do individuals have under GDPR? GDPR gives people the right to be informed, to access their data, to rectification, to erasure, to restrict processing, to data portability and to object. It also limits decisions based solely on automated processing with significant effects. Organizations must answer requests within one month, extendable by two further months for complex or numerous requests, and explain any refusal.
What rights does the CCPA give California consumers? California consumers can learn what personal information a business collects and shares, delete it, correct it, and opt out of its sale or sharing. They can also limit the use of sensitive personal information and must not face discrimination for using these rights. Businesses respond within 45 calendar days, extendable once by 45 more with notice.
What are the fines for violating the CCPA and GDPR in 2026? GDPR fines reach EUR 10 million or 2% of worldwide annual turnover in the lower tier, and EUR 20 million or 4% in the upper tier, whichever is higher. CCPA administrative fines are up to $2,663 per violation and $7,988 per intentional violation or one involving minors under 16, adjusted from January 1, 2025.
Is the CCPA still in effect in 2026? The CCPA is fully in effect in 2026 and has grown stronger. Proposition 24 amended it from January 1, 2023, new regulations took effect on January 1, 2026, and SB 923, signed on September 27, 2026, extends deletion rights to data obtained from third parties from January 1, 2027. CalPrivacy and the Attorney General enforce it.
Is the CCPA now called the CPRA? The law is still called the California Consumer Privacy Act. The California Privacy Rights Act, passed by voters as Proposition 24 in November 2020, amended the CCPA and created the California Privacy Protection Agency, now known as CalPrivacy. People often say CPRA when they mean the amended CCPA, yet the statute keeps its original name.
How does the CPRA compare with GDPR? The CPRA moved California closer to GDPR by adding a right to correct data, limits on sensitive personal information, data minimization duties and a dedicated regulator. Real differences remain. GDPR still requires a lawful basis before processing, applies to people in the EU, and carries turnover-based fines, while California keeps its opt-out model and per-violation penalties.
What are data controllers, processors and service providers? Under GDPR, a controller decides why and how personal data is processed, and a processor handles data on the controller’s behalf under an Article 28 contract. The CCPA uses business for the decision maker, and service provider or contractor for vendors bound by a qualifying contract. Sharing data with a vendor without that contract creates legal risk.
Do GDPR or CCPA require a data protection officer? GDPR Article 37 requires a data protection officer for public bodies, for organizations whose core activities involve large-scale regular and systematic monitoring of people, and for large-scale processing of special-category data. The CCPA has no DPO requirement. Businesses covered by either law still benefit from naming a privacy lead who owns the program and its evidence.
What must a CCPA privacy notice include? A CCPA notice at collection tells California consumers what categories of personal information are gathered, why, whether they are sold or shared, and how long they are kept. The full privacy policy also explains consumer rights and how to use them. Job applicants and employees need their own notices, a gap regulators cited against Tractor Supply.
Does California follow GDPR or have its own privacy law? California has its own law, the California Consumer Privacy Act, amended by the California Privacy Rights Act in 2020. It borrows ideas from GDPR, such as access and deletion rights, yet works on an opt-out model for selling and sharing data. A dedicated regulator, CalPrivacy, enforces it together with the California Attorney General’s office.
Is GDPR compliance enough to comply with the CCPA? GDPR compliance covers much of the groundwork, such as data mapping, rights requests and vendor contracts, yet it does not satisfy the CCPA alone. California adds specific duties, including a Do Not Sell or Share link, honoring Global Privacy Control signals, opt-outs without identity checks, and notices for employees and job applicants. Each needs its own control.
How long do companies have to respond to GDPR and CCPA requests? GDPR gives organizations one month from receipt to respond, extendable by two further months when requests are complex or numerous, with the person told why. The CCPA allows 45 calendar days, extendable once by another 45 days with notice. Opt-out requests under the CCPA should take effect quickly and need no identity verification at all.
Do businesses have to honor Global Privacy Control signals? Businesses covered by the CCPA must treat a user-enabled Global Privacy Control signal as a valid request to opt out of selling and sharing personal information. After honoring it, a business must wait 12 months before asking the person to opt back in. CalPrivacy fined Tractor Supply $1,350,000 in September 2025 partly for failing to process these signals.
Does the CCPA apply to employee and B2B data? The CCPA has covered employee, job applicant and business-to-business contact data since the temporary exemptions expired on December 31, 2022. Workers and business contacts can now use the same rights as consumers, including access, deletion and correction. HR systems, applicant tracking tools and sales CRMs therefore need notices, data mapping and request workflows like customer systems.
Can consumers ask a business to delete their data from AI systems? Deletion rights under GDPR and the CCPA apply to personal data wherever a business holds it, which can include AI training sets, prompts and outputs. How far deletion reaches inside a trained model is still unsettled in law. Businesses should track which datasets feed which models, so they can remove records and retrain or filter when needed.
Does the USA have a federal equivalent to GDPR? The United States has no single federal privacy law like GDPR. Privacy rules come from sector laws, such as HIPAA for health data and GLBA for financial data, plus a growing set of state laws. California led with the CCPA, and Indiana, Kentucky and Rhode Island added broad consumer privacy laws that took effect on January 1, 2026.
What is GDPR in simple terms? GDPR is the European Union’s data protection law, in force since May 2018. It sets rules for how organizations collect, use, store and share personal data about people in the EU. It is a legal compliance obligation with fines, and it gives people rights to see, correct, delete and move their data and to object to some uses.
Who does GDPR apply to? GDPR applies to organizations established in the EU that process personal data, wherever the processing happens. Under Article 3(2) it also applies to organizations outside the EU that offer goods or services to people in the EU or monitor their behaviour there. Size does not matter, so a small US online store selling to EU shoppers can be covered.
Does GDPR protect the data of US customers? GDPR protects people who are in the EU when their data is collected, whatever their nationality. A US customer shopping from Chicago is usually outside its scope, while the same person browsing from Paris can fall inside it. For US customers, state laws such as the CCPA and the newer Indiana, Kentucky and Rhode Island laws apply instead.
Is GDPR compliance mandatory for US companies? GDPR is mandatory for a US company when it offers goods or services to people in the EU or monitors their behaviour there. Signs include EU shipping, prices in euros, EU-language pages and tracking EU visitors for advertising. A US company with no EU customers and no EU monitoring is generally outside GDPR, though US state laws may still apply.
What do the 2026 CCPA regulations require? California’s regulations finalized on September 23, 2025 took effect on January 1, 2026. Risk assessments start in 2026, rules for automated decision-making in significant decisions apply from January 1, 2027, and risk-assessment attestations are due April 1, 2028. Cybersecurity audit certifications follow from April 2028 to April 2030 depending on company revenue.
Who needs to comply with the CCPA? A for-profit business that handles California residents’ personal information must comply if it meets one test. The tests are annual gross revenue above $26,625,000, buying, selling or sharing data on 100,000 or more California consumers or households, or earning half its revenue from selling or sharing personal information. Location outside California does not exempt it.