How does the CCPA's opt-out model differ from the GDPR's lawful-basis model, and what does that mean for product defaults?
answer
- permission first, or objection later
- six bases, consent only one
- notice at collection, then opt-out
- where California still needs opt-in
- Art. 6(1) versus 1798.120
basics
~20 sUnder the GDPR, processing is unlawful until one of six Art. 6(1) bases applies, so consent-based features start off; under the CCPA, collection with notice is allowed and consumers opt out of sale, sharing and some sensitive-data uses.
solid answer
~50 sThe GDPR starts from **prohibition**: processing is lawful *only if and to the extent that* one of the six bases in **Art. 6(1)** applies, such as contract, legal obligation, legitimate interests or consent. Consent is only one of them, but where it is the basis the feature must stay **off until the person opts in**, and withdrawal must be as easy as giving it (Art. 7(3)). The CCPA as amended by the CPRA starts from **notice**: a business may collect after telling consumers what and why (Civil Code 1798.100(a)), and the consumer may then **opt out** of sale or sharing (1798.120) and **limit** sensitive-data use (1798.121). So EU defaults are *off unless justified*, California defaults are *on unless the consumer objects*. The CCPA still requires opt-in in places: selling or sharing data of consumers known to be **under 16** (1798.120(c)) and purposes that fail the CPRA's reasonable-expectations test (11 CCR 7002(e)).
go deeper
Recall the core contrast: the GDPR needs one of six lawful bases before processing, the CCPA allows collection with notice and gives consumers opt-outs.
Explain how that turns into defaults per feature, and name the CCPA's opt-in exceptions: under-16 sales, resuming after opt-out, unexpected purposes.
Show how you would configure one feature flag per purpose that resolves to off-until-consent in the EU and on-until-opt-out in California.
Decide whether the product runs one strictest default everywhere or regional defaults, and what that costs in engineering and in consent rates.
## Two starting points The **General Data Protection Regulation (GDPR)** and the **California Consumer Privacy Act (CCPA)**, as amended by the **California Privacy Rights Act (CPRA)**, begin from opposite questions. The GDPR asks *what entitles you to process this at all?* The CCPA asks *have you told the consumer, and have they told you to stop?* | | GDPR | CCPA as amended by the CPRA | |---|---|---| | Default rule | processing lawful **only if** an Art. 6(1) basis applies | collection permitted **with notice** (1798.100(a)) | | Role of consent | one of six bases; required where no other basis fits | needed only in specific cases | | Individual's lever | withdraw consent (Art. 7(3)), object (Art. 21) | opt out of sale or sharing (1798.120), limit sensitive data (1798.121) | | Terms | controller, processor, data subject | business, service provider, contractor, consumer | ## The GDPR: a lawful basis first Art. 6(1) lists six bases: **consent**, **contract**, **legal obligation**, **vital interests**, **public task** and **legitimate interests**. A common mistake is to equate the GDPR with "consent for everything"; most core-service processing runs on contract or legitimate interests. But where consent is the basis, it must be *freely given, specific, informed and unambiguous* (Art. 4(11)), the controller must be able to **demonstrate** it (Art. 7(1)), and withdrawal must be **as easy as giving** it (Art. 7(3)). The CJEU held in **Planet49** (case C-673/17) that a **pre-ticked checkbox** does not amount to valid consent. For defaults, that means a consent-based feature ships **off**. ## The CCPA: notice, then opt-out The CCPA has no general lawful-basis requirement. A business that controls collection must, at or before collection, disclose the categories, purposes, whether data is sold or shared, and retention (1798.100(a)). It may then process, subject to: - the consumer's right to **opt out of sale or sharing** (1798.120(a)); - the right to **limit** use of **sensitive personal information** to what the service reasonably needs (1798.121(a)); - the CPRA's rule that collection, use, retention and sharing be **reasonably necessary and proportionate** to disclosed or compatible purposes (1798.100(c)). For defaults, the processing ships **on**, and the business must build the **off switch**: the "Do Not Sell or Share" and "Limit" links or the alternative signal route (1798.135), and, under the regulations, processing of valid **opt-out preference signals** (11 CCR 7025(b)). ## Where California still requires opt-in The CCPA is opt-out in general, not everywhere: 1. **Minors.** A business may not sell or share data of a consumer it actually knows is **under 16** unless the consumer (13 to 15) or a parent or guardian (under 13) has **affirmatively authorized** it (1798.120(c)). 2. **After an opt-out.** Once a consumer opts out, the business may sell or share again only if the consumer later **consents** (1798.120(d)). 3. **Unexpected purposes.** A purpose inconsistent with the consumer's reasonable expectations or incompatible with the collection context requires **consent** under 11 CCR 7002(e). ## What this means for one product's defaults | Feature | EU user (GDPR) | California consumer (CCPA) | |---|---|---| | Core service processing | on, on the contract basis | on, with notice | | Cross-context behavioural advertising | on only if a lawful basis holds, often consent | on with notice, off when the consumer opts out of sharing or sends a valid signal | | Sensitive or special-category data | Art. 9 prohibition unless a condition applies | allowed with notice; consumer may limit | | User known to be 15, ad data sold | depends on basis; Art. 8 governs consent for online services to children | off unless the consumer affirmatively authorized it | ## What each model forces the system to store - **GDPR:** a lawful-basis decision per purpose, made before launch, and, where the basis is consent, a per-purpose consent state the controller can prove (Art. 7(1)) and the user can withdraw. - **CCPA:** an opt-out and limit state checked before any sale, sharing or non-essential sensitive-data use, plus a notice at collection that matches what is actually collected. - **Both:** a purpose register, because both now tie use to disclosed or compatible purposes (GDPR Art. 5(1)(b); Civil Code 1798.100(c)). That shared purpose limitation is where the CPRA narrowed the gap. ## Misconceptions - "The GDPR requires consent for all processing": it requires **a** lawful basis. - "The CCPA never requires opt-in": minors, post-opt-out resumption and unexpected purposes do. - "A California opt-out banner makes an EU launch compliant": opt-out is not a lawful basis.
- Under the GDPR, can a product avoid consent for analytics by relying on legitimate interests?Sometimes. Art. 6(1)(f) permits processing necessary for the controller's legitimate interests unless the data subject's interests or rights **override** them, so it needs a documented balancing. The data subject may object under Art. 21(1). The CCPA has no equivalent test; a California consumer's lever is the opt-out, not a balancing the business performs.
- Under the CCPA, what happens to a consumer's opt-out if the business later wants to sell their data again?It stays in force. 1798.120(d) prohibits selling or sharing after the opt-out **unless the consumer subsequently provides consent**. That is one of the places where the CCPA switches from opt-out to opt-in, much like the GDPR's consent model.
The GDPR is a building with locked doors where you need a key before entering any room; the CCPA is a building with open doors and a sign on each, where occupants can ask you to leave certain rooms.
saying these in an interview costs you the question
- The GDPR requires consent for every kind of processing.
- The CCPA never requires opt-in consent for anything.
- A 'Do Not Sell' link gives an EU launch a lawful basis.
- Pre-ticked consent boxes are fine under the GDPR if users can untick them.
- Under the CCPA, collection needs no notice as long as an opt-out exists.