AI Summarize

Share

The General Data Protection Regulation (GDPR) is the main data protection law of the European Union (EU) and took effect on May 25, 2018. GDPR requirements apply to many US businesses, including those without a physical presence in the EU.

Does GDPR apply to US companies? Yes. The GDPR applies to US companies of any size that offer goods or services to people in the EU or monitor their behavior. This includes e-commerce businesses, SaaS companies, ad-tech companies, multinational organizations, and businesses in the hospitality and health industries. Noncompliance carries fines of up to €20 million or 4% of worldwide annual turnover, whichever amount is higher. In addition to avoiding enforcement actions, GDPR compliance helps organizations serve customers across the EU, which includes more than 450 million people.

This guide explains GDPR requirements US businesses need to understand. It covers applicability, data transfers, a GDPR checklist, fines, the average cost of compliance, an FAQ, and how TermsFeed helps businesses comply with the GDPR through Privacy Policy generators and consent tools.

Our Privacy Policy Generator makes it easy to create a Privacy Policy for your business. Just follow these steps:

  1. At Step 1, select the Website option or App option or both.

    TermsFeed Privacy Policy Generator: Create Privacy Policy - Step 1

  2. Answer some questions about your website or app.

    TermsFeed Privacy Policy Generator: Answer questions about website - Step 2

  3. Answer some questions about your business.

    TermsFeed Privacy Policy Generator: Answer questions about business practices  - Step 3

  4. Enter the email address where you'd like the Privacy Policy delivered and click "Generate."

    TermsFeed Privacy Policy Generator: Enter your email address - Step 4

    You'll be able to instantly access and download your new Privacy Policy.



Does the GDPR Apply to US Companies?

Yes, the GDPR applies to many U.S. companies even though it is a European law.

The GDPR protects people located in the EU and applies to businesses outside the EU when they offer goods or services to people in the EU or monitor their behavior.

For example, a US company that provides goods to people in the EU but doesn't have an EU office, EU servers, or an EU legal entity still must comply with the GDPR.

Many US businesses ask, "Does GDPR apply to US companies?" because they assume a European law doesn't affect their organization. However, GDPR extraterritorial scope means a company does not need to be based in the EU for the GDPR to apply.

Article 3 of the GDPR explains that the law applies to organizations that process personal data in connection with offering goods or services to people in the EU or monitoring their behavior.

GDPR - Article 3 - Territorial scope

The following section explains the two main GDPR Article 3 US companies triggers in more detail.

The Two Triggers: Offering Goods/Services and Monitoring Behavior

Article 3(2) of the GDPR describes two triggers that bring organizations outside the EU within GDPR scope: offering goods or services to people in the EU and monitoring their behavior.

1. Offering Goods and Services to EU Residents Can Trigger GDPR

A US business falls within GDPR scope when it offers goods or services to people in the EU, even if the business has no office or legal entity in the EU. The GDPR does not require a customer to complete a purchase for this trigger to apply. Free services also count, including SaaS platforms, mobile apps, newsletters, and other online services.

Examples of activities that indicate a business targets people in the EU include:

  • Accepting payments in euros or other EU currencies
  • Shipping physical products to EU addresses
  • Offering a website in EU languages or using EU country domains, such as .fr or .pl
  • Running ad campaigns that target EU consumers
  • Displaying EU user testimonials
  • Providing free services, such as SaaS, apps, and newsletters

A common question among US businesses is, "Does GDPR apply to US websites?" A website does not fall within GDPR scope simply because it is accessible to users in the EU. However, if it offers goods or services to people in the EU or monitors their behavior, then the GDPR applies.

Recital 23 of the GDPR provides examples of factors that help determine whether a business intends to offer goods or services to people in the EU, including language options, currency choices, and references to EU customers or users.

GDPR Info - Recital 23: Applicable to processors not established in the Union if data subject within the union are targeted

2. Monitoring the Behavior of People Can Trigger GDPR

The GDPR also applies to organizations that monitor the behavior of people in the EU. This often occurs through analytics tools, advertising platforms, and tracking technologies.

Examples of GDPR monitoring behavior include:

  • Using tracking cookies, Google Analytics, Meta Pixel, retargeting, or similar technologies to track or analyze online activity
  • Using geolocation data or device fingerprinting to track users or analyze their behavior
  • Running behavioral advertising campaigns or creating user profiles based on online activity

It's Location-Based, Not Citizenship-Based

A common question is, "Does GDPR apply to US citizens?" The answer depends on where the individual is located, not their nationality.

Under the GDPR, EU citizens in US aren't protected based on citizenship alone. For instance, an EU citizen visiting the US and using a website that offers products only to US customers is not protected by the GDPR. However, a US citizen visiting or living in the EU is protected by the GDPR.

Scenario Does the GDPR apply?
A US citizen visiting France uses a food delivery app that collects their personal data Yes
An EU citizen living in the US shops on a website that only offers services to US customers No
A customer in Germany orders a product from a US company for delivery to Germany Yes

The GDPR location-based approach helps businesses determine when the law applies to them. The key factors are where the individual is located and whether the specific data processing activity falls within the scope of the GDPR.

For example, if a US business offers goods or services to people in Germany, it needs to consider GDPR requirements whether those customers are German nationals, US citizens living in Germany, or citizens of another country.

Does the GDPR Apply to the US Government?

US federal and state agencies that target individuals in the EU or track their behavior are expected to comply with the GDPR.

People often ask, "Does GDPR apply to the US government?" The answer depends on the nature of the processing, whether the activity falls within the territorial scope of the GDPR, and whether an exemption from Article 2 applies. The GDPR does not provide a general exemption for US government agencies.

GDPR - Article 2 - Material scope

Contractors and vendors that process personal data on behalf of the US government are subject to the GDPR, depending on their role and the nature of the processing.

Does Company Size Matter for GDPR Compliance?

No, the GDPR has no small-business exemption. If a business of any size offers goods or services to people in the EU or monitors their behavior, the GDPR applies.

Unlike US state privacy laws, GDPR company size does not determine whether the regulation applies. State laws such as the California Consumer Privacy Act (CCPA) and the Indiana Consumer Data Protection Act (CDPA) exempt certain small businesses based on revenue or the volume of personal data they process.

This means a two-person startup with customers in Germany faces many of the same core GDPR obligations as a Fortune 500 company with a global audience.

The GDPR does provide a limited exception for records of processing activities (ROPA). Under Article 30, organizations with fewer than 250 employees do not need to maintain ROPA unless the processing is non-occasional, presents a risk to the rights and freedoms of data subjects, or involves special categories of personal data or personal data related to criminal convictions and offenses.

The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10.

- GDPR, Article 30

This exception does not exempt small organizations from other GDPR requirements. A small business still needs to comply with requirements such as providing privacy information, keeping personal data secure, and honoring data subject rights when its data processing falls within the scope of the GDPR.

The GDPR has no small business exemption, so a small business needs to look at its own processing activities and where its data subjects are located to know whether the GDPR applies.

The European Commission Application of the GDPR website explains that small and medium-sized enterprises (SMEs) must comply with the law when their data processing activities pose a high risk to the rights and freedoms of individuals in the EU.

European Commission Application of the GDPR - Specific rules for SMEs

Data Controller vs. Data Processor: What's Your Role?

Your GDPR obligations depend on whether you are a controller, a processor, or both.

A data controller decides why and how personal data is processed. For example, a company that collects customer email addresses for marketing purposes acts as a controller for that processing.

Controllers are responsible for identifying a lawful basis for processing, providing required privacy information, honoring data subject rights, and establishing agreements with vendors that process personal data on their behalf.

A data processor processes personal data on behalf of a controller and acts on documented instructions from the controller. For example, a SaaS platform that hosts customer data for a client acts as a processor.

Article 4 of the GDPR defines controllers as those who decide why and how to process personal data and processors as those who process personal data for a controller.

(7) ‘controller' means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
(8) ‘processor' means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;...

- GDPR, Article 4

Many US SaaS companies act as both controllers and processors. For example, a SaaS company can act as a data controller when it determines the purposes and means of processing its own marketing and employee data, and as a data processor when it processes customer data on behalf of an enterprise client, as illustrated by the roles Stripe describes in its Data Processing Agreement.

Stripe - DPA - Stripe as Data Processor and Data Controller clause

The distinction between a data controller vs data processor matters because the role determines which GDPR obligations apply and affects contracts, including data processing agreements (DPAs) and Privacy Policies. Many organizations are both controllers and processors, so the GDPR rules that apply depend on the specific data processing activity.

What Counts as Personal Data Under the GDPR?

The GDPR defines personal data far more broadly than most U.S. laws. The GDPR personal data definition is any information relating to an identified or identifiable natural person, also called a data subject.

Examples of personal data include:

  • Names: The first and last name of a customer identifies them directly.
  • ID numbers: Customer numbers, driver's license numbers, and passport numbers identify a person directly or indirectly.
  • Email addresses: Personal or work email addresses count as personal data when they relate to an identifiable person.
  • Phone numbers: Phone numbers that identify or are linked to a person qualify as personal data.
  • IP addresses: A website that records the IP addresses of visitors processes personal data when an IP address relates to an identifiable individual.
  • Media Access Control (MAC) addresses: A business that records MAC addresses from devices processes personal data when the information relates to an identifiable person.
  • Device IDs: Device or advertising identifiers (such as those collected via a mobile app) count as personal data when they distinguish or help identify a user.
  • Location data: User location data (such as data collected through a mobile app) is considered personal data when the information relates to an identifiable individual.
  • Certain cookie data: Cookie identifiers count as personal data when they allow a user to be identified or distinguished from other users.

Article 4(1) of the GDPR defines personal data as any information related to a data subject.

EUR LEX GDPR Article 4(1): Definition of Personal Data

The GDPR definition of personal data includes more types of information than most US privacy laws, although the CCPA comes close. Because the GDPR treats so many types of information as personal data, data minimization is especially important.

Data minimization practices include:

  • Collecting only the personal data needed for a specific purpose
  • Recording what personal data is collected and why
  • Identifying the lawful basis for processing each type of personal data
  • Tracking where the data came from and who receives it
  • Protecting personal data against unauthorized access
  • Deleting personal data when it is no longer needed

Before collecting or using personal data, US companies need to understand that information that appears harmless or anonymous on its own still counts as personal data under the GDPR when combined with other data that identifies a person.

Special Categories of Personal Data

The GDPR gives extra protection to special categories of personal data.

Special category data GDPR rules apply to the following types of personal data:

  • Racial or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade union membership
  • Genetic data
  • Biometric data used to identify a person
  • Data concerning health
  • Data concerning sex life
  • Data concerning sexual orientation

Sensitive personal data GDPR rules prohibit processing these categories unless one of the conditions in Article 9(2) applies. Explicit consent is one condition, although others apply in specific situations.

Processing special categories of personal data triggers data protection officer (DPO) and Data Protection Impact Assessment (DPIA) requirements in some situations.

Article 37 of the GDPR explains that a DPO is required when the core activities of an organization involve large-scale processing of special categories of personal data.

GDPR Article 37: Designation of the data protection officer - section 1

Criminal conviction data follows a separate, stricter set of rules under Article 10 of the GDPR.

Processing special category data requires both an ordinary lawful basis under Article 6 and an additional condition under Article 9(2).

Key GDPR Requirements for US Businesses

If the GDPR applies to your U.S. business, a specific set of obligations follows. GDPR requirements for US businesses depend on factors such as the types of personal data being processed and the nature of the processing.

The main GDPR compliance requirements include:

  • Establishing a lawful basis for every processing activity
  • Honoring data subject rights and responding to data subject access requests (DSARs) within one month
  • Reporting data breaches within 72 hours
  • Appointing a DPO and an EU representative when required
  • Signing DPAs with vendors
  • Implementing data security measures

Let's take a closer look at each of the GDPR obligations US companies need to be aware of.

Establish a Lawful Basis for Processing

When the GDPR applies, organizations need a GDPR lawful basis for every personal data processing activity. Organizations need to identify and document the lawful basis that applies before collecting or using personal data.

Article 6 of the GDPR identifies the six legal bases for processing:

  1. Consent: The individual gives permission for a specific type of processing.
  2. Contract performance: Processing is necessary to perform a contract with the individual or to take steps requested by the individual before entering into a contract.
  3. Legal obligation: Processing is necessary to comply with a legal obligation that applies to the organization.
  4. Vital interests: Processing is necessary to protect the life of an individual.
  5. Public task: Processing is necessary to perform a task carried out in the public interest or under official authority.
  6. Legitimate interests: Processing is necessary for a legitimate interest pursued by the organization or a third party, as long as the interests or fundamental rights and freedoms of the individual do not override that interest.

The Intuit Global Privacy Statement includes a link to a table that explains the purpose, category of personal data, and lawful basis for each of its data processing activities.

Intuit - Legal Bases for Porcessing personal data - Table excerpt

Many US B2B companies rely on contract performance or legitimate interests as their lawful basis for processing, while consent often applies to certain marketing and analytics activities.

Businesses that rely on consent as their legal basis need to ensure that consent is freely given, specific, informed, and unambiguous.

To comply with GDPR consent requirements, organizations should make withdrawing consent as easy as giving consent and avoid:

  • Using pre-ticked consent boxes
  • Bundling consent for unrelated purposes
  • Treating inactivity as consent

For each processing activity, organizations need to identify and document the legal basis for processing. GDPR requirements include maintaining a Privacy Policy that explains data processing activities and includes the applicable legal basis.

Selecting a legal basis before collecting or using personal data is an important part of GDPR compliance. Organizations need to choose a basis that matches the actual purpose and circumstances of the processing rather than selecting the most convenient option.

Honor Data Subject Rights (DSARs)

The GDPR requires organizations to respond to requests from individuals to exercise their rights, including data subject access requests.

The main GDPR data subject rights include:

  • Access: The right to obtain a copy of personal data and information about how it is being processed.
  • Rectification: The right to correct inaccurate personal data.
  • Erasure (also called "the right to be forgotten"): The right to request deletion of personal data.
  • Restriction: The right to limit how personal data is processed.
  • Data portability: The right to receive certain personal data in a structured, commonly used, and machine-readable format and transmit it to another organization.
  • Objection: The right to object to certain types of processing, including direct marketing.

Under Article 12 of the GDPR, organizations have one month to respond to a DSAR. For complex or numerous requests, the GDPR allows an extension of up to two additional months. Organizations still need to notify the individual within one month of receiving the request and explain the reason for the extension.

Many US businesses underestimate the work involved in responding to DSARs. A Privacy Policy that describes privacy practices and lists data subject rights is not enough to comply with the GDPR.

Goodreads users submit a DSAR from their account Settings tab and have the option to fill out a contact form for specific requests.

GoodReads - User - Settings - DSAR option

Businesses need a process for handling DSARs from start to finish, which includes:

  • Receiving requests
  • Verifying identity
  • Finding requested data (which often requires searching customer relationship management (CRM) platforms, email systems, and billing systems)
  • Producing a response within the required timeframe

The 72-Hour Data Breach Notification Rule

The GDPR breach notification requirements apply when a personal data breach creates a risk to individuals.

The 72-hour data breach rule is found in Article 33 of the GDPR, and requires organizations to notify the supervisory authority within 72 hours of becoming aware of a personal data breach that poses a risk to individuals.

If the notification is made to the supervisory authority after 72 hours, it must be accompanied by a reason for the delay.

Notification requirements for a GDPR data breach US companies need to be aware of are:

  • A description of the nature of the data breach
  • The categories and approximate number of people affected
  • The categories and approximate number of personal data records involved
  • The name and contact information of the DPO or designated contact
  • The likely consequences of the data breach
  • The measures that will be taken to address the breach and mitigate its effects

If the breach poses a high risk to individuals, such as in cases involving identity theft or financial loss, then Article 34 of the GDPR requires the organization to also notify impacted individuals without undue delay. However, notification is not required when security measures like strong encryption make the affected personal data unreadable to unauthorized people.

Mercor provides an example of how a large company responded to a data breach. On June 25, 2026 Mercor published an Update on Mercor security incident blog post that explained that it was in the process of notifying individuals affected by a recent data breach.

Mercor reported that a March 2026 supply chain attack involving the open-source tool LiteLLM had a limited impact, affecting sensitive information belonging to only a small number of its experts. The company said it was notifying affected individuals directly and offering identity protection services. Customer information was also minimally affected, and no employee data was compromised. Mercor said it has since taken additional steps to strengthen its security and protect customer and expert information.

Preparing for data breaches before an incident occurs helps organizations identify breaches quickly, assess risk, gather required information, and meet notification deadlines.

Appoint a Data Protection Officer (When Required)

The GDPR requires organizations to appoint a DPO when their status or data processing activities meet certain criteria.

If you're wondering, "Do I need a DPO?" the answer depends on the nature of your organization and its core processing activities.

A DPO is mandatory when:

  • The organization is a public authority or body, except for courts acting in their judicial capacity
  • Core activities require regular and systematic monitoring of individuals on a large scale
  • Core activities involve large-scale processing of special categories of personal data or personal data related to criminal convictions and offenses

The Amazon Global Candidate Privacy Notice explains that EU candidates contact its DPO for privacy-related questions.

Amazon - Global Candidate Privacy Notice - Questions and queries - DPO linked

A DPO advises the organization on and monitors GDPR compliance, provides advice on DPIAs, helps train employees, and cooperates with and acts as a point of contact for the supervisory authority. A DPO works as an employee or as an outsourced contractor.

When choosing a DPO, US companies need to select an individual who has expert knowledge of data protection law and practices, operates independently, and reports directly to the highest level of management.

Data protection officer GDPR restrictions prohibit organizations from instructing DPOs on how to perform their tasks or dismissing or penalizing them for performing those duties.

Appoint an EU Representative

Organizations that are subject to the GDPR but aren't established in the EU are required to appoint an EU representative.

An EU representative is different from a DPO. The representative serves as a local point of contact in the EU, while a DPO advises the organization on GDPR compliance.

Article 27 of the GDPR establishes the following requirements for EU representatives:

  • Be established in an EU Member State where relevant data subjects are located
  • Be appointed in writing
  • Serve as a contact for supervisory authorities and data subjects for GDPR-related issues
  • Maintain ROPA where applicable
  • Make ROPA available to supervisory authorities upon request

ZeroFox maintains an EU Representative page that explains how EU data subjects contact its EU representative.

ZeroFox Terms and Transparency - EU Representative

The GDPR does not require an EU representative in the following cases:

  • Organizations that process personal data only occasionally, do not engage in large-scale processing of special categories of personal data or criminal conviction data, and are unlikely to create a risk to the rights and freedoms of individuals
  • Public authorities or bodies

To comply with the GDPR, the EU representative for a US company must be located in an EU member state and have the ability to communicate with data subjects and supervisory authorities.

Failure to appoint a required EU representative is a GDPR violation with fines of up to the higher amount of EUR 10 million or 2% of total worldwide annual turnover from the preceding financial year.

Sign Data Processing Agreements with Vendors

Organizations that use third-party vendors to process personal data on their behalf need a data processing agreement (DPA) with each processor.

Common examples of vendors include email platforms, CRM systems, cloud hosting providers, payment processors, and analytics providers.

Businesses looking for information about GDPR DPA vendors need to understand that a DPA sets the rules for how a vendor handles personal data.

A signed DPA obligates the processor to meet Article 28 data processor requirements, including:

  • Processing personal data according to the documented instructions of the data controller
  • Ensuring that authorized personnel keep personal data confidential
  • Implementing technical and organizational security measures
  • Obtaining authorization from the controller before using sub-processors
  • Assisting the controller with DSARs
  • Assisting with security obligations, data breach notifications, and DPIAs as needed
  • Deleting or returning personal data after the processing relationship ends, unless the law requires continued storage

The Revalize DPA restricts the processing of personal data, including its sale or use for purposes beyond those specified by the customer.

Revalize, Inc. DPA - Processing of personal data clause

Controllers are responsible for choosing and overseeing their vendors. A GDPR violation by a processor creates potential compliance problems for the controller, making vendor oversight an ongoing responsibility rather than a one-time task.

Organizations need to regularly review the companies that handle personal data for them, the sub-processors those companies use, security practices, and contract terms, and ensure that all required DPAs are in place.

Implement Data Security Measures

The GDPR requires organizations to implement technical and organizational measures to protect personal data.

To comply with Article 32 of the GDPR, US companies must:

  • Choose security measures based on the risks involved
  • Maintain the confidentiality, integrity, availability, and resilience of processing systems and services
  • Have processes for quickly restoring access to personal data after a security incident
  • Test the effectiveness of security measures

Security measures include:

  • Encryption and pseudonymization
  • Access controls and role-based permissions
  • Multi-factor authentication (MFA)
  • Logging and monitoring
  • Vulnerability management:

Article 25 of the GDPR requires organizations to follow data protection by design and by default. This means building privacy and data protection into the way products, services, and systems collect and use personal data from the outset.

GDPR - Article 25 - Data protection by design and default

International Data Transfers from the EU to the US

Getting personal data from the EU to the U.S. is one of the hardest GDPR problems.

Under the GDPR, the US is a "third country" because it is outside the EU. Personal data cannot lawfully flow from the EU to the US unless one of the GDPR data transfer safeguards, an adequacy decision, or a derogation applies.

Three common mechanisms for an EU-US data transfer include:

  • The EU-U.S. Data Privacy Framework: Allows participating US organizations to receive personal data from the EU under an EU adequacy decision.
  • Standard Contractual Clauses (SCCs): Allow organizations to transfer personal data from the EU to the US under a contract containing specific data protection requirements.
  • Article 49 derogations: Allow data transfers in limited situations that meet specific GDPR requirements.

The right transfer method depends on the circumstances of the transfer and how US laws affect the level of protection provided by the chosen safeguard.

The rules governing transfers between the EU and the US have changed significantly over time and are legally complex. Organizations should seek legal advice to verify that the mechanism used for each transfer is valid and appropriate for the specific circumstances.

The EU-US Data Privacy Framework (2023)

The EU-US Data Privacy Framework (DPF) provides a way for participating US organizations to receive personal data from the EU.

The European Commission adopted the framework through an adequacy decision on July 10, 2023, representing the third major attempt to create a system for EU-US data transfers. The Court of Justice of the EU (CJEU) invalidated the Safe Harbor framework in 2015 and the Privacy Shield framework in 2020 in the Schrems II decision.

US organizations participate through Data Privacy Framework self-certification. A company self-certifies to the US Department of Commerce that it complies with the DPF Principles. Once a business appears on the official DPF list, organizations in the EU are allowed to transfer personal data to that company under the adequacy decision without relying on a separate transfer mechanism, such as SCCs.

The United Kingdom (UK) Extension to the EU-US DPF covers data transfers from the UK to the US, while the Swiss-US DPF governs data transfers between Switzerland and the US.

DPF self-certification only covers the transfer of personal data to a participating US organization. It does not replace other GDPR obligations. Organizations still need to follow applicable rules on transparency, processing personal data, data subject rights, security, and data retention.

The CJEU invalidated both previous EU-US data transfer frameworks. On June 29, 2026, the US Supreme Court held in Trump v. Slaughter that the President may remove Federal Trade Commission (FTC) commissioners at will, ending the agency's independence. The following day, privacy organization None of Your Business (NOYB) wrote to the European Commission calling for an orderly withdrawal of the adequacy decision, on the grounds that the DPF depends on the FTC acting as an independent enforcement body.

While some businesses don't rely on the EU-US Framework and instead use SCCs, NOYB argues that the decision affects those organizations because they need to assess whether US laws provide sufficient protection for transferred personal data. The European Commission has not withdrawn the DPF adequacy decision, and the DPF remains in force. Organizations should monitor legal developments, review international transfer arrangements, and maintain SCCs as a fallback as the situation develops.

Standard Contractual Clauses (SCCs)

Standard Contractual Clauses (SCCs) are legally binding data protection terms adopted by the European Commission. EU companies use international transfer SCCs in contracts with organizations located outside of the European Economic Area (EEA) to meet GDPR requirements when an adequacy decision does not apply.

In 2021, the European Commission adopted two sets of SCCs for different purposes:

  1. SCCs for controller-processor relationships: This set of SCCs helps organizations comply with Article 28 of the GDPR and Article 29 of the EU Data Protection Regulation (EUDPR). SCCs for controller-processor relationships are available for use by public and private entities and EU agencies, bodies, institutions, and offices.
  2. International transfer SCCs: This set of SCCs provides safeguards for transferring personal data to countries outside the EEA. SCCs for international transfers are for use by data exporters, and don't require prior authorization from a data protection authority.

The Schrems II decision changed how organizations use SCCs for international transfers. The CJEU held that data controllers and processors relying on SCCs to transfer data must ensure that personal data receives a level of protection essentially equivalent to that provided under EU law. That means that even when using SCCs, organizations must review the laws and practices in the destination country to determine whether additional safeguards are needed to protect personal data.

When relying on SCCs for international data transfers, US organizations should:

  • Conduct a transfer impact assessment to evaluate the risks associated with a transfer and determine whether additional protections are needed
  • Use additional safeguards, such as strong encryption, when necessary to prevent unauthorized access to personal data

If the protections in place do not adequately protect the data from foreign government access, the transfer is not lawful.

Article 49 Derogations

Article 49 derogations are limited exceptions to the rules for international data transfers. They apply only in specific situations where an adequacy decision or appropriate safeguards are absent.

GDPR derogations include:

  • Consent: The data subject explicitly consents to the transfer after receiving information about the recipient, transfer location, purpose, data categories, withdrawal rights, and the risks associated with the absence of an adequacy decision or appropriate safeguards.

    For example, an EU student applies to a US university and explicitly consents to the transfer of their personal data to the US as part of the application process.

  • Contract: The transfer is necessary to perform or enter into a contract with the individual, or to perform a contract in the individual's interest.

    For example, a travel agency sending a customer's personal data to a hotel in the US to arrange a booking relies on this derogation.

  • Additional derogations: Transfers necessary for important reasons of public interest, legal claims, vital interests, and certain public registers.

These derogations are not intended for routine, ongoing data transfers. Organizations should use an adequacy decision or an appropriate transfer safeguard for regular international transfers and rely on an Article 49 derogation only when its specific requirements are met.

The Jabil Restricted Stock Unit Award Agreement explains that in the absence of appropriate safeguards, personal data will not be transferred to a third party outside the EEA unless an Article 49 derogation applies.

In the absence of appropriate safeguards, Grantee's Personal Data will not be transferred to a third party located outside the EEA, unless a specific derogation applies in the sense of Article 49 of the GDPR.

Update Your Privacy Policy

A GDPR-compliant Privacy Policy is the foundation of U.S. compliance. GDPR Privacy Policy requirements are found in Articles 12-14 of the law and require organizations to tell individuals how they collect, use, and protect personal data and explain their privacy rights.

A GDPR compliant Privacy Policy US organizations use needs to be clearly written, easily accessible, and contain the following clauses:

  • Business contact information: The contact details of the controller and their representative and DPO, where applicable.
  • Personal data processing purposes: The types of personal data the organization processes and the reasons for processing it.
  • Lawful bases: The lawful basis for each processing activity. If processing is based on legitimate interests, the Privacy Policy should include a list of those interests.
  • Data sharing: The categories of third parties that receive personal data, including US-based vendors and service providers.
  • International data transfers: The safeguards used for transfers of personal data outside the EEA, such as the EU-US DPF or SCCs.
  • Data retention: How long the organization retains personal data or the criteria for determining the retention period.
  • Data subject rights: How individuals in the EU exercise GDPR rights and file complaints with the relevant supervisory authority.
  • Contractual requirement: Whether the personal data is a statutory or contractual requirement and what happens if the data subject doesn't provide their data.
  • Automated decision-making: Whether automated decision-making, including profiling, exists, and its consequences.
  • Source of data: The source of personal data not obtained from the data subject, and whether it came from publicly accessible sources.

When researching what to include in a GDPR-compliant Privacy Policy, organizations should look closely at Articles 12-14 of the GDPR. Generic US Privacy Policy templates often include California Online Privacy Protection Act (CalOPPA)-style disclosures that are limited to descriptions of categories of personal data collected and categories of third parties that receive personal data instead of the detailed information required by the GDPR.

If your U.S. website uses non-essential cookies on EU visitors, GDPR-level consent applies. The EU ePrivacy Directive requires prior consent for non-essential cookies, while the GDPR sets the standard for valid consent.

GDPR cookies US website requirements apply to analytics, advertising, personalization, and other non-essential cookies that process personal data.

The ePrivacy Directive and GDPR cookie consent US requirements include:

  • Prior consent: Non-essential cookies load only after the user provides prior, informed, opt-in consent.
  • Valid consent: Consent is freely given, specific, informed, unambiguous, recorded, and as easy to withdraw as to give. Pre-ticked boxes and cookie walls do not satisfy GDPR requirements.
  • Cookie banner: A compliant cookie banner provides users with the ability to accept, reject, or manage consent for different categories of non-essential cookies and blocks those cookies until consent is received.

Businesses need to understand the GDPR requirements that apply when using Google Analytics. For US organizations, GDPR compliance includes addressing both cookie consent and international data transfer obligations.

Several EU Data Protection Authorities, including those in Austria, France, Italy, and Denmark, found that standard Google Analytics implementations violated the GDPR because transfers of personal data to the US lacked sufficient safeguards.

Organizations reduce compliance risks by:

  • Using a GDPR-compliant analytics alternative
  • Implementing Google Consent Mode to help respect website visitor consent choices
  • Blocking non-essential analytics cookies until valid consent is received
  • Reviewing international data transfer mechanisms used by analytics providers

GDPR vs. US Privacy Laws (CCPA, CPRA, and More)

CCPA compliance is a useful foundation, but it is not GDPR compliance. Understanding the differences between GDPR vs CCPA helps US organizations determine which privacy laws apply to their processing activities and reduce compliance risks.

The US equivalent of GDPR does not exist. Instead, the US relies on a combination of sector-specific federal laws and state privacy laws, including the following:

  • Health Insurance Portability and Accountability Act (HIPAA): Protects health information by setting rules for how it is collected, used, shared, and secured.
  • Gramm-Leach-Bliley Act (GLBA): Requires financial institutions to inform customers about how they share information and to keep sensitive data secure.
  • Children's Online Privacy Protection Act (COPPA): Protects the online privacy of children under 13 by requiring parental notice and consent before collecting, using, or disclosing their personal information.
  • California Consumer Privacy Act (CCPA): Gives California residents privacy rights, including the rights to know, delete, and opt out of the sale and sharing of their personal information.
  • California Privacy Rights Act (CPRA): Expands the CCPA by adding new consumer rights and additional business obligations.
  • Virginia Consumer Data Protection Act (VCDPA): Gives Virginia residents rights over their personal data and requires certain businesses to meet data processing obligations.
  • Colorado Privacy Act (CPA): Gives Colorado residents privacy rights and requires covered businesses to provide transparency, protect personal data, and obtain consent before processing certain sensitive personal data.

Federal privacy proposals, including the American Data Privacy and Protection Act (ADPPA) and the American Privacy Rights Act (APRA), have been introduced but have not resulted in a comprehensive federal privacy law.

When comparing GDPR vs US privacy laws, businesses need to be aware of differences between consent requirements, privacy rights, enforcement, and regulatory scope.

Dimension GDPR US (CCPA/CPRA + federal laws)
Consent model: Opt-in consent where required and a lawful basis for processing Primarily opt-out under the CCPA/CPRA and similar state privacy laws, with additional consent requirements under certain state and federal laws
Scope: Broad definition of personal data with extraterritorial application No single national privacy law; state privacy laws and federal laws apply to specific industries and types of data
Rights: Access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making Access, deletion, correction, and opt-out rights that vary by state
Penalties: Administrative fines of up to €20 million or 4% of worldwide annual turnover, whichever is higher Civil penalties that vary by law and jurisdiction, often assessed on a per-violation basis
Enforcement: EU supervisory authorities State attorneys general, state privacy regulators, or federal agencies, depending on the law.

GDPR Compliance Checklist for US Businesses

GDPR compliance steps depend on whether the GDPR applies to your organization and how personal data is processed.

This checklist outlines the key GDPR requirements for US businesses.

Determine applicability: Confirm whether your organization offers goods or services to individuals in the EU or monitors their behavior.

Identify your role(s): Determine whether your organization acts as a controller, processor, or both.

Conduct a data mapping audit: Document what EU personal data you process, where it is stored, who has access, how it is used, and how long it is retained.

Document a lawful basis for each processing activity: Record the GDPR lawful basis that applies to each processing activity, such as consent, contract, legal obligation, legitimate interests, vital interests, or a task carried out in the public interest.

Update your Privacy Policy: Include all information required by the GDPR, including lawful bases for processing, data subject rights, data sharing practices, international data transfers, and data retention practices, to meet GDPR transparency requirements.

Implement consent mechanisms: Use consent forms, cookie banners, and similar tools that request consent before processing personal data where required. Ensure consent is freely given, granular, recorded, and as easy to withdraw as it is to give.

Establish DSAR procedures: Set up a process for receiving, tracking, and responding to DSARs within the required timeframe.

Sign DPAs: Enter into written agreements with vendors that process personal data on your behalf.

Appoint an EU representative and a DPO: Appoint an EU representative if your organization is outside the EU but offers goods or services to individuals in the EU or monitors their behavior and no exceptions apply. Appoint a DPO if the organization is a public authority or body or its core activities involve large-scale monitoring of individuals or large-scale processing of special categories of personal data.

Implement security measures: Protect personal data by implementing appropriate technical and organizational security measures, such as encryption, access controls, MFA, and security monitoring.

Establish data breach response protocols: Develop a plan for responding to personal data breaches, documenting incidents, determining whether notification is required, and reporting breaches within 72 hours when required.

Implement safeguards for international data transfers: Identify transfers of personal data outside the EEA and implement an appropriate transfer mechanism, such as certification under the EU-US DPF or the use of SCCs.

Conduct DPIAs: Complete a DPIA before carrying out processing activities that are likely to result in a high risk to the rights and freedoms of individuals.

Provide GDPR training: Train employees on GDPR responsibilities, data protection practices, and security procedures, and conduct regular compliance audits.

Maintain ROPA: Keep records describing processing activities, including processing purposes, categories of personal data, recipients, international data transfers, retention periods, and security measures.


GDPR Fines and Enforcement Against US Companies

The GDPR has two categories of fines based on the type and severity of the violation. Supervisory authorities decide whether to impose a fine and determine the amount based on factors such as the nature, gravity, duration, and circumstances of the infringement. The maximum fine depends on which GDPR requirement was violated.

GDPR fines US companies need to be aware of include:

  • Up to €10 million or 2% of total worldwide annual turnover: Applies to issues such as recordkeeping failures, security shortcomings, or failure to appoint an EU representative where required.
  • Up to €20 million or 4% of total worldwide annual turnover: Applies to infringements such as unlawful processing, violations of data subject rights, or unlawful international data transfers.

Article 83 of the GDPR describes the factors supervisory authorities consider when deciding whether to impose a fine and determining the amount.

GDPR - Article 83 - General conditions for imposing fines - Clause 2 excerpt

Can the EU enforce the GDPR against a U.S. company? Yes. Many US organizations fall within the scope of the GDPR because they offer goods or services to individuals in the EU or monitor their behavior. When the GDPR applies, EU data protection authorities take enforcement action against US organizations that fail to comply.

Enforcement measures include:

  • Administrative fines
  • Orders to bring processing activities into compliance
  • Orders to restrict or stop processing personal data, including temporary or permanent bans on processing

Many authorities publish enforcement decisions, creating financial and reputational consequences. Understanding GDPR penalties US organizations face helps businesses evaluate compliance risks.

The following examples show that EU authorities have imposed significant GDPR fines on US companies.

Company HQ Penalty Year Enforcer Issue
X/Twitter US €450,000 2020 Ireland DPC Delayed breach notification
Amazon US €746 million 2021 Luxembourg National Data Protection Commission (CNPD) Personal data processing
Meta Platforms (Facebook) US €60 million 2022 CNIL Cookie consent violations
Meta Platforms (Instagram) US €405 million 2022 Ireland Data Protection Commission (DPC) Personal data belonging to children
Google US €150 million 2022 Commission nationale de l'informatique et des libertés (CNIL) Cookie consent violations
Clearview AI US €20 million 2022 Italian Data Protection Authority Unlawful biometric data processing
Meta Platforms US €1.2 billion 2023 Ireland DPC Unlawful EU-US data transfers
Clearview AI US €30.5 million 2024 Dutch Data Protection Authority Unlawful biometric data processing

How to Handle a Data Subject Access Request (DSAR)

A DSAR allows individuals to find out whether an organization processes their personal data and to request access to that information. Having a data subject access request process helps organizations respond consistently and meet GDPR deadlines.

Here's the step-by-step process for how to handle a DSAR:

  1. Receive and log the request: Record each request as soon as it arrives, regardless of whether it is submitted by email, an online form, chat, or another communication channel.
  2. Verify the identity of the requester: Confirm the identity of the requester before providing access to personal data. Ask only for the information needed to confirm identity and avoid collecting unnecessary personal data.
  3. Clarify the scope: If the request is broad or unclear, ask the requester to specify the information or processing activities involved.
  4. Search all relevant systems: Search every system that stores or processes personal data relating to the requester, including CRM systems, email, billing platforms, customer support tools, document storage, and analytics systems.
  5. Apply exemptions: Redact information that the GDPR or other applicable laws do not require you to disclose, such as personal data relating to other individuals or information protected by legal privilege.
  6. Prepare the response: Explain what personal data you hold and provide a copy of that data, along with the purposes of processing, categories of personal data, recipients, retention periods, and information about GDPR rights.
  7. Respond within the required timeframe: Provide the response within one month of receiving the request. For complex requests or multiple requests from the same individual, the GDPR allows up to two additional months if the requester is notified within the first month.
  8. Document the outcome: Record how the request was handled, the response date, any information that was withheld, and documents showing how the organization met GDPR requirements.

DSAR challenges often arise when personal data is stored in multiple systems or staff haven't received DSAR training. Clear procedures, employee training, and organized records help provide the GDPR DSAR response US organizations need to stay compliant.

How Much Does GDPR Compliance Cost a US Business?

The GDPR compliance cost US organizations pay varies widely and depends on factors such as the size of the organization and the amount of personal data processed.

According to a 2016 PwC survey, 68% of US organizations with more than 500 employees planned to spend between $1 million and $10 million on GDPR compliance, while 9% expected to spend more than $10 million.

Typical GDPR compliance costs include:

  • Legal and consulting services: Legal advice, compliance assessments, and implementation support.
  • DPO: Salary and benefits for an internal DPO or fees for an outsourced DPO.
  • Privacy documentation: Drafting or updating Privacy Policies, DPAs, internal policies, and other required documentation.
  • Consent management: Consent management platforms (CMPs), cookie banners, cookie scanning, and consent recordkeeping tools.
  • Security upgrades: Encryption, MFA, access controls, monitoring, and other technical and organizational security measures.
  • Employee training: GDPR awareness training and role-specific privacy training.
  • Audits and DPIAs: DPIAs and compliance reviews.
  • Ongoing monitoring: Regular policy updates, vendor assessments, and monitoring of legal developments.

The overall GDPR compliance budget depends on factors such as how much personal data an organization processes, how complex its operations are, how many systems store or use personal data, and the privacy and security measures already in place. A small software startup with a limited number of EU customers often spends much less than a large company operating in multiple countries.

When evaluating how much does GDPR cost, organizations need to consider the price of non-compliance. GDPR violations potentially result in fines, orders to change business practices, legal expenses, and lost business opportunities in the EU.

Free GDPR Privacy Policy Template

This free GDPR Privacy Policy template is a starting point for creating a Privacy Policy that addresses common GDPR transparency requirements. Every organization collects and uses personal data differently, so the template requires customization before publication.

Review each section carefully and replace the placeholder text with information about how the organization collects, uses, shares, and stores personal data, along with applicable GDPR rights. A GDPR Privacy Policy template does not replace legal review or updates based on the actual data practices of the organization.

The TermsFeed GDPR Privacy Policy Generator helps organizations create a customized Privacy Policy by guiding users through a series of questions about how they collect and use personal data.

You can download the Sample GDPR Privacy Policy Template as HTML code below. Copy it from the box field below (right-click > Select All and then Copy-paste) and then paste it on your website pages.

Screenshot of the Sample GDPR Privacy Policy Template


GDPR for US Businesses: Frequently Asked Questions

The following FAQs include answers to common questions about GDPR requirements for US businesses.

Yes. The GDPR applies to many US companies that offer goods or services to individuals in the EU or monitor their behavior. A business does not need a physical presence in the EU for the GDPR to apply.

Yes, the GDPR applies to US citizens when they are in the EU. The GDPR protects individuals based on where they are located, not their citizenship. A US citizen in the EU receives GDPR protections, while an EU citizen in the US does not.

Sometimes. A US website falls within the scope of the GDPR if it targets individuals in the EU or monitors their behavior, such as through tracking technologies used for analytics or advertising.

No, company size does not determine whether the GDPR applies. Both small businesses and large organizations need to comply with the GDPR when it applies to their data processing activities.

However, some requirements include limited exceptions for smaller organizations. For example, the requirement to maintain ROPA includes an exception for organizations with fewer than 250 employees, depending on the type and frequency of their data processing activities.

GDPR penalties include fines of up to €10 million or 2% of total worldwide annual turnover, or up to €20 million or 4% of total worldwide annual turnover, depending on the violation. Authorities also issue orders requiring organizations to change or stop certain data processing activities.

The US does not have a single federal privacy law equivalent to the GDPR. Instead, privacy requirements come from a combination of federal laws and state laws, including state laws such as the CCPA and the VCDPA and industry-specific federal laws.

A DPO is required only in specific situations described in Article 37 of the GDPR. For example, a DPO is required for public authorities and organizations whose core activities involve large-scale monitoring of individuals or large-scale processing of special categories of data.

Personal data transfers from the EU to the US require a valid transfer mechanism under the GDPR. Common options include certification under the EU-US DPF or the use of SCCs, depending on the circumstances.

When a US company offers goods or services to individuals in the EU or monitors their behavior but fails to comply with the GDPR, supervisory authorities take enforcement action. Enforcement measures include fines, orders to change business practices, restrictions on processing personal data, and public enforcement decisions.


Summary and Key Takeaways

The following summary covers the key GDPR requirements US businesses need to understand.

  • The GDPR applies to many US businesses when they offer goods or services to individuals in the EU or monitor their behavior.
  • The GDPR applies based on where an individual is located, not their citizenship, and there is no general small-business exemption from compliance.
  • Organizations need to identify whether they operate as a controller, a processor, or both, and document a lawful basis for each personal data processing activity.
  • Organizations must meet the core GDPR requirements, including publishing a Privacy Policy, establishing a DSAR process, reporting personal data breaches within 72 hours when required, appointing a DPO or EU representative where required, using vendor DPAs, and implementing appropriate security measures.
  • Organizations need to use a valid transfer mechanism for personal data transferred from the EU to the US, such as certification under the EU-US DPF or SCCs.
  • Although the CCPA and the GDPR share some privacy principles, meeting CCPA requirements does not mean an organization complies with the GDPR.
  • Supervisory authorities actively enforce the GDPR against US organizations, and violations result in significant fines and other enforcement measures.

The TermsFeed Privacy Policy Generator helps organizations create a customized Privacy Policy that reflects their data processing activities. TermsFeed also provides consent management tools to help organizations manage cookie consent and support GDPR compliance.

Privacy Policy Generator
The first step to compliance: A Privacy Policy.

Stay compliant with our agreements, policies, and consent banners — everything you need, all in one place.

Generate Privacy Policy