Compliance guide
Which Privacy Laws Apply to My Website?
GDPR, CCPA, and CalOPPA can all apply to the same US-based website at once — because these laws are triggered by where your visitors are, not where you are. Here's exactly which laws cover you and what each one requires.
- The four main laws
- Which apply to you
- GDPR vs CCPA: key differences
- One policy for all three
- Generate yours free
- FAQ
The four main privacy laws for website operators
Most websites that collect any personal data fall under at least one — and often two or three — of the following frameworks simultaneously.
| Law | Jurisdiction | Who it covers | Size threshold |
|---|---|---|---|
| GDPR | EU & UK | Any organization processing personal data of EU/UK residents, regardless of where the organization is based | None. A one-person side project with EU visitors is covered if it processes their personal data. |
| CalOPPA | California (US) | Any operator of a commercial website or online service that collects personal information from California residents | None. "Commercial" is interpreted broadly — free tools with any commercial intent qualify. Applies to out-of-state operators. |
| CCPA / CPRA | California (US) | For-profit businesses that serve California residents and meet at least one size threshold | Must meet one of: $25M+ annual revenue; personal data on 100,000+ consumers; or 50%+ revenue from selling personal data. Most small sites don't qualify — but CalOPPA still applies to them. |
| COPPA | US federal | Any website or online service that knowingly collects data from children under 13 | None. Requires a privacy policy plus verifiable parental consent before collecting data from under-13 users. Triggered by audience, not site size. |
The single most important thing to understand about this table: every law above is triggered by your visitors' location or age, not yours. A US developer with zero EU customers still owes GDPR obligations for EU visitors who land on their site. CalOPPA applies to a developer in any US state — or any country — whose site reaches California residents.
Which laws apply to your website
Work through this in order. Multiple laws can — and usually do — apply at once.
- Is your site publicly accessible? If yes, EU and UK residents can visit it. Proceed to GDPR check.
- Does your site collect any personal data from those visitors? This includes IP addresses (logged by virtually every host), analytics cookies, contact form submissions, or any third-party script. If yes, GDPR applies.
- Is your site publicly accessible to US visitors? If yes, California residents can visit it — even if you have no California presence. CalOPPA applies to any commercial site (including free tools) that collects California residents' personal data.
- Is your business for-profit and does it meet a CCPA threshold? (≥$25M revenue, data on ≥100k consumers, or ≥50% revenue from data sales.) If yes, CCPA/CPRA also applies on top of CalOPPA, adding opt-out rights and additional disclosure requirements.
- Does your site target or knowingly attract children under 13? If yes, COPPA applies — and collecting any data without verifiable parental consent is prohibited, regardless of your privacy policy.
For a typical public-facing website — a SaaS app, a portfolio, a free tool, a newsletter landing page — the result is almost always: GDPR applies (EU visitors + analytics = personal data processing) and CalOPPA applies (California visitors + same data collection = CalOPPA trigger). CCPA applies if the business meets a size threshold. All three require a privacy policy. None of them care that your server is in the US.
GDPR vs CCPA: the key differences that affect your policy
Both laws give residents rights over their personal data. But they differ in important ways that change what your privacy policy must say.
| Requirement | GDPR | CCPA / CPRA |
|---|---|---|
| Lawful basis for processing | Required for each category of processing. The six bases are: consent, contract, legal obligation, vital interests, public task, and legitimate interests. You must state which applies. | Not required. CCPA is opt-out rather than opt-in: you may process data unless the consumer opts out of selling or sharing. |
| "Selling" personal data | No specific "selling" concept. Sharing with processors under a DPA is permitted; sharing with third parties for their own use requires consent or another lawful basis. | CCPA defines "selling" broadly — including sharing for cross-context behavioral advertising (retargeting pixels, ad networks). If you run ads, you likely "sell" data under CCPA and must disclose it with a "Do Not Sell or Share My Personal Information" opt-out link. |
| Breach notification | Controllers must notify their supervisory authority within 72 hours of discovering a breach affecting personal data. | No specific CCPA breach notification timeline; California's separate breach notification law (Cal. Civ. Code §1798.82) governs and has a "expedient time" standard. |
| Data subject rights | Access, correction, deletion, portability, restriction, and objection (to legitimate-interest processing). Must respond within 30 days. | Know (access), correct, delete, and opt out of data selling/sharing. Must respond within 45 days. |
| Fines | Up to €20M or 4% of global annual turnover, whichever is higher. Supervisory authorities (ICO, CNIL, BfDI, etc.) enforce per country. | $2,500 per violation (unintentional), $7,500 per intentional violation. Enforced by the California AG and the California Privacy Protection Agency (CPPA). |
One privacy policy can cover all three laws
You don't need separate policies for GDPR, CalOPPA, and CCPA. A single document satisfies all three if it addresses each framework's required disclosures.
The practical approach — used by most well-drafted policies — is a general section covering the core disclosures that all laws require (what you collect, why, who you share it with, how long you keep it, how users can contact you), followed by jurisdiction-specific addenda:
- GDPR addendum States the lawful basis for each category of processing (e.g., analytics = legitimate interests; marketing email = consent). Identifies the data controller. Describes EU/UK residents' rights and how to exercise them.
- CCPA / CPRA addendum Lists the categories of personal information collected, sold, or shared. Explains how California residents can submit requests to know, delete, correct, and opt out. If you run advertising pixels, adds the "Do Not Sell or Share My Personal Information" disclosure.
- CalOPPA minimum Already satisfied by the general section — CalOPPA requires that you have a policy, that it's conspicuously linked (footer of every page), and that it includes a "Last updated" date. It adds no disclosures beyond what GDPR and CCPA already require.
GDPR is the most demanding of the three frameworks — writing to its standard and adding the CCPA-specific disclosures covers all three laws in one document. That's exactly how ComplyKit structures the output when you select multiple regions.
Generate a compliant policy for all three laws
ComplyKit's questionnaire asks which regions your site serves, what data you collect, and which third-party services you use. Toggle on EU/UK, California, and US, and the output includes all required GDPR disclosures (lawful basis table, data controller identification, subject rights) and CCPA/CPRA-specific sections (categories of data sold/shared, opt-out disclosure) — in a single document, entirely in your browser.
For most indie apps, side projects, and small business sites, the output covers what regulators and automated scanners expect to see. For complex situations — sensitive data categories, regulated industries, multiple EU entities — have a lawyer review before you publish.
Generate my privacy policy free →
Frequently asked questions
Do I need to comply with GDPR if I'm a US company?
Yes, if you have EU or UK visitors. GDPR applies based on where your visitors are, not where your company is. The law explicitly covers businesses outside the EU that offer goods or services to, or monitor the behavior of, EU residents. A US developer with a publicly accessible site using Google Analytics is collecting personal data (IP addresses) from EU visitors and owes GDPR obligations for that traffic — regardless of having no EU office, no EU employees, and no deliberate intent to target Europe.
What is the difference between GDPR and CCPA?
GDPR (EU) applies to any organization processing EU residents' data, with no size threshold, and requires a lawful basis for each category of processing. CCPA applies to for-profit California businesses above a size threshold ($25M revenue, 100k consumers, or 50% of revenue from data sales); most small sites don't meet CCPA thresholds but are still covered by CalOPPA. Both give residents rights to access, correct, and delete their data. GDPR additionally requires a formal legal basis for processing and gives residents the right to object — an obligation CCPA does not impose.
Does CalOPPA apply to me if I'm not in California?
Yes, if your site is accessible to California residents — which any public website is. CalOPPA applies to any operator of a commercial website that collects personal information from California residents, regardless of where the operator is located. It has no size or revenue threshold. The California AG has used it against out-of-state operators. The practical test: is your site publicly accessible and does it collect any personal data from California visitors? If yes, CalOPPA applies.
Which privacy law is strictest — GDPR, CCPA, or CalOPPA?
GDPR is the most demanding: it requires a lawful basis for every category of processing, mandates data minimization, imposes a 72-hour breach notification deadline, and carries fines of up to 4% of global revenue. A GDPR-compliant policy also satisfies CalOPPA. Adding the CCPA-specific disclosures — categories of data sold or shared, opt-out instructions — gives you a single document that covers all three laws.
My website is a side project — does GDPR really apply?
GDPR has no size threshold, revenue floor, or side-project exemption. The single trigger is whether you process personal data of EU residents. If your site is publicly accessible and uses analytics, has a contact form, or runs third-party scripts (almost all sites do), you are processing personal data. An IP address alone is personal data under GDPR. The only genuine exception is a completely static page with no analytics, no forms, no third-party scripts, and no server logging — which describes almost no real websites.
What is the difference between CCPA and CPRA?
CPRA is the 2023 amendment that expanded CCPA. It added a "sensitive personal information" category (SSN, health data, race, sexual orientation, precise geolocation) with additional restrictions, created the California Privacy Protection Agency (CPPA) as an enforcement body, and added a right to correct inaccurate data. For privacy policy purposes: CPRA added the sensitive-data disclosures. Most sites already covered by CCPA are automatically subject to CPRA — the thresholds are the same.
Do I need separate privacy policies for GDPR and CCPA?
No. A single policy with a general section and jurisdiction-specific addenda satisfies all three frameworks. Structure it with the core disclosures (what you collect, why, who you share with, retention periods, contact information) plus a GDPR section (lawful basis per processing category, subject rights, controller identification) and a CCPA/CPRA section (categories of data sold or shared, opt-out instructions). ComplyKit generates a combined document structured this way when you select multiple regions.
What if my policy only covers one law but I'm covered by multiple?
You're compliant with the law you addressed and non-compliant with the others. Regulators enforce their own law independently: the California AG doesn't credit your thorough GDPR section, and an EU supervisory authority doesn't credit your CCPA disclosures. Automated demand-letter tools also check for specific disclosures by law — a "Do Not Sell or Share" link for CCPA, a "Data Controller" identification for GDPR — and flag their absence regardless of what else your policy says. A combined policy that addresses each framework's required disclosures is the right approach.
Also in the Copper Bay Labs ship-safety suite
Privacy compliance is one of several things to audit before you ship. These free tools cover security, accessibility, and exposed secrets:
Checks your live site for accessibility and privacy-law gaps that attract ADA demand letters.
Secret scanning LeakCheckPaste code or a config file and see exposed API keys and tokens flagged before they reach the repo.
Security headers HardenCheckScan your live site's HTTP headers for missing CSP, HSTS, and other security hardening flags.
Post-deploy ExposureCheckScan your live URL for exposed .env files, .git directories, and bundled secrets.