Most CCPA vs GDPR articles were written years ago and quietly recycled. They tell you "GDPR is opt-in, CCPA is opt-out" and call it a day. True — and dangerously incomplete in 2026.
Since January 1, 2026, California's updated CCPA regulations are in force: accept and reject paths must be symmetrical, closing a banner no longer counts as anything, and your site must now display that it processed a Global Privacy Control signal. Meanwhile, California regulators have moved from warning letters to real money: Honda ($632,500), Disney ($2.75 million, February 2026), and GM ($12.75 million, May 2026).
So the real question is: what does my cookie banner have to do differently for a visitor from Berlin versus one from Los Angeles? That's what this guide answers — with the 2026 rules, not the 2020 ones.
What is the difference between CCPA and GDPR?
The GDPR (with the ePrivacy Directive) requires opt-in consent: non-essential cookies must stay off until an EU/EEA visitor actively agrees. The CCPA works the other way: you may set cookies and use data by default, but California residents get the right to opt out of the "sale" or "sharing" of their personal information — via a "Do Not Sell or Share" link and the Global Privacy Control browser signal, both of which you must honor. GDPR fines scale to €20 million or 4% of global annual turnover; CCPA penalties are $2,663 per violation ($7,988 if intentional or involving minors), counted per consumer.
Opt-in vs opt-out is the spine of every other difference. Let's walk through what that means for an actual banner.
Consent models: opt-in vs opt-out
Under GDPR/ePrivacy, consent is the gate. Article 5(3) of the ePrivacy Directive (as amended in 2009) requires consent before you store or read anything non-essential on a user's device, and GDPR Article 4(11) defines that consent as freely given, specific, informed, and unambiguous — an affirmative act. Pre-ticked boxes, scrolling, and silence don't count, and rejecting must be as easy as accepting. Scripts fire only after a "yes."
Under CCPA, there is no general consent gate. You can load analytics and ad tags on first paint, as long as you've given notice at collection. The consumer's power kicks in afterward: the right to opt out of sale/sharing, the right to limit use of sensitive personal information, and the right to have a browser-level signal (GPC) treated as a valid opt-out automatically. Opt-in consent only appears in specific spots — most notably for consumers under 16, and to re-enroll someone who previously opted out.
One practical consequence: a GDPR-compliant opt-in banner generally over-complies for California. The reverse is never true — an opt-out banner is flatly illegal for EU traffic. For which countries need which model, see our opt-in consent world map.
Scope, thresholds, and who's covered
| GDPR | CCPA (as amended by CPRA) | |
|---|---|---|
| Who it protects | Anyone in the EU/EEA (residence and citizenship irrelevant) | California residents ("consumers") |
| Who it binds | Any organization, anywhere, offering goods/services to or monitoring people in the EU — no size threshold | For-profit businesses doing business in California that meet a threshold |
| Thresholds (2026) | None | >$26,625,000 annual gross revenue, or buys/sells/shares personal info of 100,000+ consumers or households, or derives 50%+ of revenue from selling/sharing personal info |
| Consent default | Opt-in before non-essential cookies | Collect by default; opt-out of sale/sharing |
| Key trigger concept | "Processing personal data" | "Selling" or "sharing" personal information |
Note that revenue figure: the statute said $25 million, but the CPPA adjusts monetary thresholds for inflation every odd year. As of the January 2025 adjustment (in force through 2026), it's $26,625,000.
"Sale or share" is broader than you think
CCPA's "sale" covers disclosing personal information for any valuable consideration — not just cash. "Sharing" was added by CPRA specifically to capture disclosures for cross-context behavioral advertising, even with no money changing hands. In practice: if Meta Pixel, Google Ads remarketing, or any third-party ad tag runs on your site, you are almost certainly "selling or sharing," and the opt-out machinery applies. That was Sephora's mistake in 2022 — it argued its ad-tech data flows weren't "sales." The California AG disagreed, to the tune of $1.2 million.
Sensitive data
GDPR handles sensitive data (health, religion, sexual orientation, biometrics — Article 9) with a near-ban: processing typically requires explicit consent. CCPA instead created a "right to limit": consumers can restrict use of sensitive personal information (which includes precise geolocation) to what's necessary to deliver the service, via a "Limit the Use of My Sensitive Personal Information" link. Same theme, different mechanics — GDPR asks permission first, California gives a brake pedal after.
What changed on January 1, 2026 (and why your old banner may now be illegal in California)
The CPPA's updated regulations, approved in 2025, took effect January 1, 2026. Three changes hit cookie banners directly:
- Symmetry in choice is enforced, in detail. Opting out must take the same number of steps — or fewer — than opting in. One-click "Accept All" next to a multi-toggle-plus-confirm reject path is a violation (the core of the Honda order). Visual weight must be comparable too; a big bright "Accept" next to a grey "Reject" link is a dark pattern.
- Closing the banner is not a choice. Dismissing a popup with the X, or navigating away, cannot be treated as consent or acceptance. Only an affirmative selection counts, and consent obtained through a dark pattern is void.
- You must display GPC status. Under the revised § 7025, displaying whether you've processed a visitor's opt-out preference signal moved from "may" to "must" — e.g., "Opt-out request honored" shown when a GPC signal is received.
The deeper 2026 additions — risk assessments, cybersecurity audits, automated decision-making (ADMT) rules — phase in between 2027 and 2030 and are beyond a banner's pay grade. For what's in force right now, see do you need to update your cookie banner in 2026.
Enforcement and fines: how the two regimes punish
| GDPR | CCPA | |
|---|---|---|
| Maximum fines | Up to €20M or 4% of global annual turnover (whichever is higher); lower tier €10M / 2% | $2,663 per violation; $7,988 per intentional violation or violations involving minors (2025–2026 inflation-adjusted figures) |
| How it scales | One fine, scaled to turnover and severity | Per violation, often counted per consumer — 100,000 affected users can mean nine figures in theory |
| Who enforces | National DPAs (CNIL, Irish DPC, etc.), coordinated by the EDPB | California AG + the CPPA (the only dedicated privacy regulator in the US); no private right of action for cookie issues (only data breaches) |
| Cure period | None | 30-day cure right was removed for the AG in 2023; cure is now discretionary |
California's track record is short but pointed, and almost all of it is about opt-outs:
- Sephora (2022, $1.2M) — failed to disclose sales and ignored GPC signals.
- Honda (CPPA, March 2025, $632,500) — asymmetrical cookie choices and excessive verification for opt-outs.
- Disney (AG, February 2026, $2.75M) — opt-outs and GPC signals only applied per device/per service instead of account-wide across its streaming apps.
- GM (AG, May 2026, $12.75M) — sold connected-car location and driving data to data brokers without proper notice or consent; the largest CCPA penalty to date.
GDPR's cookie-adjacent fines run an order of magnitude larger — we cover those in the biggest cookie consent fines. The lesson from both regimes is identical, though: regulators test the reject path, not the accept path.
Consumer rights at a glance (DSAR comparison)
| Right | GDPR | CCPA |
|---|---|---|
| Access / know | Yes (Art. 15) | Yes |
| Deletion | Yes (Art. 17) | Yes (with exceptions) |
| Correction | Yes (Art. 16) | Yes (added by CPRA) |
| Portability | Yes (Art. 20) | Yes (within access right) |
| Object / opt out | Object to processing, incl. direct marketing (Art. 21); withdraw consent anytime | Opt out of sale/sharing; limit sensitive PI use |
| Honor browser signals | Not (yet) legally mandated | Yes — GPC is mandatory |
| Human review of automated decisions | Yes (Art. 22) | ADMT opt-out rights phase in by 2027 |
| Non-discrimination | Implicit (consent must be freely given) | Explicit non-discrimination right |
| Response deadline | 1 month (extendable +2) | 45 days (extendable +45); 15 business days for opt-outs |
One site, two regimes: the geo-targeted banner matrix
Here's the configuration that reconciles both laws on a single site. One static banner can't do this — geolocation has to drive behavior. (Whether one banner can cover everywhere is a longer story: can one cookie banner cover every country?)
| Banner element | EU/EEA/UK visitor (GDPR + ePrivacy) | California visitor (CCPA, 2026 regs) |
|---|---|---|
| Default state | All non-essential cookies blocked until consent | Cookies may load with notice; must stop sale/share on opt-out |
| Banner style | Blocking-priority banner: Accept / Reject / Preferences | Notice banner or footer links; banner optional but must be symmetric if used |
| Required buttons/links | "Reject all" as easy as "Accept all", equal prominence | "Do Not Sell or Share My Personal Information" link; "Limit the Use of My Sensitive PI" link if applicable |
| Closing the banner means | No consent — keep cookies off | Nothing — never treat dismissal as acceptance |
| GPC signal | Good practice, not mandated | Must be honored as a valid opt-out and status displayed on site |
| Granularity | Per-purpose toggles (analytics, marketing…), none pre-ticked | Opt-out can be global; under-16 data requires opt-in |
| Consent records | Keep proof of consent (controller must demonstrate it) | Keep records of opt-out requests and GPC processing (15-business-day deadline) |
| Re-prompting | Refresh consent periodically (~6–24 months, varies by DPA) | Wait 12 months before asking an opted-out consumer to opt back in |
Other US states layer their own variations on the California pattern — universal opt-out signals are now mandatory in Colorado, Texas, and a growing list — which we map in cookie banner requirements in US states.
What to actually do: a 9-point checklist
- Geolocate visitors and serve opt-in behavior to EU/EEA/UK, opt-out behavior to California (and other US opt-out states).
- Block non-essential scripts before consent for EU traffic — verify in your browser's network tab.
- Make reject one click and visually equal to accept, everywhere. Post-Honda, this is enforced on both continents.
- Never treat dismissal as a choice. X-ing out the banner = no consent (EU) and no acceptance (California).
- Add the "Do Not Sell or Share" link in your footer if any ad tech runs on your site — and wire it to actually stop the data flows (Disney's mistake: a toggle that only half-worked).
- Honor GPC automatically and display the status ("Opt-out request honored") — mandatory under the 2026 regs.
- Apply opt-outs account-wide, not per device, if users log in.
- Log everything: consents, opt-outs, GPC signals, timestamps. Both regimes put the burden of proof on you.
- Audit quarterly with a cookie scan — tags creep in via tag managers and break both regimes silently.
Where CookieChimp fits
This dual-regime setup is exactly what CookieChimp was built for. Its geo-targeting serves an opt-in banner with an equal-weight Reject button to EU visitors and a CCPA-style notice with a "Do Not Sell or Share" link to Californians — from one snippet. GPC signals are honored automatically, every consent and opt-out is logged for audit, automatic cookie scanning catches new tags before a regulator does, and Google Consent Mode v2 support keeps your analytics intact. Simple to ship, powerful enough for both regimes.
FAQ
Does the CCPA require a cookie banner?
No. The CCPA never requires opt-in consent for cookies (except for minors under 16), so a blocking banner isn't mandatory. What it requires is notice at collection, a "Do Not Sell or Share My Personal Information" link if you sell or share data, and automatic honoring of GPC signals.
But if you do show a cookie banner to Californians, the 2026 regulations govern its design: choices must be symmetrical, nothing pre-selected, and closing the banner can't be treated as acceptance.
Can I just use my GDPR banner for California visitors?
Mostly, yes — opt-in exceeds opt-out, so it's the safe lazy option. But it doesn't cover everything: you still must honor GPC signals (a GDPR banner won't do that by itself), provide the "Do Not Sell or Share" link, and make sure an opt-out actually stops third-party ad-tech flows. You'll also suppress far more data than California requires, which is why most sites geo-target instead.
Is Global Privacy Control required under GDPR?
No. GPC is legally mandatory in California (central to the Sephora and Disney settlements) and in several other US states, but no EU law currently requires honoring it. EU regulators have discussed browser-level consent signals for years; nothing is in force as of mid-2026.
What are the CCPA fines in 2026?
The inflation-adjusted figures, set by the CPPA effective January 1, 2025 and applying through 2026, are $2,663 per violation and $7,988 per intentional violation or violations involving consumers under 16. Statutory damages for data breaches run $107–$799 per consumer per incident. Because violations are typically counted per consumer, totals escalate quickly — GM's 2026 settlement reached $12.75 million.
Does closing a cookie banner count as consent?
No — under either law. GDPR consent requires an affirmative act, and the EU's top court ruled out inferred consent back in 2019 (Planet49). California caught up on January 1, 2026: the updated regulations state that closing a popup without affirmatively selecting an option is not consent, and choices obtained through dark patterns are void.
Does the CCPA apply to companies outside California?
Yes, if you "do business in California" — read broadly to include serving California consumers remotely — and meet a threshold: $26,625,000+ in annual gross revenue, data on 100,000+ California consumers/households, or 50%+ of revenue from selling or sharing personal info. Sephora is headquartered in France; it still paid $1.2 million.
References
- EUR-Lex, "Regulation (EU) 2016/679 (GDPR)": eur-lex.europa.eu
- EUR-Lex, "Directive 2002/58/EC (ePrivacy Directive)": eur-lex.europa.eu
- California Privacy Protection Agency, "Announcement of Updated Monetary Thresholds (effective Jan. 1, 2025)": cppa.ca.gov
- California Privacy Protection Agency, "CPPA Announces Decision Requiring Honda to Pay $632,500 (Mar. 12, 2025)": cppa.ca.gov
- California Department of Justice, "Attorney General Bonta Announces $2.75 Million Settlement with Disney (Feb. 11, 2026)": oag.ca.gov
- California Department of Justice, "Attorney General Bonta, Partners Secure $12.75 Million General Motors Privacy Settlement (May 8, 2026)": oag.ca.gov
- California Department of Justice, "Attorney General Bonta Announces Settlement with Sephora (Aug. 24, 2022)": oag.ca.gov
- California Department of Justice, "Global Privacy Control (GPC)": oag.ca.gov
- Cornell Law School LII, "11 CCR § 7025 — Opt-Out Preference Signals": law.cornell.edu
- Greenberg Traurig LLP, "Revised and New CCPA Regulations Set to Take Effect on Jan. 1, 2026": gtlaw.com
Running one site for both Brussels and Burbank doesn't have to mean two consent stacks. Get started with CookieChimp and ship a banner that handles both regimes from day one.