Home / Privacy & Compliance / GDPR and CCPA for Markete...

Privacy & Compliance

GDPR and CCPA for Marketers: A Plain-English Compliance Checklist

September 06, 2026 · 11 min read
A marketer working through a plain-English privacy compliance checklist covering GDPR opt-in and CCPA opt-out requirements

Privacy law has a branding problem with marketers: it reads as a wall of acronyms and legalese written to be ignored until a lawyer forces the issue. So most marketing teams do exactly that — ignore it, hope the cookie banner someone installed in 2021 is enough, and quietly assume the rules are somebody else's job. That's a genuinely risky bet in 2026, and it's an unnecessary one, because underneath the acronyms these laws are far more understandable than they look.

Here's the whole thing in one sentence before we go deeper: GDPR makes you ask permission first; CCPA lets you collect but makes you offer an easy way out. Almost everything else — the banners, the notices, the rights requests, the vendor contracts — flows from that one difference. This is the plain-English version: what these laws actually require of a marketer, who they apply to, and a practical checklist you can work through without a law degree.

This is general guidance for marketers, not legal advice. Privacy law is complex, varies by jurisdiction, and changes often — for your specific obligations and exposure, consult a qualified privacy professional or lawyer.

The one distinction that explains everything

If you remember nothing else, remember this: the two laws are built on opposite default settings, and that single difference shapes every practical requirement downstream.

GDPR vs. CCPA/CPRA — the core differences a marketer feels
GDPR (EU) CCPA / CPRA (California)
Default Opt-in — get permission first Opt-out — collect, but offer a way out
Applies to Anyone processing EU residents' data, wherever based Qualifying businesses handling Californians' data
Before collecting Need a lawful basis (often consent) Can collect by default; must disclose
Signature requirement Clear consent, easy withdrawal "Do Not Sell or Share" option

GDPR is an opt-in framework: you generally need a lawful basis — frequently explicit, freely given consent — before you process someone's personal data. CCPA and its expansion CPRA are opt-out: you can collect data by default, but you must clearly tell people what you collect and give them a straightforward way to opt out of its sale or sharing. Everything from how you design a cookie banner to how you word a signup form traces back to which of those two defaults applies to the person in front of you.

First question: does any of this even apply to you?

The most common and most dangerous assumption in marketing is "we're not in Europe, so GDPR isn't our problem." It's frequently wrong, because GDPR reaches across borders. It applies to any business that processes the personal data of people in the EU, regardless of where the business is located. If you sell to, serve, or track the behaviour of people in the EU — even from an office on another continent — you can fall squarely under it.

CCPA works differently: it applies to businesses that meet certain thresholds (broadly, around revenue and the scale of personal data they handle) and process the data of California residents. And it no longer stands alone — a growing number of US states now have their own comprehensive privacy laws with overlapping requirements. The practical takeaway is to stop asking "are we exempt?" and start asking "whose data do we actually touch?" If your audience meaningfully includes EU residents or Californians — and for most online businesses it does — assume these rules apply and plan accordingly. Knowing exactly whose data you hold is also the foundation of a sound first-party data strategy, so this work does double duty.

The marketer's compliance checklist

Here's the practical core — the things a marketing team is actually responsible for, in plain language. None of these requires legal training to understand, though the details of implementation may warrant professional review.

Featured Recommendation AD · AFFILIATE
Close logo
4.7 / 5.0

Close

All-in-one sales CRM with built-in calling, email and SMS for outbound teams.

Best for: Inside and outbound sales teams that live on phone and email

1. Have a lawful basis, and get consent properly

Under GDPR, don't collect or use personal data without a valid reason for doing so, and where that reason is consent, it must be freely given, specific, and unambiguous — a pre-ticked box or a buried checkbox doesn't count. Just as importantly, withdrawing consent must be as easy as giving it. For marketing specifically, this is why a clean, permission-based approach to building your email list matters so much: an audience that genuinely opted in is both more compliant and more engaged — the whole premise behind betting on an owned newsletter audience — and it makes honest segmentation cleaner too.

2. Tell people what you're doing — clearly

Both frameworks require transparency. Maintain a clear, accessible privacy notice that explains what data you collect, why, how long you keep it, who you share it with, and what rights people have. Plain language beats legalese here — a notice nobody can understand doesn't satisfy the spirit of the law and, increasingly, not the letter either.

3. Honour people's rights over their data

This is the operational heart of both laws, and the good news is the core rights overlap heavily, so you can handle them as one set rather than two. People can generally ask you to:

  • Access the data you hold on them.
  • Delete it (with some lawful exceptions).
  • Correct inaccurate information.
  • Port it — receive it in a usable, transferable format.
  • Opt out of certain processing — including the sale or sharing of their data, and direct marketing.

They're also protected from being penalised for exercising any of these rights. What you need isn't legal genius; it's a reliable, documented process to receive, verify, and fulfil these requests within the required timeframes, so you're not improvising each time one lands — which is far easier when your CRM and data live in one place rather than scattered across tools.

4. Get cookie consent right

The cookie banner is where compliance meets marketing most visibly. Under an opt-in regime, non-essential cookies — analytics, advertising, tracking — shouldn't fire until the user has agreed, which means "reject" needs to be as easy as "accept," and a banner that drops tracking cookies before anyone clicks is a problem. This directly affects your data collection and measurement, which is one reason honest attribution keeps getting harder — but a properly consented setup is both lawful and more trustworthy to your audience, and it's pushing measurement toward privacy-safe approaches like marketing mix modelling.

5. Practise data minimisation and retention discipline

Collect only what you'll genuinely use, and don't keep it forever. "Collect everything just in case" is precisely the instinct these laws push against, and it creates risk with no marketing upside. Set retention periods and actually honour them.

6. Get your vendor contracts in order

You're responsible for the data you hand to the tools and partners you use. Both frameworks expect appropriate contracts with the vendors that process data on your behalf — GDPR calls for processor agreements, and CCPA requires California-specific service-provider terms. It's an unglamorous box to tick, but a real one, and it's easy to overlook the martech stack quietly sharing data on your behalf — a discipline that matters even more for B2B and regulated industries.

The mindset shift Compliance isn't a tax on marketing; it's the same discipline as good marketing. Permission-based audiences engage better. Clear notices build trust. Minimised data is safer data. The teams that treat privacy as a feature, not a burden, are also the ones customers trust with their information.

The CCPA-specific extras you can't skip

If you're already built to GDPR's stricter standard, you're most of the way to CCPA — but a handful of California-specific requirements have no GDPR equivalent, and missing them is a common gap. The most visible is a clear "Do Not Sell or Share My Personal Information" link (often paired with a "Your Privacy Choices" control), which needs to be genuinely easy to find and use.

Beyond that, you generally need to honour opt-out preference signals that a browser can send on a user's behalf, provide specific notices where you offer a financial incentive in exchange for data (a discount for signing up, for instance), and use California-specific language in your vendor contracts. These are the details that catch out businesses who assumed GDPR compliance covered everything. Recent CCPA/CPRA updates have also added obligations around risk assessments and automated decision-making for certain higher-risk activities — another reason to treat this as a living program rather than a one-time project.

The strategy that saves you the most work

For any business subject to both laws — and to the widening patchwork of US state privacy laws behind them — there's one approach that beats trying to maintain separate compliance programs for each jurisdiction.

Build to the strictest standard, then layer the rest on top

→ GDPR is generally the stricter framework, so meeting it satisfies much of the CCPA baseline (the reverse isn't true). Build your core program to GDPR level.

→ Then layer the CCPA-specific extras on top — the "Do Not Sell or Share" link, opt-out signals, financial-incentive notices, California vendor terms. You're adding a thin compliance layer, not building a second program.

→ For the rest of the state-law patchwork, applying your strictest standard everywhere is usually simpler and safer than geo-detecting and switching rules per visitor — one high bar, cleared once.

Result: one privacy program, one high standard, small jurisdiction-specific additions — instead of a tangle of separate rulebooks.

This is why the effort compounds rather than multiplying: the hard work of consent, transparency, rights-handling, and minimisation is shared across every framework, and each new law mostly asks you to add a notice or a link rather than rebuild from scratch. It's the same logic behind treating accessibility requirements as one standard to meet rather than a per-rule scramble — do it well once, and compliance becomes maintenance rather than crisis.

Why this is worth doing properly

Beyond the fact that it's the law, there are two hard reasons to take this seriously. The first is enforcement, which is real and active: EU regulators have issued very substantial GDPR fines, and CCPA enforcement has produced real settlements against companies that ignored opt-out signals or failed to disclose data practices. Treating privacy as optional is a bet against increasingly well-resourced regulators.

The second reason is the one marketers underrate: trust is a growth asset. A large share of customers will abandon a transaction over data concerns, and a business visibly careful with personal data earns exactly the confidence that makes people willing to share more of it. That's the throughline of this whole category — handled well, privacy compliance isn't a drag on marketing, it's part of what makes modern email and inbox strategy work at all, and it protects the personalization you build on top of consented data. Compliance and good marketing point the same way.

The short version

GDPR and CCPA look intimidating and aren't, once you hold the one distinction that organises everything: GDPR is opt-in (ask first), CCPA is opt-out (collect, but offer an easy exit). Don't assume you're exempt — GDPR reaches any business serving EU residents, and most online audiences include people these laws protect. Work the checklist: a lawful basis and real consent, a clear privacy notice, a documented process for honouring access, deletion, correction, portability, and opt-out requests, honest cookie consent, data minimisation, and vendor contracts in order. Add the CCPA-specific extras — the "Do Not Sell or Share" link chief among them. And save yourself the most work by building to the strictest standard once and layering the rest on top. Do that, and privacy stops being the thing you dread and becomes part of the trust that makes your marketing work.

Want marketing that performs and stays compliant?

We help brands build privacy-first marketing that respects the rules and the customer.

Explore Email Marketing & Automation →

Frequently asked questions

What's the main difference between GDPR and CCPA?

It comes down to one distinction that shapes everything else: consent philosophy. GDPR is an opt-in framework — you generally need a lawful basis, which often means explicit consent, before you process someone's personal data. CCPA/CPRA is an opt-out framework — you can collect data by default, but you must clearly tell people what you collect and let them opt out of its sale or sharing. That single difference drives how your cookie banners, privacy notices, website design, and internal data handling all need to work. Understand opt-in versus opt-out and most of the rest of the compliance picture organises itself around it.

Does GDPR apply to a business outside the EU?

Often, yes. GDPR has extraterritorial reach: it applies to any business that processes the personal data of EU residents, regardless of where the business itself is located. If you sell to, serve, or monitor the behaviour of people in the EU, you can fall under GDPR even with no physical European presence. This is the assumption that trips marketers up most — "we're not based in Europe, so it doesn't apply to us" is frequently wrong. The practical response is to check honestly whether any meaningful part of your audience is in the EU, and if so, treat GDPR as applicable rather than hoping it isn't.

If I'm already GDPR-compliant, am I CCPA-compliant too?

Largely, but not entirely. Because GDPR is the stricter framework in most respects, being GDPR-compliant typically satisfies much of the CCPA/CPRA baseline — the reverse is not true. However, several CCPA-specific obligations remain even for GDPR-compliant businesses, most notably a clear "Do Not Sell or Share My Personal Information" link, honouring opt-out preference signals, financial-incentive notices where you offer rewards tied to data, and California-specific contract terms with your vendors. The efficient strategy for a business subject to both is to build your program to the stricter GDPR standard, then layer the CCPA-specific requirements on top rather than running two separate programs.

What rights can people ask me to honour under these laws?

The core rights overlap substantially across GDPR and the growing set of US state laws, which makes them easier to handle as one set. People can generally ask to access the data you hold on them, to have it deleted (with some exceptions), to correct inaccurate information, to receive their data in a portable format, and — critically for marketers — to opt out of certain processing, including the sale or sharing of their data and direct marketing. They're also protected from being discriminated against for exercising these rights. The practical requirement is having a reliable, documented process to receive, verify, and fulfil these requests within the legally required timeframes, rather than scrambling each time one arrives.

THE LAB REPORT

Tactics that move metrics — every Tuesday.

Be an early subscriber. No spam, unsubscribe anytime.