Start with where your data subjects are, not where you are incorporated. The answer determines which obligations apply, at what threshold, and on what timeline.
The question most businesses ask is 'are we covered by GDPR?' The more useful question is 'where are our data subjects, and what does that trigger?' Incorporation and registered address are almost never the deciding factors. Establishment, market targeting, behavioral monitoring, and the nature of the processing are.
Each framework linked below sets out who it reaches, what the core obligations are, and where the genuine differences sit — thresholds, exemptions, assessment triggers, transfer mechanisms. The goal is a clear picture of what applies, so that the compliance work addresses the right obligations rather than the largest or most visible ones.
In practice most companies build to the strictest applicable standard and apply it uniformly, because operating divergent processes by jurisdiction costs more than it saves. The guides below are intended to help you reach that starting point.
For US state law, start with where your data subjects are, then test against each state's thresholds — typically revenue, the number of residents whose data you process, or the share of revenue derived from selling personal data.
For GDPR and UK GDPR, the test is establishment in the EU or UK, or, without one, deliberate targeting of people there or monitoring of their behavior. Having EU or UK customers is not automatically decisive; having EU or UK employees often is.
For the EU AI Act, the question is whether you place an AI system on the EU market or whether the output of your system is used in the EU — regardless of where you are established. The first step is not compliance work; it is an inventory and a classification, because most companies find their EU exposure is narrower than feared and concentrated in one or two systems.
Where any of these reach you, the pages below set out what follows.
A scoping conversation takes an hour. We work through where your data subjects are, what you do with their data, and which obligations follow from that — before any engagement begins.
A short note about your situation is plenty. Replies come from rasha.hisham@appliedprivacyconsulting.com.
We use Google Analytics 4 to understand how this site is used and to measure our advertising. These set cookies on your device. Nothing loads until you choose. How we handle your data.