CCPA vs GDPR in 2026: What Your Cookie Banner Must Do Differently

CCPA is opt-out, GDPR is opt-in — but 2026 rules changed the details. Compare consent models, GPC, fines, and how to configure one banner for both.

Written by
Daniel
Published on
CCPA vs GDPR in 2026: What Your Cookie Banner Must Do Differently

Most CCPA vs GDPR articles were written years ago and quietly recycled. They tell you "GDPR is opt-in, CCPA is opt-out" and call it a day. True — and dangerously incomplete in 2026.

Since January 1, 2026, California's updated CCPA regulations are in force: accept and reject paths must be symmetrical, closing a banner no longer counts as anything, and your site must now display that it processed a Global Privacy Control signal. Meanwhile, California regulators have moved from warning letters to real money: Honda ($632,500), Disney ($2.75 million, February 2026), and GM ($12.75 million, May 2026).

So the real question is: what does my cookie banner have to do differently for a visitor from Berlin versus one from Los Angeles? That's what this guide answers — with the 2026 rules, not the 2020 ones.

What is the difference between CCPA and GDPR?

The GDPR (with the ePrivacy Directive) requires opt-in consent: non-essential cookies must stay off until an EU/EEA visitor actively agrees. The CCPA works the other way: you may set cookies and use data by default, but California residents get the right to opt out of the "sale" or "sharing" of their personal information — via a "Do Not Sell or Share" link and the Global Privacy Control browser signal, both of which you must honor. GDPR fines scale to €20 million or 4% of global annual turnover; CCPA penalties are $2,663 per violation ($7,988 if intentional or involving minors), counted per consumer.

Opt-in vs opt-out is the spine of every other difference. Let's walk through what that means for an actual banner.

Under GDPR/ePrivacy, consent is the gate. Article 5(3) of the ePrivacy Directive (as amended in 2009) requires consent before you store or read anything non-essential on a user's device, and GDPR Article 4(11) defines that consent as freely given, specific, informed, and unambiguous — an affirmative act. Pre-ticked boxes, scrolling, and silence don't count, and rejecting must be as easy as accepting. Scripts fire only after a "yes."

Under CCPA, there is no general consent gate. You can load analytics and ad tags on first paint, as long as you've given notice at collection. The consumer's power kicks in afterward: the right to opt out of sale/sharing, the right to limit use of sensitive personal information, and the right to have a browser-level signal (GPC) treated as a valid opt-out automatically. Opt-in consent only appears in specific spots — most notably for consumers under 16, and to re-enroll someone who previously opted out.

One practical consequence: a GDPR-compliant opt-in banner generally over-complies for California. The reverse is never true — an opt-out banner is flatly illegal for EU traffic. For which countries need which model, see our opt-in consent world map.

Scope, thresholds, and who's covered

GDPR CCPA (as amended by CPRA)
Who it protects Anyone in the EU/EEA (residence and citizenship irrelevant) California residents ("consumers")
Who it binds Any organization, anywhere, offering goods/services to or monitoring people in the EU — no size threshold For-profit businesses doing business in California that meet a threshold
Thresholds (2026) None >$26,625,000 annual gross revenue, or buys/sells/shares personal info of 100,000+ consumers or households, or derives 50%+ of revenue from selling/sharing personal info
Consent default Opt-in before non-essential cookies Collect by default; opt-out of sale/sharing
Key trigger concept "Processing personal data" "Selling" or "sharing" personal information

Note that revenue figure: the statute said $25 million, but the CPPA adjusts monetary thresholds for inflation every odd year. As of the January 2025 adjustment (in force through 2026), it's $26,625,000.

"Sale or share" is broader than you think

CCPA's "sale" covers disclosing personal information for any valuable consideration — not just cash. "Sharing" was added by CPRA specifically to capture disclosures for cross-context behavioral advertising, even with no money changing hands. In practice: if Meta Pixel, Google Ads remarketing, or any third-party ad tag runs on your site, you are almost certainly "selling or sharing," and the opt-out machinery applies. That was Sephora's mistake in 2022 — it argued its ad-tech data flows weren't "sales." The California AG disagreed, to the tune of $1.2 million.

Sensitive data

GDPR handles sensitive data (health, religion, sexual orientation, biometrics — Article 9) with a near-ban: processing typically requires explicit consent. CCPA instead created a "right to limit": consumers can restrict use of sensitive personal information (which includes precise geolocation) to what's necessary to deliver the service, via a "Limit the Use of My Sensitive Personal Information" link. Same theme, different mechanics — GDPR asks permission first, California gives a brake pedal after.

What changed on January 1, 2026 (and why your old banner may now be illegal in California)

The CPPA's updated regulations, approved in 2025, took effect January 1, 2026. Three changes hit cookie banners directly:

  1. Symmetry in choice is enforced, in detail. Opting out must take the same number of steps — or fewer — than opting in. One-click "Accept All" next to a multi-toggle-plus-confirm reject path is a violation (the core of the Honda order). Visual weight must be comparable too; a big bright "Accept" next to a grey "Reject" link is a dark pattern.
  2. Closing the banner is not a choice. Dismissing a popup with the X, or navigating away, cannot be treated as consent or acceptance. Only an affirmative selection counts, and consent obtained through a dark pattern is void.
  3. You must display GPC status. Under the revised § 7025, displaying whether you've processed a visitor's opt-out preference signal moved from "may" to "must" — e.g., "Opt-out request honored" shown when a GPC signal is received.

The deeper 2026 additions — risk assessments, cybersecurity audits, automated decision-making (ADMT) rules — phase in between 2027 and 2030 and are beyond a banner's pay grade. For what's in force right now, see do you need to update your cookie banner in 2026.

Enforcement and fines: how the two regimes punish

GDPR CCPA
Maximum fines Up to €20M or 4% of global annual turnover (whichever is higher); lower tier €10M / 2% $2,663 per violation; $7,988 per intentional violation or violations involving minors (2025–2026 inflation-adjusted figures)
How it scales One fine, scaled to turnover and severity Per violation, often counted per consumer — 100,000 affected users can mean nine figures in theory
Who enforces National DPAs (CNIL, Irish DPC, etc.), coordinated by the EDPB California AG + the CPPA (the only dedicated privacy regulator in the US); no private right of action for cookie issues (only data breaches)
Cure period None 30-day cure right was removed for the AG in 2023; cure is now discretionary

California's track record is short but pointed, and almost all of it is about opt-outs:

  • Sephora (2022, $1.2M) — failed to disclose sales and ignored GPC signals.
  • Honda (CPPA, March 2025, $632,500) — asymmetrical cookie choices and excessive verification for opt-outs.
  • Disney (AG, February 2026, $2.75M) — opt-outs and GPC signals only applied per device/per service instead of account-wide across its streaming apps.
  • GM (AG, May 2026, $12.75M) — sold connected-car location and driving data to data brokers without proper notice or consent; the largest CCPA penalty to date.

GDPR's cookie-adjacent fines run an order of magnitude larger — we cover those in the biggest cookie consent fines. The lesson from both regimes is identical, though: regulators test the reject path, not the accept path.

Consumer rights at a glance (DSAR comparison)

Right GDPR CCPA
Access / know Yes (Art. 15) Yes
Deletion Yes (Art. 17) Yes (with exceptions)
Correction Yes (Art. 16) Yes (added by CPRA)
Portability Yes (Art. 20) Yes (within access right)
Object / opt out Object to processing, incl. direct marketing (Art. 21); withdraw consent anytime Opt out of sale/sharing; limit sensitive PI use
Honor browser signals Not (yet) legally mandated Yes — GPC is mandatory
Human review of automated decisions Yes (Art. 22) ADMT opt-out rights phase in by 2027
Non-discrimination Implicit (consent must be freely given) Explicit non-discrimination right
Response deadline 1 month (extendable +2) 45 days (extendable +45); 15 business days for opt-outs

One site, two regimes: the geo-targeted banner matrix

Here's the configuration that reconciles both laws on a single site. One static banner can't do this — geolocation has to drive behavior. (Whether one banner can cover everywhere is a longer story: can one cookie banner cover every country?)

Banner element EU/EEA/UK visitor (GDPR + ePrivacy) California visitor (CCPA, 2026 regs)
Default state All non-essential cookies blocked until consent Cookies may load with notice; must stop sale/share on opt-out
Banner style Blocking-priority banner: Accept / Reject / Preferences Notice banner or footer links; banner optional but must be symmetric if used
Required buttons/links "Reject all" as easy as "Accept all", equal prominence "Do Not Sell or Share My Personal Information" link; "Limit the Use of My Sensitive PI" link if applicable
Closing the banner means No consent — keep cookies off Nothing — never treat dismissal as acceptance
GPC signal Good practice, not mandated Must be honored as a valid opt-out and status displayed on site
Granularity Per-purpose toggles (analytics, marketing…), none pre-ticked Opt-out can be global; under-16 data requires opt-in
Consent records Keep proof of consent (controller must demonstrate it) Keep records of opt-out requests and GPC processing (15-business-day deadline)
Re-prompting Refresh consent periodically (~6–24 months, varies by DPA) Wait 12 months before asking an opted-out consumer to opt back in

Other US states layer their own variations on the California pattern — universal opt-out signals are now mandatory in Colorado, Texas, and a growing list — which we map in cookie banner requirements in US states.

What to actually do: a 9-point checklist

  1. Geolocate visitors and serve opt-in behavior to EU/EEA/UK, opt-out behavior to California (and other US opt-out states).
  2. Block non-essential scripts before consent for EU traffic — verify in your browser's network tab.
  3. Make reject one click and visually equal to accept, everywhere. Post-Honda, this is enforced on both continents.
  4. Never treat dismissal as a choice. X-ing out the banner = no consent (EU) and no acceptance (California).
  5. Add the "Do Not Sell or Share" link in your footer if any ad tech runs on your site — and wire it to actually stop the data flows (Disney's mistake: a toggle that only half-worked).
  6. Honor GPC automatically and display the status ("Opt-out request honored") — mandatory under the 2026 regs.
  7. Apply opt-outs account-wide, not per device, if users log in.
  8. Log everything: consents, opt-outs, GPC signals, timestamps. Both regimes put the burden of proof on you.
  9. Audit quarterly with a cookie scan — tags creep in via tag managers and break both regimes silently.

Where CookieChimp fits

This dual-regime setup is exactly what CookieChimp was built for. Its geo-targeting serves an opt-in banner with an equal-weight Reject button to EU visitors and a CCPA-style notice with a "Do Not Sell or Share" link to Californians — from one snippet. GPC signals are honored automatically, every consent and opt-out is logged for audit, automatic cookie scanning catches new tags before a regulator does, and Google Consent Mode v2 support keeps your analytics intact. Simple to ship, powerful enough for both regimes.

FAQ

Does the CCPA require a cookie banner?

No. The CCPA never requires opt-in consent for cookies (except for minors under 16), so a blocking banner isn't mandatory. What it requires is notice at collection, a "Do Not Sell or Share My Personal Information" link if you sell or share data, and automatic honoring of GPC signals.

But if you do show a cookie banner to Californians, the 2026 regulations govern its design: choices must be symmetrical, nothing pre-selected, and closing the banner can't be treated as acceptance.

Can I just use my GDPR banner for California visitors?

Mostly, yes — opt-in exceeds opt-out, so it's the safe lazy option. But it doesn't cover everything: you still must honor GPC signals (a GDPR banner won't do that by itself), provide the "Do Not Sell or Share" link, and make sure an opt-out actually stops third-party ad-tech flows. You'll also suppress far more data than California requires, which is why most sites geo-target instead.

Is Global Privacy Control required under GDPR?

No. GPC is legally mandatory in California (central to the Sephora and Disney settlements) and in several other US states, but no EU law currently requires honoring it. EU regulators have discussed browser-level consent signals for years; nothing is in force as of mid-2026.

What are the CCPA fines in 2026?

The inflation-adjusted figures, set by the CPPA effective January 1, 2025 and applying through 2026, are $2,663 per violation and $7,988 per intentional violation or violations involving consumers under 16. Statutory damages for data breaches run $107–$799 per consumer per incident. Because violations are typically counted per consumer, totals escalate quickly — GM's 2026 settlement reached $12.75 million.

Does closing a cookie banner count as consent?

No — under either law. GDPR consent requires an affirmative act, and the EU's top court ruled out inferred consent back in 2019 (Planet49). California caught up on January 1, 2026: the updated regulations state that closing a popup without affirmatively selecting an option is not consent, and choices obtained through dark patterns are void.

Does the CCPA apply to companies outside California?

Yes, if you "do business in California" — read broadly to include serving California consumers remotely — and meet a threshold: $26,625,000+ in annual gross revenue, data on 100,000+ California consumers/households, or 50%+ of revenue from selling or sharing personal info. Sephora is headquartered in France; it still paid $1.2 million.

References

  1. EUR-Lex, "Regulation (EU) 2016/679 (GDPR)": eur-lex.europa.eu
  2. EUR-Lex, "Directive 2002/58/EC (ePrivacy Directive)": eur-lex.europa.eu
  3. California Privacy Protection Agency, "Announcement of Updated Monetary Thresholds (effective Jan. 1, 2025)": cppa.ca.gov
  4. California Privacy Protection Agency, "CPPA Announces Decision Requiring Honda to Pay $632,500 (Mar. 12, 2025)": cppa.ca.gov
  5. California Department of Justice, "Attorney General Bonta Announces $2.75 Million Settlement with Disney (Feb. 11, 2026)": oag.ca.gov
  6. California Department of Justice, "Attorney General Bonta, Partners Secure $12.75 Million General Motors Privacy Settlement (May 8, 2026)": oag.ca.gov
  7. California Department of Justice, "Attorney General Bonta Announces Settlement with Sephora (Aug. 24, 2022)": oag.ca.gov
  8. California Department of Justice, "Global Privacy Control (GPC)": oag.ca.gov
  9. Cornell Law School LII, "11 CCR § 7025 — Opt-Out Preference Signals": law.cornell.edu
  10. Greenberg Traurig LLP, "Revised and New CCPA Regulations Set to Take Effect on Jan. 1, 2026": gtlaw.com

Running one site for both Brussels and Burbank doesn't have to mean two consent stacks. Get started with CookieChimp and ship a banner that handles both regimes from day one.

The content of this article is provided for information purposes only and does not constitute legal or other advice.