Does GDPR Apply to US Companies? Article 3 Explained (2026)

By Recording Law Editorial TeamReviewed June 9, 202630 min read
Does GDPR Apply to US Companies? Article 3 Explained (2026)

Frequently Asked Questions

Does GDPR apply to US companies?

Yes, GDPR applies to US companies that meet either test in Article 3(2): the company offers goods or services to people in the EU (even for free), or it monitors the behaviour of people in the EU, for example through advertising pixels, analytics profiling, or location tracking. Physical presence or establishment in the EU is not required. The analysis turns on whether the company intentionally targets EU users or technically monitors their behaviour while they are in the Union.

Does my US website need to comply with GDPR?

It depends on whether your website meets either trigger in Article 3(2). If your website accepts EU-currency checkout, offers EU shipping, runs EU-targeted advertising, or uses analytics or advertising pixels that track individual EU visitors over time, GDPR likely applies. Recital 23 makes clear that mere website accessibility in the EU is not enough: a US-only English site with no EU-facing features, EU payment options, or EU-directed advertising is unlikely to trigger GDPR on its own, even if EU residents occasionally visit it.

What is an Article 27 EU representative and does my US company need one?

An Article 27 representative is a natural person or organisation established in an EU Member State that a non-EU company designates as its local point of contact for data subjects and supervisory authorities. Your US company needs one if Article 3(2) applies to your processing and the Article 27(2) narrow exception does not: that exception covers only processing that is occasional, does not involve large-scale special-category data, and poses minimal risk to data subjects. Most US companies with an ongoing EU customer base, marketing list, or analytics programme must appoint a representative. Failing to do so is a Tier 1 Article 83(4) violation with fines up to EUR 10 million or 2% of global annual turnover.

Can the EU fine a US company with no EU assets?

Yes. GDPR fines are assessed against the undertaking and can be enforced in multiple ways: through the Article 27 representative, through orders directing EU-based partners to suspend data transfers to the non-compliant US company, and through cross-border legal enforcement mechanisms. EU DPAs have imposed fines exceeding EUR 1 billion against US-headquartered companies operating through EU subsidiaries. A US company that operates entirely without EU assets is harder to collect against, but the reputational and commercial consequences of an enforcement order blocking EU data transfers are severe regardless.

What is the difference between GDPR and CCPA for a US business?

GDPR requires a lawful basis for every processing activity before it begins (a prior-permission model), while CCPA/CPRA uses a post-hoc opt-out model for the sale or sharing of personal information. GDPR's consent standard requires freely given, specific, informed, and unambiguous indication of agreement; CCPA's general framework permits processing unless the consumer opts out of sale or sharing. GDPR applies to any company targeting or monitoring EU residents, regardless of revenue; CCPA/CPRA applies to for-profit California businesses meeting specific revenue or data-volume thresholds. A company with both EU and California exposure needs both compliance programmes, though the data-mapping and vendor-management backbone can be shared.

What is the EU-US Data Privacy Framework and how does self-certification work?

The EU-US Data Privacy Framework (DPF) is an adequacy mechanism adopted by the European Commission on 10 July 2023 (Decision 2023/1795). It allows EU entities to transfer personal data to self-certified US organisations without executing Standard Contractual Clauses for each transfer. A US company self-certifies annually to the US Department of Commerce by committing to the seven DPF Principles (Notice, Choice, Accountability for Onward Transfer, Security, Data Integrity and Purpose Limitation, Access, and Recourse Enforcement and Liability). Certification is limited to companies under FTC or Department of Transportation jurisdiction. DPF-certified organisations are listed publicly at dataprivacyframework.gov.

Does DPF certification mean a US company is fully GDPR compliant?

No. DPF certification addresses only the data transfer mechanism: it allows EU personal data to flow lawfully to the certified US company without per-transfer SCC execution. It does not substitute for full GDPR compliance. A DPF-certified US company still must have a lawful basis for every processing activity, provide an Article 13/14 privacy notice, respond to data subject rights requests, maintain Article 30 processing records, execute Article 28 processor agreements with vendors, and satisfy all other GDPR obligations. DPF is a transfer-law solution, not a general GDPR compliance badge.

Which EU supervisory authority has jurisdiction over a US company?

A non-EU company without an EU establishment is subject to the jurisdiction of any EU Member State's supervisory authority where its EU data subjects are located. If a US company designates an Article 27 representative in, for example, Ireland, the Irish Data Protection Commission has primary jurisdiction for matters arising through the representative. Without a representative, any DPA in a Member State where affected data subjects reside can open an investigation. This differs from the one-stop-shop mechanism available to EU-established controllers, where a single lead authority coordinates cross-border enforcement.

Do US B2B companies need to comply with GDPR for EU business contacts?

Yes, if they process personal data of individuals at EU businesses. GDPR protects natural persons, not legal entities. Individual business contacts (names, work email addresses, direct-dial numbers of employees at EU companies) are personal data under GDPR because they identify a natural person. A US SaaS platform, marketing automation tool, or outbound sales team processing EU employee contact data for prospecting, outreach, or CRM purposes may be covered under the targeting test (if EU businesses are deliberately targeted) or the monitoring test (if contact data is used for profiling or behavioural tracking). The exemption for business contact data found in some national data protection laws does not exist in GDPR.

What are the biggest GDPR fines against US companies?

The largest on record as of mid-2026 is the EUR 1.2 billion fine against Meta Platforms by the Irish DPC in May 2023, for transferring EU user data to US servers without adequate safeguards. Luxembourg's CNPD fined Amazon EUR 746 million in July 2021 for processing EU users' advertising data without a valid lawful basis. The Irish DPC fined WhatsApp EUR 225 million in September 2021 for transparency violations. France's CNIL fined Google LLC EUR 150 million in January 2022 for cookie-consent practices that made refusal harder than acceptance. These actions involved US-headquartered companies operating through EU subsidiaries.

Sources and References

  1. GDPR Arts. 3, 27, 83 and Recitals 23-24 (Regulation (EU) 2016/679)(eur-lex.europa.eu)
  2. EDPB Guidelines 3/2018 on Territorial Scope (Article 3 GDPR), Version 2.0, adopted 12 November 2019(edpb.europa.eu)
  3. Commission Implementing Decision (EU) 2023/1795: EU-US Data Privacy Framework Adequacy Decision, 10 July 2023(eur-lex.europa.eu)
  4. Commission Implementing Decision (EU) 2021/914: Standard Contractual Clauses for International Transfers, 4 June 2021(eur-lex.europa.eu)
  5. EU-US Data Privacy Framework Program: Seven Principles(dataprivacyframework.gov)
  6. EU-US Data Transfers: Available Mechanisms Overview(commission.europa.eu)
  7. CJEU: Data Protection Commissioner v. Facebook Ireland (Schrems II), Case C-311/18, 16 July 2020(curia.europa.eu)
  8. CJEU: Google Spain v AEPD and Mario Costeja Gonzalez, Case C-131/12, 13 May 2014(curia.europa.eu)
Share: