Does GDPR Apply to Your US-Based Service?

Share

California's pioneering consumer data privacy law, the California Online Privacy Protection Act (CalOPPA), was once the de facto data privacy law nationwide: if you had users in California (and you did), you needed to comply with CalOPPA -- whether your business was located in California, Delaware, or South Dakota.

Today, CalOPPA has been overshadowed by California's far-more-comprehensive (and messy) California Consumer Privacy Act (CCPA). And while CCPA led the push for comprehensive data privacy laws in at least 19 other states, California's position as the standard setter for data privacy regulation is increasingly being eclipsed by the EU's General Data Protection Regulation (GDPR).

As with CalOPPA before it, GDPR reaches far beyond the borders of the EU, to companies and organizations worldwide that process the personal data of people in the EU. Here's how to tell if your service is subject to the requirements of the GDPR.

GDPR applicability: services targeting the EU, monitoring of people in the EU, or EU establishment

GDPR applies to your US operation if:

  1. Your processing of EU personal data is related to the activities of an EU "establishment," or
  2. You process the personal data of "data subjects" in the EU (technically the EEA, which also includes Iceland, Liechtenstein, and Norway) if:a. The processing is related to the offering of goods or services to those data subjects; orb. The processing is related to the monitoring of the data subjects' behavior within the EU.

We'll cover EU establishments last, since most US services are likely to be more concerned with being captured by the second prong (processing of EU personal data).

(Note: despite Brexit, the UK maintains a consumer data privacy law almost identical to GDPR, so this analysis applies there as well.)

Offering goods or services

If your organization (1) offers goods or services to people in the EU and (2) you process their data to provide that offering, the GDPR applies to you.

Note that to meet the first criteria, you don't need to be offering goods or services to data subjects who are EU citizens or even EU residents -- they just have to be in the EU. If you offer a map application for tourists to the EU (e.g. with maps of Paris to be used while in Paris), then the EU Data Protection Board (EDPB) says that you are targeting data subjects in the EU.

Your targeting of data subjects in the EU does have to be knowing or intentional, however. It's not enough to run a service that is accessible to the broader Internet, or that a handful of EU data subjects happen to use -- you must intentionally be targeting EU data subjects.

EU regulators may infer intentional targeting of EU residents from any number of factors, including:

  • offering localization for EU languages or by otherwise specifically marketing your product in the EU
  • offering an app to EU territories via an app store
  • accepting euros, handling EU VAT, or processing EU payment methods
  • continuing to provide services to users in the EU after becoming aware that they are using your service

There's no clear line at which "offering a public service that has some EU users" crosses over to "targeting EU users." However, as the Italian regulator's enforcement against DeepSeek demonstrates, publicly accessible services with large EU user bases will likely be deemed to be "offering... services" to them.

Monitoring behavior

EU regulators have generally found that "monitoring" EU users' behavior consists of collecting data on specific individuals over time, for the purpose of tracking or identifying them. All of the enforcement actions in this area have been against a single US company, Clearview AI, that provides an AI-enabled facial recognition product.

It's a safe bet that the "monitoring" prong also applies to data brokers that compile behavioral data on individuals in the EU over time. It's not yet clear how the "monitoring" prong of Art. 3(2) might be applied to less on-the-nose data-collection scenarios, where the purpose of the data collection is less clearly focused on tracking individuals.

Establishment in the EU

Naturally, the GDPR applies to EU entities, but it also applies to EU "establishments." But what is an establishment, and does your company have one in the EU? The answer is clearly yes for companies that have EU subsidiaries, but even for companies with no formal corporate presence in the EU, the bar is low.

GDPR defines "establishment" broadly as "the effective and real exercise of activity through stable arrangements," specifically saying that "the legal form" of those arrangements is "not the determining factor." The EU's top court (the CJEU) found that a foreign company was "established" in Hungary by virtue of the presence of a single representative in the country, together with a mailing address, local bank account, and localized website.

The CJEU has also held that the actual processing of EU personal data doesn't have to take place in the EU, so long as the EU establishment's activities are "inextricably linked" to the processing.

So if you have staff or integrated contractors in the EU and their work relates at all to your personal data processing activities, there's a fair chance you're "established" in the EU and subject to the GDPR.

So do I have to comply with GDPR or not?

As you can see, the GDPR is intentionally broad, and many roads lead US services to regulation in the EU. Still, US services can pretty clearly be marked safe from GDPR if they meet all of the following criteria:

  1. No EU establishment. You don't have any staff, integrated contractors, or agents/representatives based in the EEA. Having services providers (like hosting providers) or truly independent contractors there is fine.
  2. No EU targeting. You aren't localizing your website for EU countries/languages, marketing to EU audiences, or charging users in Euros or handling EU VAT. Your app isn't made available to EU territories in the app stores.
  3. (Effectively) no EU data subjects. If you have any EU users, it's accidental, and they make up a very small proportion of your user base. You're not knowingly collecting or processing personal data of non-users in the EU.

Taking action

If you're not confident you can check those boxes, then take a moment this week to count your EU users, check your app-store territory settings, and ask whether anyone in the EU does ongoing work for you. Those three facts decide almost the entire analysis.

Create compliance checkpoints so you can run the analysis again if you hire in the EU, or expand your app or service's reach to the EU.