Marketing Measurement ·

What marketers need to know about California data privacy law vs GDPR and measurement

A plain-language breakdown of how the CCPA and GDPR differ, and what those differences mean for marketers navigating tracking and consent rules today.

Listen
0:00 / 0:00
AI-generated audio
What marketers need to know about California data privacy law vs GDPR and measurement

Think about two different security systems protecting the same house. One locks every door by default and hands the key back only when someone specifically asks for it. The other leaves the doors open until a resident posts a sign asking people to stay out. Both systems protect the house, but they start from opposite assumptions about who has to do the asking.

That's roughly the difference between the GDPR and California's data privacy law. The European Union's General Data Protection Regulation assumes personal data should stay locked down until a consumer opts in. The California Consumer Privacy Act, now expanded by the California Privacy Rights Act, assumes data collection is fine by default until a consumer opts out.

For marketing teams building campaigns across both regions, sorting out which rules apply to which data set has real consequences, from how consent banners get built to which tracking pixels still work as expected. Before you can make good calls about your data practices, it helps to know exactly where these two laws agree, where they diverge, and what that means for how you collect and use personal information.

Key takeaways

  • GDPR and the CCPA both give consumers more control over their personal data, but they start from opposite defaults: GDPR requires opt-in consent, while the CCPA operates on an opt-out model.
  • GDPR applies to any organization worldwide that processes data belonging to EU residents, while the CCPA only applies to for-profit entities that meet specific revenue or data-volume thresholds.
  • The CCPA has been significantly expanded by the CPRA, which added new consumer rights and created the California Privacy Protection Agency as a dedicated enforcer.
  • Penalties differ sharply in scale. GDPR fines can reach into the tens of millions of euros or a percentage of global annual revenue, while CCPA penalties are calculated per violation and are comparatively modest.
  • California isn't the only state with a comprehensive privacy law, which matters more to multi-state businesses than a CCPA-only comparison suggests. (We're working on other guides for these states and their privacy laws.)
  • Both laws are accelerating the same underlying trend for marketers: less access to reliable, identity-based tracking data.

What is GDPR?

The General Data Protection Regulation took effect in 2018 as the European Union's answer to a data economy that had outgrown its existing rules. It's built around the idea that personal data belongs to the individual, and any business that wants to collect, store, or process it needs a clear legal basis for doing so.

GDPR applies to any organization that processes personal data belonging to EU residents, regardless of where that organization is headquartered. A company based in California that markets to customers in Germany still has to comply. The law defines personal data broadly, covering anything relating to an identified or identifiable natural person, whether that person, known in the law as the data subject, can be identified directly or by combining data points to indirectly identify them.

GDPR requires explicit consent for most data collection. Businesses can't rely on implied consent or a pre-checked box; they need affirmative, informed permission before collecting most types of personal data, and that permission has to be as easy to withdraw as it was to give. This gets stricter still for sensitive categories like medical information, biometric data, or precise geolocation. Consumers also get a set of rights under the law, including the right to access their data, correct it, delete it, and receive it in a portable format so they can move it to another provider.

What is the CCPA, and how did the CPRA change it?

California passed the Consumer Privacy Act in 2018, making it the first comprehensive state-level privacy law in the U.S. The original CCPA gave California residents the right to know what personal information businesses collect about them, from browsing history and purchase records to precise location data, and to request that it be deleted or opt out of having it sold to third parties. GDPR and CCPA rules both grew out of the same basic idea, that a natural person should have some say over the personal data companies hold on them, even though the two laws express that idea differently.

In 2023, the California Privacy Rights Act took effect and expanded those protections. The CPRA added new consumer rights, including the right to correct inaccurate personal information and the right to limit how businesses use sensitive personal information, like health records, precise geolocation, or genetic data. It also created the California Privacy Protection Agency, a dedicated regulator with rulemaking and enforcement authority. Before the CPRA, enforcement fell to the California attorney general's office alone.

The CCPA applies to for-profit entities doing business in California that meet at least one of the following criteria:

  • Annual gross revenue over $25 million
  • Buying, selling, or sharing the personal information of 100,000 or more California residents or households
  • Deriving 50% or more of annual revenue from selling or sharing California consumers' personal information

A business only needs to meet one of these thresholds, not all three, for the CCPA's requirements to apply. Nonprofit organizations and businesses that fall below these thresholds generally aren't covered, which is a meaningful difference from GDPR's broader reach, since GDPR doesn't carve out a revenue-based exemption for smaller organizations handling EU residents' personal data.

Who's responsible for your data under each law

Both GDPR and CCPA rules assign specific roles to the businesses that handle personal data, and knowing which role you're playing determines what your obligations actually are. GDPR uses the terms data controller and data processor:

  • A data controller decides why and how personal data gets processed
  • A data processor handles that processing on the controller's behalf, usually under a contract that spells out data security requirements the processor has to follow
  • The identifiable natural person whose data is being handled is called the data subject throughout the regulation, and that data subject retains rights over their information no matter which party is doing the processing
  • Many organizations that fall under GDPR are also required to appoint a data protection officer to oversee compliance internally

The CCPA takes a similar approach with different labels. A business that collects data directly from California consumers is the primary party responsible for honoring their rights, while any outside vendor handling that collected data on the business's behalf is considered a service provider, bound by contract to use personal information only for the purposes it was given. National data protection authorities in the EU and California's enforcement bodies alike tend to look at who actually controlled the personal data when deciding where responsibility falls after a data breach involving a natural person's records.

Core differences between GDPR and the CCPA

Both laws are trying to solve a similar problem, but the mechanics differ enough that compliance with one doesn't automatically mean these data protection laws overlap perfectly. Here's how the key differences stack up.

GDPRCCPA/CPRA
Consent modelOpt-in: explicit, prior consent required before collectionOpt-out: collection allowed by default, consumers can opt out
Who it applies toAny organization processing EU residents' data, regardless of sizeFor-profit entities meeting revenue or data-volume thresholds
Enforcement bodyNational data protection authorities in each EU member stateCalifornia Privacy Protection Agency and the state attorney general
PenaltiesUp to €20 million or 4% of global annual turnover, whichever is higherUp to $2,500 per unintentional violation, $7,500 per intentional violation, plus statutory damages for certain data breaches
Data portabilityExplicit right to receive and transfer dataRight to access data, but portability is less formalized
Cross-border transfersRequires standard contractual clauses or an adequacy decisionNo direct equivalent; the CCPA doesn't regulate international data transfers the same way

A few of these differences are worth calling out beyond the table. GDPR's penalty structure scales with a company's size, since a fine calculated as a percentage of global annual turnover hits a multinational far harder than a flat dollar figure would. The CCPA draws a clear line between an unintentional violation, capped at $2,500, and an intentional violation, which can run up to $7,500. Its statutory damages provision also gives California consumers a way to seek compensation directly if a business discloses their personal information in a data breach caused by a failure to maintain reasonable security practices, even without proving specific financial harm.

Enforcement paths differ too. The California attorney general handled all CCPA enforcement before the CPRA passed; today, that authority is shared with the California Privacy Protection Agency, and either body can pursue a business over noncompliance. GDPR enforcement instead runs through the national data protection authority in whichever EU member state a business is investigated in, which is part of why cross-border GDPR cases can take longer to resolve than a single-state CCPA complaint.

California isn't the only state with a privacy law

Treating this as a two-law comparison undersells what's actually happening at the state level. Unlike the European Union, where the General Data Protection Regulation sets one standard across all member states, the U.S. has no single federal privacy law to unify things. Colorado, Virginia, Connecticut, Utah, and a growing list of other states have all passed their own comprehensive privacy laws in the past few years, each with slightly different thresholds, consumer rights, and data breach notification timelines.

For a business operating in just one state, that's a manageable detail. For a business marketing across the country, it means the CCPA is one piece of a larger, still-forming patchwork rather than a single national standard. A marketing team building consent flows or data handling practices around California's rules specifically may find those same processes don't fully cover requirements in Colorado or Virginia.

What these laws mean for marketing measurement

Both GDPR and CCPA rules restrict how businesses can collect personal data, share it with service providers, and use it for targeting, and those restrictions show up as gaps in the data marketers have historically relied on. Any company that processes personal data for advertising purposes now has to account for consent requirements that simply didn't exist a decade ago, and the data security expectations attached to that processing have only gotten stricter since.

Consent requirements limit what a business can collect before an EU visitor takes action, or what it has to stop using once a California resident opts out. Third-party cookies, device identifiers, and cross-site tracking have all gotten harder to rely on as a direct result, and browsers have layered on their own tracking restrictions in response to the same regulatory pressure. The practical effect is that multi-touch attribution models, which depend on tracking individual users across touchpoints, are working with an increasingly incomplete data set no matter which region a campaign runs in.

That's pushed a lot of marketing teams toward measurement approaches that don't depend on identifying or tracking individual consumers at all. Marketing mix modeling looks at aggregated spend and outcome data instead of user-level signals, which means it doesn't run into the same wall when a consumer opts out or a browser blocks a cookie. It's one of the reasons MMM has picked up steam as privacy regulation has expanded, not as a replacement for testing or attribution, but as a measurement layer that keeps working regardless of what happens to individual-level tracking.

Where Prescient comes in

Privacy regulation isn't going away, and every new state law or CPRA-style amendment tends to tighten consumer data rights further rather than loosen them. That makes it worth building a measurement strategy that doesn't rebuild itself every time a new opt-out requirement rolls out. Prescient's marketing mix modeling platform measures performance using aggregated spend and outcome data across your channels, including retail and marketplace data from partners like Target, Walmart, and Amazon, so your reporting doesn't depend on the kind of individual-level tracking these laws restrict.

Book a demo and our team of experts will walk you through the Prescient platform, including how it's future-proof to changing data privacy regulation.

FAQs

What is the California equivalent of the GDPR?

The closest California equivalent to the GDPR is the California Consumer Privacy Act, as expanded by the California Privacy Rights Act. Like other privacy laws around the world, it gives residents rights over their personal data, including the right to know what's collected, request deletion, and limit certain uses. The two laws aren't identical, though. The CCPA applies to businesses that clear specific revenue or data-volume thresholds, while GDPR requires opt-in consent and applies more broadly regardless of a company's annual gross revenue.

Which is better, CCPA or GDPR?

Neither law is strictly "better" since they're built for different goals and legal systems. GDPR gives consumers stronger default protections because it requires opt-in consent and applies to a wider range of organizations, which many privacy advocates consider more protective. The CCPA gives California residents meaningful rights too, particularly after the CPRA expansion, but it places more of the burden on consumers to actively opt out rather than requiring businesses to ask first.

Is GDPR more strict than CCPA?

In most respects, yes. GDPR's opt-in consent requirement, broader scope, and significantly higher penalty ceiling of up to €20 million or 4% of global annual turnover make it more demanding than the CCPA's opt-out model and flat per-violation fines. That said, the CCPA's statutory damages provision for certain data breaches gives California consumers a direct path to compensation that GDPR doesn't offer in quite the same form.

Does California have data privacy laws?

Yes. California has some of the most comprehensive data privacy laws in the United States, starting with the California Consumer Privacy Act in 2018 and significantly expanded by the California Privacy Rights Act in 2023. Together, they give California residents the right to know what personal information businesses collect, request its deletion, opt out of having it sold or shared, and limit the use of sensitive personal information like health or financial data.

The Halo

Exclusive insights, every week.

Subscribe to The Halo for sharper marketing thinking.

Keep reading