Regulatory scope

Which regulations apply to you

Start with where your data subjects are, not where you are incorporated. The answer determines which obligations apply, at what threshold, and on what timeline.

Scope first, then obligations

The question most businesses ask is 'are we covered by GDPR?' The more useful question is 'where are our data subjects, and what does that trigger?' Incorporation and registered address are almost never the deciding factors. Establishment, market targeting, behavioral monitoring, and the nature of the processing are.

Each framework linked below sets out who it reaches, what the core obligations are, and where the genuine differences sit — thresholds, exemptions, assessment triggers, transfer mechanisms. The goal is a clear picture of what applies, so that the compliance work addresses the right obligations rather than the largest or most visible ones.

In practice most companies build to the strictest applicable standard and apply it uniformly, because operating divergent processes by jurisdiction costs more than it saves. The guides below are intended to help you reach that starting point.

How to read your own exposure

For US state law, start with where your data subjects are, then test against each state's thresholds — typically revenue, the number of residents whose data you process, or the share of revenue derived from selling personal data.

For GDPR and UK GDPR, the test is establishment in the EU or UK, or, without one, deliberate targeting of people there or monitoring of their behavior. Having EU or UK customers is not automatically decisive; having EU or UK employees often is.

For the EU AI Act, the question is whether you place an AI system on the EU market or whether the output of your system is used in the EU — regardless of where you are established. The first step is not compliance work; it is an inventory and a classification, because most companies find their EU exposure is narrower than feared and concentrated in one or two systems.

Where any of these reach you, the pages below set out what follows.

Not sure which frameworks reach you?

Start the conversation

A scoping conversation takes an hour. We work through where your data subjects are, what you do with their data, and which obligations follow from that — before any engagement begins.

Write to us

Prefer email? Start here.

A short note about your situation is plenty. Replies come from rasha.hisham@appliedprivacyconsulting.com.