Your Boston SaaS company signs its first customer in Berlin. The product team has already connected that workspace to analytics, support, billing, and a U.S.-based backup system. Then the customer submits a data access request, and your founders discover that not having an EU office is not the real issue. The real issue is whether your business falls within GDPR’s territorial scope.
If you are asking whether GDPR applies to US companies, the short answer is yes, sometimes. A U.S. company can fall under GDPR if it offers goods or services to people in the EU or monitors their behavior there. In many cases, that also raises the question of whether the company must appoint an Article 27 EU representative.
Document the risk, then reduce it
Compare the mechanism to the flow
Cross-Border Data Transfers Without the Headache
Days 71 through 90, continuous operations
Days 46 through 70, representation and transfer review
Days 22 through 45, documentation and lawful basis
Days 1 through 21, scope and inventory
A 90-Day Compliance Roadmap for US Companies
The Two Triggers That Make GDPR Apply to You
FAQ: Article 27 for US Companies
The Three Decisions That Move the Needle
A representative is not an EU subsidiary
What Article 27 Actually Requires and What It Does Not
Core Obligations Most US Teams Underestimate
Trigger one is deliberate offering
When US Companies Get Pulled Into GDPR Territory
This guide explains when GDPR for US companies becomes relevant, what Article 27 actually requires, and the practical steps to build a workable compliance program.
Table of Contents
- Does GDPR Apply to US Companies?
- What Triggers GDPR for US Companies?
- What GDPR Obligations Apply to US Companies?
- What Is Article 27 GDPR and Do US Companies Need It?
- How GDPR Connects to UK GDPR, DSA, AI Act, and NIS2
- The Three Decisions That Matter Most
- FAQ: GDPR for US Companies and Article 27
- Does GDPR apply to US companies?
- Do US companies always need an Article 27 representative?
- What is the fastest way to tell if we likely need one?
- Does appointing a representative make us GDPR compliant?
- Where should the representative be located?
- Do US companies need a ROPA?
- Can a US SaaS company rely on the occasional-processing exemption?
- Is an EU representative the same as opening an EU office?
Does GDPR Apply to US Companies?
Yes, GDPR can apply to a U.S. company even if it has no EU office, employees, or servers. A U.S. business can enter GDPR territory through ordinary growth decisions. You launch a European landing page, accept customers in the EU, personalize advertising for visitors there, or analyze their behavior across your product.
The GDPR has applied since 25 May 2018. By March 2025, EU data protection authorities had issued about €5.65 billion in GDPR fines, with U.S.-based companies accounting for roughly 83%, or about €4.68 billion, of that total, according to an analysis of GDPR fines against U.S. firms. These figures do not mean every startup faces an immediate fine. They do show that being headquartered in the United States is not a practical defense.

The location test matters more than the passport
GDPR protection follows the circumstances of the processing, not the company’s flag or the individual’s nationality. A U.S. company processing personal data in connection with people in the EU can fall within the regulation even when its servers, employees, and legal entity are in the United States.
For the Berlin customer, the first practical questions are simple:
- Market intent: Are you deliberately selling, onboarding, or supporting people in the EU?
- Behavioral visibility: Are you tracking EU users for analytics, personalization, advertising, or product decisions?
- Operational exposure: Can you locate the data, explain its purpose, answer rights requests, and respond to regulators?
If the answer is yes, treat GDPR as a launch requirement, not an after-the-fact legal project. Your first EU customer may expose gaps in notices, rights handling, vendor contracts, transfer safeguards, and incident response at the same time.
Senior advisor’s view: The real risk is not that a founder missed a line in a privacy policy. It is that nobody can explain where EU personal data goes or who owns the response when a request arrives.
What Triggers GDPR for US Companies?
A U.S. SaaS company can reach GDPR territory without opening an EU office. The regulation usually enters through one of two routes. Article 3(1) applies where an EU establishment is involved in processing. Article 3(2) can apply to a business outside the EU that offers goods or services to people in the EU or monitors their behavior.
The second route covers many U.S. SaaS, ecommerce, advertising, and digital product companies. Treat it as a scope question to resolve before launch, not as paperwork to fix after the first complaint.

Trigger one is offering goods or services
You do not need to charge an EU customer to create exposure. The relevant issue is whether your conduct shows an intention to serve people in the EU.
Look for these signals:
- Localized commercial design: Euro pricing, EU shipping terms, local-language pages, or checkout flows aimed at European buyers.
- Targeted acquisition: Campaigns directed at EU audiences, regional search pages, or sales outreach to EU prospects.
- Customer operations: Contracts with EU individuals, accounts provided to them, or support for their market.
An accessible website and incidental EU traffic do not automatically subject a U.S. company to every European obligation. Commercial intent and the processing connected to that activity determine the analysis.
Trigger two is monitoring behavior
Monitoring extends beyond watching a person’s screen. It can include analytics, identifiers, advertising technology, location signals, or product telemetry used to evaluate or predict behavior.
Have the growth team check whether it:
- Profiles EU visitors for retargeting.
- Measures EU sessions to personalize content.
- Tracks activity across devices or services.
- Uses location or timing data to infer user patterns.
- Builds audiences from EU interactions.
B2B is not a blanket exemption. Processing contact details for an EU company may still involve employees or other identifiable people. Map the individuals, purposes, systems, and decisions involved instead of classifying the entire activity as outside GDPR.
Use the European Data Protection Board guidance on territorial scope to record your scope assessment. Recheck it when your markets, product, or tracking stack changes.
Senior advisor’s view: The central risk is not a missing sentence in a privacy policy. It is an unowned data flow, an unclear tracking purpose, or a team that cannot explain its scope decision when challenged. An EU representative may provide a contact point, but it does not cure those failures or shield the company from transfer, security, and accountability duties.
What GDPR Obligations Apply to US Companies?
Once GDPR applies, a privacy policy alone will not carry the program. The regulation reaches product design, marketing, engineering, security, procurement, customer support, and executive decision-making.
Start with the processing purpose. For each activity, record the lawful basis, the purpose, the data involved, the retention approach, the recipients, and the person responsible. Consent is not a universal repair tool. If a team chooses consent, it must make the choice informed, specific, freely given, and easy to withdraw. If it chooses contract necessity or legitimate interests, document why that basis fits the actual processing.
Build the operating layer
Your minimum operating layer should include:
- Clear notices: Explain what you collect, why you use it, how long you retain it, who receives it, and how people can exercise their rights.
- Rights intake: Route access, deletion, correction, objection, and portability requests to an accountable owner. Identity checks should prevent unauthorized disclosure without creating unnecessary barriers.
- A living processing record: Maintain a current record of processing activities. A spreadsheet can work for a small company if it has owners, version control, and enough detail to support an audit.
- Breach readiness: Your incident plan must identify the decision-maker, legal reviewer, security lead, communications owner, and regulator contact. The relevant notification clock starts when the organization becomes aware of a qualifying breach, so escalation cannot depend on one person being online.
- Risk assessment: Use a data protection impact assessment for processing that could create significant risks, especially systematic monitoring or sensitive data use.
- Security controls: Apply access restrictions, encryption where appropriate, logging, secure deletion, vendor controls, and tested recovery procedures.
A record of processing activities, often called a ROPA, is one of the most useful operating documents for a U.S. company under GDPR. It helps your team map purposes, systems, vendors, transfers, retention, and ownership, and it is often the first record needed when handling rights requests, supporting an Article 27 representative, or answering customer due diligence questions.
Operational rule: If your support team cannot recognize a rights request, your legal basis is not recorded, or engineering cannot identify every production data store, the program is not operational yet.
Vendor management deserves its own workstream. Your customer relationship, help desk, product analytics, email platform, cloud environment, and backup provider may each process personal data. Review every data processing agreement, subprocessor disclosure, security commitment, deletion provision, and international transfer mechanism. A useful starting point for customer and vendor contract work is this GDPR data processing agreement resource.
A small U.S. team can handle much of the inventory, workflow design, and documentation internally. Get specialist advice when the product uses sensitive data, extensive profiling, complex group structures, or high-volume international transfers. Do not wait for a regulator or enterprise customer to reveal that the evidence folder is empty.
What Is Article 27 GDPR and Do US Companies Need It?
An Article 27 representative is a formal in-market contact for a non-EU organization covered by Article 3(2), unless a narrow exemption applies. The appointment must be in writing, and the representative must be established in a Member State where affected data subjects are located.
The role has a defined operating purpose. The representative can receive communications from data subjects and supervisory authorities, maintain the controller’s record of processing activities, and cooperate with regulators. Appointment does not reduce your company’s responsibility or liability. The representative is a contact point, not a liability shield.
An EU representative is not an EU office
An EU representative does not create an EU establishment, manage your product, approve your lawful bases, or take on your compliance duties. Your company remains responsible for processing, contracts, security, privacy notices, rights workflows, and transfer decisions.
Treat any mailbox-only service with caution. A representative should have a documented mandate, a reliable intake process, appropriate records, and a clear escalation route to your organization. Your privacy notice should identify the representative’s contact details where required.
The exemption is narrow. It generally requires processing to be occasional, unlikely to create risks to individuals, and unrelated to large-scale special-category or criminal-conviction data. An ongoing SaaS subscription, recurring ecommerce activity, or continuous behavioral tracking calls for a documented exemption analysis rather than an assumption that Article 27 does not apply.
The representative also sits inside a wider compliance stack. It cannot replace your records, vendor controls, rights procedures, transfer analysis, or evidence of lawful processing. In practice, that usually includes access to a current ROPA so your team can answer scope, purpose, vendor, and data-flow questions with something more reliable than memory.
How to decide whether to appoint one
Use three tests before appointing one:
- Scope test: Confirm that Article 3(2) applies and identify the Member States where affected individuals are located.
- Exemption test: Document why the occasional-processing exemption does or does not apply.
- Operating test: Confirm that the provider can receive, log, forward, and escalate authority and data-subject communications.
A formal EU GDPR Article 27 representative service can satisfy the contact-point requirement, but it cannot repair an unlawful transfer, unsupported processing purpose, or weak internal controls. Appoint the representative, then build the operating evidence behind it.
Need a practical next step? If your team likely falls under Article 3(2), review your scope, exemption position, and response workflow before EU growth makes the gap harder to defend. Dilicheck Rep can help structure that process before your next launch.
How GDPR Connects to UK GDPR, DSA, AI Act, and NIS2
A European launch rarely creates one compliance relationship. It creates a network of market-access rules, each with its own trigger, scope, records, and regulator interface.
The UK GDPR can require a separate UK representative for a non-UK organization subject to the UK regime. Since Brexit, the UK runs its own data protection framework and regulator interface, even though many compliance concepts still look familiar to teams already working on EU GDPR. That means a U.S. company selling into both the EU and UK may need to assess two territorial-scope positions, two representative questions, and two response workflows instead of assuming one appointment covers both markets.
If your growth plan includes UK customers, users, or marketing, treat UK GDPR as a parallel launch requirement and confirm early whether you need a formal UK point of contact.
Need UK coverage too? If your company is reaching people in the UK, review whether a separate UK GDPR representative or contact model belongs in your market-entry plan alongside your EU setup.
The Digital Services Act may affect in-scope digital services and online platforms. The EU AI Act can impose duties on non-EU providers placing covered AI systems on the EU market. NIS2 can create cybersecurity governance and contact obligations for organizations and suppliers within its scope.
Build one governance map
Do not appoint separate contacts blindly and hope the organization can coordinate later. Create a framework matrix covering:
- Territorial trigger: Which customer, user, product, or activity brings the framework into scope?
- Representative requirement: Is a formal representative, authorized representative, or contact point required?
- Evidence set: Which mandates, notices, records, technical files, or incident logs must be maintained?
- Escalation path: Who receives regulator communications, customer complaints, and urgent notices?
A unified operating model can reduce fragmented intake, but it does not merge legal duties. A DSA representative does not satisfy GDPR Article 27, and a GDPR representative does not automatically satisfy an AI Act role. Dilicheck Rep describes a DSA legal representative service as part of a broader representation model, but your scope assessment still needs to identify each framework separately.
Practical insight: Consolidate administration where possible. Keep legal analyses, mandates, records, and accountability distinct where the law requires them to be distinct.
The Three Decisions That Matter Most
The first decision is your lawful basis for the product’s core processing. Choose it by processing purpose, not by convenience. Consent should not become a substitute for product architecture, and legitimate interests should not become a label applied after the fact. Document the decision, the balancing analysis where relevant, and the user-facing explanation.
The second decision is your representative model. Choose a provider that can execute a written mandate, maintain the required records, receive communications, and escalate promptly. Avoid treating the representative as an insurance policy. The company still owns the processing, liability, rights response, security, and transfer position.
The defensible default is simple: appoint the right contact, then build the controls that make the contact useful.
The third decision is your single source of truth for transfers. Keep the vendor register, data-flow map, transfer mechanisms, impact assessments, supplementary measures, and contract versions connected. If procurement, security, engineering, and legal maintain separate versions, nobody knows which one reflects production reality.
U.S. companies should also plan for enforcement that reaches organizations without an EU establishment. The existence of a representative does not remove exposure, and the absence of one does not make the underlying processing disappear. A defensible program is not perfect paperwork. It is a set of current decisions, assigned owners, working workflows, and evidence that matches what the product does.
FAQ: GDPR for US Companies and Article 27
Does GDPR apply to US companies?
Yes, it can. GDPR may apply to a U.S. company if it offers goods or services to people in the EU or monitors their behavior there. Having no EU office does not automatically keep a company out of scope.
Do US companies always need an Article 27 representative?
Not always. A U.S. company generally needs an Article 27 representative when GDPR applies under Article 3(2) and no exemption fits. Because the exemption is narrow, most teams should document the analysis early, especially before signing EU customers or expanding EU marketing.
What is the fastest way to tell if we likely need one?
Start with two questions. Are you offering goods or services to people in the EU, or monitoring their behavior? If yes, Article 27 may apply. A quick scope review can usually confirm whether representation should be part of your launch checklist.
Does appointing a representative make us GDPR compliant?
No. A representative gives you a formal contact point in the EU, which is important, but compliance still depends on your notices, lawful bases, contracts, transfers, security, and rights handling. The practical value is strongest when representation is paired with a working internal process.
Where should the representative be located?
The representative should be established in an EU Member State where some affected individuals are located. In practice, the best choice is usually the market or group of markets where your company is actively selling, supporting, or tracking users.
Do US companies need a ROPA?
Often, yes. A record of processing activities helps a U.S. company explain what personal data it handles, why it handles it, which systems and vendors are involved, how long data is kept, and where responsibility sits internally. Even when a team is small, a current ROPA is often one of the most useful documents for handling rights requests, supporting an Article 27 representative, and showing that the program matches production reality.
Can a US SaaS company rely on the occasional-processing exemption?
Sometimes, but many SaaS companies struggle to qualify. If you have recurring EU customers, ongoing product use, or regular analytics and tracking, the exemption may be hard to defend. That is why many teams choose to validate the exemption carefully or appoint a representative before growth creates avoidable risk.
Is an EU representative the same as opening an EU office?
No. An Article 27 representative is not an EU office, branch, or subsidiary. It is a formal regulatory contact role that helps your company meet a specific requirement without creating a local establishment.
Dilicheck Rep provides formal EU and UK regulatory representation, including GDPR Article 27, EU AI Act, Digital Services Act, Data Act, and NIS2 contact-point services, with mandate documentation and structured handling of authority and data subject communications. Review your representation scope and operating model with Dilicheck Rep before your next EU market launch.
Disclaimer: This guide is provided for general information purposes only and does not constitute legal advice. The application of EU data protection and other regulatory requirements depends on the specific circumstances of each organisation. You should obtain appropriate legal advice where necessary before relying on this information or making compliance decisions.
Disclosure: This article was prepared with AI assistance and human review.
