In the United States, data privacy is managed through a patchwork of state-level laws, rather than a single federal framework. The most influential state framework is the California Consumer Privacy Act (CCPA), which was expanded by the California Privacy Rights Act (CPRA).
Comparing US and EU Data Protection Models
While the GDPR uses an opt-in model—where companies must secure explicit consent before collecting data—the US framework relies primarily on an opt-out model. This structure allows companies to collect data by default, provided they give consumers a clear way to stop the sale or sharing of their personal information.
Key Operational Differences

Structural Parameter EU GDPR Framework Standards California CCPA / CPRA Standards
Consent Model Strict Opt-In before processing can begin. Opt-Out allowed via explicit web links.
Notice Requirements Broad privacy notice required at collection point. Mandatory “Do Not Sell My Info” link on homepages.
Private Right of Action Broad; users can sue for any violation. Limited strictly to validated data breaches.
Sensitive Data Limits Prohibits processing sensitive data by default. Gives users the right to limit sensitive data usage.