GDPR (EU) and CCPA (California) are the two most significant data privacy laws affecting U.S. small businesses. Compliance with both sounds complex—and in edge cases it is—but for most small businesses, the core requirements are straightforward.
Who Needs to Comply
CCPA applies to businesses that (1) have $25M or more in annual gross revenue, (2) buy or sell personal information of 100,000 or more California consumers or households annually, or (3) derive 50% or more of annual revenue from selling personal information. Many small businesses fall below these thresholds. GDPR applies to any business that processes personal data of EU residents.
What Compliance Looks Like in Practice
For most small businesses, CCPA compliance means: adding a "Do Not Sell My Personal Information" link to your website, providing a privacy policy that describes what data you collect and why, and having a process for responding to consumer requests to access, delete, or correct their data. GDPR compliance adds consent requirements and data processing agreements with vendors.
Key Takeaways
- Many small businesses fall below CCPA revenue thresholds—check before assuming you must comply.
- GDPR applies to EU personal data regardless of where your business is located.
- A clear privacy policy and a data request process are the foundation of compliance for most small businesses.


