skip to content

GDPR Comparison & CPRA Changes

CCPA asks users to opt out where GDPR requires a lawful basis up front, and CPRA narrowed the gap with sensitive-data rules, minimisation and a dedicated agency. Interviewers ask for the comparison because most products have to satisfy both from a single implementation.

part ofCompliance & governance standardsoverview, primer and where to startread it →
on this pageshow

questions

5

How does the CCPA's opt-out model differ from the GDPR's lawful-basis model, and what does that mean for product defaults?

level: juniorimportance: must knowfreq 55%

answer

  1. permission first, or objection later
  2. six bases, consent only one
  3. notice at collection, then opt-out
  4. where California still needs opt-in
  5. Art. 6(1) versus 1798.120

basics

~20 s

Under the GDPR, processing is unlawful until one of six Art. 6(1) bases applies, so consent-based features start off; under the CCPA, collection with notice is allowed and consumers opt out of sale, sharing and some sensitive-data uses.

solid answer

~50 s

The GDPR starts from **prohibition**: processing is lawful *only if and to the extent that* one of the six bases in **Art. 6(1)** applies, such as contract, legal obligation, legitimate interests or consent. Consent is only one of them, but where it is the basis the feature must stay **off until the person opts in**, and withdrawal must be as easy as giving it (Art. 7(3)). The CCPA as amended by the CPRA starts from **notice**: a business may collect after telling consumers what and why (Civil Code 1798.100(a)), and the consumer may then **opt out** of sale or sharing (1798.120) and **limit** sensitive-data use (1798.121). So EU defaults are *off unless justified*, California defaults are *on unless the consumer objects*. The CCPA still requires opt-in in places: selling or sharing data of consumers known to be **under 16** (1798.120(c)) and purposes that fail the CPRA's reasonable-expectations test (11 CCR 7002(e)).

go deeper

for a junior

Recall the core contrast: the GDPR needs one of six lawful bases before processing, the CCPA allows collection with notice and gives consumers opt-outs.

for a middle

Explain how that turns into defaults per feature, and name the CCPA's opt-in exceptions: under-16 sales, resuming after opt-out, unexpected purposes.

for a senior

Show how you would configure one feature flag per purpose that resolves to off-until-consent in the EU and on-until-opt-out in California.

for a principal

Decide whether the product runs one strictest default everywhere or regional defaults, and what that costs in engineering and in consent rates.

## Two starting points The **General Data Protection Regulation (GDPR)** and the **California Consumer Privacy Act (CCPA)**, as amended by the **California Privacy Rights Act (CPRA)**, begin from opposite questions. The GDPR asks *what entitles you to process this at all?* The CCPA asks *have you told the consumer, and have they told you to stop?* | | GDPR | CCPA as amended by the CPRA | |---|---|---| | Default rule | processing lawful **only if** an Art. 6(1) basis applies | collection permitted **with notice** (1798.100(a)) | | Role of consent | one of six bases; required where no other basis fits | needed only in specific cases | | Individual's lever | withdraw consent (Art. 7(3)), object (Art. 21) | opt out of sale or sharing (1798.120), limit sensitive data (1798.121) | | Terms | controller, processor, data subject | business, service provider, contractor, consumer | ## The GDPR: a lawful basis first Art. 6(1) lists six bases: **consent**, **contract**, **legal obligation**, **vital interests**, **public task** and **legitimate interests**. A common mistake is to equate the GDPR with "consent for everything"; most core-service processing runs on contract or legitimate interests. But where consent is the basis, it must be *freely given, specific, informed and unambiguous* (Art. 4(11)), the controller must be able to **demonstrate** it (Art. 7(1)), and withdrawal must be **as easy as giving** it (Art. 7(3)). The CJEU held in **Planet49** (case C-673/17) that a **pre-ticked checkbox** does not amount to valid consent. For defaults, that means a consent-based feature ships **off**. ## The CCPA: notice, then opt-out The CCPA has no general lawful-basis requirement. A business that controls collection must, at or before collection, disclose the categories, purposes, whether data is sold or shared, and retention (1798.100(a)). It may then process, subject to: - the consumer's right to **opt out of sale or sharing** (1798.120(a)); - the right to **limit** use of **sensitive personal information** to what the service reasonably needs (1798.121(a)); - the CPRA's rule that collection, use, retention and sharing be **reasonably necessary and proportionate** to disclosed or compatible purposes (1798.100(c)). For defaults, the processing ships **on**, and the business must build the **off switch**: the "Do Not Sell or Share" and "Limit" links or the alternative signal route (1798.135), and, under the regulations, processing of valid **opt-out preference signals** (11 CCR 7025(b)). ## Where California still requires opt-in The CCPA is opt-out in general, not everywhere: 1. **Minors.** A business may not sell or share data of a consumer it actually knows is **under 16** unless the consumer (13 to 15) or a parent or guardian (under 13) has **affirmatively authorized** it (1798.120(c)). 2. **After an opt-out.** Once a consumer opts out, the business may sell or share again only if the consumer later **consents** (1798.120(d)). 3. **Unexpected purposes.** A purpose inconsistent with the consumer's reasonable expectations or incompatible with the collection context requires **consent** under 11 CCR 7002(e). ## What this means for one product's defaults | Feature | EU user (GDPR) | California consumer (CCPA) | |---|---|---| | Core service processing | on, on the contract basis | on, with notice | | Cross-context behavioural advertising | on only if a lawful basis holds, often consent | on with notice, off when the consumer opts out of sharing or sends a valid signal | | Sensitive or special-category data | Art. 9 prohibition unless a condition applies | allowed with notice; consumer may limit | | User known to be 15, ad data sold | depends on basis; Art. 8 governs consent for online services to children | off unless the consumer affirmatively authorized it | ## What each model forces the system to store - **GDPR:** a lawful-basis decision per purpose, made before launch, and, where the basis is consent, a per-purpose consent state the controller can prove (Art. 7(1)) and the user can withdraw. - **CCPA:** an opt-out and limit state checked before any sale, sharing or non-essential sensitive-data use, plus a notice at collection that matches what is actually collected. - **Both:** a purpose register, because both now tie use to disclosed or compatible purposes (GDPR Art. 5(1)(b); Civil Code 1798.100(c)). That shared purpose limitation is where the CPRA narrowed the gap. ## Misconceptions - "The GDPR requires consent for all processing": it requires **a** lawful basis. - "The CCPA never requires opt-in": minors, post-opt-out resumption and unexpected purposes do. - "A California opt-out banner makes an EU launch compliant": opt-out is not a lawful basis.

  • Under the GDPR, can a product avoid consent for analytics by relying on legitimate interests?
    Sometimes. Art. 6(1)(f) permits processing necessary for the controller's legitimate interests unless the data subject's interests or rights **override** them, so it needs a documented balancing. The data subject may object under Art. 21(1). The CCPA has no equivalent test; a California consumer's lever is the opt-out, not a balancing the business performs.
  • Under the CCPA, what happens to a consumer's opt-out if the business later wants to sell their data again?
    It stays in force. 1798.120(d) prohibits selling or sharing after the opt-out **unless the consumer subsequently provides consent**. That is one of the places where the CCPA switches from opt-out to opt-in, much like the GDPR's consent model.

The GDPR is a building with locked doors where you need a key before entering any room; the CCPA is a building with open doors and a sign on each, where occupants can ask you to leave certain rooms.

saying these in an interview costs you the question

  • The GDPR requires consent for every kind of processing.
  • The CCPA never requires opt-in consent for anything.
  • A 'Do Not Sell' link gives an EU launch a lawful basis.
  • Pre-ticked consent boxes are fine under the GDPR if users can untick them.
  • Under the CCPA, collection needs no notice as long as an opt-out exists.
open as a page

An EU company expanding to California asks whether the CCPA reaches it as the GDPR does — how do their scope rules and terms differ?

level: middleimportance: should knowfreq 40%

basics

~20 s

The GDPR reaches any controller or processor with an EU establishment, or targeting or monitoring people in the Union, whatever its size; the CCPA reaches only for-profit businesses in California meeting a revenue, volume or data-sales threshold.

open as a page

What did the CPRA add to the CCPA, and which of those additions moved California closer to the GDPR?

level: middleimportance: should knowfreq 45%

basics

~20 s

The CPRA, operative 2023-01-01, added 'sharing' for cross-context behavioural advertising, sensitive personal information with a right to limit, a right to correct, data minimisation and retention limits, and the CPPA, moving the CCPA toward GDPR principles while keeping opt-out.

open as a page

A US SaaS company launching in the EU wants one privacy programme — how can one request pipeline serve both GDPR and CCPA requests, and where must it branch?

level: seniorimportance: should knowfreq 48%

basics

~20 s

One intake, identity and fulfilment pipeline can serve both if each request is tagged with its regime: branch on deadlines (GDPR one month plus two; CCPA 45 days plus 45), the rights offered, verification, and consent versus opt-out handling.

open as a page

Should a global product apply GDPR-style opt-in everywhere or run per-region defaults, and why does 'GDPR everywhere' still not make it CCPA compliant?

level: principalimportance: should knowfreq 30%

basics

~20 s

Either can work, but 'GDPR everywhere' is not a CCPA superset: California still needs its own notice contents, opt-out links or signal handling, a 45-day clock, a 24-month request log and under-16 sale rules, so a strict core needs California adapters.

open as a page