GDPR and CCPA Basics for Small Business Privacy Policies
The two biggest privacy laws most small businesses actually run into, explained without the compliance-platform sales pitch.
Last updated: August 2026
This page covers general, comparatively stable concepts. Specific figures like thresholds and penalty amounts change and are called out separately below.
GDPR, in plain terms
The General Data Protection Regulation has applied across the EU and UK since May 25, 2018. It applies to any business processing personal data of EU or UK residents, regardless of where the business itself is located, so a small US-based site with European visitors is genuinely in scope.
GDPR's core requirement is consent-based: for most data processing, you need a valid legal basis, most commonly the visitor's informed consent, and you need to tell them clearly what you're collecting and why. It also grants specific rights: access, correction, deletion, and data portability.
CCPA/CPRA, in plain terms
California's Consumer Privacy Act, later expanded by the California Privacy Rights Act, works differently. Rather than requiring opt-in consent upfront like GDPR, it's opt-out based: you can collect and use data by default, but California residents have the right to know what you collect, request its deletion, and opt out of having it sold or shared.
CCPA/CPRA applies to businesses meeting specific thresholds. The exact revenue and data-volume thresholds are adjusted periodically and change over time, so if you're near the line, check the current figures directly rather than relying on a number that may be out of date by the time you read this.
What changed for CCPA in 2026
California's privacy regulator (the CPPA) finalized a new package of CCPA regulations that took effect January 1, 2026, covering things like mandatory cybersecurity audits, formal risk assessments, and rules around automated decision-making technology. If that sounds like a lot, the reassuring part for most small businesses: the heaviest of these requirements have staggered deadlines running through 2027 and 2028, and several only apply once you're already well past the basic revenue or data-volume thresholds. If your business is small enough that you're reading a "basics" guide rather than hiring a compliance team, the core things this page already covers, disclosure, deletion, and opt-out rights, are still the part that applies to you first.
The key differences
| GDPR | CCPA/CPRA | |
|---|---|---|
| Consent model | Opt-in (consent required before collecting) | Opt-out (collect by default, opt out of sale/sharing) |
| Who it covers | EU/UK residents, regardless of where the business is | California residents, if the business meets applicable thresholds |
| Core rights | Access, correction, deletion, portability | Know, delete, opt out of sale/sharing |
| Applies based on | Whether you have EU/UK visitors at all | Meeting specific revenue or data-volume thresholds |
What to put in your policy
For most small businesses with any international or California traffic, the practical approach is to write one privacy policy that satisfies the stricter of the two where they differ, rather than maintaining separate versions. That typically means: clear disclosure of what you collect and why (satisfies both), a rights section covering access/correction/deletion (core to both), and a statement about whether you sell or share data (CCPA-specific, but harmless to include even if GDPR doesn't require it in the same form). If you'd rather start from a document already shaped this way, this free template includes a GDPR/CCPA rights section by default. If any of the terminology here (controller, processor, consent) isn't familiar, the data privacy glossary covers it in plain English. Ready to work through what to actually do about CCPA specifically? See our CCPA compliance checklist.
Frequently asked questions
Does GDPR apply to me if I'm a small US business?
If you have any visitors from the EU or UK, potentially yes. GDPR doesn't have a small-business exemption based on where you're located, it's based on whose data you're processing.
How do I know if CCPA applies to my business?
It depends on current revenue and data-volume thresholds, which are adjusted periodically. Check the current thresholds directly through California's official CCPA resources, or consult a lawyer if you're close to the line, rather than relying on a number from an article that may have aged.
Can one privacy policy cover both GDPR and CCPA?
Yes, and that's the common approach for small businesses: one policy written to satisfy the stricter requirement wherever the two laws differ, rather than maintaining two separate documents.
Do the new 2026 CCPA rules mean I need to redo my privacy policy?
Probably not dramatically. The 2026 additions target things like automated decision-making disclosures and cybersecurity audits, which mostly apply once a business is already well past the basic thresholds. For most small sites, the core disclosure, deletion, and opt-out language this page already covers remains the main thing to get right.
What if I actually have a data breach?
That's a different, more urgent topic than what this page covers. See data breach notification requirements for the general framework of what you're required to do.
Related reading: do you actually need a privacy policy, if you're still working that out before diving into GDPR and CCPA specifics.
Sources
- General Data Protection Regulation (Regulation (EU) 2016/679), in effect since May 25, 2018
- California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA)
- California Privacy Protection Agency (CPPA), finalized regulations effective January 1, 2026
This page deliberately does not cite specific CCPA revenue or data-volume thresholds, exact penalty amounts, or a count of state privacy laws, since those figures move and a stale number here would be worse than no number. If you need the current figures, check California's official CCPA resources directly or talk to a lawyer.