Skip to content
    August 23, 2026| Top Floor Team| 12 min read

    Does GDPR Apply to My US Company?

    GDPR reaches a US company with no EU establishment at exactly two triggers and no third. Under Article 3(2), the Regulation applies to processing the personal data of people who are in the Union where the processing relates to "the offering of goods or services, irrespective of whether a payment of the data subject is required," or to "the monitoring of their behaviour as far as their behaviour takes place within the Union." The threshold most people are hunting for does not exist: no revenue floor, no employee count, no user count, no small-business exemption. A four-person shop that ships to Dublin is in scope, and a four-thousand-person shop that does not is out of it. Here is the part the ranking pages will not tell you, because they are almost all published by companies that sell consent banners or compliance automation: the honest answer is often no. The European Data Protection Board's Guidelines 3/2018 on territorial scope state that "the fact of processing personal data of an individual in the Union alone is not sufficient to trigger the application of the GDPR," and that the services trigger "is aimed at activities that intentionally, rather than inadvertently or incidentally, target individuals in the EU."

    This article walks both triggers in the language of the instruments, the evidence a regulator actually weighs, the fact patterns that put you outside the Regulation, and the obligation most US companies discover late once they decide they are inside it.

    Key takeaways

    • Article 3(2) has two triggers, offering goods or services to people in the Union and monitoring their behaviour in the Union, and no financial or headcount threshold under either.
    • EU visitors landing on a US-targeted site do not put you in scope. Intentional targeting does, and the EDPB says so in terms.
    • The monitoring trigger catches more US companies than the offering trigger, because behavioural advertising and cookie-based tracking are named examples of monitoring.
    • If Article 3(2) reaches you and you have no EU establishment, Article 27 usually requires an EU representative; the derogation is narrow and its "occasional" test is stricter than it sounds.
    • Being out of scope for GDPR is not the same as being out of scope for privacy law generally, which is where most US companies actually have exposure.

    The two triggers, in the words of the Regulation

    Paragraph 1 is the establishment criterion, which catches processing "in the context of the activities of an establishment of a controller or a processor in the Union." If you have an EU subsidiary, a branch, or staff with an EU office, start there and stop reading this section; you are in scope for the processing done in that context regardless of where the servers sit.

    Paragraph 2 is the targeting criterion, and it is the one that reaches a company whose entire footprint is in Ohio. It applies to processing "of data subjects who are in the Union," which the EDPB is careful to note is a location test, not a nationality test: the guidelines state that "the nationality or legal status of a data subject who is in the Union cannot limit or restrict the territorial scope of the Regulation," and that the requirement to be in the Union is assessed at the moment of the offer or the monitoring. An EU citizen living in Denver is not the trigger. A Colorado resident on holiday in Lisbon might be, if you targeted them there.

    The targeting test: what a regulator actually weighs

    Recital 23 sets the standard and it is a standard about intent, not about traffic. It is worth quoting because most summaries invert it: "the mere accessibility of the controller's, processor's or an intermediary's website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention." What can demonstrate intention is "the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union."

    The EDPB's guidelines borrow a longer factor list from the Court of Justice's Pammer and Hotel Alpenhof line of cases, and the list is the most useful operational thing in the document. The factors it names, to be weighed in combination rather than individually, include: an EU country or the EU named with reference to the good or service; paying a search engine for referencing to reach consumers in the Union, or running marketing campaigns aimed at an EU audience; the international nature of the activity; dedicated addresses or phone numbers reachable from an EU country; using a top-level domain other than the one for your own country, such as .de or a neutral .eu; describing travel instructions from EU Member States; presenting an international clientele of EU customers; using a language or currency other than the one generally used in your country; and offering delivery of goods in EU Member States.

    Read that list as a self-audit rather than as law. If your marketing team buys ads targeted at Germany, your pricing page offers euros, and your homepage carries logos of Dutch customers, you have three of them and the intent argument is not close.

    Signals you are probably not in scope

    This is the section the vendor pages do not write, so here is the mirror image, drawn from the EDPB's own worked examples.

    An Australian company offers a news and video service exclusively to users in Australia, who must supply an Australian phone number to subscribe. A subscriber travels to Germany and keeps using it. The guidelines conclude that the service "is not 'targeting' individuals in the Union" and the processing is outside the GDPR. Incidental EU use of a service aimed elsewhere is not targeting, and the guidelines say explicitly that a service offered only to individuals outside the EU does not come into scope merely because it is not withdrawn when a user travels.

    A Monaco company processes employee personal data for payroll, and many of those employees are French and Italian residents. Human resources management by a third-country company "cannot be considered as an offer of service" under Article 3(2)(a), so the processing is outside the Regulation.

    A Swiss university runs an open admissions process with no EU-specific advertising and takes payment only in Swiss francs. Outside. The same university then advertises a summer course specifically at German and Austrian universities. Inside, for that processing.

    The pattern across all three is that scope attaches to a processing activity and its purpose, not to a company as a whole. It is normal for one product line to be in scope and another not, and building around the in-scope activity is cheaper than declaring the whole company subject to a Regulation that reaches one workflow.

    Monitoring is the trigger most US companies actually trip

    Companies spend their analysis on the offering test and get caught by the second one. Recital 24 defines behaviour monitoring by reference to whether "natural persons are tracked on the internet including potential subsequent use of personal data processing techniques which consist of profiling a natural person, particularly in order to take decisions concerning her or him or for analysing or predicting her or his personal preferences, behaviours and attitudes."

    The EDPB's list of activities that can amount to monitoring includes behavioural advertisement, geo-localisation for marketing purposes, online tracking through cookies or other techniques such as fingerprinting, personalised diet and health analytics, CCTV, market surveys based on individual profiles, and regular reporting on an individual's health status. Note what is not on that list: server logs, aggregate traffic counts, and analytics you never turn into an individual profile. The guidelines are explicit that the EDPB "does not consider that any online collection or analysis of personal data of individuals in the EU would automatically count as 'monitoring'," and that the controller's purpose is the key consideration.

    Note the asymmetry, because it cuts against you. The intentional-targeting requirement the EDPB reads into Article 3(2)(a) is not written into Article 3(2)(b). If your retargeting pixel builds profiles of whoever shows up, and some of whoever shows up is in Paris, the analysis is about your purpose in profiling, not about your intent to reach France.

    If you are in scope, Article 27 usually comes with it

    Article 27(1) is short: "Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union." That is the obligation US companies discover last, often when a customer's security questionnaire asks for the representative's name.

    The derogation in Article 27(2)(a) is real but narrow. It applies to processing that is "occasional," that does not include large-scale processing of special-category or criminal-offence data, and that "is unlikely to result in a risk to the rights and freedoms of natural persons." Two details make it harder to rely on than it reads. First, the EDPB, following the Article 29 Working Party, treats a processing activity as "occasional" only "if it is not carried out regularly, and occurs outside the regular course of business or activity of the controller." A recurring product workflow is not occasional no matter how few EU users it touches. Second, the guidelines highlight that the exemption is limited to processing unlikely to result in "a risk," not a high risk, which is a lower bar to trip than the one used elsewhere in the Regulation.

    One structural rule worth knowing before you shop: the EDPB "does not consider the function of representative in the Union as compatible with the role of an external data protection officer," because a representative acts under the controller's mandate and instruction while a DPO must act independently. The same entity cannot be both, which is worth checking before you sign with a provider offering the pair as a bundle. Which role your facts call for is an Article 37 question, and for a private company Article 37 is the narrower trigger: it attaches where core activities consist of processing operations requiring "regular and systematic monitoring of data subjects on a large scale," or of "processing on a large scale of special categories of data" or criminal-offence data.

    On the enforcement side, Article 27 sits in the lower of the two fine tiers: Article 83(4) covers Articles 25 to 39 and caps at 10,000,000 euros or 2 percent of total worldwide annual turnover. The rights and principles articles sit in the upper tier at 20,000,000 euros or 4 percent.

    When you should not hire a consultancy like this one

    If your answer to the targeting test is a clean no, do not buy a GDPR programme. Write down the analysis, name the facts it rests on, date it, and set a reminder to redo it when your go-to-market changes. That memo is a perfectly good compliance artifact and it costs you an afternoon. Spend the budget instead on the state privacy laws that do reach you, a larger exposure for most US businesses and the subject of our US privacy laws resource.

    If your answer is a clean yes but your scope is narrow, one product, a handful of EU customers, no special-category data, you can very likely get to a defensible position with an EU representative, a records-of-processing exercise, an honest privacy notice, and a working data subject request process. That is a project, not a programme, and plenty of teams run it in-house.

    Where outside help earns its fee is the ambiguous middle: several product lines with different answers, a monitoring analysis that turns on what your ad stack actually does, or a customer contract that has already promised something the Regulation does not require. Those are judgment calls with evidence behind them, and getting them wrong in either direction is expensive.

    Where Top Floor fits

    Our GDPR service starts with the scope memo, not with a tool purchase, because the memo determines whether anything else is needed. If the answer is that you are in scope for part of what you do, global privacy handles the programme that follows, and international compliance is where the GDPR analysis gets reconciled with the other regimes that reach the same data, including India's DPDP Act if you have users there. If the answer is that you are out of scope, we will say so in writing and you can take the memo to your next customer questionnaire.

    How to decide this week

    1. Pull analytics by country for the last 90 days and separate EU visits from EU customers. Visits are not the test; they are the prompt to run it.

    2. Walk the Pammer factor list against your own site: currencies accepted, languages offered, delivery destinations, ad targeting, named EU customers, top-level domains. Write down which ones you hit.

    3. Ask your growth team one question in writing: does any campaign target an EU country? Ad platform settings answer that faster than a legal analysis does.

    4. List every tag, pixel and SDK on your site and say whether each builds a per-person profile. That list is the monitoring analysis.

    5. Write the conclusion down with a date on it. Both answers are defensible; only an undocumented answer is not.

    Frequently asked questions

    Is there a small-business exemption from GDPR?

    No. Article 3 sets no revenue threshold, no employee count and no user count, so scope turns entirely on whether you are established in the Union or whether your processing relates to offering goods or services to people in the Union or monitoring their behaviour there. Company size does affect some downstream obligations, notably the record-keeping derogation in Article 30(5), but it never changes whether the Regulation applies to you in the first place.

    Do EU visitors to our website put us in scope?

    Not by themselves. Recital 23 says the mere accessibility of your website in the Union is insufficient to establish an intention to offer goods or services there, and the EDPB adds that processing the personal data of an individual in the Union alone is not enough to trigger the GDPR without the targeting element. What can put you in scope is what you do with those visitors, so if a tag on the page builds behavioural profiles of them, look hard at the monitoring trigger in Article 3(2)(b) rather than at the visit count.

    If GDPR applies to us, do we need an EU representative or a DPO?

    Usually a representative, and the two are different obligations with different triggers. Article 27 requires a representative in the Union whenever Article 3(2) applies and you have no EU establishment, subject to a narrow derogation for occasional low-risk processing, while a data protection officer is required only in the specific circumstances Article 37 lists. The EDPB also treats the two roles as incompatible, so one provider cannot serve as both, which is worth checking before you sign with a vendor offering a bundle.

    Does GDPR reach EU citizens living in the United States?

    Not on the strength of their citizenship. The EDPB is explicit that the nationality or legal status of a data subject cannot limit or extend the territorial scope of the Regulation, and that the requirement is that the person be in the Union at the moment the offer is made or the behaviour is monitored. A German national who lives in Chicago and buys from your US store is, for Article 3(2) purposes, a person in Chicago.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.