This page explains how the GDPR applies to U.S. businesses, the legal tests that trigger extraterritorial application, common scenarios that bring U.S. companies into scope, and the practical implications of GDPR compliance for organisations with no European footprint.
The Legal Foundation: Article 3 GDPR
The territorial scope of the GDPR is governed by Article 3 GDPR, which sets out three independent bases for application. These provisions together establish the GDPR’s extraterritorial effect.
Under Article 3, the GDPR applies:
- Where processing is carried out in the context of the activities of an establishment in the EU, regardless of where the processing itself occurs;
- Where a controller or processor not established in the EU processes personal data of individuals in the EU, and that processing relates to:
- the offering of goods or services to those individuals; or
- the monitoring of their behaviour within the EU;
- Where processing is subject to Member State law by virtue of public international law.
For U.S. businesses, the second basis—often referred to as the “targeting” or extraterritorial test—is the most relevant.
GDPR Applies Based on Location of the Individual, Not Their Nationality
A common misconception among U.S. companies is that the GDPR only protects “EU citizens.” This is incorrect.
Article 3(2) GDPR applies where personal data relates to data subjects who are in the Union at the time of processing, irrespective of nationality or residence status. Temporary presence in the EU—for example, tourism, business travel, or short‑term residence—is sufficient.
As regulators have emphasised, the decisive factor is the individual’s physical location in the EU, not their citizenship or the business’s intent to target citizens specifically.
The Establishment Criterion: Article 3(1)
When U.S. Businesses Are Considered “Established” in the EU
Under Article 3(1), the GDPR applies where personal data is processed in the context of the activities of an establishment in the EU. An establishment is interpreted broadly and does not require a legal entity incorporated in Europe.
According to the Court of Justice of the European Union and EDPB guidance, an establishment may exist where there is:
- real and effective activity;
- exercised through stable arrangements;
- such as a branch, subsidiary, sales office, or even a single employee acting permanently.
If a U.S. company has an EU‑based affiliate or representative whose activities are inextricably linked to the processing of personal data, the GDPR may apply to the organisation’s global processing operations, even if data is processed exclusively in the United States.
“In the Context of the Activities”
Processing does not need to occur within the EU. The key question is whether the processing is carried out in the context of the EU establishment’s activities. Regulators interpret this requirement expansively to prevent circumvention of EU data protection protections.
The Targeting Criterion: Article 3(2)
For many U.S. businesses, GDPR applicability arises under Article 3(2), which covers non‑EU companies with no establishment in the EU.
Offering Goods or Services to Individuals in the EU
Article 3(2)(a) applies where a U.S. business offers goods or services to individuals in the EU, irrespective of whether payment is required.
Offering goods or services requires intentional targeting of the EU market. Simply operating a website that is accessible from Europe is not enough. Regulators assess targeting using objective indicators, including:
- use of EU languages other than English;
- display of prices in euros;
- shipping or delivery options to EU countries;
- EU‑specific marketing campaigns;
- references to EU customers or users; and
- offering customer support tailored to EU time zones.
[glocertint…tional.com], [commission.europa.eu]
Importantly, free services—such as mobile apps, streaming platforms, SaaS tools, or newsletters—may trigger GDPR applicability if directed at the EU market.
Monitoring the Behaviour of Individuals in the EU
Article 3(2)(b) extends the GDPR to U.S. businesses that monitor the behaviour of individuals in the EU, where that behaviour takes place within the Union.
Behavioural monitoring includes:
- tracking individuals on the internet;
- use of cookies, device fingerprinting, or advertising identifiers;
- profiling for marketing, analytics, or predictive purposes;
- location tracking via devices or applications.
This provision is particularly relevant to U.S. companies operating in:
- digital advertising;
- online analytics;
- social media;
- ad‑tech and mar‑tech;
- wearable technology and IoT.
Where monitoring activities are designed to analyse or predict preferences, behaviour, or movements of EU‑located individuals, GDPR obligations attach—regardless of the absence of EU targeting for sales.
Processors Outside the EU: GDPR Also Applies
GDPR’s extraterritorial reach extends not only to controllers but also to processors located outside the EU.
Where a U.S. service provider processes personal data on behalf of an EU‑established controller, and in the context of that relationship, GDPR obligations apply—even if the processor has no direct relationship with EU individuals.
This affects many U.S. cloud providers, data analytics platforms, and outsourced service vendors supporting EU clients.
What GDPR Extraterritorial Application Does Not Require
It is equally important to understand what does not automatically trigger GDPR applicability:
- Passive website accessibility from the EU without targeting;
- Accidental or incidental contact with EU individuals;
- Data processing unrelated to EU‑focused activities;
- Isolated EU visitors with no behavioural monitoring or service offering.
Regulators consistently stress that intention matters. The GDPR does not impose universal jurisdiction over the internet; it targets purposeful engagement with EU individuals.
Consequences of GDPR Applicability for U.S. Businesses
Once GDPR applies, U.S. businesses must comply with all applicable GDPR obligations, including:
- identifying a lawful basis for processing;
- providing transparent privacy notices under Articles 13 and 14;
- enabling data subject rights;
- implementing appropriate technical and organisational security measures;
- complying with international transfer restrictions;
- maintaining records of processing; and
- in some cases, appointing an EU representative or a Data Protection Officer.
Failure to comply exposes organisations to regulatory enforcement and administrative fines of up to €20 million or 4% of global annual turnover, whichever is higher.
The EU Representative Requirement (Article 27)
U.S. businesses subject to GDPR under Article 3(2) must generally appoint a representative in the EU, unless a narrow exception applies.
The representative acts as:
- a point of contact for supervisory authorities; and
- a contact point for data subjects.
Failure to appoint a representative where required is itself a standalone GDPR violation.
Enforcement Against U.S. Businesses
GDPR enforcement against non‑EU companies is no longer theoretical. European supervisory authorities have:
- issued enforcement decisions against U.S. and other non‑EU companies;
- cooperated internationally on investigations;
- relied on reputational, commercial, and contractual leverage to secure compliance.
Even where direct collection of fines may be challenging, regulators increasingly use data‑transfer restrictions and market‑access pressure to enforce compliance.
Interaction with U.S. Law and International Transfers
GDPR applicability is distinct from transfer mechanisms such as:
- the EU‑U.S. Data Privacy Framework;
- standard contractual clauses;
- binding corporate rules.
A U.S. company may need to comply with GDPR and separately justify international data transfers under Chapter V GDPR.
Extraterritorial applicability under Article 3 does not itself authorise data transfers; it determines whether GDPR obligations attach at all.
Practical Risk Assessment for U.S. Businesses
U.S. organisations should undertake a structured assessment addressing:
- whether EU individuals are targeted;
- whether behavioural monitoring occurs;
- whether EU establishment links exist;
- whether services or analytics platforms are EU‑facing.
Documentation of this assessment is critical and may form part of regulatory evidence in the event of investigation.
Strategic Compliance Considerations
For U.S. businesses operating globally, GDPR compliance is increasingly a strategic governance issue, not merely a regulatory checkbox. Organisations that proactively align with GDPR standards often find:
- improved trust with international customers;
- smoother global data flows;
- alignment with emerging privacy laws beyond Europe.
Conversely, underestimating extraterritorial reach remains a common and avoidable compliance failure.
Conclusion
The GDPR’s extraterritorial application fundamentally reshaped global data‑protection law. For U.S. businesses, the GDPR applies not based on geography alone, but on how data is used and whose data is involved.
Any U.S. organisation that offers goods or services to individuals in the EU, monitors their behaviour, or processes data in the context of EU‑linked activities must assess—carefully and honestly—whether GDPR applies.
Understanding Article 3 is the starting point. Implementing compliant governance structures is the ongoing challenge.
