A US company can be subject to the EU GDPR even without an EU office when its relevant processing concerns offering goods or services to people in the EU or monitoring their behaviour there. The correct response is an activity-specific Article 3 assessment followed by operational controls—not a blanket conclusion based on website traffic or company location alone.
Determine territorial scope
Article 3 contains two common routes:
- EU establishment: processing in the context of the activities of an EU establishment, whether or not processing occurs in the EU.
- Targeting or monitoring: a non-EU controller or processor processes personal data in connection with offering goods or services to people in the EU or monitoring their behaviour in the EU.
Relevant indicators of offering goods or services can include deliberate EU targeting, Member State languages or currencies in context, EU delivery, or EU customer references. Mere accessibility of a US website from Europe is not necessarily enough. Behavioural advertising, tracking and profiling can constitute monitoring where the Article 3 test is met.
Document scope by product, processing activity, entity and role. The GDPR may apply to some activities and not others.
Check EU representation and DPO duties
A controller or processor subject to Article 3(2) generally must designate in writing a representative in the EU under Article 27. The exception requires all of these elements: processing is occasional, does not include large-scale Article 9 or Article 10 processing, and is unlikely to risk individuals’ rights and freedoms considering its nature, context, scope and purposes. Public authorities and bodies are excluded under Article 27(2).
The representative must be established in a Member State where relevant individuals are located and be addressable by supervisory authorities and individuals. Appointment does not reduce the US organisation’s responsibility or liability.
A DPO is a separate question under Article 37. There is no automatic DPO duty just because the company is American or sells in the EU.
Build the compliance foundation
- Map EU-related processing. Include product, analytics, advertising, support, sales, security, workforce and vendor flows.
- Determine roles. Identify controller, joint-controller and processor relationships based on actual decisions.
- Choose lawful bases. Map each purpose to Article 6; add an Article 9 condition where special-category data is involved.
- Provide transparent information. Align Articles 13 and 14 notices with real processing, recipients, retention and transfers.
- Operate rights procedures. Support the relevant rights and the general one-month response period, including qualified extensions and exceptions.
- Control processors. Use Article 28 terms and proportionate oversight.
- Screen for DPIAs. Complete one before processing likely to result in high risk.
- Prepare breach response. Record breaches and apply Articles 33 and 34 thresholds and timing.
US sectoral privacy compliance does not automatically satisfy these duties. Reuse sound security and governance controls where they fit, but map the GDPR requirements explicitly.
Handle EU–US data transfers
First identify the exporter, importer, roles, data, purpose and onward transfers. Then determine the applicable Chapter V route. Where relying on an adequacy decision or framework participation, verify current status and that the specific recipient and data are covered. Do not assume every US recipient is covered.
Where using the European Commission’s 2021 SCCs, choose the correct module, complete the annexes, assess whether the clauses provide effective protection in the transfer context, and use supplementary measures where necessary. SCC signature is not the end of the assessment.
Enforcement and practical risk
Article 83 provides maximum fine tiers reaching €20 million or 4% of total worldwide annual turnover for the preceding financial year for specified infringements, whichever is higher for an undertaking. These are maxima, not automatic outcomes. Supervisory authorities also have Article 58 powers such as orders, limitations and bans on processing.
Prioritise processing with high impact on people, opaque monitoring, sensitive data, weak security, unsupported transfers, or an inability to honour rights. Keep evidence of decisions and remediation.
Vision Compliance can act as an EU representative where the legal criteria and service scope fit. Our data protection services support the wider programme; the representative role alone is not a complete compliance solution.
Sources and review
- Regulation (EU) 2016/679, including Articles 3, 27 and Chapter V
- EDPB Guidelines 3/2018 on territorial scope
- European Commission: international dimension of data protection
Reviewed on 8 August 2026. Scope, representative exceptions, transfers and fine exposure are stated as conditional legal tests rather than universal outcomes.
Ivana Ludiga, mag. iur., is an Associate at Vision Compliance focused on data protection, GDPR implementation, and regulatory advisory. She supports compliance projects for organizations across healthcare, financial services, and technology sectors.