GDPR can apply to your US website in two specific situations: when you offer goods or services to people in the EU, or when you monitor EU residents’ online behavior through tools like analytics or ad pixels. There is no revenue threshold or physical presence requirement. If either trigger applies, your site must meet GDPR’s consent, transparency, and data transfer obligations, regardless of where your company is incorporated.
TL;DR:
- If your US site displays prices in EU currencies, offers content in EU languages, or runs EU-targeted ads, GDPR obligations apply regardless of physical presence.
- Monitoring EU visitors through cookies, analytics, or tracking pixels triggers GDPR duties even if there is no deliberate EU targeting.
- Compliance requires establishing a legal basis for processing, implementing true consent with granular options, and maintaining records of consent events.
- US companies must verify their vendors have current transfer mechanisms like the EU-US Data Privacy Framework or Standard Contractual Clauses and document the transfer process.
- Most issues stem from unblocked trackers, inaccurate privacy notices, or missing EU representatives; addressing these is achievable within a week for small sites.
Table of Contents
- When GDPR applies to US sites: territorial scope and targeting signals
- Core GDPR obligations every covered website must meet
- Consent and cookies: implementing compliant consent management for EU visitors
- Transfers to the US: safe mechanisms and what US businesses should do now
- Step-by-step compliance checklist you can run this week
- Enforcement: who enforces GDPR and intersection with U.S. regulators
- How agencies implement GDPR-safe website builds (Depeche Code practical notes)
- Specific challenges and strategies for US websites with mixed EU and US users
- Examples of common compliance pitfalls for US websites and how to avoid them
- Handling employee and internal data under GDPR for US companies
- Differences and overlaps between GDPR and relevant US privacy laws
- Updating and managing vendor and third-party processor contracts
- Author perspective: high-impact next steps for small U.S. sites
- Depeche Code services that help implement GDPR requirements on U.S. websites
- Authoritative primary sources and guidance to consult
- Sources
- FAQ
When GDPR applies to US sites: territorial scope and targeting signals
Article 3(2) of the GDPR extends the regulation beyond the EU’s borders. According to EDPB Guidelines 3/2018 on territorial scope, a US company falls under GDPR if it offers goods or services to individuals in the EU or monitors their behavior, even without any physical EU presence. Simply being accessible from Europe is not enough to trigger the law. What matters is whether your business shows intent to reach EU visitors.
The EDPB guidance lists concrete signals that distinguish deliberate targeting from mere accessibility:
- Displaying prices in euros or other EU currencies rather than only US dollars.
- Offering content translated into an EU language, especially one not spoken widely in the US.
- Running paid ad campaigns aimed at EU countries or using EU-specific domain extensions.
- Mentioning EU customers, addresses, or phone numbers in marketing materials.
- Offering shipping or service delivery to EU addresses.
Monitoring is the second trigger, and it catches many US sites that never intended to court European customers. If your site uses cookies, tracking pixels, or analytics tools that profile visitor behavior, and some of those visitors are in the EU, you may be monitoring their behavior under GDPR’s definition. This includes cross-site advertising pixels, heatmap tools, and any script that builds a behavioral profile tied to an EU-based visitor. A US retailer with no EU marketing at all can still trigger GDPR obligations simply by running broad analytics that capture EU traffic without any way to exclude it.
Core GDPR obligations every covered website must meet
Once GDPR applies, a handful of obligations take priority over everything else. These are the ones that draw the most scrutiny from regulators and the ones most US site owners get wrong first.
- Establish a lawful basis for processing. Consent is usually the right basis for online tracking and marketing, since legitimate interest rarely covers behavioral advertising or third-party cookies.
- Publish a compliant privacy notice. At minimum it must name the controller, explain processing purposes, state retention periods, list data subject rights, and give contact details for data protection inquiries.
- Build a working data subject rights process. You need a documented way to accept requests, verify the requester’s identity, and respond to access, deletion, portability, or objection requests within the required timeframe.
- Apply reasonable security measures and prepare for breaches. The European Commission’s data protection guidance confirms controllers must notify the relevant supervisory authority within 72 hours of becoming aware of a breach affecting personal data.
- Run a Data Protection Impact Assessment when processing is high risk. Large-scale profiling, systematic monitoring, or processing of sensitive categories of data typically triggers this requirement.
- Appoint an EU representative if you lack an EU establishment. Article 27 requires non-EU controllers subject to GDPR to designate, in writing, a representative based in the European Union who can be contacted by supervisory authorities and data subjects.
Most US businesses underestimate the EU representative requirement because it sounds bureaucratic, but it is one of the simplest fixes on this list: a single written designation resolves a legal gap that otherwise leaves EU regulators with no easy way to reach you. Skipping it does not remove your GDPR obligations, it just makes you harder to hold accountable, which supervisory authorities notice.
Security and breach readiness deserve their own attention beyond the DPIA and 72-hour clock. A practical guide to website security covers the baseline protections that make breach response faster and less damaging when something does go wrong.
Consent and cookies: implementing compliant consent management for EU visitors
Consent is where most US websites fail GDPR, not because the concept is complicated, but because American cookie banner habits do not meet the European standard. The EDPB Guidelines on consent require consent to be freely given, specific, informed, unambiguous, granular, and easy to withdraw. Each of those words carries legal weight, and a banner that only says “we use cookies, by continuing you agree” satisfies none of them.
Cookie walls, the practice of blocking site access entirely until a visitor accepts tracking, are explicitly called out as invalid. The EDPB’s guidance includes a specific example showing that forcing a binary choice between accepting all cookies or leaving the site does not qualify as freely given consent. Pre-ticked consent boxes fail for the same reason: consent must be an active, affirmative action, not a default a visitor has to notice and undo.
A working consent setup for a US site handling EU traffic typically includes:
- Non-essential scripts blocked by default until the visitor actively consents.
- A granular interface letting visitors accept or reject categories like analytics, advertising, and functional cookies separately.
- A visible, one-click way to withdraw consent at any time, not buried in a settings page.
- Consent choices tested across desktop and mobile, since many banners silently fail on smaller screens.
Pro Tip: Log every consent event with a timestamp, the specific purposes accepted or rejected, and the banner version shown, since regulators can ask you to prove consent was valid months after the fact.
Recordkeeping matters as much as the banner itself. A consent management platform that blocks trackers but does not retain a receipt of what was shown and accepted leaves you unable to demonstrate compliance if a supervisory authority ever asks. Our guide to US cookie consent requirements walks through the technical side of blocking trackers before consent fires.
![]()
Transfers to the US: safe mechanisms and what US businesses should do now
Every time an EU visitor’s data lands on a US server, whether through hosting, analytics, or a CRM, that is an international transfer under GDPR, and it needs a legal mechanism behind it.
The EU-US Data Privacy Framework lets US companies self-certify that they meet EU-equivalent protections for personal data they receive from Europe. If your hosting provider, email platform, or analytics vendor is DPF-certified, transfers to them are treated as adequate without extra paperwork. Standard Contractual Clauses (SCCs) are the fallback when a vendor is not DPF-certified: pre-approved contract terms that bind the US recipient to GDPR-level protections. The European Commission’s guidance on data transfers notes that SCCs sometimes require supplemental measures, such as encryption, when the destination country’s surveillance laws could undermine the contractual protections.
Practical steps for a US site owner handling EU data:
- Check whether each vendor touching EU visitor data (hosting, analytics, email, CRM) is DPF-certified or has signed SCCs.
- Add or update data processing addenda in vendor contracts to reflect the transfer mechanism in use.
- Apply encryption or pseudonymization to personal data in transit and at rest where feasible.
- Document a transfer risk assessment for each vendor relationship that moves EU data to US servers.
None of this requires migrating your infrastructure out of the US. It requires knowing which vendors touch EU data and confirming each one has a valid transfer basis on file.
Step-by-step compliance checklist you can run this week
You do not need months to get the basics in place. Most of the highest-impact work fits into a focused week if you work through it in order.
- Audit your data flows. Map every third-party script, form, and analytics tool on your site, and note which ones collect or transmit personal data.
- Control your scripts. Install a consent management platform that blocks non-essential trackers until a visitor opts in, not just one that displays a banner.
- Update your privacy notice. Add controller identity, processing purposes, retention periods, and contact details for data protection requests.
- Build a data subject request workflow. Create a template for acknowledging requests and a documented process for verifying identity and responding within the required window.
- Check your DPIA triggers. If you run large-scale profiling or behavioral advertising, draft a Data Protection Impact Assessment and treat it as a living document you revisit.
- Update vendor contracts and appoint an EU representative if needed. Confirm transfer mechanisms are documented and, if you lack an EU establishment, designate a representative under Article 27.
Pro Tip: Do the script audit first. It usually reveals more third-party trackers than site owners expect, and fixing the consent gate around them resolves the bulk of your exposure before you touch policy language.
Enforcement: who enforces GDPR and intersection with U.S. regulators
GDPR enforcement runs through national data protection authorities in each EU member state, with the EDPB coordinating cross-border cases that affect multiple countries. A US company with no EU establishment can still be investigated if a DPA identifies EU residents’ data being processed unlawfully, particularly once an EU representative is on record to receive that contact.
Remedies are not always financial. DPAs can order a company to change its practices, suspend processing, or submit to an audit, and fines are just one tool among several.
In the US, the FTC’s privacy and security enforcement program adds a separate layer of exposure. The FTC pursues deceptive privacy practices under Section 5, and a cookie banner or privacy notice that misrepresents what your site actually does with visitor data can trigger a US enforcement action independent of anything happening in Europe.
For most small and mid-size US sites, the practical move is a risk-based one:
- Fix consent and tracking first, since that is the most visible gap to both EU regulators and US visitors.
- Make sure your privacy notice matches your actual practices, since mismatches are what invite FTC scrutiny.
- Treat EU representative and vendor contract gaps as lower urgency but not optional.
How agencies implement GDPR-safe website builds (Depeche Code practical notes)
Some web design agencies build websites with non-essential third-party scripts blocked by default and a consent management platform wired in before launch, so tracking never fires ahead of visitor choice. Common template pitfalls include pixels hard-coded into theme files and analytics snippets that load regardless of consent status. Both are simple to catch during a build review but easy to miss when a site is assembled from stock templates.
For client hand-off, deliverables may include consent logs, a records-of-processing outline, DPIA notes for any high-risk processing, and vendor contract addenda covering data transfers. Our note on how web design choices protect your SME website covers more of these implementation patterns. Businesses unsure where their own site stands can seek out audits to see what needs attention.
Specific challenges and strategies for US websites with mixed EU and US users
A site serving both US and EU visitors faces a practical problem: applying GDPR-level consent to every visitor is safer but can add friction for US users who are not legally owed the same protections. Geolocation-based consent banners solve part of this, showing GDPR-compliant consent flows only to EU-based IP addresses while US visitors see a simpler notice. The tradeoff is that IP-based geolocation is not perfect, and VPN use or shared corporate networks can misclassify a visitor’s location.
The more reliable strategy for mixed-audience sites is to build the stricter standard once and apply it everywhere. A consent management platform that blocks non-essential trackers until opt-in, offers granular category choices, and logs every decision meets GDPR requirements for EU visitors and creates no legal problem for US visitors, since asking for consent is never prohibited domestically. This avoids maintaining two separate banner logics and two sets of records.
Where geolocation is used, document the logic clearly: which regions get which experience, how edge cases are handled, and how often the IP database is updated. A stale geolocation database is a common reason mixed-audience sites end up treating EU visitors as domestic ones without realizing it.
Examples of common compliance pitfalls for US websites and how to avoid them
The most frequent mistake is a cookie banner that displays a notice but does not actually block anything, meaning analytics and advertising scripts fire the instant the page loads regardless of what the visitor clicks. The fix is a CMP that gates scripts behind consent at the code level, not just visually behind a banner.
A second common pitfall is a privacy notice copied from a template that references data practices the site does not actually follow, such as naming a retention period or listing rights procedures that were never built out. This kind of mismatch is exactly what invites FTC scrutiny under Section 5 for deceptive practices, separate from any GDPR exposure.
Third, many US sites collect data subject requests through a generic contact form with no defined response process, which means requests get lost or answered inconsistently. A dedicated intake process with a documented response timeline closes this gap.
Finally, sites often assume that because their business is US-based, GDPR simply does not apply, and skip the targeting and monitoring assessment entirely. That assumption is the pitfall most likely to go unnoticed until an EU visitor files a complaint.
Handling employee and internal data under GDPR for US companies
GDPR is not limited to customer-facing website data. If a US company has EU-based employees, contractors, or job applicants, their personal data, including payroll details, performance records, and application materials, falls under the same obligations as customer data. This applies even when the company’s website itself is entirely US-facing.
The practical implications include needing a lawful basis for processing employee data (usually contractual necessity or legitimate interest rather than consent, since consent is rarely considered freely given in an employment relationship), providing employees with a privacy notice covering how their data is used, and honoring access or deletion requests from EU staff the same way you would for an EU customer.
Internal HR systems, applicant tracking tools, and payroll vendors that store data on EU personnel need the same transfer safeguards as customer-facing vendors, whether that is Data Privacy Framework certification or Standard Contractual Clauses. Companies with a small number of EU remote hires sometimes overlook this because their attention is focused on website compliance, but the obligations are identical in substance.
Differences and overlaps between GDPR and relevant US privacy laws
GDPR and US state privacy laws like the CCPA share a common foundation, transparency about data collection, rights to access and delete personal data, and limits on how data can be shared, but they differ in scope and mechanics. GDPR applies based on whether you target or monitor EU residents, with no revenue or size threshold. CCPA and similar state laws apply based on business size, revenue, or data volume thresholds tied to California residents specifically.
Consent standards also diverge. GDPR generally requires opt-in consent before non-essential tracking occurs. CCPA operates primarily on an opt-out model, letting businesses collect and use data by default until a consumer exercises their right to opt out of sale or sharing.
For a US website with both EU and California traffic, the overlap actually simplifies things: building a consent flow that meets GDPR’s stricter opt-in standard will generally satisfy CCPA’s more permissive opt-out requirements as well, since offering more control than required rarely creates a compliance gap. Our breakdown of CCPA website compliance fixes covers the state-law side in more detail, including how DSR workflows differ between the two frameworks.
Updating and managing vendor and third-party processor contracts
Every vendor that touches personal data on your behalf, analytics providers, email platforms, CRM systems, hosting companies, needs a data processing agreement that spells out what they can and cannot do with that data. Under GDPR, you remain responsible for how your processors handle data even when something goes wrong on their end, so contract review is not optional paperwork.
A working vendor review process checks three things for each processor: whether they have signed a data processing addendum reflecting current GDPR requirements, whether their transfer mechanism (DPF certification or SCCs) is current and documented, and whether their own subprocessors are disclosed and similarly bound. Many vendor contracts predate current transfer frameworks and need updating rather than replacing.
Set a recurring review, at least annually, since vendors change subprocessors, certifications lapse, and new tools get added to a site faster than contracts get updated. A vendor list that was accurate at launch is often stale within a year, especially for sites that add marketing or analytics tools incrementally.
Author perspective: high-impact next steps for small U.S. sites
If you run a small US business site, the three moves that matter most are auditing your third-party scripts, gating them behind real consent, and rewriting your privacy notice to match what you actually do. Most of GDPR’s risk for a small site lives in those three items, not in elaborate legal infrastructure.
You need a lawyer when transfers get complex or a regulator contacts you. You do not need one to block a tracking pixel or fix a cookie banner. Treat compliance as ongoing housekeeping, not a project with an end date, since new tools and vendors quietly reopen gaps you already closed.
— Donovan Wells – Founder and CEO
Depeche Code services that help implement GDPR requirements on U.S. websites
Getting consent gating, script blocking, and hosting security right on your own site takes time most small business owners do not have. Some agencies build privacy-aware websites with consent management wired in from the start, while hosting and maintenance plans help keep those protections current as browsers, vendors, and regulations shift.

If your site needs a technical review of trackers, consent flows, or hosting security, our services page outlines where to start.
Authoritative primary sources and guidance to consult
For consent standards, the EDPB Guidelines on consent remain the definitive reference on what makes a cookie banner valid. For territorial scope questions, the EDPB Guidelines on territorial scope explain when a US site counts as targeting or monitoring EU residents. The European Commission’s data protection overview covers breach notification and DPIA basics in plain language. On the US regulatory side, the FTC’s enforcement page shows how deceptive privacy claims get pursued domestically. For a secondary plain-language summary, Skypher’s GDPR overview for US organizations is a useful supplement, and Revoxy’s assessment tools offer a starting point for automated privacy and security checks.
Sources
FAQ
Is there an equivalent of GDPR in the US?
The US has no single federal law equivalent to GDPR. Instead, states like California enforce their own privacy laws such as the CCPA, which share some goals with GDPR but differ in scope, thresholds, and consent model.
Does the United States have GDPR laws?
No, GDPR is an EU regulation, not a US law, but it can still apply to a US website if that site targets or monitors EU residents. US privacy protection instead comes from a patchwork of state laws and FTC enforcement under Section 5.
What are the GDPR requirements for a website?
A covered website needs a lawful basis for processing, a privacy notice disclosing who controls the data and why it is collected, a working process for honoring data subject rights, and a consent mechanism that blocks non-essential trackers until visitors opt in. Sites without an EU establishment that fall under GDPR must also designate an EU representative under Article 27.
How do I know if my website is GDPR compliant?
Check whether your site targets EU visitors through language, currency, or advertising, or monitors them through cookies and tracking pixels, since either trigger brings GDPR into play. From there, confirm your consent banner blocks trackers by default, your privacy notice matches your actual practices, and your data subject request process actually works when tested.

