← Back to blog

GDPR for US Companies: Applicability Test & Compliance Checklist

August 8, 2026
GDPR for US Companies: Applicability Test & Compliance Checklist

GDPR applies to many U.S. companies right now, whether or not they have a single office in Europe. Under Article 3 of the GDPR, the regulation reaches any organization that processes personal data of individuals located in the EU when offering them goods or services, or when monitoring their behavior. The European Data Protection Board (EDPB) has confirmed this in its Guidelines 3/2018 on territorial scope, making the legal position clear: geography of incorporation does not determine applicability.

Three triggers can bring your U.S. company into scope:

  • Article 3(1) — Establishment: You have an office, subsidiary, or stable arrangement in the EU, and your processing relates to that establishment's activities.
  • Article 3(2)(a) — Offering goods or services: You offer products or services to individuals located in the EU, even for free.
  • Article 3(2)(b) — Monitoring behavior: You track, profile, or analyze the online behavior of individuals in the EU, including via cookies, analytics, or ad targeting.

Non-compliance carries real consequences. Fines reach up to €20 million or 4% of global annual turnover, whichever is higher, and supervisory authorities have demonstrated willingness to pursue U.S.-based entities.


Key Takeaways

GDPR applies to US companies that target or monitor EU individuals, regardless of where the company is incorporated, and non-compliance carries fines up to €20 million or 4% of global annual turnover, whichever is higher.

PointDetails
Run the applicability test firstCheck for EU establishment, active targeting of EU users, or behavioral monitoring before assuming GDPR doesn't apply.
Build your RoPA immediatelyDocument every EU-relevant data flow, legal basis, and processor relationship as your compliance foundation.
Execute DPAs with all processorsEvery vendor touching EU personal data needs a signed DPA; missing agreements are a top enforcement trigger.
Prepare for the 72-hour breach ruleAssign breach response ownership and draft your notification template before an incident occurs.
Cannatract can automate the operational workCannatract builds DSR workflows, retention automation, and secure integrations for US companies managing GDPR obligations.

Table of Contents

Does GDPR apply to your US business? Run this quick test

Before spending a dollar on legal counsel, run this 30-minute assessment. It will tell you whether GDPR compliance for your US company is a live obligation or a future consideration.

Work through each question:

  • Do you have an EU establishment? Any office, branch, subsidiary, or even a single employee with a stable presence in an EU member state counts. If yes, GDPR applies to all processing connected to that establishment's activities.
  • Do you actively offer goods or services to EU-located individuals? This is not about whether an EU resident could find your website. Regulators look for deliberate targeting signals.
  • Do you monitor the behavior of EU-located individuals? Web analytics, behavioral advertising, cookie tracking, and user profiling all qualify.

Targeting markers regulators actually look for

The IAPP's practitioner guidance identifies the signals supervisory authorities use to determine intent to target EU users:

  • Pricing displayed in euros
  • Shipping options to EU addresses
  • Marketing pages translated into EU languages (German, French, Spanish, etc.)
  • EU-specific advertising campaigns (Google Ads, Meta targeting EU countries)
  • Accepting EU payment methods (SEPA, iDEAL)
  • Domain extensions like .de, .fr, or .eu

Removing these markers proactively can help demonstrate you are not targeting the EU, which matters if you want to argue GDPR does not apply.

Real-world examples where US companies get caught

A SaaS company selling subscriptions to EU businesses is clearly in scope. A U.S. e-commerce brand shipping to Germany is in scope. A U.S. marketing analytics platform running behavioral tracking scripts on EU-facing websites is in scope under the monitoring prong.

Pro Tip: Even if you don't market to the EU, acting as a data processor for an EU controller pulls you into GDPR's reach. If your software processes personal data on behalf of an EU client, Article 28 obligations apply to you regardless of where you're incorporated.


Why US companies can't afford to ignore GDPR obligations

The financial exposure alone should get your attention. Fines under GDPR reach up to €20 million or 4% of global annual turnover, whichever is higher. For a mid-size U.S. company with $50 million in global revenue, the fine for non-compliance could reach up to $2 million, but the final amount is determined as either €20 million or 4% of global annual turnover, whichever is higher.

Enforcement against U.S. entities is not theoretical. In 2024, the Dutch Data Protection Authority fined Clearview AI tens of millions of euros and considered holding its executives personally liable, a signal that regulators are willing to pursue U.S.-based companies aggressively. Clearview had no EU establishment and argued GDPR did not apply. The regulator disagreed.

Beyond fines, the operational consequences stack up quickly: mandatory records, timely responses to data subject requests, prompt breach notifications, and impact assessments for high-risk processing.

The commercial costs are less visible but just as real. EU enterprise clients now routinely require a signed Data Processing Agreement (DPA) before signing any contract. Without one, you lose the deal.


GDPR compliance checklist for US companies

This checklist follows the accountability structure the GDPR requires. Work through it in order, since each step builds on the last. The Gdpr covers the core obligations in detail.

  1. Determine your role. Decide whether your company is a controller (you determine the purpose and means of processing), a processor (you process on behalf of a controller), or both. Your obligations differ significantly.
  2. Build your Records of Processing Activities (RoPA). Document every processing activity: what data you collect, why, the legal basis, who has access, retention periods, and any transfers outside the EU.
  3. Document lawful bases. For each processing activity, identify the legal basis: contract performance, legitimate interests, consent, legal obligation, vital interests, or public task. Consent must be freely given, specific, and withdrawable.
  4. Update privacy notices. Your privacy policy must tell EU users what data you collect, why, how long you keep it, their rights, and how to exercise them. Generic U.S.-style privacy policies usually fall short.
  5. Execute Data Processing Agreements. Sign DPAs with every vendor that processes EU personal data on your behalf. Review subprocessor chains.
  6. Implement security measures. Encryption at rest and in transit, access controls, logging, and a tested incident response plan are the baseline.
  7. Build a breach notification process. You have 72 hours from discovery to notify the relevant supervisory authority. Prepare a template and assign ownership now, not after a breach.
  8. Run DPIAs for high-risk processing. Biometric data, large-scale profiling, systematic monitoring, and sensitive data categories all require a DPIA before processing begins.
  9. Assign roles. Designate an internal GDPR owner. Appoint an EU representative under Article 27 if required. Assess whether a Data Protection Officer (DPO) is mandatory for your processing activities.

How to implement GDPR compliance step by step

Knowing the checklist is one thing. Running the program is another. Here is how compliance teams at U.S. SMEs and tech providers typically execute it.

Step 1: Scope and appoint an owner

Start by defining which business units, products, and data flows touch EU personal data. Appoint a single internal GDPR owner, whether that is your General Counsel, a privacy manager, or an operations lead. Without a named owner, nothing gets done.

Step 2: Run a data mapping exercise

Map every data flow involving EU personal data: collection points, storage locations, third-party processors, and cross-border transfers. This becomes your RoPA. Tools like OneTrust, Osano, or a structured spreadsheet work for SMEs. For a deeper look at how data architecture decisions affect this work, data warehouse vs. data lake choices matter more than most teams realize when building audit-ready documentation.

Processing ActivityLikely Legal BasisNotes
B2B SaaS contract deliveryContract performanceCovers data needed to provide the service
Marketing to prospectsLegitimate interests or consentLegitimate interests requires a balancing test
Employee HR dataLegal obligation / contractVaries by EU member state
Behavioral analyticsConsentRequires opt-in cookie banner
Customer support recordsLegitimate interestsDocument the balancing test

Step 4: Execute contracts and vendor review

Every processor you use must have a signed DPA. Key clauses to include:

  • Processing instructions and permitted purposes
  • Security measures and standards (ISO 27001, SOC 2 are common references)
  • Subprocessor approval and notification obligations
  • Breach notification timing (typically 24–48 hours to give you time to meet the 72-hour rule)
  • Audit rights and cooperation with supervisory authorities
  • Data deletion or return on contract termination

Review your CRM, marketing automation, cloud hosting, and analytics vendors. If you're evaluating CRM platforms, the HubSpot vs. Salesforce comparison for regulated teams covers how each handles data processing obligations.

Step 5: Build operational workflows

Set up a data subject rights (DSR) intake process. Individuals located in the EU can submit access, deletion, rectification, or portability requests, and you generally have 30 days to respond. Assign ownership, build a verification step (confirm the requester's identity), and log every request. Cannatract's privacy rights request process shows one way to structure this intake.

Prepare a breach response playbook with a 72-hour notification template, escalation contacts, and a log of incidents.

Pro Tip: Triage your DPIAs before you run them all. High-risk processing (biometrics, large-scale profiling, systematic monitoring) gets a DPIA first. Everything else can follow. This approach cuts your initial compliance sprint from months to weeks.

Roles and responsibilities

RoleKey Responsibilities
GDPR Owner (Privacy Lead)RoPA maintenance, DSR oversight, DPIA coordination
IT / EngineeringSecurity controls, encryption, access management, deletion workflows
Legal / CounselDPA negotiation, lawful basis documentation, breach notification
Vendor ManagerProcessor DPA execution, subprocessor review
EU RepresentativeSupervisory authority contact, Article 27 obligations

How do you legally transfer EU personal data to the US?

Three mechanisms are available today. Each has different requirements and practical tradeoffs.

  • EU–U.S. Data Privacy Framework (DPF): The European Commission adopted an adequacy decision for the DPF in July 2023, replacing the invalidated Privacy Shield. U.S. organizations must self-certify with the U.S. Department of Commerce, commit to DPF principles, and maintain annual recertification. Once certified, transfers to the U.S. are treated as adequate without additional safeguards.
  • Standard Contractual Clauses (SCCs): The most widely used mechanism for organizations not certified under the DPF. You execute the European Commission's approved SCC modules between the EU data exporter and the U.S. data importer. When a transfer risk assessment identifies elevated risk (e.g., U.S. government access concerns), you add supplementary measures: encryption, pseudonymization, access restrictions, and contractual commitments.
  • Binding Corporate Rules (BCRs): Suitable for multinational groups with intra-group transfers. BCRs require supervisory authority approval and are time-intensive to obtain. Practical for large enterprises, rarely worth the effort for SMEs.
MechanismBest ForKey Requirement
EU–U.S. Data Privacy FrameworkU.S. companies wanting the simplest transfer pathAnnual self-certification with Commerce Dept.
Standard Contractual ClausesMost US companies, especially SMEsExecute approved SCC modules; document supplementary measures
Binding Corporate RulesLarge multinationals with intra-group transfersSupervisory authority approval

Document your chosen transfer mechanism in your RoPA alongside the supplementary measures you have implemented. Regulators expect to see this evidence during audits.


What you must do if you act as a processor for EU clients

Many U.S. technology companies, SaaS providers, and service firms process EU personal data on behalf of EU controllers without fully understanding the obligations this creates. The IAPP's guidance is direct: processor exposure is one of the most underestimated GDPR risks for U.S. firms.

Processors acting under GDPR obligations must:

  1. Process data only on documented instructions from the controller.
  2. Ensure all staff with access are bound by confidentiality obligations.
  3. Implement appropriate technical and organizational security measures.
  4. Not engage subprocessors without prior written authorization from the controller.
  5. Assist the controller in responding to data subject requests.
  6. Assist with security obligations, breach notification, DPIAs, and prior consultation.
  7. Delete or return all personal data at the end of the contract.
  8. Provide all information necessary to demonstrate compliance and allow audits.

Operationally, this means:

  • Maintaining processing logs that show what data you touched, when, and why.
  • Segregating EU client data from other customer data where feasible.
  • Notifying the controller of a breach within the timeframe your DPA specifies (typically 24–48 hours, to give the controller time to meet the 72-hour supervisory authority deadline).
  • Cooperating with EU supervisory authorities when they investigate your controller clients.

To protect your own business, negotiate clear scope definitions in every DPA. Liability carve-outs for controller-caused incidents, security standard references (SOC 2 Type II, ISO 27001), and explicit subprocessor lists reduce your exposure while giving controllers the assurance they need.


What triggers GDPR enforcement and how to prioritize your risk

Supervisory authorities don't investigate randomly. Common triggers include:

  • Data subject complaints about unmet access or deletion requests
  • Failure to report a breach within 72 hours
  • Missing or inadequate DPAs discovered during an audit
  • No RoPA for significant processing activities
  • Lack of transparency in privacy notices
  • High-risk processing without a DPIA

The Clearview AI enforcement action illustrates how aggressively regulators pursue U.S. companies that collect biometric data at scale without a lawful basis. The Dutch DPA's consideration of personal executive liability signals a shift toward individual accountability, not just corporate fines.

Prioritize your remediation by risk tier:

High risk (address first):

  • Biometric data, health data, or other special-category data processing
  • Large-scale profiling or behavioral monitoring of EU users
  • Systematic surveillance or tracking

Medium risk (address within 60 days):

  • User analytics and behavioral tracking via cookies
  • Customer support systems containing personal data
  • Marketing automation with EU contacts

Low risk (document and monitor):

  • Anonymized or aggregated logs with no re-identification risk
  • Internal operational data with no EU personal data

For each high-risk activity, run a DPIA, document your legal basis, and confirm your DPAs are in place. For medium-risk activities, audit your cookie consent implementation and verify your processors have signed DPAs.


What triggers GDPR enforcement and how to prioritize your risk — overview diagram

What does GDPR compliance actually cost for a US SME?

Realistic timelines and costs vary by company size, data complexity, and existing controls. Here is what most U.S. SMEs experience:

  • Quick applicability assessment (1–2 weeks): Scoping call, data mapping kickoff, and initial gap analysis. Cost is primarily internal time or a short external counsel engagement.
  • Remediation and contracts (4–12 weeks): DPA execution, privacy notice updates, RoPA build, security gap fixes, and DPIA for high-risk processing. External legal fees for DPA templates and review typically run in the thousands to tens of thousands of dollars depending on complexity.
  • EU representative appointment: Specialist providers charge annual fees ranging from a few hundred to several thousand euros per year, depending on scope and the volume of supervisory authority contacts they handle.
  • Engineering work: Implementing retention schedules, deletion workflows, and DSR automation adds engineering hours. The range is wide, from a few days for simple setups to weeks for complex data architectures.
  • Ongoing operations: Staff training, annual RoPA reviews, and DPA renewals are recurring costs. Budget for at least one compliance review cycle per year.

The biggest cost driver is usually the data mapping exercise, especially for companies with fragmented systems. Investing in customer data unification early cuts the time and cost of every subsequent compliance activity.


Common GDPR misconceptions US companies still believe

"Our website is accessible in the EU, so GDPR applies." Not automatically. The European Commission's guidance is clear: mere accessibility is not enough. You must actively target EU users, as shown by the targeting markers above.

"GDPR is basically the same as CCPA." It is not. CCPA is a California consumer privacy law focused on sale of personal information and opt-out rights. GDPR is a comprehensive EU regulation covering all personal data processing, requiring a lawful basis for every processing activity, and granting broader rights including erasure and portability. The obligations, penalties, and enforcement mechanisms are fundamentally different.

"We're too small to be on GDPR's radar." Article 3 has no size threshold. A five-person SaaS company selling to EU customers is in scope. The risk-based obligations (DPIAs, DPOs) do scale with size and processing volume, but the core requirements apply regardless.

"Appointing an EU representative is just a formality." Under Article 27, an EU representative is your legal point of contact for supervisory authorities. That representative can receive enforcement notices, respond to investigations, and act on your behalf. Choosing a representative without operational capacity or without reflecting the role in your contracts creates real legal exposure.


The part most compliance guides won't tell you

Most GDPR articles for U.S. companies spend 80% of their words on the legal framework and 20% on what to actually do. The result is that compliance teams understand the regulation perfectly and still don't know where to start on Monday morning.

The honest reality is that GDPR compliance for a U.S. company is less a legal problem and more an operational one. The legal framework is well-documented. What breaks down is execution: no one owns the RoPA, DPAs sit unsigned in a shared drive, the breach notification template doesn't exist until the breach happens, and the EU representative is a name on a form with no operational connection to the business.

The companies that get this right treat compliance as a system, not a project. They automate the repetitive parts (DSR intake, retention enforcement, processor monitoring), assign clear ownership for the judgment calls (lawful basis decisions, DPIA sign-offs), and build documentation habits that survive staff turnover. That approach also makes GDPR compliance a commercial asset: EU enterprise clients close faster when your DPA is ready on day one.

One more thing worth saying plainly: the EU–U.S. Data Privacy Framework is the most practical transfer mechanism for most U.S. companies right now, but it has already been challenged legally once (Privacy Shield was invalidated in 2020). Building your compliance program around SCCs as a fallback, even if you certify under the DPF, is the prudent move. Regulators reward organizations that demonstrate they thought about the risk, not just the paperwork.


The part most compliance guides won't tell you — overview diagram

Cannatract builds the operational layer your GDPR program needs

Most U.S. companies have the legal advice. What they're missing is the system that makes compliance run without constant manual effort.

Cannatract

Cannatract designs and builds the operational infrastructure that turns a GDPR checklist into a working program: automated DSR intake and response workflows, retention and deletion automation, secure integrations between your CRM and data stores, and privacy notice implementations on your website. For companies that need EU representative coordination or processor contract management, we scope that into the project from the start.

Fixed quotes, 2–4 week delivery on defined-scope builds, and a free compliance automation audit to identify where your team is spending the most time on manual compliance tasks. If the applicability test above came back positive, that audit is the right next step.

Book your free compliance automation audit at Cannatract and get a clear picture of what needs to be built, what can be automated, and what a realistic timeline looks like for your business.


Sources

Bookmark these for audit evidence and ongoing compliance decisions:


FAQ

Does GDPR apply to US companies with no EU office?

Yes. Under Article 3(2), GDPR applies to any organization that offers goods or services to EU-located individuals or monitors their behavior, regardless of where the organization is based.

Is there a GDPR equivalent in the USA?

No direct federal equivalent exists. The closest U.S. frameworks are the California Consumer Privacy Act (CCPA) and sector-specific laws like HIPAA, but none match GDPR's comprehensive scope, mandatory lawful basis requirements, or penalty structure.

Is GDPR stricter than HIPAA?

In most respects, yes. GDPR covers all personal data across all industries, requires a documented lawful basis for every processing activity, and mandates 72-hour breach notification to regulators. HIPAA applies only to protected health information in covered healthcare entities and has different breach notification timelines and penalty structures.

What are the main options for US companies to comply with GDPR?

The core steps are: run an applicability test, build a RoPA, document lawful bases, execute DPAs with processors, implement security controls, prepare a breach response process, and appoint an EU representative if required. For cross-border data transfers, the EU–U.S. Data Privacy Framework and Standard Contractual Clauses are the two most practical mechanisms.

Can a US company be fined under GDPR?

Yes. Supervisory authorities have fined U.S.-based companies, including Clearview AI, which received a major fine from the Dutch Data Protection Authority in 2024. Fines can reach €20 million or 4% of global annual turnover, whichever is higher.

This article provides general information about GDPR obligations and is not legal advice. Confirm your specific compliance requirements with qualified legal counsel and consult the relevant supervisory authority's guidance for your situation.