{"id":11059,"date":"2026-02-10T10:35:09","date_gmt":"2026-02-10T09:35:09","guid":{"rendered":"https:\/\/s8.tgin.eu\/?p=11059"},"modified":"2026-02-10T10:35:11","modified_gmt":"2026-02-10T09:35:11","slug":"does-the-gdpr-apply-to-my-us-company","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/does-the-gdpr-apply-to-my-us-company\/","title":{"rendered":"Does the GDPR apply to my US company?"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Introduction<\/h2>\n\n\n\n<p>The usual assumption of most US businesses is, &#8220;the GDPR is an EU regulation, hence it does not impact my organisation.&#8221; This belief results most often in unnecessary risk. The US equivalent of this misconception would be a company registered in Texas thinking its services don\u2019t fall under the scope of the CCPA.&nbsp;<\/p>\n\n\n\n<p>The GDPR has extraterritorial effect, that is, it has effect on and more often than not, does affect organisations which are outside the European Union.<\/p>\n\n\n\n<p>Note that since Brexit, the UK has maintained GDPR provisions but further adapted them to its body of laws, this is known as the UK GDPR which adds an additional but small level of complexity for transfers of data outside the UK. For the sake of simplicity, the term GDPR used in this article will also apply to the UK.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What is the GDPR and why it has global reach<\/h2>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\"><div class=\"wp-block-image is-style-rounded\">\n<figure class=\"aligncenter size-large is-resized\"><img decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-1024x683.jpg\" alt=\"\" class=\"wp-image-11061\" style=\"width:672px;height:auto\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-1024x683.jpg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-300x200.jpg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-768x512.jpg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-1536x1024.jpg 1536w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-2048x1365.jpg 2048w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.33%\">\n<p>The GDPR is the code name for the UK and the EU\u2019s <a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj\/eng\">General Data Protection Regulation<\/a>. It shields the personal data of individuals who are within the European Union, provides rights to the data owners (i.e. individuals) and lays out obligations for the organisations handling that data. It has a general territorial scope such that it may apply to organisations outside of the EU if certain conditions are fulfilled.<\/p>\n<\/div>\n<\/div>\n\n\n\n<p><\/p>\n\n\n\n<p>A US company may be controlled by the GDPR if it is:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Providing goods or services to data subjects in the European Union <\/strong>(EEA and UK)<\/li>\n<\/ol>\n\n\n\n<p>This trigger is independent of payment or contractual terms. A business will be deemed to be targeting or envisaging an EU audience if it engages in any of the following activity:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Sending physical goods or providing access to digital services into a member state of the EU\/EEA\/UK;<\/li>\n\n\n\n<li>Taking payments in a European currency such as Euros;<\/li>\n\n\n\n<li>Running campaigns that market to email recipients in the EU\/EEA\/UK; and<\/li>\n\n\n\n<li>Providing a website or service in a language that is widely spoken across the EU\/EEA\/UK.<\/li>\n<\/ul>\n\n\n\n<ol start=\"2\" class=\"wp-block-list\">\n<li><strong>Tracking the behavior of users in the European Union<\/strong><\/li>\n<\/ol>\n\n\n\n<p>This trigger is extremely applicable to digital-first companies today. If your business is tracking or profiling users in the European Union, the GDPR will most likely apply. This includes practices like:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Tracking European Union website and app users with analytics tools;<\/li>\n\n\n\n<li>Placing cookies or other tracking tags on the devices of users in the European Union which triggers additional requirements from the ePrivacy Directive and other local laws; and<\/li>\n\n\n\n<li>Running targeted advertisement campaigns against users within the European Union on the basis of their online behavior.<\/li>\n<\/ul>\n\n\n\n<p><a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj\/eng\">Article 3 of the GDPR<\/a> expressly sets out these conditions. These are detailed in additional guidance by the European Data Protection Board (Guidelines 05\/2021). Registration of an organization outside of the EU does not necessarily remove a business from scope.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What constitutes personal data under the GDPR?<\/h2>\n\n\n\n<p><a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/HTML\/?uri=CELEX:32016R0679#d1e1374-1-1\">The GDPR defines personal data<\/a> as any information relating to an identified or identifiable natural person. This definition is deliberately broad. This is to encompass a wider range of data than the concept of <a href=\"https:\/\/techgdpr.com\/blog\/difference-between-pii-and-personal-data\/\">&#8220;personally identifiable information&#8221;<\/a> (PII) used in other jurisdictions. It is critical for any organisation to understand what information falls under this comprehensive definition to determine its compliance obligations.<\/p>\n\n\n\n<p>Personal data includes, but is not limited to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Direct identifiers:<\/strong> A person\u2019s name, email address, physical address, or telephone number.<\/li>\n\n\n\n<li><strong>Online identifiers:<\/strong> An individual\u2019s Internet Protocol (IP) address, browser cookies, and device identifiers (IP\/MAC address, IMEIs, \u2026).<\/li>\n\n\n\n<li><strong>Pseudonyms <\/strong>like user IDs, vehicle numbers (VINs), randomly chosen usernames, hashes\u2026<\/li>\n\n\n\n<li><strong>Metadata <\/strong>in context like timestamps,&nbsp;<\/li>\n\n\n\n<li><strong>Special categories of data:<\/strong> Biometric data, such as fingerprints or facial recognition information. To learn more about sensitive data under the GDPR, that is addressed in <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/HTML\/?uri=CELEX:32016R0679#d1e1374-1-1\">Art.9 of the GDPR <\/a>and our blog article detailing <a href=\"https:\/\/techgdpr.com\/blog\/difference-between-pii-and-personal-data\/\">the differences between PII and personal data<\/a>.&nbsp;<\/li>\n\n\n\n<li><strong>Other information:<\/strong> Video or photo recordings, and an individual\u2019s location data.<\/li>\n\n\n\n<li><strong>IoT data <\/strong>associated with a device purchaser, owner, user, maintenance person, etc\u2026<\/li>\n<\/ul>\n\n\n\n<p>If your organization collects any of this information from individuals in the European Union, it is processing personal data and must assess its compliance obligations under the GDPR.<\/p>\n\n\n<div class=\"wp-block-image is-style-default\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-qw.googleusercontent.com\/docsz\/AD_4nXepzGXylzIw-BZsoNOKu31212WtmCZfWWStdREWgR0Z70vBUGM5pjjwv5xw5dlNrWKbBCzoRKr6L9IQ9d8qbv0hl-HTxc1EW6uVCjJcdGGHjdjBsUHqQKArm8oj16Q4PslPyTGg?key=YlGJUm2194gxP2iGe_xdvQ\" alt=\"\"\/><\/figure>\n<\/div>\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What if my business doesn&#8217;t comply?<\/h2>\n\n\n\n<p>Non-compliance with the GDPR will result in massive financial and reputational losses. Supervisory authorities can impose fines of up to twenty million euros or four percent of the annual global turnover of an organization. This is decided by whichever is the greater. The GDPR has a highly structured framework of <a href=\"https:\/\/www.enforcementtracker.com\/\">administrative fines<\/a>, which can be applied in two tiers:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Tier 1: <\/strong>Up to \u20ac10 million, or 2% of the company&#8217;s total annual turnover worldwide in the preceding financial year. This is decided by whichever is the greater.<\/li>\n\n\n\n<li><strong>Tier 2: <\/strong>Up to \u20ac20 million, or 4% of the company&#8217;s total annual turnover worldwide in the preceding financial year. This is decided by whichever is the greater.<\/li>\n<\/ul>\n\n\n\n<p>Enforcement is also a legitimate concern for U.S. companies. For example, <a href=\"https:\/\/www.edpb.europa.eu\/news\/national-news\/2022\/french-sa-fines-clearview-ai-eur-20-million_en\">Clearview AI, a U.S.-based firm,<\/a> was the subject of enforcement action and fines by multiple EU data protection authorities for processing EU individuals&#8217; personal data lacking a sufficient legal basis.&nbsp;<\/p>\n\n\n\n<p>Along with fines, organizations can anticipate loss of customer trust, damage to their reputation, and legal restrictions on their data processing activities. Enforcement action against household names demonstrates that regulators are willing to act against organizations outside the European Union when the GDPR applies.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">A simple checklist for your U.S. company<\/h2>\n\n\n\n<p>To allow you to consider at a glance whether the GDPR applies to your business, ask yourself the following questions:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Does your company&#8217;s website, app, or service deliver goods or services to individuals in the European Union?<\/li>\n\n\n\n<li>Do you use instruments that monitor the online behavior of individuals in the European Union?<\/li>\n\n\n\n<li>Does your company process the personal data of any of your staff members working in the European Union?<\/li>\n\n\n\n<li>Do you implement any vendor tool to carry any of that data processing for you?<\/li>\n<\/ul>\n\n\n\n<p>If you answered yes to any of these queries, then it is highly likely <a href=\"https:\/\/techgdpr.com\/blog\/gdpr-as-a-non-eu-company\/\">your company is subject to the GDPR<\/a>.<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<p><strong>Real-life examples of when the GDPR applies<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>An online store in the United States accepting payment in euros and shipping goods to customers in the European Union;<\/li>\n\n\n\n<li>A company processing payroll for a remote employee working in the European Union;<\/li>\n\n\n\n<li>A marketing company running targeted campaigns aimed at audiences within the European Union.<\/li>\n<\/ul>\n\n\n\n<p>Conversely, a strictly internal website with no European customer targeting and only incidental EU visits generally will not be subject to the GDPR.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\"><div class=\"wp-block-image is-style-rounded\">\n<figure class=\"aligncenter size-large is-resized\"><img decoding=\"async\" width=\"683\" height=\"1024\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-sawyersutton-973049-683x1024.jpg\" alt=\"\" class=\"wp-image-11065\" style=\"width:259px;height:auto\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-sawyersutton-973049-683x1024.jpg 683w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-sawyersutton-973049-200x300.jpg 200w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-sawyersutton-973049-768x1152.jpg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-sawyersutton-973049-1024x1536.jpg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-sawyersutton-973049-1365x2048.jpg 1365w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-sawyersutton-973049-scaled.jpg 1707w\" sizes=\"(max-width: 683px) 100vw, 683px\" \/><\/figure>\n<\/div><\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Special Case: United States companies with EU-Based employees<\/h2>\n\n\n\n<p>The processing of employees&#8217; personal data in the European Union triggers GDPR obligations. Some examples are maintaining personal records, processing sensitive information, and monitoring work performance. Paying an employee in the European Union without additional data processing might not necessarily trigger full GDPR compliance requirements. That being the case HR processes need to be carefully reviewed. Please check out <a href=\"https:\/\/techgdpr.com\/blog\/gdpr-and-hr-data-for-non-eu-companies\/\">our blog article<\/a> on how the GDPR and effects HR data for non EU-companies for further information.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Your next steps toward compliance<\/h2>\n\n\n\n<p>If your business is subject to the GDPR, it&#8217;s essential to be forward-leaning with regards to compliance.<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\"><div class=\"wp-block-image is-style-rounded\">\n<figure class=\"aligncenter size-large is-resized\"><img decoding=\"async\" width=\"683\" height=\"1024\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-andrew-2682452-683x1024.jpg\" alt=\"\" class=\"wp-image-11068\" style=\"width:391px;height:auto\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-andrew-2682452-683x1024.jpg 683w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-andrew-2682452-200x300.jpg 200w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-andrew-2682452-768x1152.jpg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-andrew-2682452-1024x1536.jpg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-andrew-2682452-1365x2048.jpg 1365w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-andrew-2682452-scaled.jpg 1707w\" sizes=\"(max-width: 683px) 100vw, 683px\" \/><\/figure>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\">\n<ul class=\"wp-block-list\">\n<li><strong>Carry out a data mapping exercise:<\/strong> This will lead to Records of Processing Activities, the details of which are outlined in Art. 30 of the GDPR. Record all personal data your organization gathers and processes, the reason for the data, and where it is stored;<\/li>\n\n\n\n<li><strong>Determining a lawful basis for all your data processing activities: <\/strong>This provides a documented and valid legal rationale for collecting and using personal data. This could be e.g., user consent, contractual necessity with the person, or legitimate interest of your organization, EU legal obligation;<\/li>\n\n\n\n<li><strong>Drafting accessible&nbsp; privacy notices:<\/strong> Provides an intelligible and accessible <a href=\"https:\/\/www.youtube.com\/watch?v=xCMTumbewKE\">privacy notice<\/a> describing data collection, purposes, storage, and data sharing practices;<\/li>\n\n\n\n<li><strong>Respecting the rights of data subjects:<\/strong> Enable individuals to exercise their rights under the GDPR. These rights include access, rectification, erasure, restriction, and objection;<\/li>\n\n\n\n<li><strong>Appointing a Data Protection Officer (DPO):<\/strong> <a href=\"https:\/\/techgdpr.com\/consultancy\/data-protection-officer-dpo\/\">Appoint a DPO<\/a> where required. This could be due to processing vast volumes of sensitive personal data or conduct systematic monitoring of individuals;<\/li>\n\n\n\n<li><strong>Consider <\/strong><a href=\"https:\/\/techgdpr.com\/consultancy\/art-27-eu-representative-gdpr-service\/\"><strong>an EU Representative<\/strong><\/a><strong>:<\/strong> If your business is established outside of the European Union, you may need to have a representative within one of the member states under Article 27; and\/or<\/li>\n\n\n\n<li><a href=\"https:\/\/techgdpr.com\/consultancy\/achieve-gdpr-compliance\/\"><strong>Seek expert advice<\/strong><\/a><strong>: <\/strong>The GDPR is complex. For complete compliance, it would be ideal to obtain a professional GDPR compliance audit.<\/li>\n<\/ul>\n<\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p>Whether the GDPR affects an American business or not is not a matter of a business&#8217;s physical presence, but if it has a connection with individuals in the European Union. If your business offers goods or services to EU residents or monitors their activities, then it is very likely the GDPR will affect you. The penalty for failure to comply can be extremely high, both financially and with regard to one&#8217;s reputation.<\/p>\n\n\n\n<p>It is suggested that all U.S. businesses conduct an internal examination of data processing operations. If unsure, securing a professional GDPR compliance assessment can guarantee a clear and secure path forward.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction The usual assumption of most US businesses is, &#8220;the GDPR is an EU regulation, hence it does not impact my organisation.&#8221; This belief results most often in unnecessary risk. The US equivalent of this misconception would be a company registered in Texas thinking its services don\u2019t fall under the scope of the CCPA.&nbsp; The [&hellip;]<\/p>\n","protected":false},"author":29,"featured_media":11061,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[10,88],"tags":[95,58,185],"class_list":["post-11059","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-beyond-eu","category-gdpr","tag-eu-us-data-transfer","tag-gdpr-compliance","tag-us-law"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-scaled.jpg",2560,1707,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-300x200.jpg",300,200,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-768x512.jpg",640,427,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-1024x683.jpg",640,427,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-1536x1024.jpg",1536,1024,true],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-2048x1365.jpg",2048,1365,true],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-200x200.jpg",200,200,true]},"post_excerpt_stackable":"<p>Introduction The usual assumption of most US businesses is, &#8220;the GDPR is an EU regulation, hence it does not impact my organisation.&#8221; This belief results most often in unnecessary risk. The US equivalent of this misconception would be a company registered in Texas thinking its services don\u2019t fall under the scope of the CCPA.&nbsp; The GDPR has extraterritorial effect, that is, it has effect on and more often than not, does affect organisations which are outside the European Union. Note that since Brexit, the UK has maintained GDPR provisions but further adapted them to its body of laws, this is&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/beyond-eu\/\" rel=\"category tag\">Beyond EU<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/gdpr\/\" rel=\"category tag\">GDPR<\/a>","author_info":{"name":"AJ Richter","url":"https:\/\/techgdpr.com\/blog\/author\/aj\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-scaled.jpg",2560,1707,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-300x200.jpg",300,200,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-768x512.jpg",640,427,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-1024x683.jpg",640,427,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-1536x1024.jpg",1536,1024,true],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-2048x1365.jpg",2048,1365,true],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-200x200.jpg",200,200,true]},"post_excerpt_stackable_v2":"<p>Introduction The usual assumption of most US businesses is, &#8220;the GDPR is an EU regulation, hence it does not impact my organisation.&#8221; This belief results most often in unnecessary risk. The US equivalent of this misconception would be a company registered in Texas thinking its services don\u2019t fall under the scope of the CCPA.&nbsp; The GDPR has extraterritorial effect, that is, it has effect on and more often than not, does affect organisations which are outside the European Union. Note that since Brexit, the UK has maintained GDPR provisions but further adapted them to its body of laws, this is&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/beyond-eu\/\" rel=\"category tag\">Beyond EU<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/gdpr\/\" rel=\"category tag\">GDPR<\/a>","author_info_v2":{"name":"AJ Richter","url":"https:\/\/techgdpr.com\/blog\/author\/aj\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Does the GDPR apply to my US company? - TechGDPR<\/title>\n<meta name=\"description\" content=\"In our latest blog article, learn about why the GDPR might be a valid concern for your business even if you are based in the US.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/does-the-gdpr-apply-to-my-us-company\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Does the GDPR apply to my US company? - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"In our latest blog article, learn about why the GDPR might be a valid concern for your business even if you are based in the US.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/does-the-gdpr-apply-to-my-us-company\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2026-02-10T09:35:09+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-02-10T09:35:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-scaled.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1707\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"AJ Richter\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"AJ Richter\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/does-the-gdpr-apply-to-my-us-company\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/does-the-gdpr-apply-to-my-us-company\\\/\"},\"author\":{\"name\":\"AJ Richter\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/8f2611c391ad1b631e1bbb97c5a92eb3\"},\"headline\":\"Does the GDPR apply to my US company?\",\"datePublished\":\"2026-02-10T09:35:09+00:00\",\"dateModified\":\"2026-02-10T09:35:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/does-the-gdpr-apply-to-my-us-company\\\/\"},\"wordCount\":1525,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/does-the-gdpr-apply-to-my-us-company\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/pexels-davegarcia-32269244-scaled.jpg\",\"keywords\":[\"EU-US data transfer\",\"GDPR Compliance\",\"US law\"],\"articleSection\":[\"Beyond EU\",\"GDPR\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/does-the-gdpr-apply-to-my-us-company\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/does-the-gdpr-apply-to-my-us-company\\\/\",\"name\":\"Does the GDPR apply to my US company? - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/does-the-gdpr-apply-to-my-us-company\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/does-the-gdpr-apply-to-my-us-company\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/pexels-davegarcia-32269244-scaled.jpg\",\"datePublished\":\"2026-02-10T09:35:09+00:00\",\"dateModified\":\"2026-02-10T09:35:11+00:00\",\"description\":\"In our latest blog article, learn about why the GDPR might be a valid concern for your business even if you are based in the US.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/does-the-gdpr-apply-to-my-us-company\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/does-the-gdpr-apply-to-my-us-company\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/does-the-gdpr-apply-to-my-us-company\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/pexels-davegarcia-32269244-scaled.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/pexels-davegarcia-32269244-scaled.jpg\",\"width\":2560,\"height\":1707},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/does-the-gdpr-apply-to-my-us-company\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Does the GDPR apply to my US company?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/8f2611c391ad1b631e1bbb97c5a92eb3\",\"name\":\"AJ Richter\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/AJ_OF_3211_700-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/AJ_OF_3211_700-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/AJ_OF_3211_700-150x150.jpg\",\"caption\":\"AJ Richter\"},\"description\":\"AJ Richter (CIPT) is a technical data protection analyst at TechGDPR. Her programming experience allows her to engage with technical teams on functional and non-functional privacy requirements, and to perform in-depth reviews and analysis.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/alexis-richter-9b4852145\\\/\"],\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/aj\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Does the GDPR apply to my US company? - TechGDPR","description":"In our latest blog article, learn about why the GDPR might be a valid concern for your business even if you are based in the US.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/does-the-gdpr-apply-to-my-us-company\/","og_locale":"en_US","og_type":"article","og_title":"Does the GDPR apply to my US company? - TechGDPR","og_description":"In our latest blog article, learn about why the GDPR might be a valid concern for your business even if you are based in the US.","og_url":"https:\/\/techgdpr.com\/blog\/does-the-gdpr-apply-to-my-us-company\/","og_site_name":"TechGDPR","article_published_time":"2026-02-10T09:35:09+00:00","article_modified_time":"2026-02-10T09:35:11+00:00","og_image":[{"width":2560,"height":1707,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-scaled.jpg","type":"image\/jpeg"}],"author":"AJ Richter","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"AJ Richter","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/does-the-gdpr-apply-to-my-us-company\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/does-the-gdpr-apply-to-my-us-company\/"},"author":{"name":"AJ Richter","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/8f2611c391ad1b631e1bbb97c5a92eb3"},"headline":"Does the GDPR apply to my US company?","datePublished":"2026-02-10T09:35:09+00:00","dateModified":"2026-02-10T09:35:11+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/does-the-gdpr-apply-to-my-us-company\/"},"wordCount":1525,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/does-the-gdpr-apply-to-my-us-company\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-scaled.jpg","keywords":["EU-US data transfer","GDPR Compliance","US law"],"articleSection":["Beyond EU","GDPR"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/does-the-gdpr-apply-to-my-us-company\/","url":"https:\/\/techgdpr.com\/blog\/does-the-gdpr-apply-to-my-us-company\/","name":"Does the GDPR apply to my US company? - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/does-the-gdpr-apply-to-my-us-company\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/does-the-gdpr-apply-to-my-us-company\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-scaled.jpg","datePublished":"2026-02-10T09:35:09+00:00","dateModified":"2026-02-10T09:35:11+00:00","description":"In our latest blog article, learn about why the GDPR might be a valid concern for your business even if you are based in the US.","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/does-the-gdpr-apply-to-my-us-company\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/does-the-gdpr-apply-to-my-us-company\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/does-the-gdpr-apply-to-my-us-company\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-scaled.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/08\/pexels-davegarcia-32269244-scaled.jpg","width":2560,"height":1707},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/does-the-gdpr-apply-to-my-us-company\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"Does the GDPR apply to my US company?"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/8f2611c391ad1b631e1bbb97c5a92eb3","name":"AJ Richter","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/AJ_OF_3211_700-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/AJ_OF_3211_700-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/AJ_OF_3211_700-150x150.jpg","caption":"AJ Richter"},"description":"AJ Richter (CIPT) is a technical data protection analyst at TechGDPR. Her programming experience allows her to engage with technical teams on functional and non-functional privacy requirements, and to perform in-depth reviews and analysis.","sameAs":["https:\/\/www.linkedin.com\/in\/alexis-richter-9b4852145\/"],"url":"https:\/\/techgdpr.com\/blog\/author\/aj\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11059","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/29"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=11059"}],"version-history":[{"count":8,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11059\/revisions"}],"predecessor-version":[{"id":11562,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11059\/revisions\/11562"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/11061"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=11059"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=11059"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=11059"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}