TopDoc Templates is reader-supported. When you buy through links on our site, we may earn an affiliate commission — at no extra cost to you. Learn more

Privacy Policy: CCPA vs GDPR in 10 Minutes

Collect emails, run analytics, or sell anything online? Then at least one privacy law already applies to you. Here is what GDPR and California’s CCPA/CPRA demand — and what your policy must contain to satisfy both.

GDPR (European Union) in 30 seconds

Applies if you handle data of EU residents, wherever you sit. Requires a legal basis (usually consent), clear notices, and user rights: access, correction, deletion, portability, objection. Breaches must be reported within 72 hours. Fines scale with global turnover — that’s why even small sites comply.

CCPA / CPRA (California) in 30 seconds

Applies to for-profit businesses meeting revenue, data-volume, or data-selling thresholds — many growing stores qualify sooner than they think. Core rights: know, delete, correct, opt out of sale/sharing, and no discrimination for exercising them. No opt-in banners required like GDPR, but the “Do Not Sell or Share” link is mandatory where applicable.

Get a policy template →

Side-by-side: where they differ

  1. Scope: GDPR = anyone handling EU data; CCPA = larger businesses touching California data.
  2. Consent: GDPR usually opt-in; CCPA usually opt-out (with exceptions).
  3. Enforcement: GDPR = regulators with turnover-based fines; CCPA = regulator fines per violation plus limited private lawsuits after breaches.
  4. Children: both raise the bar for under-13/16 data — check the template notes.

What your policy must contain (checklist)

  1. What you collect (emails, cookies, payments) and why.
  2. Legal bases / categories of sources and purposes.
  3. Cookies and analytics disclosure.
  4. User rights and exactly how to exercise them (email + response time).
  5. Contact details and the policy’s last-updated date.

3 costly mistakes

  1. Copy-pasting a giant’s policy — it describes their practices, not yours.
  2. No update date — looks abandoned to regulators and customers.
  3. Cookie banner with no matching policy text — the mismatch is the violation.

The bottom line

Start from a template written for both regimes, then tailor it to what you actually collect: Legal Templates.

Compare policy templates →