GDPR · Territorial scope

Does GDPR apply to my US company?

Probably — but not for the reason most articles give you, and not automatically.

The short answer

GDPR can apply to a company with no EU office, no EU staff and no EU bank account. What triggers it is not where you are. It is who you are aiming at.

And the opposite is also true, which almost nobody writes down: if EU residents happen to find your website and buy something, that alone does not put you in scope. The regulation says so explicitly.

The rest of this page is the actual test, in the actual words, and the four misconceptions that send US founders in the wrong direction.


The test that matters: Article 3(2)

GDPR has two doors. Most US companies are worried about the wrong one.

Two words to pin down first, because the regulation leans on them constantly — and which one you are changes what you owe.

Controller

You decide why and how data gets used. That is you, for your own customer list, your marketing contacts and your staff records.

Processor

You handle data on someone else's instructions. That is you, for whatever your customers put into your product.

Most software companies are both at once, in different directions. Where this page says "controller or processor," read it as "your company, in one role or the other."

With that settled: GDPR has two doors, and most US companies are worried about the wrong one.

Door 1 · usually not you Establishment

Article 3(1) covers processing "in the context of the activities of an establishment… in the Union." No EU entity, no branch, no staff there — this one probably does not catch you.

Door 2 · the one that does Targeting

Article 3(2) covers companies not established in the Union that offer goods or services to people in the EU, or monitor their behaviour there.

Door 2 is the whole game for a US company. Here is what it actually says:

GDPR Article 3(2)

"(a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or

(b) the monitoring of their behaviour as far as their behaviour takes place within the Union."

Read (a) again, because two details in it catch people out.

"Irrespective of whether a payment is required." A free tier counts. A free trial counts. A free downloadable guide that collects email addresses counts. Revenue is not the trigger.

"To such data subjects in the Union" — not citizens, not residents. People in the Union. An American on a business trip in Berlin counts, for as long as they are there. This is a wider net than nationality-based thinking suggests, and it is why "we only sell to Americans" is a weaker defence than it sounds if some of those Americans are in Europe when they use your product.

And (b) — monitoring behaviour — catches analytics, behavioural advertising, session recording and profiling of people in the EU, whether or not you sell them anything at all.

What "offering goods or services" actually requires

Here is the part that most content on this subject gets wrong, usually in the direction of scaring you.

Being reachable from Europe is not the test. Recital 23 — the interpretive text that goes with Article 3 — draws the line explicitly, and it cuts both ways:

Not enough on its own
  • "mere accessibility" of your website from the EU
  • publishing "an email address or other contact details"
  • "the use of a language generally used in the third country where the controller is established" — English, for a US company
Evidence you are targeting the EU
  • "the use of a language or a currency generally used in one or more Member States" — pricing in euros, or a German or French version of your site
  • "the mentioning of customers or users who are in the Union" — EU logos, EU case studies, European testimonials

So an English-language site, run from Ohio, priced in dollars, reachable worldwide, that has never mentioned Europe, is not automatically in scope just because a German can load it.

The threshold the recital sets is whether "it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States." Envisages. It is a question about your intent, evidenced by what you have published.

The practical version: look at your own marketing and ask what it would look like to a regulator. Do you price in euros? Do you have a page about serving European customers? Does your ad targeting include EU countries? Do you name EU customers? Each of those is evidence you envisaged EU users. None of them individually decides it, and their absence is meaningful too.

This is a real test with a real answer, not a formality where everyone is in scope. That cuts both ways — which is why guessing is a bad strategy in either direction.

Four things that do not get you out of it

Each of these is something US founders say with real confidence. Each is wrong — and three of the four are wrong for an interesting reason.

1"We have fewer than 250 employees"

The 250-person rule is real — but it exempts you from one piece of paperwork, not from GDPR. And most software companies do not qualify for it anyway.

Article 30(5) is narrow in two ways almost nobody mentions. First, all it excuses is keeping records of what you do with data. Whether GDPR applies to you, your reason for using the data, people's rights over it, breach notification, security: all untouched.

Second, three conditions cancel it — and you only need to hit one:

  • the handling is "likely to result in a risk to the rights and freedoms of data subjects"
  • "the processing is not occasional"
  • you handle sensitive data — health, biometrics, religious or political views (Article 9(1)) — or criminal conviction records (Article 10)

What this means for you: a five-person SaaS company with European customers handles their data every working day. That is not "occasional," so the exemption is gone on the middle condition alone — and even if you did qualify, it would only ever have saved you from writing one document.

2"We're B2B, so it's company data, not personal data"

There is no B2B exemption in GDPR. Your business contacts are people, and the regulation protects people.

A work email address, a name, a job title, an IP address, a login record — all of it is personal data about a human being who happens to be at their desk.

The confusion is reasonable, though, because some other EU rules genuinely do draw that line. The ePrivacy Directive's marketing rules say at Article 13(5) that they "shall apply to subscribers who are natural persons," then ask only that Member States ensure the interests of other subscribers "are sufficiently protected" — leaving business-to-business to national law.

What this means for you: you might lawfully cold-email a German company address under German marketing rules, and still owe that same person a privacy notice, a lawful basis, and the right to have their data deleted. Marketing rules vary by country. GDPR does not.

3"We use a US cloud provider, so the data never leaves the US"

Where you keep the data does not decide whether GDPR applies. It only adds a second question once it already does.

Two separate questions run in order here. Does GDPR apply? — settled by Article 3, above. May you send that data to the US? — a different question with different rules, and you only reach it after the first is answered yes.

What this means for you: moving your database from Frankfurt to Virginia does not get you out of GDPR. It gets you GDPR and a transfer problem.

4"We'll deal with it if a European customer signs up"

The obligations start when you start handling the data — not when somebody asks you about it.

Your written record of what you hold, your reason for holding it, a privacy notice that describes what your system actually does, and a way for someone to ask what you have on them are all supposed to exist before the first EU user arrives.

What this means for you: the first request you receive arrives with a one-month deadline attached. That is not enough time to work out your lawful basis, write an accurate privacy notice and build a way to answer it — so the work has to happen in the quiet, not under the clock.

So it applies. What actually follows?

Not the panic version. Six things change — and most of them are paperwork you do once and then maintain.

1
A named contact inside the EU

Regulators and individuals get someone in the Union to write to instead of chasing you across the Atlantic. Article 27 requires this wherever Article 3(2) applies. There is an exemption, but it only covers handling that is genuinely occasional — a product your EU customers use every day is not that.

It is a paid service, billed annually, and the representative has to be named in your privacy notice. We appointed ours in July 2026, so this is a step we have been through rather than one we are describing from the outside.

2
A reason you are allowed to use the data

The regulation calls this a "lawful basis," and you need one for every separate purpose you use the data for. Decide it before you start — not in a privacy policy written afterwards to describe what you already did.

3
A privacy notice that matches what your system actually does

This is where most small companies fail, and the failure is entirely self-inflicted: the notice describes an architecture the company has since changed.

4
A written record of what you hold and why

Unless you genuinely clear the Article 30(5) bar described above — and if you have read this far, you probably do not.

5
A way for people to exercise their rights

They can ask to see their data, correct it, or have it deleted. You have one month to respond, so this needs to be a route that exists rather than one you improvise on the day.

6
Telling the regulator about a breach

Your national data protection authority — the regulation calls it a "supervisory authority" — within 72 hours of becoming aware, where the breach is likely to put people at risk.

And one that is genuinely unsettled: sending data to the US

If your data lands on US servers, you need a lawful route for moving it there. For most US companies that route is the EU–US Data Privacy Framework, and it survived its first major legal challenge: on 3 September 2025 the European General Court dismissed Latombe v Commission (Case T-553/23), holding that the US provides an adequate level of protection.

That is not the end of the story, and the detail matters if you are about to build on it.

The Framework is under appeal
Upheld3 September 2025 — European General Court, Latombe v Commission (T-553/23)
Appealed31 October 2025 — to the Court of Justice, on surveillance and redress grounds
StatusNo ruling as of August 2026
Also noteThe Commission may "suspend, amend or repeal" it if US law changes
Track recordThird attempt — Safe Harbour and Privacy Shield were both struck down by the same court now hearing the appeal

Why this matters to you: nothing to do today. But if the Framework is the only thing holding up your US transfers and the court strikes it down, you re-paper every one of them at once, under time pressure, alongside everyone else doing the same. Sign standard contractual clauses as well, and the same ruling costs you a read-through.

So: the Framework is valid today and usable today — just not the only thing you build on. Certify if it helps you win deals, and keep standard contractual clauses in place underneath it. Those clauses are pre-approved contract wording that authorises a transfer on its own, and signing them costs you an afternoon. That is not pessimism; it is what the last ten years of this particular question have taught anyone paying attention.

What getting it wrong costs

The statutory maxima under Article 83 are two-tier:

Article 83(4) · lower tier
€10 million
or 2% of worldwide annual turnover, whichever is higher

Security, records, and the representative requirement.

Article 83(5) · upper tier
€20 million
or 4% of worldwide annual turnover, whichever is higher

The basic principles, your reason for using the data, people's rights, and international transfers.

Two things about those numbers deserve saying plainly, because most articles quote them and stop.

They are maxima, not tariffs. Article 83 requires fines to be "effective, proportionate and dissuasive," assessed against a list of factors including the nature and gravity of the infringement, whether it was negligent or intentional, and what you did to mitigate it. The headline figures come from cases involving very large companies and serious, sustained infringements. A small company that got something wrong and fixed it is not in that category.

The fine is usually not the real cost anyway. For a small B2B company, the practical damage arrives earlier and more quietly: an enterprise prospect's security review that you cannot answer, a procurement questionnaire that stalls the deal, a customer asking for a signed data processing agreement you do not have. Those cost you revenue long before a regulator ever looks at you.

Working out where you actually stand

The honest summary of everything above: applicability is a real question with a real answer, and it depends on specifics about your business — what you publish, who you target, what you process, and how continuously.

Most companies in this position are guessing. They have read a few articles, concluded either "we're fine, we're small" or "we're doomed, it's €20 million," and both conclusions are usually wrong.

Our scope checker exists to replace that guess with an answer. It asks about seven plain-language questions and tells you whether GDPR, NIS2 and the EU AI Act reach your business.

Four things about how it works, because they are the reasons to trust the result:

  • It tests both Article 3 routes. Not just the targeting question this page has spent most of its length on, but establishment as well — an EU-registered company whose customers are all American is still covered by Article 3(1), and the checker will not tell you otherwise.
  • It runs entirely in your browser. Your answers never reach our servers. You do not need an account and you do not need to give us an email address to see the result.
  • It will tell you a regulation does not apply, and name the clause that decided it. "Not in scope" is a real answer that we are happy to give, and knowing why you are out matters — being under a size threshold and being outside a sector entirely are very different futures.
  • Where the honest answer is "it depends," it says so rather than guessing, and if you answer "not sure" it assumes the regulation applies until you find out. It is built to err toward telling you to look harder.

What it does not do is settle the harder judgement calls. Whether your marketing amounts to targeting the EU under Recital 23, and whether you clear the Article 27 or Article 30 thresholds, are questions this page can teach you to ask but no seven-question tool should claim to answer. The checker tells you which door you are at. It does not replace a lawyer for what is behind it — and as it says itself, a quiet result is a starting point, not a clearance.

If it turns out GDPR does reach you, the free readiness check goes a level deeper: a score out of 100 against the controls that matter, your top three gaps, and the single thing to fix first.

Find out what actually applies to you

About seven plain-language questions. Free, no account, and your answers never leave your device.

Sources cited on this page

  • GDPR Article 3 — territorial scope
  • GDPR Recital 23 — offering goods or services to data subjects in the Union
  • GDPR Article 27 — representatives of controllers or processors not established in the Union
  • GDPR Article 30(5) — records of processing, small-organisation exemption
  • GDPR Article 83(1), 83(4) and 83(5) — administrative fines
  • ePrivacy Directive Article 13(5) — unsolicited communications and legal persons
  • Latombe v Commission, Case T-553/23 — European General Court, 3 September 2025; under appeal to the CJEU since 31 October 2025
This page explains what the regulation says and cites it directly so you can read the text yourself. It is general information about how GDPR works, not legal advice about your specific situation — the territorial, size and sector tests all have real nuance, and for your own position you want a qualified data protection lawyer. Kaixon is a product of Radius Studios LLC.
Last reviewed: 8 August 2026.