The direct answer
This surprises many US business owners. GDPR is not limited to European companies. It is a data protection law that protects EU residents, and it applies to any organisation worldwide that processes their data. This is known as the "extraterritorial scope" of GDPR and is explicitly stated in Article 3.
Why GDPR applies to US businesses
Article 3 of GDPR establishes two triggers that bring a non-EU organisation into scope:
Trigger 1: You offer goods or services to EU residents
If your website is accessible to EU residents and you clearly intend to serve them — for example, your site mentions EU countries, accepts euros, ships to EU addresses, or displays content in EU languages — GDPR applies. You don't need to charge them or have a formal business relationship. Free services, free apps, and free newsletters all count.
Trigger 2: You monitor EU residents' behaviour
If you track EU residents' online behaviour — through analytics, advertising pixels, retargeting, or behavioural profiling — GDPR applies. Installing Google Analytics on a publicly accessible website almost certainly triggers this.
Note what's not required: you don't need EU employees, EU servers, EU customers who have paid you money, or any physical presence in Europe. EU visitors = GDPR applies.
Which US businesses are covered?
The following US businesses are subject to GDPR:
- E-commerce stores that ship to or accept orders from EU customers
- SaaS products with EU users (even free-tier users)
- Newsletters and email lists with EU subscribers
- Apps downloaded by EU users from the App Store or Google Play
- Content websites (blogs, news, media) with EU readers, if they run analytics or ads
- B2B software used by EU employees of EU companies
- Online marketplaces and platforms with EU sellers or buyers
- US companies that process EU employee data (even just payroll data for EU staff)
The following are generally not covered (absent other factors):
- A purely local US business whose website receives no EU traffic (and has geo-blocking in place)
- A US company that processes only data of US residents with no EU activity
What you must actually do
GDPR compliance for a typical US website or SaaS product involves five main areas:
1. Cookie consent banner
If you use analytics, advertising pixels, or any tracking that sets cookies on EU visitors' devices, you need a compliant cookie consent banner. Cookies must not fire until the visitor gives explicit, informed consent. "Implied consent" (continuing to browse = consent) is not valid under GDPR.
Full guide: Do I need a cookie banner? →
2. GDPR-compliant privacy policy
Your privacy policy must include, at minimum:
- What personal data you collect and how
- The legal basis for processing (consent, legitimate interest, contract, legal obligation)
- Who you share data with (third parties, processors, sub-processors)
- Whether data is transferred outside the EU and the safeguards in place
- How long you retain data
- EU residents' rights: access, rectification, erasure, portability, restriction, objection
- How to exercise those rights (contact method, response time)
- Your contact details and, if applicable, your EU representative's details
3. Data subject rights process
You need a way for EU residents to submit requests to access, correct, or delete their data — and you must respond within 30 days. This can be as simple as a dedicated email address (privacy@yourcompany.com) or a web form. Larger companies use dedicated DSAR (Data Subject Access Request) workflow tools.
4. Data Processing Agreements (DPAs)
For every third-party service that processes EU personal data on your behalf — your email provider, analytics platform, CRM, cloud host — you need a Data Processing Agreement in place. Major vendors (Google, AWS, Mailchimp, HubSpot) provide these automatically in their terms or upon request. Keep a record of all processors.
5. Data breach notification
If you experience a personal data breach, you must notify the relevant EU supervisory authority within 72 hours of becoming aware. If the breach poses a high risk to individuals, you must also notify affected EU residents directly. Document all breaches, even those you don't need to notify.
Fines and enforcement: what actually happens
GDPR has two tiers of fines:
- Lower tier: Up to €10 million or 2% of global annual turnover — for violations of data security requirements, processor obligations, or breach notification failures
- Upper tier: Up to €20 million or 4% of global annual turnover — for violations of core principles, lawfulness of processing, data subjects' rights, or international transfers
US companies that have been fined under GDPR
| Company | Fine | Authority | Reason |
|---|---|---|---|
| Meta (Facebook) | €1.2 billion | Ireland DPC | Unlawful EU-US data transfers |
| Amazon | €746 million | Luxembourg CNPD | Advertising targeting without proper consent |
| Meta (Instagram) | €405 million | Ireland DPC | Children's data handling |
| €310 million | Ireland DPC | Unlawful processing for targeted advertising | |
| TikTok | €345 million | Ireland DPC | Children's data and default privacy settings |
While these are large-company cases, EU supervisory authorities also routinely fine small and mid-size businesses. German, French, and Italian DPAs in particular have issued fines to individual website operators for missing cookie consent or defective privacy policies.
Do you need an EU representative?
Article 27 of GDPR requires non-EU organisations that regularly process EU personal data (not just occasionally) to appoint an EU representative — a person or entity physically located in the EU that can act as a contact point for EU data protection authorities and EU residents.
You likely need an EU representative if:
- You regularly receive EU visitors or customers (even if not paying)
- You run analytics that track EU residents' behaviour
- You have EU subscribers to your email list
- You process EU employees' data
You don't need one if your processing of EU data is occasional, low-risk, and does not include special category data.
EU representative services are available from third-party providers for around $200–$500 per year. It is a low-cost compliance checkbox that protects you from authorities being unable to contact you.
Transferring data from the EU to the US
When EU personal data is transferred to or accessed from the US — including by your US-based cloud infrastructure, support team, or analytics provider — you need a legal transfer mechanism.
EU-US Data Privacy Framework (DPF)
As of July 2023, the EU-US Data Privacy Framework is the primary transfer mechanism. US companies can self-certify with the DPF via the US Department of Commerce. Certification covers transfers to your own organisation. It does not cover transfers from your organisation to sub-processors.
Standard Contractual Clauses (SCCs)
For transfers to US processors (AWS, Google Cloud, Mailchimp, Stripe, etc.), the transfer is covered by Standard Contractual Clauses included in those vendors' Data Processing Agreements. When you sign a DPA with a major US provider, SCCs are typically included automatically.
GDPR compliance checklist for US companies
Use this as a starting point. Work through each item and document your progress.
Foundations
- ☐ Confirm whether GDPR applies (check analytics for EU traffic)
- ☐ Identify all personal data you collect from EU residents
- ☐ Map where that data is stored and who can access it
- ☐ Identify all third-party processors (email, analytics, CRM, hosting, payments)
Legal documents
- ☐ Update privacy policy to meet GDPR disclosure requirements
- ☐ Sign Data Processing Agreements with all third-party processors
- ☐ Add cookie policy (can be a section of your privacy policy)
- ☐ Update terms of service if you handle EU customer data
Consent & cookies
- ☐ Install a GDPR-compliant cookie consent banner
- ☐ Confirm cookies are blocked before consent fires
- ☐ Offer granular consent categories (analytics, advertising, etc.)
- ☐ Implement a way for visitors to withdraw consent
- ☐ Store consent records
Data subject rights
- ☐ Create a process to receive and respond to access requests
- ☐ Create a process to handle deletion requests (right to erasure)
- ☐ Document your 30-day response commitment
- ☐ Test the process with an internal request
Transfers & representation
- ☐ Confirm EU-US transfer mechanism (DPF self-certification or SCCs via vendor DPAs)
- ☐ Appoint an EU representative if required (Article 27)
- ☐ Add EU representative details to your privacy policy
Security & incidents
- ☐ Implement appropriate security for personal data (encryption, access controls)
- ☐ Create a data breach response plan
- ☐ Know how to identify the relevant EU supervisory authority for your users' countries
Tools that help US companies become GDPR compliant
CookieYes
Fastest cookie banner to set up. Free up to 25k visits/month, blocks cookies before consent, Google Consent Mode v2 ready.
iubenda
Lawyer-vetted privacy policy and cookie banner in one subscription. Covers GDPR, CCPA, and LGPD. Ideal if you need compliant legal documents and consent management together.
Plausible Analytics
Cookie-free analytics. No consent banner needed for analytics tracking. Replace Google Analytics and eliminate an entire GDPR compliance step. No affiliate relationship — we use Plausible ourselves and recommend it on that basis.
Frequently asked questions
Does GDPR apply to US companies?
Yes. GDPR applies to any organisation that processes the personal data of EU residents, regardless of where the organisation is located. A US startup, a freelancer in Texas, and a Fortune 500 company are all subject to GDPR if they have EU visitors or customers.
What happens if a US company ignores GDPR?
EU data protection authorities can fine organisations up to €20 million or 4% of global annual turnover — whichever is higher. US companies are not immune: Meta, LinkedIn, and Amazon have all been fined under GDPR. EU authorities can also issue orders to stop processing EU data, which effectively means stopping service to EU customers.
Do I need a GDPR privacy policy if I'm a US company?
Yes. If you have EU visitors or customers, your privacy policy must meet GDPR standards: disclose what data you collect, why, the legal basis for processing, how long you keep it, whether you transfer it outside the EU, and users' rights (access, deletion, portability, objection).
Can I just block EU visitors to avoid GDPR?
Technically yes, but it's rarely practical or advisable. Blocking EU traffic costs you a significant customer base, and you must implement geo-blocking correctly and consistently. Most US businesses find it cheaper to simply implement a cookie banner and a GDPR-compliant privacy policy.
Do I need to appoint a Data Protection Officer (DPO) as a US company?
Not always. A DPO is required only if you (a) are a public authority, (b) carry out large-scale systematic monitoring of individuals, or (c) process special category data at large scale. Most US SMBs do not meet these thresholds. However, GDPR Article 27 requires non-EU companies to appoint an EU representative if they regularly process EU residents' data.
What is an EU representative and do I need one?
An EU representative is a contact point for EU data protection authorities and individuals — a person or company physically located in the EU. If you're a non-EU business that regularly processes EU personal data (not just occasionally), Article 27 of GDPR requires you to appoint one. Services like VeraSafe and DataRep offer this for around $200–$500/year.
Does the EU-US Data Privacy Framework replace GDPR compliance?
No. The EU-US Data Privacy Framework (DPF) only covers the legal mechanism for transferring EU personal data from the EU to the US. It does not replace GDPR compliance obligations — you still need a cookie banner, privacy policy, data subject rights process, and all other GDPR requirements. DPF certification solves only the cross-border transfer piece.
Is GDPR the same as CCPA?
No. GDPR is EU law protecting EU residents; CCPA is California law protecting California residents. They have different requirements. GDPR requires opt-in consent before processing; CCPA requires opt-out mechanisms. You may need to comply with both if you have EU and California visitors. See our GDPR vs CCPA comparison →