"Does this law apply to me?" is a different question from "what do I have to do about it?" Most compliance guides skip straight to the second question, consent banners, data subject rights, breach notification, without ever settling the first one. That order gets a lot of businesses stuck arguing about cookie banners and opt-out links for a law that never covered them in the first place.
GDPR and CCPA answer "who's covered" using two completely unrelated tests. One is about whose data you touch. The other is about how big your business is and how much data it moves. Knowing which test to run, and running it correctly, is the actual first step, before any policy gets written.
GDPR's test has nothing to do with company size
GDPR's territorial scope comes from Article 3, and it is built around data, not revenue. There are two ways to fall inside it.
Article 3(1) covers any organization established in the EU, full stop, regardless of where the actual data processing happens. A company headquartered in France that processes data on US servers is still squarely inside GDPR.
Article 3(2) is the one that catches US-only businesses off guard. If you're not established in the EU, GDPR still applies to your processing of an EU resident's personal data if you either offer goods or services to people in the EU, paid or free, or you monitor their behavior to the extent that behavior takes place in the EU. There's no revenue minimum written into the statute, no employee count, no minimum number of EU visitors. In principle, processing one EU resident's data under either of those two conditions is enough.
That said, "offering goods or services" means actually targeting an EU audience, not simply being reachable by one. European Data Protection Board guidance lists the kind of signals regulators look for: shipping or delivery options to EU countries, pricing displayed in euros, a country-code top-level domain like .de or .fr, marketing copy or ad campaigns aimed at an EU audience, EU phone numbers or addresses listed as contact points. A US blog that gets occasional organic traffic from Germany, with no EU shipping, no euro pricing, and no EU-directed marketing, is not "offering" anything to EU residents just because the site is on the public internet. "Monitoring behavior" is a separate trigger and covers things like ad-tech tracking, profiling, or analytics used to build behavioral profiles of visitors physically located in the EU, which is a lower bar than most businesses expect.
GDPR also splits obligations between two roles, and which one you occupy changes what "in scope" actually requires of you. A controller decides why and how personal data gets processed, the business collecting the data directly from EU visitors, in most of the scenarios above. A processor handles data on a controller's behalf, a cloud host, an email delivery service, a customer support platform, and its GDPR obligations run mostly through a data processing agreement with the controller rather than directly to the data subject. A US company that only processes data on behalf of an EU client, without ever deciding why that data is collected, is still in scope, but the compliance shape looks different: a signed processing agreement and appropriate security measures, rather than a full public-facing privacy policy rewrite.
CCPA/CPRA's test is entirely about size and data volume
CCPA, as amended by the CPRA, works the opposite way. Under Cal. Civ. Code 1798.140, a "business" is covered if it does business in California, is organized for profit, and meets at least one of three thresholds:
- Annual gross revenue over $26,625,000 (the original $25 million figure, adjusted for inflation by the California Privacy Protection Agency every two years, currently effective since January 1, 2025).
- Buys, sells, or shares the personal information of 100,000 or more California consumers or households in a calendar year.
- Derives 50% or more of annual revenue from selling or sharing California consumers' personal information.
Notice what's absent from that list: nothing about where your customers live, nothing about whether you're a big company nationally, just California-connected business activity plus one of three numeric floors. A business with $200 million in revenue but zero California customers and no data collection there isn't "doing business in California" in the way the statute means, and falls outside CCPA entirely.
The "organized for profit" requirement also matters more than people assume. Genuine nonprofits generally don't meet CCPA's definition of "business" at all, since the statute requires an entity operated for the profit or financial benefit of its shareholders or owners. A handful of narrow exceptions exist, a nonprofit running a for-profit subsidiary, or in a joint venture with a covered business, but a standard donation-and-newsletter nonprofit sits outside CCPA's scope by default.
The thresholds are also worth rechecking on a schedule, not just once at launch. Revenue and data-volume figures move year to year, and a business that comfortably sat below all three CCPA thresholds in one fiscal year can cross the line in the next simply through normal growth, without any change in how it actually operates. The $26.6 million figure itself isn't fixed either: the CPPA adjusts it for inflation every two years, on odd-numbered years, so the exact number to check against shifts over time even if your own revenue doesn't. Treat the applicability question as something to revisit annually alongside your other compliance reviews, not a box checked once and forgotten.
The two tests, side by side
GDPR vs CCPA: how each law decides who is covered
| GDPR | CCPA / CPRA | |
|---|---|---|
| What triggers coverage | Processing an EU resident's data | Size and data-volume thresholds |
| Revenue minimum | None | $26.6M annual gross revenue |
| Data-volume minimum | None, one EU data subject can qualify | 100,000+ CA consumers or households |
| Business type covered | Any controller or processor | For-profit businesses only |
| Nonprofits | Covered like any other controller | Generally excluded |
| Where you're based | Irrelevant if you target EU residents | Must be doing business in California |
What this looks like for three real businesses
A twelve-person SaaS startup doing $2 million in annual revenue, with a free trial that's picked up a few dozen sign-ups from Germany and the Netherlands, is nowhere close to any CCPA threshold. But GDPR's targeting test doesn't care about revenue: if the trial's marketing or product actively serves those EU sign-ups, that processing is in scope.
A US-only e-commerce brand doing $40 million a year, shipping exclusively within the US, with no EU marketing or currency options, sits outside GDPR's reach but comfortably clears the CCPA revenue threshold if it has California customers.
A free, ad-supported content site with modest revenue but 150,000 monthly California readers, and an ad stack that shares visitor data with ad networks, trips CCPA's data-volume prong even though its revenue is far below $26.6 million. Revenue isn't the only door in.
The three CCPA/CPRA thresholds, and GDPR's lack of one
If you land inside one, both, or neither
A lot of businesses end up inside exactly one of these laws rather than both, and the practical next step is different depending on which one it is. If GDPR applies, the priority is a documented lawful basis for the processing that put you in scope and a policy that spells out EU data subject rights. If CCPA applies, the priority is the notice-at-collection and opt-out mechanics the statute requires at the point of data collection, not just in a policy nobody reads. If neither test is met today, it's still worth building a policy that names your actual data practices accurately, since thresholds and traffic sources change, and an inaccurate policy is its own liability regardless of which law technically governs it.
Our Privacy Policy Generator lets you select which jurisdictions your business operates in and builds the applicable GDPR and CCPA/CPRA clauses accordingly, so you're not guessing which disclosures a given law actually requires once you've confirmed you're in scope. If you're specifically weighing consent-banner mechanics rather than applicability, see our companion guide on GDPR vs CCPA cookie consent requirements. For a closer look at how many businesses actually clear the CCPA thresholds, see how many businesses must comply with the CCPA.
The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.