The General Data Protection Regulation (GDPR) is an EU law that works to protect the privacy rights of EU residents. Businesses that collect or process personal data from people within the EU must comply with the GDPR.
But what about if your company is located in the EU and your customers are in the United States?
This article will explain how and why the GDPR applies to EU-based companies that exclusively target U.S.-based companies, and what the cross-border data protection obligations are when their users are located outside of the EU.
Our Privacy Policy Generator makes it easy to create a Privacy Policy for your business. Just follow these steps:
-
At Step 1, select the Website option or App option or both.
-
Answer some questions about your website or app.
-
Answer some questions about your business.
-
Enter the email address where you'd like the Privacy Policy delivered and click "Generate."
You'll be able to instantly access and download your new Privacy Policy.
- 1. When Does the GDPR Apply?/What's the GDPR's Territorial Scope?
- 2. Does the GDPR Apply to EU-Based Businesses Targeting Only U.S.-Based Customers?
- 2.1. Key Question: Is Personal Data Being Processed?
- 3. What are the Cross-Border Data Protection Obligations of an EU Business Targeting U.S. Customers?
- 3.1. 1. Have a Lawful Basis for Processing Personal Data (Article 6)
- 3.2. 2. Have a Comprehensive Privacy Policy (Articles 13 and 14)
- 3.3. 3. Facilitate Data Subject Rights (Articles 15 to 22)
- 3.4. 4. Implement Adequate Data Security Measures (Article 32)
- 3.5. 5. Follow Cross-Border Data Transfer Rules (Chapter 5)
- 3.6. 6. Appoint a Data Protection Officer (DPO) if Required (Articles 37-39)
- 3.7. 7. Keep Records of Your Data Processing Activities (Article 30)
- 4. What are the Penalties for Not Complying with the GDPR?
- 5. Summary
When Does the GDPR Apply?/What's the GDPR's Territorial Scope?
The GDPR's territorial scope, or when it applies, is defined in Article 3 of the regulation. Article 3 outlines 3 different types of scenarios where the GDPR will apply.
- When a business is established in the EU (Article 3(1)): The GDPR applies to businesses that are established within the EU, regardless of whether the data processing activities take place in the EU.
-
When a business anywhere targets individuals in the EU (Article 3(2)): The GDPR applies to businesses that are not established within the EU if they process personal data of individuals in the EU and the processing relates to:
- Offering goods or services to individuals in the EU, or
- Monitoring the behavior of individuals in the EU, such as through tracking or profiling
- When public international law applies (Article 3(3)): The GDPR applies when it's by virtue of public international law, such as with diplomatic missions.
For EU-based companies, Article 3(1) is particularly relevant.
Does the GDPR Apply to EU-Based Businesses Targeting Only U.S.-Based Customers?
Yes, the GDPR applies to EU-based businesses that target only U.S.-based customers. This is because of Article 3 (1) of the GDPR, outlined in the previous section.
Article 3 (1) makes it so that if a company is established in the EU, the GDPR will apply to its data processing activities, even if the data subjects (individuals whose data is processed) are located outside of the EU, such as in the United States.
The GDPR's applicability under Article 3 (1) does not depend on the geographical location of the data subjects or the company's target market. It depends on the geographical location of the business.
The purpose of this is to prevent EU-based businesses from trying to evade the GDPR's requirements by targeting non-EU markets.
For example, consider an EU SaaS provider that targets its product to U.S. customers. It will be subject to the GDPR if it processes personal data as part of its business operations. The fact that the customers are U.S.-based does not exempt the company from the GDPR because the data processing happens as part of its EU-established business.
Key Question: Is Personal Data Being Processed?
While the GDPR applies to businesses in the EU even if they only serve U.S. customers, there's one more question that needs to be asked to see if the EU business must comply with the GDPR's strict requirements: Is personal data being processed by the EU business?
The GDPR only applies to the processing of personal data. If the EU-based company processes any personal data, from data subjects anywhere, then the GDPR is triggered under Article 3 (1).
Chances are your EU-based business processes personal data of some type, as this can be something as simple as collecting IP addresses for data analytics, or email addresses to send out an email newsletter.
Consider these examples of how personal data is commonly processed. Each of these scenarios will trigger the GDPR, regardless of where the data subjects are located. They.can be in the EU, U.S., or elsewhere:
- B2C Transactions: In business-to-consumer transactions, an EU company will likely collect a lot of personal data such as financial information, mailing addresses, email addresses, phone numbers and analytics data.
- B2B Transactions: In business-to-business transactions, an EU company might collect contact information such as names, email addresses and phone numbers of employees or representatives of U.S.-based companies during contract negotiations, customer relationship management, or to deliver a service or product.
- Employee Data: An EU company can process the personal data of its own employees who are located within the EU. This can be for HR records, employee files, and payroll information.
- Third-Party Services: An EU company may use third-party services that involve personal data, such as analytics programs or CRM software.
If the EU business doesn't process any personal data at all, then the GDPR does not apply. However, this is very rare and chances are your business is collecting at least one and likely many forms of protected personal data.
What are the Cross-Border Data Protection Obligations of an EU Business Targeting U.S. Customers?
When an EU-based business is processing personal data and targeting U.S.-based customers, a number of GDPR-required obligations arise. These obligations are in place to ensure that personal data is processed lawfully, transparently, and securely, regardless of where data subjects are located.
Below are the key obligations for cross-border data protection for businesses located within the EU with customers located outside of the EU/within the U.S.:
1. Have a Lawful Basis for Processing Personal Data (Article 6)
Article 6 of the GDPR requires that there be a lawful basis for processing personal data. This applies regardless of where the personal data originates from, so data collected from U.S. consumers would be included.
A lawful basis is simply a "valid purpose," and the GDPR offers 6 legal bases:
- Consent
- Contract
- Legal obligation
- Vital interests
- Public task
- Legitimate interests
While "legitimate interests" is a very common legal basis for processing personal data, we recommend that you go with "consent" whenever possible. This means that you would get explicit consent from a user before processing personal data. Consent is appropriate in some contexts, but "legitimate interests" may be more flexible and less burdensome in others, especially in B2B.
A great way to get consent is with an "I Agree" checkbox next to a statement that explains what you're requesting consent for.
For example, here's how you can use a checkbox to get consent to process someone's personal data for marketing and profiling purposes:
If you go with consent as your legal basis, always include a link to your Privacy Policy when you request consent, as seen in the image above.
2. Have a Comprehensive Privacy Policy (Articles 13 and 14)
The GDPR requires that data subjects are provided with clear and accurate information about which of their data is processed, why (lawful basis), and how. Even for U.S.-based individuals, an EU company must provide a Privacy Policy.
Make sure your GDPR-compliant Privacy Policy includes the following information:
- Your identity
- What personal data you collect and process
- Your lawful basis for processing
- How you use the personal data/for what purposes
- Any third parties you may share the data with
- What GDPR rights the data subject has (Right to access, rectification, erasure, etc.)
- What U.S. rights the data subject has, such as the CCPA/CPRA's right to not have personal data sold to third parties. You can include CCPA rights for marketing clarity, but it's not a GDPR requirement.
Here's an example of a good Privacy Policy table of contents, from Volkswagen:
Here's how Volkswagen addresses state rights of its U.S. customers:
It also outlines the rights granted by the GDPR:
Include a link to your Privacy Policy at the time and place of data collection, as seen in the last section with the consent checkbox.
Make your Privacy Policy available at any time by including it in your website's footer, in a relevant in-app menu, on a SaaS dashboard menu, and anywhere else that's relevant.
Here's how Volkswagen links its Privacy Policy to its site footer with other relevant and important links:
3. Facilitate Data Subject Rights (Articles 15 to 22)
The GDPR grants 8 rights to data subjects, and U.S. data subjects are able to exercise these rights as well. You will need to disclose these rights and make sure you have processes in place to honor any requests users may make regarding these rights.
The rights are as follows:
- Right to be informed
- Right of access
- Right to rectification
- Right to object to data processing
- Right to restrict data processing
- Right to data portability
- Right to be forgotten
- Right to object to automated decision making and profiling
Make sure you have mechanisms in place to be able to facilitate these rights to all of your users. Disclose these rights to your users via your Privacy Policy, as mentioned in the last section.
4. Implement Adequate Data Security Measures (Article 32)
The GDPR requires appropriate technical and organizational security measures be in place so that the personal data of data subjects from any country is protected.
For an EU-based company, this includes the following:
- Encrypting personal data
- Implementing access controls to prevent unauthorized access and keep personal data confidential
- Regularly testing organizational security measures
You should also implement a data breach response plan as part of your security measures. If a data breach occurs, you must notify the relevant EU supervisory authority within 72 hours and inform affected data subjects within the U.S. and elsewhere.
5. Follow Cross-Border Data Transfer Rules (Chapter 5)
The GDPR has strict rules for when personal data is transferred outside the EU. If you work with any third party services that you share personal data with, and the third party is located outside of the EU, this will be very relevant to you.
-
Transfers to U.S. Customers: If an EU-based company shares personal data with a U.S.-based customer, such as contact details of a U.S. customer that's sent to a third party delivery service), this constitutes a data transfer. The EU-based company must ensure the transfer complies with GDPR, typically through:
- Standard Contractual Clauses (SCCs): Legally binding agreements that help ensure the recipient of the data protects the data to GDPR standards.
- EU-U.S. Data Privacy Framework: This is a voluntary framework that replaces Privacy Shield and helps companies transfer data from the EU to the U.S. in a compliant way.
- Adequacy Decisions: Since Schrems II was invalidated in 2020, the EU has not granted the U.S. an adequacy decision. For transfers to the U.S., SCCs or the EU-U.S. Data Privacy Framework is required.
- Binding Corporate Rules (BCRs): This is for transfers within a corporate group, such as if you have a branch office in the U.S. and you transfer personal data from the EU branch to the U.S. branch.
- Third-Party Processors: If the EU business uses any U.S.-based third party processors, it must create a Data Processing Agreement (DPA) and SCCs with the third party processor.
The EU company will need to conduct a Transfer Impact Assessment (TIA) to determine if the transfer is legal, and to evaluate the risks of transferring data to the United States.
6. Appoint a Data Protection Officer (DPO) if Required (Articles 37-39)
This won't be applicable to all EU businesses, but if you fall within the following, you'll need to appoint a DPO:
- A public authority (except courts)
- Monitoring people on a large scale
- Processing a large amount of of special category or criminal record data
If you do have a DPO, make sure you publish the DPO's contact information in your Privacy Policy.
Here's how BMW UK does this:
7. Keep Records of Your Data Processing Activities (Article 30)
One of the best defenses against non-compliance is to keep detailed records of all of your data processing activities. It's also a GDPR requirement.
Include the following information in your records:
- Information about your company
- Specifically what personal data you're processing and for what specific purposes
- what security measures you have in place
Note that businesses with less than 250 employees don't need to keep these records unless one of the following applies:
- The data processing is likely to result in a risk to the freedoms or rights of data subjects,
- The processing is not only occasional, or
- The processing includes special categories of data, or data that relates to criminal offenses and convictions
What are the Penalties for Not Complying with the GDPR?
Not complying with the GDPR can come with fines of up to €20 million or 4% of annual global turnover, whichever is higher.
EU supervisory authorities actively enforce the GDPR for EU-based companies, even in cross-border scenarios, such as with an EU company that serves only U.S. customers. Violations will come with fines and reputational damage.
Additionally, your U.S.-based data subjects could potentially exercise GDPR rights, and they must be facilitated or you can potentially be fined.
You must take steps to ensure you don't end up with penalties for not complying with the GDPR.
Summary
The GDPR applies to EU-based businesses that process personal data, even if they only target U.S.-based customers. This is because of Article 3 (1).
This is done to ensure that businesses in the EU don't attempt to escape the GDPR's obligations by only focusing on markets outside of the EU.
If you're an EU business that serves U.S. customers, your key obligations include:
- Establishing a lawful basis for your data processing
- Getting appropriate consent if required, or if it's your lawful basis
- Publishing a transparent Privacy Policy that discloses what personal data you process and why, as well as what rights users have and how they can exercise them
- Having robust data security measures in place
- Complying with cross-border data transfer rules
- Appointing a DPO if applicable
- Keeping records of your data processing activities
Not complying with the GDPR can bring costly fines, penalties and reputational damage.
The first step to compliance: A Privacy Policy.
Stay compliant with our agreements, policies, and consent banners — everything you need, all in one place.