| Jurisdiction | EU residents worldwide | California residents | U.S. consumers (federal) |
| Coverage Threshold | Any processing of EU data | $25M revenue or 100K consumers | 200K consumers or 100K + 25% revenue from data sales |
| Consent Model | Opt-in for all processing (lawful basis required) | Opt-out for data sales; opt-in for minors | Opt-out for general data; opt-in for sensitive data |
| Consumer Rights | Access, rectification, erasure, portability, objection | Know, delete, opt-out, non-discrimination | Access, correction, deletion, portability |
| Private Right of Action | Yes — individuals can sue | Limited (data breaches under CPRA) | No private right of action |
| Enforcement Authority | Data Protection Authorities (DPAs) | California AG + CPPA | FTC + State Attorneys General |
| Maximum Penalties | 4% of global annual revenue or €20M | $7,500 per intentional violation | $10,000 per violation per day |
| Data Protection Assessment | Required (DPIA) for high-risk processing | Required under CPRA for certain processing | Required for high-risk processing activities |
| Breach Notification | 72 hours to supervisory authority | Varies by state law | 72 hours to FTC for 500+ consumers |
| Preemption Effect | N/A (EU law) | State law only | Preempts all state privacy laws |