CCPA vs GDPR: What Finance Teams Need to Know
GDPR comfort doesn't automatically transfer to California's CCPA. Here's exactly where the two regimes diverge and a practical compliance framework for firms with a US footprint.
A finance team that's spent years getting comfortable with GDPR often assumes that comfort transfers automatically to any other data privacy law they encounter. It mostly does — the underlying principles rhyme — but the California Consumer Privacy Act (CCPA), as strengthened by the California Privacy Rights Act (CPRA), has its own specific mechanics, and firms with US clients, US subsidiaries or California-resident customers need to know precisely where it diverges from GDPR rather than assuming the two are interchangeable.
What CCPA Actually Is
The CCPA is a California state privacy law, not a federal US law — the US still has no single, GDPR-equivalent federal data privacy statute, which is itself a key structural difference worth understanding. It gives California residents specific rights over their personal information held by covered businesses: the right to know what's collected, the right to delete it, the right to opt out of its sale or sharing, and the right to correct inaccurate information. The CPRA, which substantially amended and strengthened the CCPA from 2023, added a right to limit use of sensitive personal information and created a dedicated enforcement agency, the California Privacy Protection Agency (CPPA).
Where CCPA and GDPR Actually Diverge
- Legal basis for processing. GDPR requires an affirmative legal basis (consent, contract, legitimate interest, etc.) before processing personal data at all. CCPA takes an opt-out model by default for most processing — businesses can generally process data unless and until the individual exercises a specific right, most notably opting out of "sale or sharing."
- Scope of "personal information." Both cover broad categories of personal data, but CCPA's specific carve-outs and definitions (household data, certain employment and B2B data historically had different treatment) don't map one-to-one onto GDPR's definitions.
- Who it applies to. CCPA applies based on specific thresholds (revenue, volume of California consumer data processed, or revenue from selling personal information) rather than GDPR's broader "any business processing EU residents' data" scope — a business can be squarely in scope for one and out of scope for the other.
- Enforcement and penalties. GDPR fines scale to global annual turnover (up to 4%); CCPA/CPRA penalties are calculated per violation, with a distinct private right of action for certain data breaches that GDPR doesn't have in the same form — meaning CCPA can create direct litigation exposure GDPR doesn't.
A Practical Compliance Framework
- Map which law actually applies, don't assume. A UK-headquartered firm with no California customers, employees or data isn't in scope for CCPA regardless of GDPR compliance status — check the specific thresholds before building unnecessary controls.
- Don't assume your GDPR consent mechanism satisfies CCPA. CCPA's opt-out-of-sale mechanism (often implemented as a "Do Not Sell or Share My Personal Information" link) is a distinct requirement from GDPR consent banners, and one doesn't substitute for the other.
- Build a single data map that tags both regimes. Rather than running parallel compliance programmes, map personal data flows once and tag which regulations apply to each category — most of the operational work (knowing what you hold, where, and why) is genuinely shared infrastructure.
- Watch the state law patchwork, not just California. Virginia, Colorado, Connecticut and a growing list of other US states have since passed their own privacy laws with meaningful variations — CCPA is the most prominent, not the only one, and firms with a genuinely national US footprint need to track the pattern, not just one state.
Worked Example: A UK Firm Onboarding a US Client
A UK-based advisory firm wins a new client relationship with a California-headquartered company and will process some personal data belonging to that client's California-resident employees as part of the engagement. Rather than assuming its existing GDPR programme automatically covers this, the firm's data protection lead checks the specific CCPA applicability thresholds, confirms the firm itself doesn't independently meet them (it doesn't sell personal information and processes a relatively small volume), but still updates its data processing agreement with the client to reflect CCPA-specific obligations the client itself carries as the data controller. The distinction matters contractually even where the firm isn't directly regulated by CCPA itself.
Common Pitfalls
The most common mistake is assuming "we're GDPR compliant" is a complete answer to any data privacy question, when CCPA's opt-out model, specific consumer rights and private right of action require distinct, additional controls. The second is missing that CCPA applicability is threshold-based rather than universal — some firms build unnecessary CCPA infrastructure they don't actually need, while others miss real exposure because they only checked GDPR-style "any processing" logic.
Building This Into Team Practice
Firms that manage this well maintain a single data inventory tagged by applicable regulation, reviewed whenever a new client relationship, market or data flow is added, rather than treating each privacy law as a separate, siloed compliance project.
Why This Belongs in a Structured CPD Programme
The US state privacy law landscape is still actively expanding, and structured CPD gives compliance and finance professionals a current, documented understanding of a genuinely moving target, rather than a static GDPR-only picture that gets out of date as US firms and clients expand their footprint.
How This Fits Into a Broader Compliance Programme
Data privacy compliance across multiple jurisdictions sits alongside AML, cybersecurity and financial-crime programmes as part of a firm's broader risk and governance architecture — the data-mapping and vendor-management infrastructure built for GDPR is largely reusable for CCPA and the growing list of US state laws, making this an extension of existing capability rather than a parallel new function.
FAQ
Does GDPR compliance automatically satisfy CCPA?
No — the two regimes share underlying principles but have distinct mechanics, particularly around consent versus opt-out and specific consumer rights, and need to be assessed separately.
Does CCPA apply to a UK firm with no US operations?
Generally no, unless the firm meets CCPA's specific thresholds around California consumer data or revenue — but firms with US clients or subsidiaries should check specifically rather than assume either way.
Is California the only US state with a comprehensive privacy law?
No — a growing number of US states have passed their own laws with meaningful variations, so firms with a genuinely national US footprint need to track the broader pattern, not just CCPA.
For related reading, see our guides to GDPR requirements and the GDPR compliance checklist. Build your team's data privacy knowledge with Learnsignal's CPD courses.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.
View all posts by Learnsignal Education Team

