How Much Does GDPR Compliance Cost a US Company?
The most widely quoted number in this market is USD 1.7 million a year for a small business, a figure from GDPR's 2018 implementation year that Usercentrics' cost guide still leads with, attributed to the Federal Trade Commission. Usercentrics sells consent management, so a large scary number is not against its interest, and neither that guide nor the chain beneath it defines what "small business" means. Price the line items you can actually buy instead, at published rates, and a US software company with modest EU exposure and no DPO obligation lands at a first-year GDPR total of roughly $5,000 to $12,000, most of it your own payroll rather than invoices. The expensive version of GDPR is real, but it is bought by companies whose core business is personal data, not by a 40-person B2B SaaS company with European customers.
This article prices each line separately, shows the arithmetic, and names the three things that move the total by an order of magnitude.
Key takeaways
- The famous USD 1.7 million figure is a 2018 implementation-year number with no stated scope definition, published by vendors who benefit from it. Do not budget against it.
- Priced from published rates, the buyable lines are the smaller part of the bill: a representative appointment at $600 to $1,400 a year, consent and notice tooling from under $200 to about $2,400 a year, and a transfer mechanism at a low three-figure government fee or zero.
- The real cost is internal hours: data mapping and Article 30 records for a first-time programme run 40 to 80 hours of your own people's time.
- First-year GDPR total for a US SaaS company with modest EU exposure and no DPO obligation: roughly $5,000 to $12,000 as of August 2026.
- Three things multiply that: a DPO obligation under Article 37, special-category data, and high data subject request volume.
Why the headline numbers are unusable
Usercentrics' guide is a fair example of the genre and it is more transparent than most, because it names its sources. Working through what it cites: USD 1.7 million a year for small businesses and USD 70 million for large enterprises from an FTC figure tied to GDPR's 2018 implementation; EUR 3,000 to EUR 7,000 a year of data subject request handling from a UK privacy practitioner survey via Statista; an average GDPR fine of EUR 2.8 million from Enforcement Tracker's 2024 data, alongside an average fine for small and mid-sized businesses of EUR 69,119 from a 2021 to 2023 study; DPIA costs of EUR 688 to EUR 2,236 per assessment for SMBs from an academic study, against European Commission figures of EUR 14,000 to EUR 149,000 depending on complexity.
Look at what those numbers disagree about. A DPIA costs either about EUR 1,500 or about EUR 80,000 depending on which source you read, and both figures appear on the same page. That is not sloppiness; it is the honest result of averaging across companies whose exposure differs by three orders of magnitude.
So the average is the wrong tool. What you want is the cost of the specific obligations that attach to your specific business, each priced at a rate you can go and pay today.
Line one: the Article 27 representative
If you are in scope with no establishment in the Union, you owe a representative appointment. Published prices as of August 2026 start at a stated minimum of EUR 100 a year at DataRep and reach GBP 1,500 a year at GRC Solutions for an organisation of 11 to 500 employees; Engage Compliance advertises a standalone appointment from EUR 59 a month billed annually. Those are all providers pricing their own service. Budget EUR 500 to EUR 1,200 a year for a small company and treat anything materially above that as a bundle you should ask about.
The trigger analysis and the DPO comparison are covered separately in EU representative vs DPO, because getting that test wrong is the single largest swing in this budget.
Line two: consent, notice and preference tooling
This line has collapsed in price and most buyers have not noticed. Termly publishes a Pro+ tier at $15 a month billed annually with unlimited policies, unlimited banner views and consent logging. Osano publishes a Plus tier at $199 a month covering three domains and 30,000 monthly visitors, which notably bundles UK and GDPR representative appointments into the price. Usercentrics publishes an Essential web tier at EUR 7 a month for up to 1,500 sessions, quoted in euros because that is the unit its price list uses. Those are the vendors' own published prices, so they are asking prices, and they are also the prices you will actually pay because they are self-service.
Call it under $200 a year at the low end and about $2,400 a year at the Osano tier. Enterprise privacy suites cost far more, and the reason to buy one is workflow scale rather than legal coverage.
Line three: the transfer mechanism
If your EU data comes to the United States, you need a lawful transfer route. Self-certifying under the EU-US Data Privacy Framework carries a US government fee that scales with revenue and is genuinely small at the bottom, and standard contractual clauses carry no fee at all but real drafting and assessment work. The comparison, the fee table and the durability question all sit in Data Privacy Framework vs SCCs; the point for a budget is that the mechanism itself is close to free and the assessment around it is not.
Line four: the hours, which is where the money actually goes
Everything above is invoices. The bulk of a first GDPR programme is time, and it concentrates in three artefacts.
The data map: what personal data you hold, where it came from, where it sits, who it goes to, and how long you keep it. The Article 30 record of processing activities, which is the formal version of the data map and the thing your representative is expected to hold. And the request runbook: how an access, deletion or objection request gets recognised, routed, verified and answered inside the Article 12(3) deadline of one month, extendable by two further months for complex or numerous requests with notice inside the first month.
For a 40-person SaaS company with one product, one CRM, one data warehouse and a dozen or so subprocessors, building those three from nothing is 40 to 80 hours of work split between someone who knows the data flows and someone who knows what Article 30 requires. At the $100 loaded hourly rate this site uses for internal staff time, that is $4,000 to $8,000 of your own people's time.
Outside help does not remove those hours. It compresses them, and more usefully it tells you which of them mattered, because a first-time team will spend a week on the subprocessor list and ten minutes on retention when the ratio should be closer to the reverse.
The total, worked
Add the lines for the base case: a US B2B software company, European customers, no special-category data, no Article 37 DPO trigger, transfers handled under one mechanism.
Representative appointment: about EUR 500 to EUR 1,200 a year, call it $600 to $1,400. Tooling: under $200 to about $2,400 a year. Transfer mechanism: a low three-figure government fee at the smallest revenue tier, or zero plus drafting time on the clauses route. Internal hours: $4,000 to $8,000.
That is a first-year GDPR total of roughly $5,000 to $12,000 at this profile, and the majority of it is payroll you are already paying. Year two is materially lower, because the data map and the records exist and the work becomes maintenance: re-reviewing the record when systems change, handling requests, and refreshing the notice.
We publish that band because the inputs are all named above and you can check the arithmetic, which also means being explicit about the line it does not carry. The 40 to 80 hours buy the data map, the Article 30 record and the request runbook. Standing the transfer mechanism up is separate work that sits on top of them: on the Data Privacy Framework route that is an independent recourse mechanism, the arbitration contribution and a conforming privacy policy, and on the standard contractual clauses route it is picking the right module, drafting, and writing the transfer impact assessment. Data Privacy Framework vs SCCs sets out both, and we are not going to average work whose size depends on how many transfer relationships you have: one destination is a day or two, a subprocessor chain running through several countries is a standing programme. Budget the mechanism separately and do not read the band as covering it.
The band is also not a survey, and it does not describe an adtech company, a consumer health app, or anyone whose product is built on personal data.
The three things that multiply it
A DPO obligation. If Article 37 catches you, you have added a recurring service line in the low thousands of euros a month, sourced in How much does an outsourced DPO cost. That single trigger can double or triple the first-year total on its own.
Special-category data. Health, biometric, genetic or criminal-offence data pulls in Article 9 or Article 10, and usually a Data Protection Impact Assessment programme. The published DPIA figures span EUR 688 to EUR 149,000 per assessment depending on whose study you read, which tells you the honest answer is that it depends on complexity and you should scope it rather than budget an average.
Request volume. A consumer product with a support inbox generates data subject requests continuously; the UK practitioner survey Usercentrics cites puts annual request handling at EUR 3,000 to EUR 7,000. A B2B product with a few hundred enterprise accounts generates a handful a year. Look at your actual inbox before you buy a request-management workflow.
What the fines actually are, and why they are the wrong planning input
Article 83 sets two tiers: up to EUR 10 million or 2 percent of total worldwide annual turnover for the lower tier, and up to EUR 20 million or 4 percent for the higher tier, whichever is greater in each case. Those ceilings get quoted at small companies constantly, and they are close to irrelevant to a 40-person SaaS company's planning.
The relevant number is the one for companies your size. The study Usercentrics cites puts the average fine on small and mid-sized businesses at EUR 69,119 across 2021 to 2023. That is a real number and it is not existential, which is the point: for most small companies the rational driver of GDPR spend is enterprise sales and contractual exposure, not regulatory fear. Your European customers will ask for your Article 30 records and your transfer mechanism in procurement long before a supervisory authority does.
Anyone selling you GDPR work on the strength of the EUR 20 million ceiling is selling you fear. Ask them for the fine data at your revenue band instead.
When not to spend this money
Two honest cases.
You are not in scope. Article 3(2) requires that you offer goods or services to people in the Union or monitor their behaviour there, and Recital 23 says mere accessibility of your site from the Union does not do it. If you sell only to US customers, price only in dollars, market only to a US audience and do not deliberately track Union visitors, the right spend is a scoping memo and a calendar reminder, not a programme. Write down the factors and the conclusion, date it, and revisit when you start marketing into Europe.
You are pre-product-market-fit with a handful of European signups. GDPR obligations are not proportional to revenue, but your ability to absorb them is. The minimum defensible posture is a truthful privacy notice, a working way to honour a deletion request, and a written scoping decision. That is a week of work, not a programme, and it is what we would tell a seed-stage company to do rather than take our money.
If you already carry another framework, there is a third case worth naming without numbers: much of the evidence overlaps, and the cheapest GDPR programme is usually the one bolted onto a security programme you already run. Our reusing compliance evidence across frameworks piece covers how that mapping works.
Where Top Floor fits
We do the scoping memo, the Article 30 records, the notice and the request runbook, which is exactly the hours line above and the part that determines whether the rest is cheap or expensive. That is GDPR work. Where a company is dealing with the EU and the US state privacy laws at once, treating them as one programme is almost always cheaper than two, which is what global privacy is for. And where you want the calendar, the evidence and the annual refresh handled rather than advised on, that is compliance as a service.
What we will not do is sell you a DPO appointment you do not owe or a consent suite you can buy for $15 a month yourself.
How to decide this week
Start with the scoping memo, because everything downstream is conditional on it. One page: what you sell, to whom, in what currency and language, with what tracking, and whether Article 3(2) is met.
If you are in scope, do the two trigger tests next, in writing and before you talk to anyone selling a service: Article 27 (no Union establishment) and Article 37 (core-activity monitoring or large-scale special-category data). Those two answers determine whether your budget has a three-figure line or a four-figure monthly one.
Then count your systems. Write down every place personal data lands, including the CRM, the support desk, the warehouse, the product analytics and the email tool. The length of that list is the best predictor of your hours line, and it takes an hour to produce.
Finally, buy tooling last. The published self-service tiers above are available whenever you want them, and buying a consent platform before you know what you collect is how companies end up with a banner that blocks nothing.
Frequently asked questions
How much does GDPR compliance cost a US company in year one?
Priced from published rates, a US B2B software company with European customers, no special-category data and no Article 37 DPO obligation should expect a first-year GDPR total of roughly $5,000 to $12,000 as of August 2026. The buyable lines are small: an Article 27 representative appointment at published prices in the hundreds, consent and notice tooling from $15 a month at Termly's Pro+ tier to $199 a month at Osano's Plus tier, and a transfer mechanism that is close to free. The bulk is internal time, roughly 40 to 80 hours to build a data map, Article 30 records and a data subject request runbook, valued at the $100 loaded hourly rate this site uses for staff time. Those hours cover those three artefacts and nothing else, so the work of standing the transfer mechanism up, whether that is a recourse mechanism and a conforming policy under the Data Privacy Framework or module selection, drafting and a transfer impact assessment under the clauses, sits on top of the band rather than inside it.
Is the USD 1.7 million GDPR cost figure real?
It is a real published figure and an unusable planning input. It comes from GDPR's 2018 implementation year, is attributed to the Federal Trade Commission, and is repeated by consent-management vendors including Usercentrics, none of whom define what counts as a "small business" in that number. Averages across companies whose GDPR exposure differs by three orders of magnitude do not describe any particular company. Price your own obligations line by line instead: representative appointment, tooling, transfer mechanism, and internal hours.
What is the biggest driver of GDPR cost?
Whether GDPR Article 37 requires you to appoint a Data Protection Officer. That single trigger adds a recurring service in the low thousands of euros per month, which can double or triple a small company's first-year total on its own. The second largest driver is special-category data under Article 9, which pulls in Data Protection Impact Assessments whose published cost estimates range from EUR 688 to EUR 149,000 per assessment depending on complexity and on which study you read. Data subject request volume is third.
What are the GDPR fines for a small business?
GDPR Article 83 sets ceilings of up to EUR 10 million or 2 percent of worldwide annual turnover for the lower tier and EUR 20 million or 4 percent for the higher tier, whichever is greater. Those ceilings describe the maximum, not the expectation. A study of enforcement from 2021 to 2023 cited in Usercentrics' cost guide puts the average fine actually levied on small and mid-sized businesses at EUR 69,119. For most small US companies the practical driver of GDPR spend is enterprise procurement asking for records and a transfer mechanism, not fine exposure.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.