4% / EUR 20M
GDPR's penalty ceiling
GDPR fines can reach EUR 20 million or 4% of global annual revenue — whichever is higher. It applies to anyone processing EU residents' data, wherever you're based.
The moment you sell to EU or California customers, GDPR and CCPA/CPRA both apply — and your enterprise buyers and investors will ask before they sign. The smart build is one unified program: anchor on GDPR, layer California on top. We design it once so it answers both.
Book a GDPR & CCPA Strategy Call →// WHY PRIVACY, WHY NOW
4% / EUR 20M
GDPR fines can reach EUR 20 million or 4% of global annual revenue — whichever is higher. It applies to anyone processing EU residents' data, wherever you're based.
NO BORDER
Both laws are extraterritorial. A U.S. startup falls under GDPR the first time an EU user signs up, and under CCPA/CPRA once it hits a California threshold.
THE GATE
Enterprise buyers run privacy assessments before they sign; investors probe it in diligence. Weak privacy doesn't just risk fines — it stalls revenue.
// TWO LAWS, NOT TWO PROGRAMS
Running two disconnected compliance projects is the expensive way. GDPR is generally the stricter framework, so a real GDPR program satisfies most of the CCPA/CPRA baseline — data mapping, access and deletion rights, vendor controls. The reverse isn't true, and "most" isn't "all": California adds its own items GDPR never mentions, like the "Do Not Sell or Share" link and the 2026 risk-assessment and audit rules. So you build once on the stricter foundation, then layer the California-specific pieces — one program, two regulators, far less duplicated work.
// THE BUILD-ONCE STRATEGY
The efficient path isn't two compliance projects — it's one. A unified privacy program, anchored on the stricter GDPR, with the California-specific obligations layered on top. The pieces below are what that single program covers.
The strategy that saves the most work: build one privacy program on the GDPR foundation — the stricter framework, which covers most of the CCPA/CPRA baseline — then add the California-specific obligations on top. Data mapping, rights fulfillment, and vendor controls serve both regimes at once. The three pieces below are what the single program has to satisfy.
// THE FOUNDATION
GDPR (EU/EEA)
Lawful basis, consent, data-subject rights, and strict cross-border transfer controls. The stricter floor.
// THE CALIFORNIA LAYER
CCPA / CPRA
"Do Not Sell or Share," sensitive-PI limits, and the 2026 risk-assessment and cybersecurity-audit rules.
// SHARED MACHINERY
Rights & Operations
Data mapping, access/deletion/portability fulfillment, consent and opt-out handling, and vendor management.
GDPR covers most of CCPA's baseline — not all, and not the reverse.
// THE PATH
How a scaling company builds privacy once and runs it continuously. The amber stages are the moments that face the outside — a data-subject or consumer request, and a regulator inquiry or audit.
Map
Data Inventory
WK 1–4
Scope
Which Laws Apply
WK 2–4
Build
Unified Program
MO 1–4
Fulfill
Rights Requests
ONGOING
Assess
Risk & Audit (2026)
ANNUAL
Defend
Regulator or Diligence
IF TRIGGERED
Amber stages are the outward-facing moments — a data-subject or consumer rights request you must fulfill on a clock, and a regulator inquiry, audit, or buyer's diligence review where your program is examined. The rest is the build and upkeep that make those go smoothly.
// IS THIS YOU?
// 01 // SELLING ACROSS BORDERS
You're signing up EU residents or California consumers — so GDPR and CCPA/CPRA already apply, whether or not you've built anything for them yet.
// 02 // DEALS STALLING ON PRIVACY
Enterprise prospects send privacy assessments and DPAs you can't confidently answer, and deals slow down. Privacy is gating your revenue.
// 03 // RAISING OR EXITING
Investors or an acquirer are probing your data practices, and unresolved GDPR or CCPA exposure could cut your valuation or stall the deal.
// WHAT WE DO
// Phase 01 · Map
We inventory what personal data you hold, where it flows, and which laws you've triggered — the foundation both regimes are built on and the thing most companies have never fully done.
// Phase 02 · Build
We build one program on the GDPR foundation and layer the California-specific obligations — consent and opt-out, the "Do Not Sell or Share" mechanism, transfer controls, and vendor terms.
// Phase 03 · Prove
We run the privacy risk assessments the 2026 CCPA rules now require, and package your program so enterprise security reviews and investor diligence move fast instead of stalling.
// PRIVACY IS A REVENUE GATE NOW
// FREQUENTLY ASKED
Because the GDPR is extraterritorial: it applies based on whose data you process, not where your company sits. If you offer goods or services to people in the EU or EEA, or monitor their behavior — signing up EU users, selling to EU customers, tracking EU visitors — you can fall under the GDPR with no office or entity in Europe. For a scaling tech company this happens earlier than most founders expect, often the first time an EU customer signs up or an EU enterprise prospect runs you through a data protection assessment.
The same logic applies to CCPA/CPRA, which reaches any qualifying business processing California residents' data regardless of location. So you usually don't get to choose whether these laws apply — your customers and users decide it the moment you serve them. The right response is to determine which regimes you've triggered and build a program that covers them, rather than assuming a U.S. address keeps you out of scope.
Mostly, but not entirely — and the gap is where companies get caught. Because the GDPR is generally the stricter framework, a genuine GDPR program satisfies most of the CCPA/CPRA baseline — data inventory, access and deletion rights, limited collection, vendor management. That's why organizations serving both markets anchor a unified program on the GDPR.
However, CCPA/CPRA has specific obligations the GDPR doesn't, and GDPR compliance doesn't create them for you: the "Do Not Sell or Share My Personal Information" link, a "Limit the Use of My Sensitive Personal Information" mechanism, financial-incentive disclosures, and California's newer risk-assessment and automated-decision rules. And it doesn't run the other way — a CCPA-only program leaves large GDPR gaps around lawful basis, consent, and cross-border transfers. GDPR gets you most of the way to CCPA, but you still close the California-specific items deliberately.
The updates effective January 1, 2026 are the most significant expansion of California privacy obligations since the CPRA amendments in 2023, and they push CCPA/CPRA closer to the GDPR. The headline additions: mandatory risk assessments for certain high-risk processing (paralleling GDPR's data protection impact assessments); annual cybersecurity audits for businesses meeting the thresholds; extended consumer access rights; and new protections for minors' data.
There's also a separate, later milestone: the obligations around automated decision-making technology for significant decisions — opt-out and access rights when automated systems, including AI, make consequential decisions about people — take effect January 1, 2027, not 2026, so don't treat those as already required. For a tech company, the practical impact is that California now expects documented, repeatable privacy governance — risk assessments before risky processing, and audit-ready security — not just notices and opt-out links. We help you build that documentation and the underlying processes so the new requirements are met and evidenced.
Because privacy compliance has become a procurement and due-diligence gate, not just a legal obligation. When you sell to a larger company, that customer is itself accountable for the data it shares with you, so its security and privacy teams assess whether you handle personal data lawfully before they sign — through data protection assessments, data processing terms, and questions about how you support data-subject and consumer rights. The same holds in fundraising and acquisition diligence, where unresolved EU and California privacy exposure can reduce valuation or stall a deal.
In other words, GDPR and CCPA/CPRA readiness increasingly determines whether you can close enterprise contracts and pass investor scrutiny, independent of the fines themselves. That makes a credible privacy program a revenue enabler, not a cost center: it shortens security reviews, unblocks deals, and signals operational maturity. We build the program and assemble the documentation those reviews ask for, so privacy stops slowing your deals down.
// THE NEXT MOVE
Book a 30-minute GDPR and CCPA strategy call with a WatchUr6 advisor. Bring where your users are, what privacy work you've done, and which deals or raises are waiting on it. You'll walk away knowing which laws you've triggered, your biggest gaps, and a path to one program that satisfies both — whether you hire us or not.
Book a GDPR & CCPA Strategy Call →SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED