Having EU customers is not automatically decisive. The test turns on whether you target EU residents deliberately, monitor their behavior, or have an establishment — including employees — in the EU.
GDPR applies if you have an establishment in the EU. Without one, it still applies if you offer goods or services to people in the EU or monitor their behavior there.
Having EU customers is not automatically decisive, and having EU employees often is. The page below sets out the three tests in order.
The first test is establishment. If you have an EU entity, a branch, or any stable arrangement through which you carry out real and effective activity — including employees — GDPR applies to the processing carried out in that context.
The second test is deliberate targeting. Offering goods or services to EU residents brings you in scope, but offering means targeting deliberately. The regulators look for evidence: local currency, EU languages on the site, marketing aimed at EU users. Being technically accessible from the EU is not enough.
The third test is behavioral monitoring. Online tracking and profiling of EU users brings you in scope even without an establishment and without targeting in the commercial sense.
Where GDPR applies without an EU establishment, you will usually need an Article 27 representative in the EU. Where UK GDPR is also engaged, you will need a separate representative in the UK. These are distinct obligations and a single representative does not satisfy both.
Transfers out of the EU require a valid mechanism. In most cases that means standard contractual clauses supported by a transfer impact assessment. Where you are certified to the Data Privacy Framework, that framework is an alternative.
Not automatically on that basis alone. The question is whether you are deliberately targeting EU residents — evidenced by things like local currency, EU languages, or EU-directed marketing — or monitoring their behavior online. Accessibility from the EU is not the same as targeting.
Yes. Having EU employees is frequently the factor that brings a US business into scope, even where the commercial offering is not directed at the EU. Employment relationships in the EU are an establishment for GDPR purposes.
Usually yes. Where GDPR applies without an establishment you will usually need an Article 27 representative in the EU. If UK GDPR is also engaged, you need a separate representative in the UK — one appointment does not cover both.
A valid transfer mechanism. In most cases that is standard contractual clauses supported by a transfer impact assessment. If you are certified to the Data Privacy Framework, that is an alternative route.
A scoped gap assessment is the right starting point. Fixed scope, fixed fee, four to twelve weeks.
A short note about your situation is plenty. Replies come from rasha.hisham@appliedprivacyconsulting.com.
We use Google Analytics 4 to understand how this site is used and to measure our advertising. These set cookies on your device. Nothing loads until you choose. How we handle your data.