Guide

GDPR and CCPA Basics for Small Business Privacy Policies

The two biggest privacy laws most small businesses actually run into, explained without the compliance-platform sales pitch.

Last updated: August 2026

This page covers general, comparatively stable concepts. Specific figures like thresholds and penalty amounts change and are called out separately below.

GDPR, in plain terms

The General Data Protection Regulation has applied across the EU and UK since May 25, 2018. It applies to any business processing personal data of EU or UK residents, regardless of where the business itself is located, so a small US-based site with European visitors is genuinely in scope.

GDPR's core requirement is consent-based: for most data processing, you need a valid legal basis, most commonly the visitor's informed consent, and you need to tell them clearly what you're collecting and why. It also grants specific rights: access, correction, deletion, and data portability.

CCPA/CPRA, in plain terms

California's Consumer Privacy Act, later expanded by the California Privacy Rights Act, works differently. Rather than requiring opt-in consent upfront like GDPR, it's opt-out based: you can collect and use data by default, but California residents have the right to know what you collect, request its deletion, and opt out of having it sold or shared.

CCPA/CPRA applies to businesses meeting specific thresholds. The exact revenue and data-volume thresholds are adjusted periodically and change over time, so if you're near the line, check the current figures directly rather than relying on a number that may be out of date by the time you read this.

What changed for CCPA in 2026

California's privacy regulator (the CPPA) finalized a new package of CCPA regulations that took effect January 1, 2026, covering things like mandatory cybersecurity audits, formal risk assessments, and rules around automated decision-making technology. If that sounds like a lot, the reassuring part for most small businesses: the heaviest of these requirements have staggered deadlines running through 2027 and 2028, and several only apply once you're already well past the basic revenue or data-volume thresholds. If your business is small enough that you're reading a "basics" guide rather than hiring a compliance team, the core things this page already covers, disclosure, deletion, and opt-out rights, are still the part that applies to you first.

The key differences

 GDPRCCPA/CPRA
Consent modelOpt-in (consent required before collecting)Opt-out (collect by default, opt out of sale/sharing)
Who it coversEU/UK residents, regardless of where the business isCalifornia residents, if the business meets applicable thresholds
Core rightsAccess, correction, deletion, portabilityKnow, delete, opt out of sale/sharing
Applies based onWhether you have EU/UK visitors at allMeeting specific revenue or data-volume thresholds

What to put in your policy

For most small businesses with any international or California traffic, the practical approach is to write one privacy policy that satisfies the stricter of the two where they differ, rather than maintaining separate versions. That typically means: clear disclosure of what you collect and why (satisfies both), a rights section covering access/correction/deletion (core to both), and a statement about whether you sell or share data (CCPA-specific, but harmless to include even if GDPR doesn't require it in the same form). If you'd rather start from a document already shaped this way, this free template includes a GDPR/CCPA rights section by default. If any of the terminology here (controller, processor, consent) isn't familiar, the data privacy glossary covers it in plain English. Ready to work through what to actually do about CCPA specifically? See our CCPA compliance checklist.

Frequently asked questions

Does GDPR apply to me if I'm a small US business?

If you have any visitors from the EU or UK, potentially yes. GDPR doesn't have a small-business exemption based on where you're located, it's based on whose data you're processing.

How do I know if CCPA applies to my business?

It depends on current revenue and data-volume thresholds, which are adjusted periodically. Check the current thresholds directly through California's official CCPA resources, or consult a lawyer if you're close to the line, rather than relying on a number from an article that may have aged.

Can one privacy policy cover both GDPR and CCPA?

Yes, and that's the common approach for small businesses: one policy written to satisfy the stricter requirement wherever the two laws differ, rather than maintaining two separate documents.

Do the new 2026 CCPA rules mean I need to redo my privacy policy?

Probably not dramatically. The 2026 additions target things like automated decision-making disclosures and cybersecurity audits, which mostly apply once a business is already well past the basic thresholds. For most small sites, the core disclosure, deletion, and opt-out language this page already covers remains the main thing to get right.

What if I actually have a data breach?

That's a different, more urgent topic than what this page covers. See data breach notification requirements for the general framework of what you're required to do.

Related reading: do you actually need a privacy policy, if you're still working that out before diving into GDPR and CCPA specifics.

Sources

  • General Data Protection Regulation (Regulation (EU) 2016/679), in effect since May 25, 2018
  • California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA)
  • California Privacy Protection Agency (CPPA), finalized regulations effective January 1, 2026

This page deliberately does not cite specific CCPA revenue or data-volume thresholds, exact penalty amounts, or a count of state privacy laws, since those figures move and a stale number here would be worse than no number. If you need the current figures, check California's official CCPA resources directly or talk to a lawyer.

Cedrick Reese

Cedrick Reese founded Ready Utilities and built this site. He's a retired veteran and web developer who got his start in affiliate marketing and niche site development in the early 2000s. He earned a Computer Systems Technician certificate from UEI College, completed Electro-Mechanical Technologies at Tulsa Welding School, and finished the Carpentry program at Florida State College at Jacksonville. He builds free, practical tools like this one, along with furniture and a garden, in his spare time.