ConsentPixel – Privacy · Verified

CIPA & Legal Risk

CIPA vs GDPR vs CCPA — What's the Difference and Which Applies to Your Site?

CIPA vs GDPR vs CCPA — What's the Difference and Which Applies to Your Site?

Three privacy laws, three completely different triggers, three different ways to get sued. Here's how CIPA, CCPA/CPRA, and GDPR actually differ — and the uncomfortable answer to which ones apply to your website.

By the ConsentPixel — Privacy · Verified team Updated June 2026 15 min read
$5,000
Statutory damages per CIPA violation — no proof of harm required
€20M / 4%
GDPR top-tier fine ceiling, or 4% of global turnover — whichever is higher
3
Different applicability triggers you have to check separately

If you run a website, you've probably been told you need to "be compliant" — and then handed a single cookie banner as if that settles it. It doesn't. CIPA, the CCPA (as amended by the CPRA), and the GDPR are three fundamentally different laws with three different theories of harm, three different ways they decide whether they apply to you, and three very different penalty structures. A setup that satisfies one can leave you fully exposed under another.

This guide breaks down what each law is, how they differ in plain terms, and walks you through the actual question on your mind: which of these apply to your site? The answer for most US eCommerce and content sites is uncomfortable — often, all three at once.

The short version

If you only read one section, read this one:

  • GDPR is a European law about how you process personal data. It applies the moment you offer goods or services to, or monitor the behaviour of, people in the EU/EEA — regardless of where your company sits.
  • CCPA/CPRA is a California law about consumer rights over their personal information (knowing, deleting, opting out of sale/share). It applies to for-profit businesses that hit one of three size thresholds and do business in California.
  • CIPA is a 1967 California anti-wiretapping statute, repurposed since 2022 to attack website trackers as illegal "interception" of communications. It has no size threshold — it can reach almost any site a Californian can load, and it carries a $5,000-per-violation private right of action.

The trap: CCPA has a size threshold, so small businesses often assume they're safe. CIPA has no such threshold — and it's the one driving the current wave of demand letters against businesses of every size.

The mental model

GDPR governs processing. CCPA governs consumer rights. CIPA governs interception. They overlap on cookies and trackers, but each asks a different legal question — which is exactly why a single banner rarely answers all three.

What each law actually is

GDPR — the EU's comprehensive data-protection regime

The General Data Protection Regulation took effect in May 2018 and is the broadest of the three. It governs the entire lifecycle of personal data: collection, storage, use, sharing, and deletion. Its consent standard is strict — consent must be freely given, specific, informed, and unambiguous, which in practice means no pre-ticked boxes and no tracking before the user actively opts in.

Crucially for US businesses, the GDPR's reach doesn't stop at Europe's borders. Article 3 establishes its territorial scope and makes clear that the location of your company doesn't determine applicability. If your business collects, stores, or processes data belonging to people in the EU, the GDPR applies regardless of where your servers are located or whether you have a single employee on European soil.

CCPA/CPRA — California's consumer-rights framework

The California Consumer Privacy Act took effect in 2020 and was substantially expanded by the California Privacy Rights Act (CPRA), which generally took effect in 2023. Together they give California residents rights to know what personal information a business collects, to delete it, to correct it, and to opt out of its sale or sharing. It's a rights-and-disclosure framework, not a wiretapping law.

It only applies to businesses that meet a size threshold (more on that below), and it's enforced by the California Attorney General and the California Privacy Protection Agency, plus a limited private right of action for certain data breaches.

CIPA — the 1967 wiretap statute that became a website problem

Passed in 1967 to address wiretapping and unauthorized surveillance, CIPA was never intended to regulate today's digital ecosystem. At its core, it prohibits the unauthorized interception, recording, or disclosure of communications, and creates both criminal liability and a private right of action with statutory damages of up to $5,000 per violation.

Since a landmark 2022 ruling, plaintiffs' firms have reinterpreted that old language to target modern web technology. Plaintiffs claim tools like pixels, session replay, chat widgets, and search bars intercept or "read" user communications and share data with third parties without valid consent. The result has been a flood of litigation. Since 2022, plaintiffs' firms have filed an estimated 50,000 to 100,000 or more claims under the statute.

CIPA vs CCPA vs GDPR at a glance

Here's the side-by-side that most "compliance checklists" skip:

 CIPACCPA / CPRAGDPR
OriginCalifornia, 1967 (wiretapping)California, 2020 / 2023European Union, 2018
Core concernUnauthorized interception of communicationsConsumer rights over personal infoLawful processing of personal data
Who it protectsPeople in CaliforniaCalifornia residentsPeople in the EU/EEA
Size thresholdNone — applies broadlyYes — revenue / volume testsNone — applies to any qualifying processing
Who can suePrivate individuals (class actions)AG & CPPA; limited private rightSupervisory authorities; data subjects
Penalty$5,000 per violation, no harm neededUp to ~$2,663 / ~$7,988 admin; $107–$799 per consumer (breach)Up to €20M or 4% of global turnover
Consent modelPrior consent before interceptionOpt-out of sale/share (+ opt-in for minors)Opt-in: freely given, specific, informed

The single most important row is "size threshold." It's the one that determines whether you can breathe easy — and for CIPA and GDPR, the answer is usually no.

Who can sue you — and for how much

The penalty structures explain why these laws feel so different in practice, even though they all touch the same cookie banner.

CIPA $5,000 per violation Private lawsuits (class actions) No proof of harm No size threshold Each session may count CCPA / CPRA $2,663–7,988 admin fine / violation AG & CPPA enforce limited private right $107–$799 per consumer (data breach actions) Size threshold applies GDPR €20M or 4% global turnover EU regulators + data subject claims Whichever is higher Lower tier: €10M / 2% Reaches non-EU firms
Three penalty structures. CIPA's private right of action with no harm requirement is what makes it the dominant litigation driver in 2026.

The reason CIPA dominates demand-letter activity is structural. A single website that serves California consumers — and most consumer-facing US websites do — can face $5,000 per violation, with each user session potentially counted separately. Because the damages are available even without proof of actual harm, a plaintiff doesn't need to show they were injured — only that a tracker fired before consent. CCPA and GDPR, by contrast, are primarily regulator-enforced, which means fewer but potentially larger actions.

Which laws apply to your site

This is the question that matters. Work through each law's trigger separately — they don't move together.

Does GDPR apply?

Ask: do you offer goods or services to people in the EU/EEA, or monitor their behaviour (analytics, ad retargeting, tracking)? If you ship to Europe, accept European customers, or run analytics that capture EU visitors, the answer is very likely yes — even with no EU office. There's no revenue threshold; the trigger is the activity.

Does CCPA/CPRA apply?

This one has a size gate. The law generally applies to for-profit businesses that meet at least one of three thresholds: annual gross revenue above the inflation-adjusted baseline (raised to $26,625,000 as of 2025); buying, selling, or sharing the personal information of 100,000 or more California consumers or households in a year; or deriving 50% or more of annual revenue from selling or sharing personal information. Note that the revenue threshold typically refers to total global gross revenue, not revenue earned in California.

Does CIPA apply?

Here's the uncomfortable part. CIPA has no size threshold at all. Companies operating websites accessible to California residents — essentially all websites — should anticipate continued and likely increased litigation. If your site uses third-party trackers and a Californian can load it, you're potentially in scope. Revenue, headcount, and EU activity are all irrelevant to whether CIPA reaches you.

Your website Any EU/EEA visitors, customers, or tracking? GDPR applies opt-in consent $26.6M+ revenue, OR 100k+ CA consumers, OR 50%+ from data sales? CCPA applies rights + opt-out Third-party trackers AND a Californian can load your site? CIPA applies no threshold to hide behind Most US eCommerce sites trigger all three at once. The branches are independent — check each one separately.
Each law has its own independent trigger. Qualifying under one says nothing about the others.

Why one banner doesn't cover all three

Here's where most businesses go wrong. They install a generic cookie banner, see it pop up, and assume the box is checked for "privacy." But the three laws demand different things from that banner:

  • GDPR wants opt-in. Nothing non-essential should load until the visitor affirmatively agrees. A banner that tracks on page load already fails.
  • CCPA wants opt-out plus rights. Californians need a clear way to opt out of sale/sharing, honour Global Privacy Control signals, and see confirmation their choice was processed — a different mechanism from GDPR's opt-in.
  • CIPA wants no interception before consent. This is the strict one. If a tracker fires before consent, the banner's mere presence is irrelevant — interception arguably already happened.

The common failure across all three is the same: banners that display a consent UI while trackers run in the background anyway. A cosmetic banner that doesn't actually block scripts satisfies none of these laws — it just creates a paper trail showing you knew consent was required and collected data before getting it.

The core distinction

There's a difference between a banner that looks compliant and one that blocks scripts before consent. CIPA in particular doesn't care what your banner says — it cares whether interception happened before the visitor agreed. Cosmetic compliance is the exposure; true script blocking is the fix.

The CIPA trap most US sites miss

Many US businesses reason like this: "We're under the CCPA revenue threshold, and we don't really sell to Europe, so we're fine." That reasoning fails precisely because CIPA doesn't work like the other two.

CIPA's danger is the combination of three features: no size threshold, a private right of action (so any individual's lawyer can sue, not just a regulator), and statutory damages with no harm requirement. And there's no relief on the horizon. The most recent legislative fix, SB 690, did not pass during the 2025 session despite strong support, passing the California Senate 33-0. While it is likely to be reintroduced, it will likely not take effect until January 1, 2027 — giving potential litigants a clear deadline to file all the claims they can. Until something passes, businesses should assume current CIPA interpretations continue to apply to their websites.

In other words: the law most likely to generate a demand letter against a small or mid-sized US site is the one those sites most often assume doesn't apply to them.

What to actually do about it

The good news is that one technical approach addresses the common core of all three laws. Because every one of them ultimately turns on whether data was collected before valid consent, the fix is the same foundation:

  • Block scripts before consent — genuinely. Non-essential trackers, pixels, analytics, session replay, and chat tools should not execute until the visitor has made a choice. This is the single most important control for CIPA and the consent backbone for GDPR.
  • Offer symmetrical, region-aware choices. Opt-in framing for EU visitors, opt-out plus GPC handling for California, with equal-weight accept/decline either way.
  • Confirm and honour signals. Detect Global Privacy Control, process opt-outs, and show visible confirmation — now expected under California's 2026 rules.
  • Keep verifiable consent records. If you're ever challenged, you need evidence of what fired, when, and what the visitor chose — not just a screenshot of a banner.
  • Audit what's actually loading. You can't block what you haven't inventoried. Scan every cookie, pixel, tag, and third-party script on the site.

Notice that none of these is "install a banner." A banner is the visible surface; the compliance actually lives in whether scripts are blocked and consent is recorded. Get that foundation right and you've addressed the shared core of all three laws at once — then layer the region-specific wording on top.

The bottom line

CIPA, CCPA/CPRA, and GDPR aren't three versions of the same rule — they're three different laws asking three different questions about the same trackers on your site. GDPR governs how you process EU data, CCPA governs Californians' rights over their information, and CIPA treats pre-consent trackers as illegal interception with $5,000-per-violation exposure and no size threshold to hide behind. Most US sites trigger all three. The unifying fix isn't a prettier banner — it's genuinely blocking scripts until consent, honouring signals, and keeping verifiable records. That foundation is what turns "we have a banner" into "we're actually defensible."

Frequently asked questions

What's the main difference between CIPA, CCPA, and GDPR?

They regulate different things. GDPR is an EU law governing how personal data is processed and requires opt-in consent. CCPA/CPRA is a California law giving residents rights over their personal information, including opting out of data sales. CIPA is a 1967 California anti-wiretapping statute now used to treat website trackers as illegal interception, carrying $5,000 in statutory damages per violation.

Does GDPR apply to a US website?

Yes, if the site offers goods or services to people in the EU/EEA or monitors their behaviour, such as through analytics or ad tracking. GDPR's territorial scope under Article 3 applies regardless of where the company or its servers are located, and there is no revenue threshold — the trigger is the activity, not the company's size.

My business is small — am I exempt from these laws?

Possibly from CCPA, which has size thresholds (roughly $26.6M revenue, 100,000+ California consumers, or 50%+ revenue from data sales). But CIPA has no size threshold and GDPR's trigger is activity-based, not size-based. A small US site using third-party trackers that a Californian can load is potentially exposed to CIPA regardless of revenue.

How much can a CIPA violation cost?

CIPA provides statutory damages of $5,000 per violation (or three times actual damages, whichever is greater), available without proof of actual harm. Because each user session can potentially be counted as a separate violation, exposure scales quickly. This per-violation structure with a private right of action is what makes CIPA the dominant driver of privacy demand letters in 2026.

Will one cookie banner make me compliant with all three?

Rarely. GDPR requires opt-in (no tracking before consent), CCPA requires opt-out and rights mechanisms plus GPC handling, and CIPA requires that no interception occur before consent. A cosmetic banner that displays a consent UI while trackers run in the background satisfies none of them. The shared fix is genuinely blocking scripts before consent, then layering region-specific wording on top.

Is SB 690 going to fix the CIPA problem?

Not yet. SB 690, which would have created a safe harbour for certain common website uses, passed the California Senate 33-0 but stalled in the Assembly during the 2025 session. If reintroduced and passed, it likely would not take effect before January 1, 2027. Until then, businesses should assume current CIPA interpretations continue to apply. This article is informational, not legal advice.

Compliant for all three — from one pixel

ConsentPixel — Privacy · Verified blocks trackers before consent, handles region-aware opt-in/opt-out, honours GPC, and keeps verifiable consent records. Real script blocking, not a cosmetic banner.

Scan my site free
ConsentPixel — Privacy · Verified
We build CIPA-first consent enforcement that blocks scripts rather than simulating consent. This article is informational and not legal advice — consult qualified counsel for your specific situation.
Scroll to Top