Back to the hub

Does the GDPR apply to a US company?

The GDPR can apply to a US company with no European offices. Under Article 3, it reaches any organisation that offers goods or services to people in the EU, or monitors their behaviour there, even if no payment is required. A US business selling to or tracking EU users is usually caught.

Applies to: Non-EU businesses, including US companies, that offer goods or services to people in the EU or monitor the behaviour of people in the EU, and any organisation with an establishment in the EU.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

A common assumption among US founders is that the GDPR is a European problem for European companies. It is not. The regulation is written to follow the person whose data is processed, not the company's postal address, so a business in New York or Austin can be fully within scope while a business in Paris might not be.

Does the GDPR reach a company with no EU office?

Yes, it can. Article 3(2) applies the GDPR to a controller or processor that is not established in the Union when its processing relates to offering goods or services to people who are in the EU, or to monitoring their behaviour as it happens in the EU. There is a second route in: Article 3(1) applies the regulation to any processing carried out in the context of an EU establishment, wherever the processing itself takes place. So an EU branch or subsidiary pulls you in even if the servers sit in the United States.

What counts as offering goods or services?

Simply having a website that Europeans can reach is not enough on its own. Recital 23 asks whether it is apparent that you envisage offering to people in the EU. The signals it lists are practical: using a language or a currency of an EU country with the ability to order in it, or mentioning customers or users who are in the EU. An English-only site priced in dollars, with no EU marketing, points away from scope. A site offering euro pricing, EU-language checkout, or EU shipping points firmly towards it.

What counts as monitoring behaviour?

Article 3(2)(b) covers monitoring the behaviour of people in the EU. Recital 24 explains this as tracking people on the internet, including profiling to analyse or predict their preferences and behaviour. In practice, common analytics, advertising pixels, and behavioural tracking aimed at or capturing EU visitors can bring a US business within scope, even where nothing is sold. If you run remarketing or detailed product analytics on EU traffic, assume this branch is in play.

If the GDPR applies, what comes first?

Two things. Many non-EU companies in scope must appoint an EU representative under Article 27, and every controller needs a valid lawful basis under Article 6 for each activity. You will also usually need a record of processing activities and data processing agreements with your vendors. The GDPR compliance hub walks through the core duties in order.

Next step

Working out whether you offer or monitor at a level that triggers Article 3 is a judgement call, and getting it wrong in either direction is costly. The free 2-minute Obligation Scan checks your setup against the territorial-scope tests and tells you whether the GDPR applies to you, then points to the representative, lawful-basis, and record-keeping steps that follow.

Compliance checklist

  • Check whether you have any establishment in the EU, such as a branch, subsidiary, or staff, which brings processing under Article 3(1).
  • Assess whether you offer goods or services to people in the EU, using signals like EU languages, EU currencies, or naming EU customers.
  • Assess whether you monitor the behaviour of people in the EU, such as web tracking, analytics, or profiling of EU visitors.
  • If either applies, check whether you must appoint an EU representative under Article 27 and identify your lawful basis under Article 6.
  • Record which activities fall within scope so your position is documented rather than assumed.

Sources

Last verified: 2026-07-21

Informational, not legal advice.