"We don't have an office in Europe, so GDPR isn't our problem" is one of the most common, and most wrong, assumptions a US-only business can make about this law. GDPR's scope isn't drawn around where a company is incorporated or headquartered. It's drawn around whose data gets processed, and that test can catch a US-only company that has never shipped a single product to Europe.

Article 3, in plain English

GDPR's territorial reach comes from a single provision, Article 3, and it has two branches.

The first, Article 3(1), covers any organization established in the EU. That one is intuitive and rarely surprises anyone: if you have an EU office, subsidiary, or staff, GDPR applies to the processing connected to that establishment, regardless of where the servers actually sit.

The second, Article 3(2), is the one that surprises US-only businesses, because it doesn't require any EU establishment at all. GDPR applies to a company with zero physical presence in the EU if it either offers goods or services to people in the EU, whether or not any payment is involved, or it monitors the behavior of people located in the EU, to the extent that behavior takes place within the EU. That's the statute's own language, and neither branch mentions revenue, headcount, or how many EU visitors you get. Read narrowly, one qualifying interaction can be enough.

"Offering goods or services": targeting, not just accessibility

Being reachable by an EU visitor because your website is on the public internet does not, by itself, satisfy this branch. European Data Protection Board guidance lays out the kind of evidence regulators actually look for to establish that a business is targeting EU residents rather than just being incidentally visible to them:

  • Naming EU countries in shipping, delivery, or service-area information.
  • Displaying prices in euros or other EU-country currencies.
  • Using a country-code domain tied to an EU country, or EU-specific language versions of a site.
  • Running ad campaigns or marketing content specifically aimed at an EU audience.
  • Listing EU phone numbers, addresses, or customer testimonials as part of the business's presentation.

A US-only e-commerce store that ships domestically, prices in dollars only, and runs no EU-directed marketing isn't "offering" anything to EU residents just because a visitor from Rome happened to land on the page. None of these signals is decisive on its own, and the EDPB has been explicit that this is a factors-based assessment rather than a checklist where any single item flips the switch. A US site that happens to accept international shipping as a general courtesy, without any EU-specific marketing, currency, or language, sits in genuinely gray territory rather than a clear yes or no, which is exactly the kind of case worth a real legal read rather than a confident guess in either direction.

"Monitoring behavior": the branch most SaaS and content sites miss

This one has a lower bar than most teams expect, and it doesn't require any intent to reach a European audience at all. Cookies, analytics, and ad-tech pixels that track and profile a visitor's behavior, for purposes like building an advertising profile or predicting preferences, count as monitoring when applied to someone physically located in the EU at the time. A US content site or SaaS product that never marketed to Europe, but runs standard analytics and retargeting pixels against every visitor including the EU ones, can trip this branch purely through how its tracking stack behaves, independent of any targeting decision the business made.

There's also a third, less-discussed way a US company ends up handling EU data without ever selling to an EU customer directly: acting as a vendor to a business that does. A US-based email delivery platform, analytics tool, or customer support software provider whose own customers are based in the EU, or have EU end users, is processing EU personal data on that customer's behalf, which brings its own GDPR obligations even though the US vendor never markets to or interacts with EU consumers itself. That relationship usually runs through a data processing agreement rather than a rewritten public privacy policy, but it's still a real form of GDPR exposure worth checking for any B2B software company with EU-based clients, regardless of where the vendor's own customers happen to sit.

Signals that point toward or away from scope

Signals that point toward or away from GDPR scope

Likely in scopeLikely out of scope
Shipping and currencyShips to EU, prices shown in eurosUS-only shipping, USD only
MarketingAd campaigns targeted at EU countriesNo EU-directed advertising or campaigns
Language and domainEU language or EU country-code domainEnglish-only, generic dot-com domain
Tracking and analyticsAd-tech pixels profiling EU visitorsNo behavioral tracking of EU visitors
Company presenceEU subsidiary, staff, or representativeNo EU establishment of any kind

No revenue floor, and why that surprises people

CCPA has three explicit numeric thresholds a business has to clear before it applies. GDPR has none. A five-person US startup with $50,000 in annual revenue and one paying EU customer is, in principle, just as squarely inside Article 3's scope as a Fortune 500 company. In practice, enforcement against very small businesses over incidental EU processing has generally meant warnings and corrective orders rather than the maximum fines GDPR is known for, but that's an enforcement posture, not a change to the scope test itself. If you're weighing GDPR against CCPA for a business that might sit inside one, both, or neither, our guide on CCPA vs GDPR applicability walks through both tests side by side.

What to do if the test says yes

Once Article 3 puts you in scope, the next steps are about the specific processing that triggered it, not a wholesale rebuild of your business. Identify a lawful basis under Article 6 for that processing, consent, contract, legitimate interest, or another applicable basis. Update your privacy policy to include the GDPR-specific disclosures: the lawful basis relied on, and the EU data subject rights (access, rectification, erasure, restriction, portability, and objection) that now apply to that data. Depending on the nature and scale of the processing, Article 27 may also require appointing an EU representative, a separate requirement from the compliance work itself and worth checking once scope is confirmed.

Article 27 carries its own exemption, and it's worth checking separately rather than assuming a representative is automatically required once Article 3 applies. All three of these have to be true at once: the processing is genuinely occasional, meaning incidental to the business's core activity rather than a regular part of how it operates, it doesn't involve large-scale special category data (health, biometric, or similar sensitive information) or criminal-record data, and it's unlikely to result in a risk to the rights and freedoms of the people whose data it involves. That bar is narrower than it first sounds: a SaaS product with an ongoing trial signup flow that regularly picks up EU sign-ups is processing EU data as a routine part of its business, not occasionally, so the exemption is a poor fit for exactly the kind of steady, low-volume EU exposure most US-only software businesses actually have. Confirming whether a representative is required is worth doing deliberately rather than assuming either way.

Our Privacy Policy Generator includes the GDPR-specific clauses, legal basis language and the full EU data subject rights list, so once you've confirmed you're in scope under Article 3, the policy itself doesn't have to be drafted from a blank page. For the fuller picture of what ongoing GDPR compliance involves beyond just the applicability question, see our GDPR compliance overview.

The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.