The Wire
Two Laws, Two Continents, One Problem
The General Data Protection Regulation (May 2018) and the California Consumer Privacy Act (January 2020) — the rights each established, the obligations each imposed on organisations holding personal data, and what each said about consent.

Two statutes, 2018 and 2020, both drafted with the third-party cookie in view.
The GDPR and the CCPA each rewrote the terms on which personal data could be held and used — from opposite sides of the Atlantic, with different architectures but the same fundamental pressure.
Rights and Obligations
The General Data Protection Regulation became applicable across European Union member states on 25 May 2018, replacing the 1995 Data Protection Directive and imposing a single compliance standard on any organisation that processed the personal data of EU residents, regardless of where that organisation was incorporated. Its jurisdictional reach was deliberately extraterritorial: a company based in Conway, Arkansas, or Downers Grove, Illinois, was subject to the regulation if it offered goods or services to individuals in the EU or monitored their behaviour online.

Navigator, 1994.
Photo: Ruben Boekeloo / Pexels
The GDPR established a set of named individual rights: the right to access data held about oneself, the right to rectification of inaccurate records, the right to erasure (widely called the "right to be forgotten"), the right to data portability, and the right to object to processing. It further required that consent to data processing be freely given, specific, informed, and unambiguous — meaning that pre-ticked boxes and bundled consent no longer satisfied the standard. Organisations were required to appoint a Data Protection Officer where processing was carried out at scale, to conduct Data Protection Impact Assessments for high-risk activities, and to notify supervisory authorities of a data breach within seventy-two hours of becoming aware of it. Maximum penalties ↗ reached €20 million or four percent of global annual turnover, whichever figure was higher.

A few bytes handed back on the next request, written in 1994 to hold a shopping basket together.
Photo: Wikidata for Digital Preservation - custom-built Wikidata interface with Netscape Navigator item Q235419 · Wikimedia Commons
The California Consumer Privacy Act, operative from 1 January 2020 and subsequently strengthened by the California Privacy Rights Act ballot measure of November 2020, took a structurally different approach. Where the GDPR was built on a lawful-basis framework requiring a positive justification for each processing activity, the CCPA was built around a disclosure-and-opt-out model. California residents gained the right to know what categories of personal information a business collected, the right to know whether that information was sold or disclosed and to whom, the right to opt out of the sale of their personal information, the right to deletion, and the right to non-discrimination — meaning a business could not penalise a consumer for exercising any of these rights.
The CCPA applied to for-profit businesses meeting at least one of three thresholds: annual gross revenues exceeding twenty-five million dollars; annual purchase, receipt, or sale of the personal information of one hundred thousand or more consumers or households; or derivation of fifty percent or more of annual revenue from selling consumers' personal information. Enforcement sat with the California Attorney General; the California Privacy Rights Act of 2020 ↗ additionally created the California Privacy Protection Agency as a dedicated regulatory body.
A Structural Divergence
The two statutes converged on purpose — constraining the accumulation and trade of personal data that the cookie, the data warehouse, and the behavioural-targeting industry had made routine — but diverged sharply in legal architecture. The GDPR established consent and five alternative lawful bases for processing: contract, legal obligation, vital interests, public task, and legitimate interests. The CCPA imposed no equivalent requirement to justify collection; it required instead that collection be disclosed and that consumers be given a meaningful exit. The phrase "Do Not Sell My Personal Information" became a required link on covered websites under the California statute, a mechanism with no direct GDPR parallel.
The direct-marketing industry encountered both laws simultaneously during the same operational period. An Acxiom or Experian managing data at scale faced GDPR obligations in European markets and CCPA obligations for California residents, often administered through different compliance teams applying different standards to the same underlying data infrastructure. The effect was not harmonisation but a layered compliance burden, reflecting the fact that two legislative bodies had arrived independently at the same problem and solved it with different tools.