// Security
CCPA vs GDPR: What's Different and Does Your Website Need Both?
GDPR and CCPA are the two most influential privacy laws affecting websites. Here's how they differ, where they overlap, and whether you need to comply with both.
In this article
The core difference: opt-in vs opt-out
GDPR (EU) and CCPA (California) are built on fundamentally different consent models. GDPR requires an opt-in for most forms of data processing — you cannot process personal data without a lawful basis, and for marketing and tracking, that lawful basis is usually explicit consent that users must actively give. The default is no data collection until the user agrees.
CCPA operates on an opt-out model. Businesses can collect and use consumer data by default; consumers have the right to opt out of the sale of their personal information. The 'Do Not Sell My Personal Information' link requirement is a manifestation of this: you can use data unless a California resident tells you not to.
In practice, for a website with both EU and California visitors, GDPR's opt-in requirements are stricter. Complying with GDPR generally satisfies the consent requirements of CCPA as well, but not vice versa. GDPR compliance puts you in a better position than CCPA-only compliance.
Who each law applies to
GDPR applies to any organization that offers goods or services to EU/EEA residents, or monitors their behavior — regardless of where the organization is located. A company in Texas serving European customers is subject to GDPR. The law has broad extraterritorial reach and European DPAs have pursued non-EU companies.
CCPA applies to for-profit companies that collect personal information from California residents AND meet at least one of three thresholds: $25M+ in annual revenue, 100,000+ consumers' data bought/sold/shared annually, or 50%+ of annual revenue from selling personal data. Many small businesses fall below all three thresholds and are not technically required to comply.
Key differences in practice
The differences that matter most for website implementation: GDPR requires a cookie consent banner with genuine opt-in for non-essential cookies; CCPA does not require a cookie banner but requires a 'Do Not Sell' link if you sell data. GDPR requires explicit disclosure of third-party data processors by name; CCPA requires disclosure of data selling but definitions of 'sale' are contested.
For most websites, the practical implication is straightforward: implement a GDPR-compliant consent mechanism with genuine opt-in/opt-out, add a privacy policy that covers CCPA rights, and add a 'Do Not Sell or Share My Personal Information' link to your footer if your business meets CCPA thresholds.
WebEnture's Cookie & Privacy Checker evaluates your site against both sets of requirements — cookie consent implementation, privacy policy content, 'Do Not Sell' link presence, and cookies being set without consent.