How does the California privacy law differ from the GDPR?
The GDPR asks for a lawful basis before processing starts; California lets processing start and gives the consumer the right to stop sale, sharing and certain uses afterwards. The compliance work is therefore ordered differently, not simply lighter.
The answer differs between the federal level and the states, see the rows below.
The answer by level
California
California builds on an opt-out model: processing may start, and the consumer may then stop sale, sharing and certain uses of sensitive personal information.
Cal. Civ. Code § 1798.100 et seq.European Union
The GDPR requires a lawful basis before processing begins, and consent is only one of the six bases in Article 6.
Federal level
At federal level the FTC does not set a lawful basis, but acts against unfair or deceptive practices, which includes a privacy promise the company does not keep.
15 U.S.C. § 45
Source lines
- The GDPR requires a lawful basis under Article 6 before processing begins, with consent as only one of six.
- California builds on notice at collection plus a right to opt out of sale and sharing and to limit the use of sensitive personal information.
- The FTC can treat a broken privacy promise as a deceptive practice under Section 5, which is the closest federal analogue to a supervisory authority.
What it means for the company
A GDPR programme transfers well on data mapping and security, but not on lawful basis, because California asks instead for correct notice and working opt-out paths.
| Level | Requirement | Source |
|---|---|---|
| California | California builds on an opt-out model: processing may start, and the consumer may then stop sale, sharing and certain uses of sensitive personal information. | Cal. Civ. Code § 1798.100 et seq. |
| European Union | The GDPR requires a lawful basis before processing begins, and consent is only one of the six bases in Article 6. | — |
| Federal level | At federal level the FTC does not set a lawful basis, but acts against unfair or deceptive practices, which includes a privacy promise the company does not keep. | 15 U.S.C. § 45 |
What it means for the individual
In the EU you may object before processing; in California you act after, by exercising the opt-out and deletion rights.
Source lines
- California Consumer Privacy Act, as amended by the CPRACal. Civ. Code § 1798.100 et seq. · read 2026-08-25 · proof f58d6c0cbe8470d3
- Virginia consumer data privacy actVa. Code §§ 59.1-575 to 59.1-585 · read 2026-08-25 · proof f58d6c0cbe8470d3
- FTC Act Section 5, unfair or deceptive practices in AI and data15 U.S.C. § 45 · read 2026-08-25 · proof f58d6c0cbe8470d3
Next step
Map your Article 6 bases against the California notice and opt-out duties, and close the gaps where a basis has no equivalent obligation.
This page reports what the sources say, with the identifier and address of the publisher. It is not legal advice and does not decide an individual matter.
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.