Does the GDPR apply to a US SaaS with no EU office?
The GDPR applies to a US SaaS with no EU office if it offers goods or services to individuals in the EU, or monitors their behaviour in the EU, under Article 3. There is no revenue or user-number threshold; targeting or monitoring EU users is enough to bring you in scope.
Applies to: Non-EU businesses, including US SaaS companies, that offer goods or services to individuals in the EU or monitor the behaviour of individuals in the EU.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanFounding 30% off with code FOUNDING until 15 August 2026
Plenty of US SaaS founders assume the GDPR is a European problem for European companies. It is not. The GDPR reaches across borders by design, and the question is never where your company is incorporated. It is whether you are dealing with people in the EU. Article 3 is the provision that decides this, and it does not care about your size.
The two ways a non-EU business gets caught
Article 3(2) extends the GDPR to a controller or processor not established in the EU in two situations. The first is offering goods or services to data subjects in the Union, whether or not payment is required. The second is monitoring the behaviour of data subjects as far as that behaviour takes place within the Union. If either is true, the whole regulation applies to that processing, even though your servers, staff, and headquarters sit in the United States.
What counts as offering goods or services
Merely running a website that Europeans can reach is not enough on its own. What matters is whether you envisage offering to people in the EU. Regulators look at signals such as using an EU language or currency, letting customers choose an EU country, quoting prices in euros, or running EU-targeted marketing. A SaaS that sells subscriptions to customers in Germany or France, in euros, is squarely in scope. If you have deliberately avoided EU customers, you have a stronger argument that you are not.
What counts as monitoring behaviour
Monitoring is broader than most founders expect. Tracking EU visitors with analytics, advertising cookies, session recording, or profiling to predict preferences all count as monitoring behaviour that takes place in the Union. This is why so many US sites end up needing a compliant cookie consent banner even without a single paying EU customer. If you set tracking technologies on people in the EU, Article 3(2)(b) is likely engaged.
There is no size threshold
This is the part that surprises people who are used to US state laws. Virginia, Utah, and Oregon all set consumer counts or revenue figures before their laws apply. The GDPR has none. A one-person startup with a handful of EU users is in scope on the same terms as a large enterprise. Size changes some downstream duties, such as the narrow Article 30 records exemption for organisations under 250 staff, but it never changes whether the GDPR applies in the first place.
Then Article 27 may follow
Once Article 3(2) catches you, Article 27 often requires you to appoint a representative established in the EU, a local contact point for individuals and supervisory authorities, unless a limited exemption fits. Alongside that you need a lawful basis, a privacy notice, and a way to handle data subject rights. The GDPR compliance hub walks through the duties in order.
Next step
Working out whether you offer or monitor, and whether you need a representative, is exactly the kind of judgement call that stalls launches. The free 2-minute Obligation Scan checks your Article 3 position and flags whether Article 27 and the core GDPR duties apply to you, so you can act on facts rather than on a founder myth.
Compliance checklist
- Decide whether you offer goods or services to individuals in the EU, using signals such as EU currencies, languages, or country targeting, not just an accessible website.
- Decide whether you monitor the behaviour of people in the EU, which includes analytics, tracking cookies, and profiling of EU visitors.
- If either is true, treat yourself as in scope under Article 3(2) regardless of company size or revenue.
- Assess whether Article 27 requires you to appoint an EU representative, and appoint one if so.
- Establish a lawful basis, a privacy notice, and a records and rights-handling process before you continue processing EU personal data.
Sources
- Regulation (EU) 2016/679 (GDPR), Article 3 (territorial scope), official text on EUR-Lex
- Regulation (EU) 2016/679 (GDPR), Article 27 (representatives not established in the Union), EUR-Lex
Last verified: 2026-07-21
Informational, not legal advice.