
GDPR and CCPA: What Actually Applies to a Growing US-Based Company
A 90-person company signs a new SaaS customer based in Germany, launches a marketing campaign that pulls in California leads, and nobody in the building has actually mapped which privacy law now applies to that customer data. This is a common gap. GDPR and CCPA get confused constantly, and the confusion usually runs in the same direction: leadership assumes company size determines whether either law applies, when in practice size is barely relevant to one of them and only partially relevant to the other.
Two Different Laws, Two Different Triggers
GDPR and CCPA are frequently discussed as if they're the same kind of requirement wearing two different acronyms. They're not. They're triggered by fundamentally different things, and understanding that difference is the fastest way to figure out which one, if either, actually reaches your company.
GDPR is activity-based. It applies based on whose data you process and what you're doing with it, regardless of your revenue, headcount, or where your company is incorporated. A five-person startup with EU customers can be fully subject to GDPR. A 500-person US company with zero EU users is not.
CCPA, and its 2023 amendment CPRA, is threshold-based. It applies to for-profit businesses that cross specific size or revenue lines and that handle California residents' personal information, regardless of whether your company has any connection to California beyond having customers, employees, or website visitors who live there.
Most growth-stage companies eventually cross one of these triggers without planning to. The question isn't whether privacy law is relevant to a 25 to 200 employee company. It's which specific law reached you first, and what it actually requires once it has.
Does GDPR Actually Apply to You?
GDPR's territorial scope is defined in Article 3 of the regulation, and it's broader than most US companies expect. It applies to any organization, anywhere in the world, that processes the personal data of people located in the EU when that processing relates to offering them goods or services, or to monitoring their behavior.
Two things matter in that sentence. First, "offering goods or services" requires an element of intent to reach EU consumers. A merely accessible website isn't enough on its own. Pricing in euros, marketing copy in German or French, shipping to EU addresses, or running ad campaigns targeted at EU countries are the kinds of signals that indicate you're intentionally offering to that market rather than just being reachable from it. Second, "monitoring behavior" covers things like tracking EU visitors across your site with analytics or advertising cookies, which catches companies that never intended to sell into the EU at all but that run standard marketing tech on a public website.
In practice, this means GDPR reaches a wider range of growth-stage US companies than most people assume: a SaaS company with a handful of EU customers, a services firm that hired an EU-based contractor whose data it processes, a company running EU-targeted ad campaigns to test a new market, or a business that interviews EU-based job candidates. None of these require any EU physical presence to trigger the law. If you don't have an EU establishment but you meet the Article 3 threshold, you're also required to appoint an EU-based representative under Article 27, which is a real compliance line item companies frequently miss because it doesn't come up in most US-focused compliance checklists.
Does CCPA/CPRA Actually Apply to You?
CCPA applies to a for-profit business that does business in California, collects California residents' personal information, and meets at least one of three thresholds set by the California Privacy Protection Agency (CPPA), the regulator created by the 2023 CPRA amendment:
| Threshold | What It Means |
|---|---|
| Revenue | Annual gross revenue over $26,625,000 (the original $25 million figure, adjusted for inflation for 2026) |
| Data volume | Buys, sells, or shares the personal information of 100,000 or more California consumers or households annually |
| Revenue mix | Derives 50% or more of annual revenue from selling or sharing consumers' personal information |
The revenue threshold catches the most attention, but the 100,000-consumer-or-household data volume threshold is the one that quietly catches growth-stage companies. It counts consumers and households together, not just paying customers, so a company running a moderately trafficked marketing website with analytics and ad pixels can cross 100,000 unique California visitors in a year well before it approaches $26 million in revenue. A company doesn't need to be large to trip this threshold. It needs a website with enough California traffic.
New CPPA regulations that took effect January 1, 2026 add further obligations for businesses the agency classifies as significant-risk: mandatory risk assessments and annual independent cybersecurity audits, with formal certification requirements to the CPPA phased in between 2028 and 2030 based on company revenue. If your company is anywhere near the CCPA thresholds today, that phase-in schedule is worth tracking now rather than in 2028, since the underlying risk-assessment and audit practices take real time to build.
The Other States You're Probably Not Tracking
California gets the attention because it moved first, but it's no longer the only state with a comprehensive consumer privacy law. As of early 2026, roughly 19 to 20 states have comprehensive privacy laws in effect, including newer entrants like Indiana, Kentucky, and Rhode Island, which took effect January 1, 2026. Estimates vary slightly by tracker depending on whether a law has been enacted versus already in effect, but the trend is consistent: this list has grown every year since Virginia's law took effect in 2023, and it shows no sign of leveling off.
The good news for a growth-stage company is that most of these state laws, including Virginia's, Colorado's, Connecticut's, and Utah's, share a common structural template: consumer rights to access, delete, and correct personal data; opt-out rights for targeted advertising and data sales; and requirements for data processing agreements with vendors. A privacy program built to a reasonably strict state's requirements, or to CCPA/CPRA's requirements, will cover most of what the others ask for with targeted adjustments rather than a separate program per state. The mistake to avoid is treating California as the only state that matters and discovering the gap only after a customer or employee in a different state files a rights request your team doesn't have a process to handle.
What Non-Compliance Actually Costs
The two laws are not close to each other in penalty structure, and that gap matters when you're deciding how much urgency to apply.
GDPR fines are tiered by severity. Lower-tier violations top out at €10 million or 2% of global annual turnover, whichever is greater. Upper-tier violations, covering core data protection principles and data subject rights, top out at €20 million or 4% of global annual turnover, whichever is greater. "Global annual turnover" means total company revenue, not EU-derived revenue, which is the detail that turns a modest EU customer base into meaningful financial exposure for a growing company.
CCPA penalties work differently. The CPPA and California Attorney General can pursue administrative and civil penalties of $2,663 per unintentional violation and $7,988 per intentional violation, figures set through the CPPA's required inflation adjustment and holding at that level through 2026. Those amounts are per violation, and each affected consumer record can constitute a separate violation, which is how CCPA enforcement actions reach seven figures against companies that treated the law as a low-priority line item. CCPA also creates a private right of action specifically for data breaches involving certain categories of personal information, letting affected consumers sue directly rather than waiting on regulatory enforcement, which is a distinct risk GDPR doesn't create in the same way.
Neither number needs to materialize for the exposure to be real. A signed data processing agreement your legal team never reviewed, a cookie consent banner that doesn't actually block tracking until consent is given, or a California consumer deletion request that sits unanswered past the required response window are the kinds of gaps that turn into the incidents that trigger these numbers.
Building a Program That Covers Both
The practical path for a growth-stage company isn't to build two separate compliance programs. It's to build one privacy program against the stricter of the two standards you're actually subject to, then layer in the specific items the other law requires that aren't already covered.
- Map your actual data footprint. Identify where EU residents' data enters your systems (customers, employees, contractors, site visitors) and separately count California consumers and households touched by your data collection, including marketing and analytics traffic, not just paying customers.
- Determine which laws you've actually triggered. Match your data footprint against GDPR's Article 3 activity test and CCPA/CPRA's three thresholds. Most companies are surprised by which one applies first.
- Build (or fix) your core mechanics. A working cookie/tracking consent mechanism, a documented process for responding to access, deletion, and correction requests within required timelines, and data processing agreements with every vendor that touches personal data are the foundation both laws require in some form.
- Close the CCPA-specific gaps. A "Do Not Sell or Share My Personal Information" mechanism, updated privacy notice disclosures, and, if you're approaching significant-risk status under the 2026 CPPA rules, a plan for risk assessments and independent audits.
- Close the GDPR-specific gaps. An EU representative if you have no EU establishment, a documented lawful basis for each category of processing, and breach notification procedures that meet the 72-hour reporting window.
- Review annually, not once. New state laws take effect nearly every January, thresholds adjust, and your own data footprint changes as the company grows. A program built once and never revisited is a program that quietly falls out of compliance.
Who Should Own This
This is squarely a fractional IT leadership function, not something to bolt onto an existing role as a side project. Your managed service provider keeps systems patched and users supported, which is necessary but isn't the same skill set as mapping data flows against two different legal frameworks, prioritizing which gaps carry the most exposure, and briefing leadership and the board on where the company actually stands. Most MSP contracts were never scoped to include that ownership, and privacy compliance without a clear owner tends to drift until an EU customer contract or a California rights request forces the issue.
A full-time privacy or compliance hire is one option, but for most companies in the 25 to 200 employee range it's a six-figure commitment for a workload that, once the program is built, doesn't require full-time attention year-round. Fractional technology leadership is built for exactly this gap: it works alongside your existing MSP, which keeps handling day-to-day infrastructure, while the fractional leader owns the data mapping, the gap-closing roadmap, and the ongoing review cadence that keeps the program current as laws and thresholds change.
Frequently Asked Questions
How much does it actually cost to build a GDPR/CCPA compliance program?
Cost varies with how much of the foundation already exists. A company starting from an unmanaged data footprint typically spends the most in year one on the data mapping exercise, consent mechanism implementation, and vendor data processing agreements. Costs drop substantially in year two once the mapping is done and the work shifts from building the program to maintaining and reviewing it annually.
Does our MSP already handle this for us?
Usually not fully. Your MSP keeps infrastructure running and handles day-to-day IT support, but most MSP contracts don't include mapping data flows against GDPR and state privacy law requirements, prioritizing compliance gaps, or briefing leadership on legal exposure. Fractional technology leadership is designed to work alongside your MSP to close that specific gap, not to replace what your MSP already does well.
We don't have any EU customers. Does GDPR still apply to us?
Possibly. GDPR applies based on activity, not intent to sell into the EU. If your website runs standard analytics or advertising tracking that reaches EU visitors, if you've hired an EU-based contractor, or if you interview EU-based job candidates, you may already be processing EU residents' data in a way that triggers GDPR even without a single EU sale.
We're well under $26 million in revenue. Are we safe from CCPA?
Not necessarily. The revenue threshold is only one of three ways to trigger CCPA. A company with meaningful California website traffic can cross the 100,000 consumer-or-household threshold well before it approaches the revenue threshold, since that count includes visitors and leads, not just paying customers.
What's the actual first step if we haven't mapped any of this yet?
Start with a data mapping exercise: where does personal data enter your systems, whose data is it, and what do you do with it. That mapping is the input every other decision, including which laws apply and what a realistic budget and timeline looks like, actually depends on.
How do the various state privacy laws differ from CCPA?
Most share a common structural template with consumer access, deletion, and correction rights, opt-out rights for targeted advertising, and vendor data processing agreement requirements. The differences tend to be in specific thresholds, enforcement mechanisms, and a handful of unique provisions per state, not in the fundamental rights they grant consumers. A program built to a reasonably strict standard covers most of what the others require with targeted adjustments.
Ready to Put This Into Practice?
Schedule a free consultation and let's talk through what this means for your organization specifically.
Schedule a Free Consultation