These are the two systems every global marketing operation runs on. The GDPR governs by permission, so every use of personal data needs a legal basis, and for advertising that basis is nearly always consent. US law governs by objection, letting companies proceed, disclose, and stop when asked. Neither is converging on the other, which is why serious operators maintain two playbooks.
| Dimension | European Union (GDPR) | United States |
|---|---|---|
| Model | One comprehensive regulation for all sectors | Sectoral federal laws + 24 state comprehensive laws (20 in effect) |
| Default for targeting | Opt-in: consent before tracking and behavioral advertising | Opt-out: targeting permitted until the consumer objects (adults, non-sensitive data) |
| Sensitive data | Explicit consent or narrow exceptions (Art. 9) | Opt-in consent in most state laws; Maryland bans sale of sensitive data; Washington MHMD adds a private right of action for health data |
| Cookies | Prior consent under the ePrivacy Directive; one-click reject enforced in France and beyond | No general cookie consent law; state opt-outs and GPC signals govern sale and share |
| Email marketing | Opt-in with a soft opt-in for existing customers | Opt-out under CAN-SPAM: no prior consent required |
| Calls and texts | Opt-in under national ePrivacy rules | Opt-in under the TCPA with $500-$1,500 statutory damages per message |
| Children | Parental consent under 13-16 (member state choice); minors' data high-risk | COPPA under 13; state laws restrict teen targeting; Maryland bans under-18 targeted advertising |
| Regulator | Independent DPA in every member state, EDPB coordination | FTC + state AGs + California's CPPA; no dedicated federal privacy agency |
| Fines | To EUR 20M or 4% of global turnover | Typically $2,500-$7,500 per violation via AG action; FTC consent decrees; class actions where private rights exist |
| Private lawsuits | Art. 79-82: judicial remedy and compensation | Rare: CCPA breach claims, Washington MHMD, Illinois BIPA, TCPA; most state laws bar private actions |
| Transfers | Restricted: adequacy, SCCs, BCRs required to export data | Unrestricted outbound; DPF governs inbound EU data |
| Accountability | DPOs, records of processing, DPIAs mandatory in scope | Risk assessments in newer state laws (CA, CO, CT); no general DPO duty |
Where the gap bites in practice
Audience building is where the gap bites first. Lookalikes, retargeting pools and data-broker enrichment are default-lawful for US adults and default-unlawful for EU users without consent, which is why the same campaign can be a commodity tactic in Dallas and a regulatory finding in Dublin. Measurement differs too, since the EU's cookie rule puts even analytics behind a banner while the US needs an opt-out link and GPC honoring. Exposure runs on different math. An EU mistake costs a percentage of global turnover, a US mistake costs per violation through an AG suit, and a US texting mistake costs per message through the TCPA class-action bar, which regularly produces eight-figure settlements.
The convergence points are real but narrow: sensitive data is heading toward opt-in on both sides, children are heading toward off-limits on both sides, and dark-pattern consent design is an enforcement priority for the CPPA, the FTC and the EDPB alike.