DIGITAL PRIVACY REGULATIONSThe Worldwide Register of Data Privacy Law
Tracking 197 jurisdictions
Language: English
Reference · The two playbooks

GDPR vs US privacy law

One system governs by permission, the other by objection. Twelve dimensions, compared, with the places the gap actually costs money.

Updated September 28, 2026 · digitalprivacyregs.com

These are the two systems every global marketing operation runs on. The GDPR governs by permission, so every use of personal data needs a legal basis, and for advertising that basis is nearly always consent. US law governs by objection, letting companies proceed, disclose, and stop when asked. Neither is converging on the other, which is why serious operators maintain two playbooks.

DimensionEuropean Union (GDPR)United States
ModelOne comprehensive regulation for all sectorsSectoral federal laws + 24 state comprehensive laws (20 in effect)
Default for targetingOpt-in: consent before tracking and behavioral advertisingOpt-out: targeting permitted until the consumer objects (adults, non-sensitive data)
Sensitive dataExplicit consent or narrow exceptions (Art. 9)Opt-in consent in most state laws; Maryland bans sale of sensitive data; Washington MHMD adds a private right of action for health data
CookiesPrior consent under the ePrivacy Directive; one-click reject enforced in France and beyondNo general cookie consent law; state opt-outs and GPC signals govern sale and share
Email marketingOpt-in with a soft opt-in for existing customersOpt-out under CAN-SPAM: no prior consent required
Calls and textsOpt-in under national ePrivacy rulesOpt-in under the TCPA with $500-$1,500 statutory damages per message
ChildrenParental consent under 13-16 (member state choice); minors' data high-riskCOPPA under 13; state laws restrict teen targeting; Maryland bans under-18 targeted advertising
RegulatorIndependent DPA in every member state, EDPB coordinationFTC + state AGs + California's CPPA; no dedicated federal privacy agency
FinesTo EUR 20M or 4% of global turnoverTypically $2,500-$7,500 per violation via AG action; FTC consent decrees; class actions where private rights exist
Private lawsuitsArt. 79-82: judicial remedy and compensationRare: CCPA breach claims, Washington MHMD, Illinois BIPA, TCPA; most state laws bar private actions
TransfersRestricted: adequacy, SCCs, BCRs required to export dataUnrestricted outbound; DPF governs inbound EU data
AccountabilityDPOs, records of processing, DPIAs mandatory in scopeRisk assessments in newer state laws (CA, CO, CT); no general DPO duty

Where the gap bites in practice

Audience building is where the gap bites first. Lookalikes, retargeting pools and data-broker enrichment are default-lawful for US adults and default-unlawful for EU users without consent, which is why the same campaign can be a commodity tactic in Dallas and a regulatory finding in Dublin. Measurement differs too, since the EU's cookie rule puts even analytics behind a banner while the US needs an opt-out link and GPC honoring. Exposure runs on different math. An EU mistake costs a percentage of global turnover, a US mistake costs per violation through an AG suit, and a US texting mistake costs per message through the TCPA class-action bar, which regularly produces eight-figure settlements.

The convergence points are real but narrow: sensitive data is heading toward opt-in on both sides, children are heading toward off-limits on both sides, and dark-pattern consent design is an enforcement priority for the CPPA, the FTC and the EDPB alike.

Cite this page: "GDPR vs US Privacy Law: The Comparison." Digital Privacy Regulations, September 28, 2026, https://digitalprivacyregs.com/gdpr-vs-us.html. Accessed [date].