HIPAA & privacy

Do I need to comply with GDPR if I am a US company?

Possibly yes. GDPR applies to organizations outside the EU/EEA when they offer goods or services to, or monitor the behavior of, people in the EU/EEA, regardless of where the company is based. So a US company with EU customers, or that tracks EU website visitors, can fall under GDPR.

The extraterritorial scope

GDPR Article 3 extends the regulation to controllers and processors outside the EU/EEA where the processing relates to offering goods or services to individuals in the EU/EEA, or monitoring their behavior. Company location is not the deciding factor.

What triggers it

Selling to or actively marketing to EU customers, or tracking the behavior of EU visitors (for example with analytics or advertising that profiles them), can bring you in scope. Merely being accessible from the EU generally is not enough on its own.

What to do

If you are in scope: identify a lawful basis for processing, publish a clear privacy notice, honor data-subject rights, put DPAs in place with processors, and be ready to report a qualifying breach to the relevant authority within 72 hours.

FAQ

Does having EU website visitors alone trigger GDPR?

Not by itself. Being merely accessible from the EU is generally not enough; targeting EU individuals or monitoring their behavior is what brings you in scope.

What about the UK?

Post-Brexit the UK has its own UK GDPR with broadly equivalent obligations, so a US company serving UK individuals should consider it alongside EU GDPR.

Related

What is GDPR? → What is a data processing agreement? → GDPR in Keel →

Get audit-ready with Keel

The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free