CCPA compliance for European companies entering the US market

Updated August 14, 2026

(Published 14 August 2026)

.

CCPA

Quick Nav.

GDPR compliance gives a European company useful habits. It does not make the company CCPA-compliant by default.

California’s privacy law uses different definitions, thresholds, consumer rights, and opt-out rules. That matters when a European business starts selling to California residents, running US ad campaigns, or adding pixels and analytics to a US-facing site. Privacy should be part of the US market-entry plan, not a policy-page task saved for launch week.

This article is general business information, not legal advice. Whether the CCPA applies depends on your revenue, data practices, corporate structure, California nexus, and vendors. Ask qualified US privacy counsel to review your situation and your live implementation.

Does the CCPA apply to a European company?

The California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to certain for-profit businesses that do business in California, collect California consumers’ personal information, determine the purposes and means of processing, and meet at least one statutory threshold.

For the current statutory thresholds, a covered business must meet one of these tests: annual gross revenues above the inflation-adjusted amount, annual buying, selling, or sharing of personal information from at least 100,000 California consumers or households, or at least half of annual revenue from selling or sharing personal information. The CPPA publishes the current monetary threshold, which is $26,625,000 for the relevant 2025 adjustment. The full CCPA statute effective January 1, 2026 and CPPA threshold notice are the sources to use, not a generic online checklist.

A company does not automatically fall outside the law because it is incorporated in Europe or has no California office. But a website receiving California traffic does not, by itself, answer every legal question either. Counsel should assess the facts: sales activity, targeting, group revenue, common branding, data volumes, and the role of each vendor.

Why GDPR compliance is not enough

The two regimes overlap, but they ask different questions.

GDPR centers on a lawful basis for processing and, in many settings, consent before nonessential processing. The CCPA gives California residents rights over their personal information and creates particular obligations around selling or sharing data, sensitive personal information, notices, and opt-out mechanisms.

The word “sharing” carries real weight. Under the CCPA, cross-context behavioral advertising can count as sharing even when no money changes hands. A marketing pixel, ad network, or SDK can therefore create an issue that a team describing itself as “not selling data” has missed.

The CCPA also protects California residents, not only customers. Visitors, leads, job applicants, and B2B contacts may appear in the company’s data flows. Do not map your GDPR privacy notice word-for-word and assume the job is done.

What a US-facing website should review

A well-designed US site needs to tell buyers what the company does. It also needs to represent its data practices accurately. That starts with an inventory, not with a cookie-banner template.

Map the data that actually moves

List every form, checkout, CRM connection, analytics tag, advertising pixel, chat tool, session-replay product, and consent platform. For each one, identify what it collects, where it sends data, why it is used, how long information is retained, and whether the recipient acts as a service provider, contractor, or third party.

This work belongs in a serious US website design process. The team that designs the site, the marketing team that installs tags, and legal counsel need the same factual picture. A privacy notice cannot be accurate if nobody knows which scripts load before a visitor can act.

Give notices where collection happens

The CCPA regulations require a notice at collection at or before the point of collection. The notice must describe the categories of personal and sensitive personal information collected, purposes, retention period or criteria, and whether categories are sold or shared. It must also point to the privacy policy and applicable opt-out rights.

That affects more than the footer. Forms, checkout flows, lead magnets, account creation, and mobile interfaces may each need a clear path to the relevant information. The regulations also require a privacy policy that is accessible, understandable, and updated at least every 12 months.

Respect opt-out rights and Global Privacy Control

When a covered business sells or shares personal information, it must provide a way to opt out. The law permits a clear “Your Privacy Choices” link when it lets users exercise the required choices. It also requires covered businesses to honor a valid opt-out preference signal, including Global Privacy Control, subject to the rules for the consumer’s browser, device, or known profile.

A cookie banner is not automatically an opt-out process. Nor does a privacy policy fix a tag configuration that continues to share data after an opt-out. California’s Global Privacy Control guidance is useful for the implementation discussion, but your counsel should assess the full site architecture.

The operational trap: marketing launches before privacy work

A common sequence is easy to recognize. The company launches paid campaigns, adds a Meta pixel, connects analytics, and later asks legal to update the privacy notice. By then, the data map has become harder to reconstruct and the customer experience is harder to change without disrupting acquisition.

Reverse that order. Decide what data you need for the first US market, what vendors are necessary, and which tools can wait. This is especially important for an eCommerce site selling to US customers, where checkout, payments, customer support, advertising, and analytics can involve several separate data flows.

Royal Cheese Agency does not provide privacy legal advice. We can help ensure that the website, conversion paths, and measurement setup are designed around the US market and documented well enough for your privacy counsel to review.

A practical review before launch

Start with the business and technical facts. Identify the US audience you are targeting and the data your commercial model truly needs. Then ask counsel to assess applicability, thresholds, notices, contracts, opt-out mechanisms, sensitive-data rules, and any 2026 obligations around automated decisionmaking technology, risk assessments, or cybersecurity audits that may apply to your processing.

The goal is not to copy a Californian footer onto a European site. It is to launch a US presence whose messaging, measurement, and privacy experience describe the same reality.

FAQ

Does the CCPA apply if our company is not in California?

It can. The statute does not require a California incorporation or office, but it has specific requirements around doing business in California and statutory thresholds. A lawyer should assess your actual commercial and data activities rather than relying on location alone.

Is a GDPR cookie banner enough for the CCPA?

Not necessarily. CCPA obligations can include notices at collection, privacy-policy disclosures, opt-out rights for sale or sharing, and recognition of Global Privacy Control. Whether your banner and tag configuration meet those requirements depends on the facts.

What does “Do Not Sell or Share” mean?

It is an opt-out right related to selling or sharing personal information. “Sharing” can include cross-context behavioral advertising, which is why advertising pixels and ad-tech vendors deserve a technical and legal review.

Are B2B contacts covered by the CCPA?

The broad employee and B2B exemptions expired at the end of 2022. The legal analysis still depends on the type of information and the company’s role, so obtain advice for your particular records and relationships.

Launch with a site your privacy team can audit

US expansion requires more than translated copy and a checkout that accepts dollars. Your site has to earn trust, explain the offer, and give legal and technical teams a clear view of what it does. If you are planning a US-facing site or a major redesign, talk with Royal Cheese Agency about your market-entry project.

Olivier GRUERE, CEO Royal Cheese Digital

Article by Olivier Gruère

Olivier Gruère is a brand strategist and the founder of Royal Cheese Agency, a boutique branding agency based in Los Angeles.

With over 15 years of experience helping more than 150 brands grow and stand out in California and across the U.S., he specializes in building brand strategies that drive both recognition and revenue. His insights on branding and local market adaptation have been featured in numerous guides and resources for small business owners looking to make their mark in Los Angeles.

Quick Nav.

Since 2018, Royal Cheese has helped over 150 brands grow and thrive in LA and across the U.S. We know how to position your brand to make a lasting impact with your audience. Every project we take on gets a tailored approach, built around your specific goals and challenges.

Choosing Royal Cheese means working with a seasoned branding team with 25 years of experience crafting strategies that turn local businesses into recognizable, revenue-driving brands. We partner with you to refine your story, define your market positioning, and navigate the competitive landscape of Los Angeles with confidence.

Got a brand to build or refresh in L.A.? Let’s talk.

Share

More articles