CCPA vs GDPR for employee data: a side-by-side for US companies
The CCPA and GDPR treat employee data differently: California relies on notices, purpose limits and contracts, while the EU requires a lawful basis for each use. Many US companies licensing workforce records therefore license US records first and carve EU and UK records out, then involve counsel on notices and de-identification.
Which regime applies to a US company's employee records?
Most US companies start with California's privacy statute and treat EU rules as an exception for the people and offices that touch Europe. The practical rule many owners use: license the US records first and carve EU and UK records out. That keeps the dataset inside one legal frame and avoids a cross-border analysis for a license that does not need one.
The two regimes are built differently. The California Consumer Privacy Act is a notice, rights and contract regime that applies to for-profit businesses meeting one of three tests. The EU General Data Protection Regulation is a lawful-basis regime: every use of personal data needs a stated legal ground, and a new use usually needs a fresh look. This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.
CCPA vs GDPR for workforce data: side-by-side
The table compares how each regime treats the records an employer actually holds: personnel files, mailboxes, chat, timesheets, badge logs and recorded calls.
| Question | California (CCPA) | EU (GDPR) |
|---|---|---|
| Who is covered | For-profit businesses doing business in California that meet a revenue, volume or data-revenue test | Organizations in the EU, and some outside it that monitor or serve people in the EU |
| Whose data | California residents, which can include employees, applicants and contractors; confirm current scope against the statute | People in the EU, including staff, applicants and contractors |
| Legal basis needed | No lawful-basis requirement as such; instead notice, purpose limits and contract terms | Every use needs a lawful basis, and a new purpose must be compatible or have its own basis |
| Notice | Notice at collection of categories, purposes, whether data is sold or shared, and retention | Transparency duties at collection, including purposes and recipients |
| Individual rights | Know, delete, correct, opt out of sale or sharing, limit sensitive data use | Access, rectification, erasure, restriction, objection and others, subject to conditions |
| Sale or sharing | A defined concept that triggers opt-out rights and contract terms | No "sale" concept; disclosure to a third party is a processing activity needing a basis |
| De-identified data | Treated differently if the business meets the statute's de-identification commitments | Truly anonymous data falls outside the regime; pseudonymized data stays inside it |
| Enforcement | State Attorney General and the California Privacy Protection Agency | National supervisory authorities |
The CCPA statute text requires notice at collection, says collection and use must be reasonably necessary and proportionate, and requires a written agreement when personal information is sold, shared or passed to a service provider. California regulations were also updated in 2026, so check current text rather than relying on older summaries.
How the "who is covered" tests work in practice
Owners often ask whether they are covered at all. The California Attorney General's overview says the CCPA applies when a business meets any one of three tests: an annual gross revenue threshold that is adjusted over time, buying, selling or sharing the personal information of a large number of California residents or households (the statute sets the figure), or deriving half or more of annual revenue from selling or sharing personal information.
For the EU side, the question is whether the company has an EU establishment or deliberately monitors or serves people in the EU. A US company with no European staff, offices or customers may have little EU workforce data. A US company with a Dublin sales office or remote engineers in Germany does.
The related page on whether the CCPA applies to your business walks through the thresholds. The companion guide on CCPA service provider, contractor and third party roles explains why the label on the recipient matters.
What changes when you license workforce data?
Licensing is a new use. Under both regimes, the question is not only whether you may keep employee records but whether you may hand a copy to a buyer for AI training.
- California: check what the notice at collection and the employee privacy notice said about disclosure. Decide whether the transfer counts as a sale or sharing, and what contract terms the buyer must accept.
- EU and UK: a change of purpose needs a compatibility assessment or a new basis. The purpose limitation guide covers that test.
- Both: a de-identification standard applies only if the company can meet its conditions. See the guide to the three commitments for de-identified data.
FTC staff guidance from February 2024 warns that quietly widening data practices, such as sharing data or AI training, through a retroactive change to terms or privacy policies may be unfair or deceptive. It is staff guidance, not a rule, and it concerns customer data. Employee notices deserve the same read.
The decision rule: license US first, carve EU out
Use this sequence before an inventory is finalized.
- List every system that holds employee, contractor or applicant records: HR, payroll, email, chat, ticketing, call recording.
- Mark which people, offices and mailboxes sit in the EU or UK.
- Exclude those records from the first license by location and domain filters. The guide on carving EU and UK records out of a US data license lists practical filters.
- For the remaining US records, check the notices, then agree redaction and de-identification rules with SourceX and the company's counsel before any work begins.
- Revisit EU records only later, with counsel, if the company wants a second license.
Employee personnel files, medical leave records, background checks and compensation data are usually excluded by default. The valuable material is work product: tickets, project threads and decisions, redacted of personal identifiers.
Where this matters to a referral partner
Partners do not handle data or give legal advice. You introduce a company, and SourceX works through qualification, inventory and rights review with the company. What you can do is spot the issue early and ask the sponsor who in the company owns privacy questions.
Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. The reward is paid only after the buyer pays and SourceX receives its fee, and no reward is guaranteed.
Questions to take to counsel
- Did our employee notice mention disclosure to third parties or use for analytics or AI?
- Which of our staff, contractors and applicants are California residents?
- Do we have EU or UK staff, offices or customers whose records sit in shared systems?
- Can we exclude those records by domain, location or workspace before delivery?
- Who signs for the company if a buyer asks for warranties about notices and rights?
Next step
Run a quick screen with the company fit checker and read how the process works. If you know a US company with 50+ full-time employees at peak (contractors excluded) and years of records, register as a partner and make the introduction.
Common questions
Does the CCPA protect employees the same way it protects customers?
The statute protects California residents, and workforce members can be among them. Rights and exceptions depend on current text, which has been amended and regulated further, so confirm with counsel how the employee notice, access and deletion rules apply to your company before relying on any summary.
Does a US company with one remote employee in Europe have to follow EU rules?
It can. Presence of even one EU-based worker may bring that person's records within EU rules, depending on how the company is established and what it does with the data. The simpler route for a license is to exclude that person's records from the dataset.
Is anonymized employee data outside both regimes?
Under the EU approach, data that truly cannot identify a person falls outside the rules, while pseudonymized data does not. California treats de-identified data differently if the business meets stated commitments. Either way the standard is demanding, so counsel and the buyer should agree the method in writing.
Do buyers want EU employee data at all?
Many buyers would rather receive a US-only dataset with documented rights than a mixed one that needs cross-border analysis. Cleaner provenance usually shortens review. Whether a buyer wants a second, EU-inclusive release is a commercial and legal question for the company and its counsel.
Can a referral partner confirm which regime applies to a company?
No. Partners make introductions and share basic fit information only. Deciding which privacy regime applies, and what a license may include, is for the company's counsel working with SourceX during rights review.
Related pages
- Does the CCPA apply to my business? Thresholds explained
- CCPA service provider vs contractor vs third party in data licensing
- GDPR further processing: can operational data be reused for AI training?
- CCPA deidentified data: the three commitments a company must make
- How to carve EU and UK records out of a US data license
- Check Company Fit for Data Licensing
Free resources
- Business succession planning assessment — Ten questions on successor, transition and documentation.
- NPV calculator — Net present value with a discounted cash flow table.
- Time value of money calculator — Future and present value with optional regular payments.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment