The direct answer

Yes, GDPR applies to your US business if any of these are true: EU residents visit your website, use your app, buy your products, or sign up for your mailing list — regardless of whether you have offices, employees, or servers in Europe.

This surprises many US business owners. GDPR is not limited to European companies. It is a data protection law that protects EU residents, and it applies to any organisation worldwide that processes their data. This is known as the "extraterritorial scope" of GDPR and is explicitly stated in Article 3.

Why GDPR applies to US businesses

Article 3 of GDPR establishes two triggers that bring a non-EU organisation into scope:

Trigger 1: You offer goods or services to EU residents

If your website is accessible to EU residents and you clearly intend to serve them — for example, your site mentions EU countries, accepts euros, ships to EU addresses, or displays content in EU languages — GDPR applies. You don't need to charge them or have a formal business relationship. Free services, free apps, and free newsletters all count.

Trigger 2: You monitor EU residents' behaviour

If you track EU residents' online behaviour — through analytics, advertising pixels, retargeting, or behavioural profiling — GDPR applies. Installing Google Analytics on a publicly accessible website almost certainly triggers this.

Note what's not required: you don't need EU employees, EU servers, EU customers who have paid you money, or any physical presence in Europe. EU visitors = GDPR applies.

Which US businesses are covered?

The following US businesses are subject to GDPR:

The following are generally not covered (absent other factors):

Real-world test: Open your Google Analytics (or equivalent). If you see sessions from Germany, France, the UK, the Netherlands, or any other EU/EEA country — GDPR applies to you.

What you must actually do

GDPR compliance for a typical US website or SaaS product involves five main areas:

1. Cookie consent banner

If you use analytics, advertising pixels, or any tracking that sets cookies on EU visitors' devices, you need a compliant cookie consent banner. Cookies must not fire until the visitor gives explicit, informed consent. "Implied consent" (continuing to browse = consent) is not valid under GDPR.

Full guide: Do I need a cookie banner? →

2. GDPR-compliant privacy policy

Your privacy policy must include, at minimum:

3. Data subject rights process

You need a way for EU residents to submit requests to access, correct, or delete their data — and you must respond within 30 days. This can be as simple as a dedicated email address (privacy@yourcompany.com) or a web form. Larger companies use dedicated DSAR (Data Subject Access Request) workflow tools.

4. Data Processing Agreements (DPAs)

For every third-party service that processes EU personal data on your behalf — your email provider, analytics platform, CRM, cloud host — you need a Data Processing Agreement in place. Major vendors (Google, AWS, Mailchimp, HubSpot) provide these automatically in their terms or upon request. Keep a record of all processors.

5. Data breach notification

If you experience a personal data breach, you must notify the relevant EU supervisory authority within 72 hours of becoming aware. If the breach poses a high risk to individuals, you must also notify affected EU residents directly. Document all breaches, even those you don't need to notify.

Fines and enforcement: what actually happens

GDPR has two tiers of fines:

US companies that have been fined under GDPR

Company Fine Authority Reason
Meta (Facebook) €1.2 billion Ireland DPC Unlawful EU-US data transfers
Amazon €746 million Luxembourg CNPD Advertising targeting without proper consent
Meta (Instagram) €405 million Ireland DPC Children's data handling
LinkedIn €310 million Ireland DPC Unlawful processing for targeted advertising
TikTok €345 million Ireland DPC Children's data and default privacy settings

While these are large-company cases, EU supervisory authorities also routinely fine small and mid-size businesses. German, French, and Italian DPAs in particular have issued fines to individual website operators for missing cookie consent or defective privacy policies.

Do you need an EU representative?

Article 27 of GDPR requires non-EU organisations that regularly process EU personal data (not just occasionally) to appoint an EU representative — a person or entity physically located in the EU that can act as a contact point for EU data protection authorities and EU residents.

You likely need an EU representative if:

You don't need one if your processing of EU data is occasional, low-risk, and does not include special category data.

EU representative services are available from third-party providers for around $200–$500 per year. It is a low-cost compliance checkbox that protects you from authorities being unable to contact you.

Transferring data from the EU to the US

When EU personal data is transferred to or accessed from the US — including by your US-based cloud infrastructure, support team, or analytics provider — you need a legal transfer mechanism.

EU-US Data Privacy Framework (DPF)

As of July 2023, the EU-US Data Privacy Framework is the primary transfer mechanism. US companies can self-certify with the DPF via the US Department of Commerce. Certification covers transfers to your own organisation. It does not cover transfers from your organisation to sub-processors.

Standard Contractual Clauses (SCCs)

For transfers to US processors (AWS, Google Cloud, Mailchimp, Stripe, etc.), the transfer is covered by Standard Contractual Clauses included in those vendors' Data Processing Agreements. When you sign a DPA with a major US provider, SCCs are typically included automatically.

Practical tip: Check whether your key vendors (email provider, CRM, analytics, payments) are DPF-certified or provide SCCs in their DPA. Most major US SaaS providers do — look for a "GDPR" or "Data Processing Agreement" page in their legal section.

GDPR compliance checklist for US companies

Use this as a starting point. Work through each item and document your progress.

Foundations

  • Confirm whether GDPR applies (check analytics for EU traffic)
  • Identify all personal data you collect from EU residents
  • Map where that data is stored and who can access it
  • Identify all third-party processors (email, analytics, CRM, hosting, payments)

Legal documents

  • Update privacy policy to meet GDPR disclosure requirements
  • Sign Data Processing Agreements with all third-party processors
  • Add cookie policy (can be a section of your privacy policy)
  • Update terms of service if you handle EU customer data

Consent & cookies

  • Install a GDPR-compliant cookie consent banner
  • Confirm cookies are blocked before consent fires
  • Offer granular consent categories (analytics, advertising, etc.)
  • Implement a way for visitors to withdraw consent
  • Store consent records

Data subject rights

  • Create a process to receive and respond to access requests
  • Create a process to handle deletion requests (right to erasure)
  • Document your 30-day response commitment
  • Test the process with an internal request

Transfers & representation

  • Confirm EU-US transfer mechanism (DPF self-certification or SCCs via vendor DPAs)
  • Appoint an EU representative if required (Article 27)
  • Add EU representative details to your privacy policy

Security & incidents

  • Implement appropriate security for personal data (encryption, access controls)
  • Create a data breach response plan
  • Know how to identify the relevant EU supervisory authority for your users' countries

Tools that help US companies become GDPR compliant

Cookie Consent

CookieYes

Fastest cookie banner to set up. Free up to 25k visits/month, blocks cookies before consent, Google Consent Mode v2 ready.

From: FreeScore: 4.8 / 5
Privacy Policy + Banner

iubenda

Lawyer-vetted privacy policy and cookie banner in one subscription. Covers GDPR, CCPA, and LGPD. Ideal if you need compliant legal documents and consent management together.

From: €4.99/moScore: 4.6 / 5
Analytics Without Consent

Plausible Analytics

Cookie-free analytics. No consent banner needed for analytics tracking. Replace Google Analytics and eliminate an entire GDPR compliance step. No affiliate relationship — we use Plausible ourselves and recommend it on that basis.

From: $9/moScore: 4.8 / 5

Frequently asked questions

Does GDPR apply to US companies?

Yes. GDPR applies to any organisation that processes the personal data of EU residents, regardless of where the organisation is located. A US startup, a freelancer in Texas, and a Fortune 500 company are all subject to GDPR if they have EU visitors or customers.

What happens if a US company ignores GDPR?

EU data protection authorities can fine organisations up to €20 million or 4% of global annual turnover — whichever is higher. US companies are not immune: Meta, LinkedIn, and Amazon have all been fined under GDPR. EU authorities can also issue orders to stop processing EU data, which effectively means stopping service to EU customers.

Do I need a GDPR privacy policy if I'm a US company?

Yes. If you have EU visitors or customers, your privacy policy must meet GDPR standards: disclose what data you collect, why, the legal basis for processing, how long you keep it, whether you transfer it outside the EU, and users' rights (access, deletion, portability, objection).

Can I just block EU visitors to avoid GDPR?

Technically yes, but it's rarely practical or advisable. Blocking EU traffic costs you a significant customer base, and you must implement geo-blocking correctly and consistently. Most US businesses find it cheaper to simply implement a cookie banner and a GDPR-compliant privacy policy.

Do I need to appoint a Data Protection Officer (DPO) as a US company?

Not always. A DPO is required only if you (a) are a public authority, (b) carry out large-scale systematic monitoring of individuals, or (c) process special category data at large scale. Most US SMBs do not meet these thresholds. However, GDPR Article 27 requires non-EU companies to appoint an EU representative if they regularly process EU residents' data.

What is an EU representative and do I need one?

An EU representative is a contact point for EU data protection authorities and individuals — a person or company physically located in the EU. If you're a non-EU business that regularly processes EU personal data (not just occasionally), Article 27 of GDPR requires you to appoint one. Services like VeraSafe and DataRep offer this for around $200–$500/year.

Does the EU-US Data Privacy Framework replace GDPR compliance?

No. The EU-US Data Privacy Framework (DPF) only covers the legal mechanism for transferring EU personal data from the EU to the US. It does not replace GDPR compliance obligations — you still need a cookie banner, privacy policy, data subject rights process, and all other GDPR requirements. DPF certification solves only the cross-border transfer piece.

Is GDPR the same as CCPA?

No. GDPR is EU law protecting EU residents; CCPA is California law protecting California residents. They have different requirements. GDPR requires opt-in consent before processing; CCPA requires opt-out mechanisms. You may need to comply with both if you have EU and California visitors. See our GDPR vs CCPA comparison →