{"id":37631,"date":"2024-06-18T20:07:47","date_gmt":"2024-06-19T00:07:47","guid":{"rendered":"https:\/\/eptura.wpengine.com\/?p=37631"},"modified":"2025-02-13T22:07:17","modified_gmt":"2025-02-14T03:07:17","slug":"gdpr-vs-ccpa-compliance-the-5-differences-you-should-know","status":"publish","type":"post","link":"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/","title":{"rendered":"GDPR vs CCPA compliance: The 5 differences you should know"},"content":{"rendered":"<p><span style=\"background-color: transparent;\">If you<span> would have told me 20 years ago that I&#8217;d be writing about <\/span><\/span><span>data privacy laws<\/span><span style=\"background-color: transparent;\"><span> inside a tech company, then I never wou<\/span>ld have believed it. But then again, most of us didn&#8217;t see all this coming.<\/span><\/p>\n<p>After decades of the relatively lawless \u201cWild West\u201d of the internet, we\u2019ve finally entered a welcome period of legal reformation. We&#8217;ve even arrived at this point where we&#8217;re comparing two <strong>different data privacy laws<\/strong>: <strong>GDPR and CCPA<\/strong>.<\/p>\n<p>The Global Data Protection Regulation <a href=\"https:\/\/eugdpr.org\/\" target=\"_blank\" rel=\"nofollow noopener\">(GDPR)<\/a> went into action on May 25, 2018, effectively redefining the entire landscape of how online user data is to be handled. Then, at the beginning of last year, a new set of regulations, the California Consumer Privacy Act <a href=\"what-is-ccpa-and-why-does-it-matter-to-you\">(CCPA)<\/a>, went live, causing some businesses to begin to worry.<\/p>\n<p>While that\u2019s to be expected, we\u2019ll start with the good news first.<\/p>\n<h2>The good news about CCPA compliance<\/h2>\n<p style=\"font-weight: normal;\">If you&#8217;ve already finished the careful process of adapting to the stringent data privacy regulations set out by the European Union (EU), then you might be wondering how the CCPA is different from the GDPR. Will this new policy require you to shift your data privacy practices all over again?<\/p>\n<p><span style=\"font-weight: normal;\">Although the GDPR and CCPA are different from one another in some notable ways, the CCPA is essentially a less strict <\/span>version of the GDPR. (Kinda like how my mother was the strict one growing up, and my dad was the CCPA to her GDPR).<\/p>\n<p>Meaning, if your business is already aligned with the GDPR, then maintaining CCPA compliance shouldn\u2019t be too much of a hassle.<\/p>\n<p>Still, to ensure no violations occur, it\u2019s essential for businesses prioritizing regulatory compliance to understand the practical differences that exist between them.<\/p>\n<h2><strong>Some background on the current shift in data privacy laws\u00a0\u00a0<\/strong><\/h2>\n<p>The GDPR protects every EU citizen from having their personal information collected and used without their consent\u2014regardless of whether it&#8217;s online or in-person.<\/p>\n<p><img decoding=\"async\" style=\"width: 400px; display: block; margin: 60px auto;\" src=\"https:\/\/cdn2.hubspot.net\/hubfs\/437856\/EU_Map_GDPR.jpg\" alt=\"EU_Map_GDPR\" width=\"400\" \/><\/p>\n<p>Thus, companies from around the world have been forced to alter their data privacy practices accordingly.<\/p>\n<p>As some predicted, this has also inspired somewhat of a positive chain reaction across <span style=\"font-weight: normal;\">international data policies.<\/span> As other countries continue depending on business with the EU (who accounted for <a href=\"https:\/\/ustr.gov\/countries-regions\/europe-middle-east\/europe\/european-union\" target=\"_blank\" rel=\"nofollow noopener\">16.3% of U.S. exports in 2019<\/a>), many governments are finding it best to simply adopt their own GDPR-style set of <strong>data privacy laws<\/strong>.<\/p>\n<p>That\u2019s how California followed suit in 2020 with the CCPA, which was <a href=\"https:\/\/www.natlawreview.com\/article\/california-consumer-privacy-act-ccpa-2020-year-review\" target=\"_blank\" rel=\"nofollow noopener\">officially enforced<\/a> on July 1 by the California Attorney General. This moment marked a great milestone in the state data privacy legislation and possibly the first step towards a comprehensive federal law in the U.S.<\/p>\n<p><img decoding=\"async\" style=\"width: 400px; margin: 60px auto; display: block;\" src=\"https:\/\/cdn2.hubspot.net\/hubfs\/437856\/US-CA-EPS-02-4001.jpg\" alt=\"California_CCPA\" width=\"400\" \/><\/p>\n<p><span style=\"color: #000000;\">Now that we\u2019ve introduced two leading players <span style=\"font-weight: normal;\">&#8211; <\/span><\/span><span style=\"color: #000000; font-weight: normal;\">GDPR and CCPA<\/span><span style=\"color: #000000;\"><span style=\"font-weight: normal;\"> &#8211; <\/span>in the data privacy arena, let\u2019s discuss what we know so far in terms of these five differences:<\/span><\/p>\n<ol>\n<li>Who they affect<\/li>\n<li>The types of data protected<\/li>\n<li>What actions constitute data collecting, selling, and processing<\/li>\n<li>The information that must be provided to data subjects<\/li>\n<li>The penalties involved<\/li>\n<\/ol>\n<h2><strong>The 5 key differences between the GDPR and CCPA<\/strong><\/h2>\n<h3><strong>1. Who they affect<\/strong><\/h3>\n<p>The GDPR\u2019s laws apply to businesses (and their websites) of every kind.<\/p>\n<p>From eCommerce businesses to the webpages of non-profit organizations, to the websites of public institutions &#8211; any entity that deals with personal data from the EU must comply with the GDPR or invite costly legal repercussions. This also includes implications for GDPR and visitor management.<\/p>\n<p>While the GDPR protects all \u201cdata subjects\u201d (the identifiable people to which personal data belongs) regardless of their residence or citizenship status, the CCPA\u2019s protections are limited to individual data subjects that legally reside in California.<\/p>\n<p>Moreover, CCPA only affects for-profit entities whose business meets at least one of the following characteristics:<\/p>\n<ul>\n<li style=\"color: #3b3b6c;\" aria-level=\"1\">has an annual gross revenue &gt;$25 million<\/li>\n<li style=\"color: #3b3b6c;\" aria-level=\"1\">collects, buys, sells, or shares the data of &gt;50,000 consumers, devices, or households in California (this includes your company&#8217;s visitors)<\/li>\n<li style=\"color: #3b3b6c;\" aria-level=\"1\">at least 50% percent of their annual revenue comes from selling this data<\/li>\n<\/ul>\n<p>To fall under CCPA compliance, the business must also meet both of the criteria below:<\/p>\n<ul>\n<li style=\"color: #3b3b6c;\" aria-level=\"1\">collects personal information from consumers in California and determines the purposes and means of processing that information, and<\/li>\n<li style=\"color: #3b3b6c;\" aria-level=\"1\">operates in California<\/li>\n<\/ul>\n<p>There are still some grey areas to this &#8220;operates in California&#8221; label, as we mentioned in &#8220;What is CCPA and why should it matter to you?&#8221;.<\/p>\n<p>We promise to keep an eye and ear out for final judgments.<\/p>\n<p>&nbsp;<\/p>\n<p><strong style=\"font-size: 26px; letter-spacing: 0px; text-transform: inherit; background-color: transparent;\">2. The types of data protected<\/strong><\/p>\n<p>The GDPR broadly covers the processing of all personal data, no matter what that data is intended for or how it\u2019s processed.<\/p>\n<p>The only two exceptions to this rule include:<\/p>\n<ul>\n<li style=\"color: #3b3b6c;\" aria-level=\"1\">non-automated, personally conducted, data processing efforts that are not going to be filed, and<\/li>\n<li style=\"color: #3b3b6c;\" aria-level=\"1\">any data processing that\u2019s undertaken by individuals for their own personal purposes.<\/li>\n<\/ul>\n<p>The CCPA, however, is a bit more particular about what kinds of data are protected under different circumstances.<\/p>\n<p>For instance, while the GDPR requires entities to clearly gain user consent with \u201copt-in\u201d options before accessing any of their data, the CCPA only requires businesses to supply the option to \u201copt-out\u201d when user information is going to be actively sold or shared.<\/p>\n<p>Furthermore, the CCPA doesn\u2019t provide protection to a wider range of user data types than the GDPR, such as:<\/p>\n<ul>\n<li style=\"color: #3b3b6c;\" aria-level=\"1\">any data that is already legally available to the public<\/li>\n<li style=\"color: #3b3b6c;\" aria-level=\"1\">medical information that\u2019s protected under California\u2019s <a href=\"https:\/\/consumercal.org\/about-cfc\/cfc-education-foundation\/cfceducation-foundationyour-medical-privacy-rights\/confidentiality-of-medical-information-act\/\" target=\"_blank\" rel=\"nofollow noopener\">Confidentiality of Medical Information Act (CMIA)<\/a> or the federal <a href=\"\/blog\/visitor-management-system-hipaa-compliance\" target=\"_blank\" rel=\"noopener\">Health Insurance Portability and Accountability Act (HIPAA)<\/a><\/li>\n<li style=\"color: #3b3b6c;\" aria-level=\"1\">personal information covered by California\u2019s <a href=\"https:\/\/www.dmv.ca.gov\/portal\/dmv\/dmvfooter2\/privacypolicy\" target=\"_blank\" rel=\"nofollow noopener\">Driver\u2019s Privacy Protection Act<\/a>, and<\/li>\n<li style=\"color: #3b3b6c;\" aria-level=\"1\">other similar data sets.<\/li>\n<\/ul>\n<p>Although this is an area that\u2019s a little trickier for California servicing companies to navigate, if they follow the stricter regulations of the GDPR, they are likely already set.<\/p>\n<p>Still, a business\u2019s safest bet is to double-check and ensure that its processes accommodate the CCPA\u2019s specific regulations.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong style=\"background-color: transparent;\">3. What actions constitute data collecting, selling, and processing<\/strong><\/h3>\n<p>Under both the <strong>GDPR and CCPA<\/strong>, the term \u201cpersonal data\u201d means any information that can directly or indirectly represent an identifiable person. This includes the data of your external visitors and contractors.<\/p>\n<p>On the other hand, anonymous data is information that can\u2019t be traced to a singular identity\u2014and therefore isn\u2019t covered by either\u2019s laws.<\/p>\n<p>But that\u2019s about where the similarities in terminology end.<\/p>\n<h4>GDPR&#8217;s definition:<\/h4>\n<p>Considers the \u201cprocessing\u201d of personal data to be any action performed on a data subject&#8217;s information. This includes everything from the initial act of collecting user or visitor data to structuring and storing that information, making it available for others to access, and to its eventual removal and erasure.<\/p>\n<h4>CCPA&#8217;s definition:<\/h4>\n<p>Splits its data-relevant terminology into multiple separate definitions.<\/p>\n<ul>\n<li style=\"color: #3b3b6c;\" aria-level=\"1\">\u201cCollecting\u201d refers to the gathering of personal information through any method, but unlike the GDPR, this alone isn\u2019t considered \u201cprocessing\u201d.<\/li>\n<li style=\"color: #3b3b6c;\" aria-level=\"1\">&#8220;Processing&#8221; only occurs once data that has already been collected is acted upon further.<\/li>\n<li style=\"color: #3b3b6c;\" aria-level=\"1\">&#8220;Selling\u201d is referred to as another separate event that includes any transference, disclosure, or other kinds of communication regarding the contents of a data subject&#8217;s personal information.\n<ul>\n<li style=\"color: #3b3b6c;\" aria-level=\"2\">Most notably, \u201cselling\u201d here doesn\u2019t necessarily mean any payment is ever involved, only that the valuable and intentional exchange of personal user information has occurred.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3><strong>4. <\/strong><strong>The information that must be provided to data subjects<\/strong><\/h3>\n<p>To ensure greater transparency on how the data is managed, both the <strong>GDPR and CCPA<\/strong> include the following:<\/p>\n<ul>\n<li aria-level=\"1\">the data sharing methods that data subjects need to be informed of and when<\/li>\n<\/ul>\n<ul>\n<li aria-level=\"1\">the requirement that they must be notified of the purposes their data is being processed for<\/li>\n<li aria-level=\"1\">the rights individuals are entitled to regarding their data and how they can contact a relevant data protection officer if desired<\/li>\n<\/ul>\n<p>As to the differences:<\/p>\n<h4>CCPA requirements<\/h4>\n<p>Companies must regularly send reports that inform data subjects when their personal information was collected, sold, or disclosed for business purposes after a 12-month time-span.<\/p>\n<p>Data subjects must also be explicitly notified by any third-parties who have obtained their information when they intend on selling it to yet another separate third-party entity.<\/p>\n<h4>GDPR requirements<\/h4>\n<p>They&#8217;re significantly more thorough.<\/p>\n<ul>\n<li style=\"color: #3b3b6c;\" aria-level=\"1\">Data subjects must be notified when information is collected directly from them and whenever their information is shared with another entity, regardless of its affiliation or intention.<\/li>\n<li style=\"color: #3b3b6c;\" aria-level=\"1\">They must be told how long their data can be retained whenever their data is applied to automated systems for profiling.<\/li>\n<li style=\"color: #3b3b6c;\" aria-level=\"1\">They must also be informed of the reasoning behind those profiling processes and be supplied reminders that they always have the right to withdraw their consent to the data they\u2019ve previously shared.<\/li>\n<\/ul>\n<p>Lastly, when their data is processed by a third-party under the GDPR, data subjects must be notified no later than one month and told exactly from what source that third-party managed to acquire their data.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>5. The penalties involved<\/strong><\/h3>\n<p><a href=\"https:\/\/gdpr-info.eu\/issues\/fines-penalties\/\" target=\"_blank\" rel=\"nofollow noopener\">GDPR financial penalties<\/a> for non-compliance and\/or data breaches can range as high as \u20ac20 million (roughly $24 million), or 4% of the violating company\u2019s annual global turnover from the previous fiscal year\u2014depending on whichever amount is higher.<\/p>\n<p>In the instance of such payouts, administrative levies are to be applied proportionately across the offending entity\u2019s total financial assets. Believe it or not, having a visitor management system can help you avoid GDPR fines when it comes to your visitor data.<\/p>\n<p>The CCPA differs from the GDPR noticeably here, in that non-compliance alone isn\u2019t considered enough cause for fining. Instead, penalties are only applied after a data breach occurs.<\/p>\n<p>When one does happen, all pre-existing violations relevant to the breach are taken into consideration and individually fined. The maximum fines are as follows:<\/p>\n<ul>\n<li style=\"color: #3b3b6c;\" aria-level=\"1\">$2,500 for violations<\/li>\n<li style=\"color: #3b3b6c;\" aria-level=\"1\">$7,500 for intentional violations<\/li>\n<li style=\"color: #3b3b6c;\" aria-level=\"1\">$100 to $750 in damages in civil court (The CCPA provides consumers affected by a breach the opportunity to independently sue the responsible party as well.)<\/li>\n<\/ul>\n<p>So while the costs for violations under both the <span style=\"font-weight: normal;\">GDPR and CCPA<\/span> should not be taken lightly, there is a major difference in their approach:<\/p>\n<ul>\n<li style=\"color: #3b3b6c;\" aria-level=\"1\">GDPR is preemptive in reprimanding an irresponsible company<\/li>\n<li style=\"color: #3b3b6c;\" aria-level=\"1\">CCPA is entirely reactionary<\/li>\n<\/ul>\n<h2><strong>Ensuring your data privacy compliance for the GDPR and CCPA<\/strong><\/h2>\n<p>The GDPR has been prompting analyses of EU-dealing businesses (and fining offenders as needed) for two years now, and a challenging 2020 hasn\u2019t slowed down the enforcement of CCPA.<\/p>\n<p>As this overview plainly demonstrates, there\u2019s a lot to consider when maintaining compliance between the <strong>GDPR and CCPA<\/strong>. And there are still more specifications to come now that the <a href=\"https:\/\/www.csoonline.com\/article\/3601123\/cpra-explained-new-california-privacy-law-ramps-up-restrictions-on-data-use.html\" target=\"_blank\" rel=\"nofollow noopener\">California Privacy Rights Act (CPRA) was passed into law<\/a> and <a href=\"\/blog\/5-pressing-questions-answered-about-gdpr-post-brexit\" target=\"_blank\" rel=\"noopener\">Brexit is official<\/a><span style=\"color: #000000;\">.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you would have told me 20 years ago that I&#8217;d be writing about data privacy laws inside a tech company, then I never would have believed it. But then again, most of us didn&#8217;t see all this coming. After decades of the relatively lawless \u201cWild West\u201d of the internet, we\u2019ve finally entered a welcome &hellip; <a href=\"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;GDPR vs CCPA compliance: The 5 differences you should know&#8221;<\/span><\/a><\/p>\n","protected":false},"author":26,"featured_media":37818,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":"","_wpscp_schedule_draft_date":"","_wpscp_schedule_republish_date":"","_wpscppro_advance_schedule":false,"_wpscppro_advance_schedule_date":"","_wpscppro_dont_share_socialmedia":null,"_wpscppro_custom_social_share_image":0,"_facebook_share_type":"default","_twitter_share_type":"default","_linkedin_share_type":"default","_pinterest_share_type":"default","_linkedin_share_type_page":"","_instagram_share_type":"default","_medium_share_type":"default","_threads_share_type":"","_google_business_share_type":"","_selected_social_profile":[],"_wpsp_enable_custom_social_template":false,"_wpsp_social_scheduling":{"enabled":false,"datetime":null,"platforms":[],"status":"template_only","dateOption":"today","timeOption":"now","customDays":"","customHours":"","customDate":"","customTime":"","schedulingType":"absolute"},"_wpsp_active_default_template":true},"categories":[7,1],"tags":[419],"class_list":["post-37631","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","category-eptura","tag-blog"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.5 (Yoast SEO v26.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>GDPR vs CCPA compliance: The 5 differences you should know | Eptura<\/title>\n<meta name=\"description\" content=\"If you would have told me 20 years ago that I&#039;d be writing about data privacy laws inside a tech company, then I never would have believed it. But then\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"GDPR vs CCPA compliance: The 5 differences you should know\" \/>\n<meta property=\"og:description\" content=\"If you would have told me 20 years ago that I&#039;d be writing about data privacy laws inside a tech company, then I never would have believed it. But then\" \/>\n<meta property=\"og:url\" content=\"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/\" \/>\n<meta property=\"og:site_name\" content=\"Eptura\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/EpturaWork\/\" \/>\n<meta property=\"article:published_time\" content=\"2024-06-19T00:07:47+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-02-14T03:07:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/eptura.com\/wp-content\/uploads\/2025\/01\/Engineers20in20mechanical20factory20reading20instructions.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"666\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Jonathan Davis\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@epturawork\" \/>\n<meta name=\"twitter:site\" content=\"@epturawork\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jonathan Davis\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/\"},\"author\":{\"name\":\"Jonathan Davis\",\"@id\":\"https:\/\/eptura.com\/#\/schema\/person\/2e140d3d2f77b87152b5e2ba941b9158\"},\"headline\":\"GDPR vs CCPA compliance: The 5 differences you should know\",\"datePublished\":\"2024-06-19T00:07:47+00:00\",\"dateModified\":\"2025-02-14T03:07:17+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/\"},\"wordCount\":1769,\"publisher\":{\"@id\":\"https:\/\/eptura.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/eptura.com\/wp-content\/uploads\/2025\/01\/Engineers20in20mechanical20factory20reading20instructions.webp\",\"keywords\":[\"Blog\"],\"articleSection\":[\"Blog\",\"Eptura\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/\",\"url\":\"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/\",\"name\":\"GDPR vs CCPA compliance: The 5 differences you should know | Eptura\",\"isPartOf\":{\"@id\":\"https:\/\/eptura.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/eptura.com\/wp-content\/uploads\/2025\/01\/Engineers20in20mechanical20factory20reading20instructions.webp\",\"datePublished\":\"2024-06-19T00:07:47+00:00\",\"dateModified\":\"2025-02-14T03:07:17+00:00\",\"description\":\"If you would have told me 20 years ago that I'd be writing about data privacy laws inside a tech company, then I never would have believed it. But then\",\"breadcrumb\":{\"@id\":\"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/#primaryimage\",\"url\":\"https:\/\/eptura.com\/wp-content\/uploads\/2025\/01\/Engineers20in20mechanical20factory20reading20instructions.webp\",\"contentUrl\":\"https:\/\/eptura.com\/wp-content\/uploads\/2025\/01\/Engineers20in20mechanical20factory20reading20instructions.webp\",\"width\":1000,\"height\":666},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/eptura.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"GDPR vs CCPA compliance: The 5 differences you should know\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/eptura.com\/#website\",\"url\":\"https:\/\/eptura.com\/\",\"name\":\"Eptura\",\"description\":\"Work your world\",\"publisher\":{\"@id\":\"https:\/\/eptura.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/eptura.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/eptura.com\/#organization\",\"name\":\"Eptura\",\"url\":\"https:\/\/eptura.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/eptura.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/eptura.com\/wp-content\/uploads\/2024\/03\/eptura-dark-svg-TM-8.png\",\"contentUrl\":\"https:\/\/eptura.com\/wp-content\/uploads\/2024\/03\/eptura-dark-svg-TM-8.png\",\"width\":1280,\"height\":800,\"caption\":\"Eptura\"},\"image\":{\"@id\":\"https:\/\/eptura.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/EpturaWork\/\",\"https:\/\/x.com\/epturawork\",\"https:\/\/www.linkedin.com\/company\/eptura\/\",\"https:\/\/twitter.com\/epturawork\",\"https:\/\/www.youtube.com\/channel\/UC6hdVbsn41BZxfIYmPUdCWQ\"],\"description\":\"A global worktech company that provides software solutions for workplaces, people, and assets that enable everyone to reach their full potential.\",\"legalName\":\"Eptura\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/eptura.com\/#\/schema\/person\/2e140d3d2f77b87152b5e2ba941b9158\",\"name\":\"Jonathan Davis\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/eptura.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/eptura.com\/wp-content\/uploads\/2024\/02\/jonathan_davis-96x96.png\",\"contentUrl\":\"https:\/\/eptura.com\/wp-content\/uploads\/2024\/02\/jonathan_davis-96x96.png\",\"caption\":\"Jonathan Davis\"},\"description\":\"As a content creator at Eptura, Jonathan Davis covers asset management, maintenance software, and SaaS solutions, delivering thought leadership with actionable insights across industries such as fleet, manufacturing, healthcare, and hospitality. Jonathan\u2019s writing focuses on topics to help enterprises optimize their operations, including building lifecycle management, digital twins, BIM for facility management, and preventive and predictive maintenance strategies. With a master's degree in journalism and a diverse background that includes writing textbooks, editing video game dialogue, and teaching English as a foreign language, Jonathan brings a versatile perspective to his content creation.\",\"sameAs\":[\"https:\/\/www.linkedin.com\/in\/jonathan-t-davis\/\"],\"jobTitle\":\"Senior Content Writer\",\"worksFor\":\"Eptura\",\"url\":\"https:\/\/eptura.com\/discover-more\/blog\/author\/jonathan-davis\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"GDPR vs CCPA compliance: The 5 differences you should know | Eptura","description":"If you would have told me 20 years ago that I'd be writing about data privacy laws inside a tech company, then I never would have believed it. But then","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/","og_locale":"en_US","og_type":"article","og_title":"GDPR vs CCPA compliance: The 5 differences you should know","og_description":"If you would have told me 20 years ago that I'd be writing about data privacy laws inside a tech company, then I never would have believed it. But then","og_url":"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/","og_site_name":"Eptura","article_publisher":"https:\/\/www.facebook.com\/EpturaWork\/","article_published_time":"2024-06-19T00:07:47+00:00","article_modified_time":"2025-02-14T03:07:17+00:00","og_image":[{"width":1000,"height":666,"url":"https:\/\/eptura.com\/wp-content\/uploads\/2025\/01\/Engineers20in20mechanical20factory20reading20instructions.webp","type":"image\/webp"}],"author":"Jonathan Davis","twitter_card":"summary_large_image","twitter_creator":"@epturawork","twitter_site":"@epturawork","twitter_misc":{"Written by":"Jonathan Davis","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/#article","isPartOf":{"@id":"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/"},"author":{"name":"Jonathan Davis","@id":"https:\/\/eptura.com\/#\/schema\/person\/2e140d3d2f77b87152b5e2ba941b9158"},"headline":"GDPR vs CCPA compliance: The 5 differences you should know","datePublished":"2024-06-19T00:07:47+00:00","dateModified":"2025-02-14T03:07:17+00:00","mainEntityOfPage":{"@id":"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/"},"wordCount":1769,"publisher":{"@id":"https:\/\/eptura.com\/#organization"},"image":{"@id":"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/#primaryimage"},"thumbnailUrl":"https:\/\/eptura.com\/wp-content\/uploads\/2025\/01\/Engineers20in20mechanical20factory20reading20instructions.webp","keywords":["Blog"],"articleSection":["Blog","Eptura"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/","url":"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/","name":"GDPR vs CCPA compliance: The 5 differences you should know | Eptura","isPartOf":{"@id":"https:\/\/eptura.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/#primaryimage"},"image":{"@id":"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/#primaryimage"},"thumbnailUrl":"https:\/\/eptura.com\/wp-content\/uploads\/2025\/01\/Engineers20in20mechanical20factory20reading20instructions.webp","datePublished":"2024-06-19T00:07:47+00:00","dateModified":"2025-02-14T03:07:17+00:00","description":"If you would have told me 20 years ago that I'd be writing about data privacy laws inside a tech company, then I never would have believed it. But then","breadcrumb":{"@id":"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/#primaryimage","url":"https:\/\/eptura.com\/wp-content\/uploads\/2025\/01\/Engineers20in20mechanical20factory20reading20instructions.webp","contentUrl":"https:\/\/eptura.com\/wp-content\/uploads\/2025\/01\/Engineers20in20mechanical20factory20reading20instructions.webp","width":1000,"height":666},{"@type":"BreadcrumbList","@id":"https:\/\/eptura.com\/discover-more\/blog\/gdpr-vs-ccpa-compliance-the-5-differences-you-should-know\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/eptura.com\/"},{"@type":"ListItem","position":2,"name":"GDPR vs CCPA compliance: The 5 differences you should know"}]},{"@type":"WebSite","@id":"https:\/\/eptura.com\/#website","url":"https:\/\/eptura.com\/","name":"Eptura","description":"Work your world","publisher":{"@id":"https:\/\/eptura.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/eptura.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/eptura.com\/#organization","name":"Eptura","url":"https:\/\/eptura.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/eptura.com\/#\/schema\/logo\/image\/","url":"https:\/\/eptura.com\/wp-content\/uploads\/2024\/03\/eptura-dark-svg-TM-8.png","contentUrl":"https:\/\/eptura.com\/wp-content\/uploads\/2024\/03\/eptura-dark-svg-TM-8.png","width":1280,"height":800,"caption":"Eptura"},"image":{"@id":"https:\/\/eptura.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/EpturaWork\/","https:\/\/x.com\/epturawork","https:\/\/www.linkedin.com\/company\/eptura\/","https:\/\/twitter.com\/epturawork","https:\/\/www.youtube.com\/channel\/UC6hdVbsn41BZxfIYmPUdCWQ"],"description":"A global worktech company that provides software solutions for workplaces, people, and assets that enable everyone to reach their full potential.","legalName":"Eptura"},{"@type":"Person","@id":"https:\/\/eptura.com\/#\/schema\/person\/2e140d3d2f77b87152b5e2ba941b9158","name":"Jonathan Davis","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/eptura.com\/#\/schema\/person\/image\/","url":"https:\/\/eptura.com\/wp-content\/uploads\/2024\/02\/jonathan_davis-96x96.png","contentUrl":"https:\/\/eptura.com\/wp-content\/uploads\/2024\/02\/jonathan_davis-96x96.png","caption":"Jonathan Davis"},"description":"As a content creator at Eptura, Jonathan Davis covers asset management, maintenance software, and SaaS solutions, delivering thought leadership with actionable insights across industries such as fleet, manufacturing, healthcare, and hospitality. Jonathan\u2019s writing focuses on topics to help enterprises optimize their operations, including building lifecycle management, digital twins, BIM for facility management, and preventive and predictive maintenance strategies. With a master's degree in journalism and a diverse background that includes writing textbooks, editing video game dialogue, and teaching English as a foreign language, Jonathan brings a versatile perspective to his content creation.","sameAs":["https:\/\/www.linkedin.com\/in\/jonathan-t-davis\/"],"jobTitle":"Senior Content Writer","worksFor":"Eptura","url":"https:\/\/eptura.com\/discover-more\/blog\/author\/jonathan-davis\/"}]}},"_links":{"self":[{"href":"https:\/\/eptura.com\/wp-json\/wp\/v2\/posts\/37631","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/eptura.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/eptura.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/eptura.com\/wp-json\/wp\/v2\/users\/26"}],"replies":[{"embeddable":true,"href":"https:\/\/eptura.com\/wp-json\/wp\/v2\/comments?post=37631"}],"version-history":[{"count":0,"href":"https:\/\/eptura.com\/wp-json\/wp\/v2\/posts\/37631\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/eptura.com\/wp-json\/wp\/v2\/media\/37818"}],"wp:attachment":[{"href":"https:\/\/eptura.com\/wp-json\/wp\/v2\/media?parent=37631"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/eptura.com\/wp-json\/wp\/v2\/categories?post=37631"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/eptura.com\/wp-json\/wp\/v2\/tags?post=37631"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}