- GDPR applies based on whether you process EU residents' data, not where your company is based.
- CCPA has specific revenue and data-volume thresholds that exempt many small businesses.
- Overlapping requirements (like a clear privacy policy) can often satisfy both frameworks at once.
- The consequence of guessing wrong is significant enough to warrant an actual legal review.
GDPR is about whose data, not where you're based
A common misconception is that GDPR only applies to companies based in Europe. In reality, it applies to any company processing the personal data of EU residents, regardless of where the company itself is headquartered — a US-based SaaS company with European customers is very likely in scope.
CCPA has real thresholds that exempt smaller businesses
The California Consumer Privacy Act includes specific revenue and data-volume thresholds — a small business well under those thresholds may not be legally required to comply with its full requirements, even if it has some California customers. Checking the actual thresholds against your specific numbers matters more than assuming you're covered.
Some requirements overlap conveniently
Certain foundational privacy practices — a clear, accurate privacy policy, a defined process for data deletion requests — satisfy requirements under both frameworks simultaneously. Building those foundational practices well often covers a meaningful portion of both GDPR and CCPA obligations at once, rather than requiring two entirely separate compliance tracks.
Guessing wrong has real consequences
The penalties and legal exposure for genuinely being in scope and not complying are significant enough that a rough guess based on general impressions isn't a responsible way to make this decision. An actual review of your specific data practices against the specific regulatory text is worth the cost for any company with meaningful user data.
This is a legal question we help implement, not one we answer for you
We build the systems — data deletion tools, consent management, access logs — that implement whatever your legal counsel determines you need to comply with. Figuring out exactly which regulations apply to your specific business is a legal determination, not a technical one, and deserves real legal review.