Home / Blog / Article
Security · 6 min read

GDPR vs CCPA: what you actually need to comply with

Most companies assume they need to worry about both, or neither. The real answer is usually more specific than either extreme.

Quick summary
  • GDPR applies based on whether you process EU residents' data, not where your company is based.
  • CCPA has specific revenue and data-volume thresholds that exempt many small businesses.
  • Overlapping requirements (like a clear privacy policy) can often satisfy both frameworks at once.
  • The consequence of guessing wrong is significant enough to warrant an actual legal review.

GDPR is about whose data, not where you're based

A common misconception is that GDPR only applies to companies based in Europe. In reality, it applies to any company processing the personal data of EU residents, regardless of where the company itself is headquartered — a US-based SaaS company with European customers is very likely in scope.

“A US-based company with European customers is very likely in GDPR's scope, regardless of where it's headquartered.”

CCPA has real thresholds that exempt smaller businesses

The California Consumer Privacy Act includes specific revenue and data-volume thresholds — a small business well under those thresholds may not be legally required to comply with its full requirements, even if it has some California customers. Checking the actual thresholds against your specific numbers matters more than assuming you're covered.

Some requirements overlap conveniently

Certain foundational privacy practices — a clear, accurate privacy policy, a defined process for data deletion requests — satisfy requirements under both frameworks simultaneously. Building those foundational practices well often covers a meaningful portion of both GDPR and CCPA obligations at once, rather than requiring two entirely separate compliance tracks.

Guessing wrong has real consequences

The penalties and legal exposure for genuinely being in scope and not complying are significant enough that a rough guess based on general impressions isn't a responsible way to make this decision. An actual review of your specific data practices against the specific regulatory text is worth the cost for any company with meaningful user data.

2
frameworks, often confused as interchangeable
thresholds
CCPA exempts many businesses below specific limits
legal review
worth the cost given the stakes
→ / Keep reading

Next note.

Prefer to talk?

Skip the reading — book a call and we'll get specific about your project.

◆ Free call◆ Reply in 24h◆ Named team