GDPR for US companies

Does GDPR apply to your US business?

Having EU customers is not automatically decisive. The test turns on whether you target EU residents deliberately, monitor their behavior, or have an establishment — including employees — in the EU.

When GDPR applies to a US company

GDPR applies if you have an establishment in the EU. Without one, it still applies if you offer goods or services to people in the EU or monitor their behavior there.

Having EU customers is not automatically decisive, and having EU employees often is. The page below sets out the three tests in order.

The three tests

The first test is establishment. If you have an EU entity, a branch, or any stable arrangement through which you carry out real and effective activity — including employees — GDPR applies to the processing carried out in that context.

The second test is deliberate targeting. Offering goods or services to EU residents brings you in scope, but offering means targeting deliberately. The regulators look for evidence: local currency, EU languages on the site, marketing aimed at EU users. Being technically accessible from the EU is not enough.

The third test is behavioral monitoring. Online tracking and profiling of EU users brings you in scope even without an establishment and without targeting in the commercial sense.

Article 27 representatives

Where GDPR applies without an EU establishment, you will usually need an Article 27 representative in the EU. Where UK GDPR is also engaged, you will need a separate representative in the UK. These are distinct obligations and a single representative does not satisfy both.

Transferring data out of the EU

Transfers out of the EU require a valid mechanism. In most cases that means standard contractual clauses supported by a transfer impact assessment. Where you are certified to the Data Privacy Framework, that framework is an alternative.

Questions on this page

We have EU customers but no EU entity. Does GDPR apply?

Not automatically on that basis alone. The question is whether you are deliberately targeting EU residents — evidenced by things like local currency, EU languages, or EU-directed marketing — or monitoring their behavior online. Accessibility from the EU is not the same as targeting.

We are hiring in Germany. Does that change anything?

Yes. Having EU employees is frequently the factor that brings a US business into scope, even where the commercial offering is not directed at the EU. Employment relationships in the EU are an establishment for GDPR purposes.

We are in scope without an EU entity. Do we need a representative?

Usually yes. Where GDPR applies without an establishment you will usually need an Article 27 representative in the EU. If UK GDPR is also engaged, you need a separate representative in the UK — one appointment does not cover both.

What do we need to transfer personal data from the EU to the US?

A valid transfer mechanism. In most cases that is standard contractual clauses supported by a transfer impact assessment. If you are certified to the Data Privacy Framework, that is an alternative route.

Last reviewed 4 September 2026. These pages are reviewed quarterly; if a date here is more than three months old, ask before relying on it.

Not sure whether GDPR applies to you?

Get in touch

A scoped gap assessment is the right starting point. Fixed scope, fixed fee, four to twelve weeks.

Write to us

Prefer email? Start here.

A short note about your situation is plenty. Replies come from rasha.hisham@appliedprivacyconsulting.com.