Does GDPR Apply to US Companies? A 2026 Compliance Guide

GDPR doesn't stop at the EU border. If you sell into Europe, target EU-based buyers, or process EU personal data, the regulation reaches your US business. Here is exactly when it applies, when it doesn't, and how to keep outbound running.

Aug 23, 2026 10 min read 2,373 words
Does GDPR Apply to US Companies? A 2026 Compliance Guide

TL;DR — does GDPR apply to US companies? Yes, in three cases.

  • You offer goods or services to people in the EU or EEA.
  • You track what those people do online.
  • You handle EU personal data on behalf of someone else.

No EU office is needed. What you do matters. Where you sit does not.

  • Cold B2B email counts as processing. firstname.lastname@company.com is personal data. So is info@ when one person owns the box.
  • Most legal EU outbound runs on legitimate interest (Article 6(1)(f)), not consent. You still need a written balancing test and a working opt-out.
  • The ePrivacy Directive sits on top of GDPR. Germany and Italy want consent first, even for B2B. The UK and Ireland allow legitimate interest.
  • Fines stop at €20 million or 4% of global turnover, whichever is higher. Regulators have chased non-EU firms since the 2021 Clearview AI rulings.

Does GDPR apply to US companies in your case? This guide walks you through it. It is written for revenue teams, not lawyers. You will see when the rule reaches you, what changes in your prospecting, and where the lines sit. It is not legal advice. Talk to counsel before you set policy.

Does GDPR apply to US companies at all?#

Yes. The trigger is behavior, not geography.

Think of it like a state sales-tax rule. You do not need a store in the state. You just need to sell into it. GDPR works the same way. Article 3 puts that reach in writing.

Two things pull you in under Article 3(2):

  1. You offer goods or services to people in the EU. Paid or free, both count. Prices in euros, a .de landing page, EU ads, or an SDR sequence aimed at Berlin all show intent.
  2. You track how people in the EU behave. That covers analytics cookies, retargeting pixels, session recording, intent scores, and visitor ID tools.

Article 3(1) is a separate case. Do you have an "establishment" in the EU? A branch, a sales office, sometimes one employee is enough. Then the rule covers that work, wherever your buyers live.

Here is what most US teams miss. GDPR protects people located in the EU, not EU citizens. A German who lives in Austin is usually out of scope. An American who works in Amsterdam is in it. What counts is where the person is at the time. Read the source text on gdpr.eu if you want the wording.

Does GDPR apply to US companies? A sales rep finds out mid-sequence
Does GDPR apply to US companies? A sales rep finds out mid-sequence

When does GDPR not apply to a US business?#

There is a real exemption. It is narrow.

Recital 23 is the one to know. A website Europeans can reach is not enough on its own. Say you sell in dollars. Your content targets US buyers. You run no EU-language pages. You do not ship to Europe. A German visitor lands from a Google search. That alone creates no duty.

So does GDPR apply to US companies that never aim at Europe? Often not, if all of this holds:

  • No EU targeting signals. No euro prices, EU languages, country domains, EU phone numbers, or EU shipping.
  • No EU-directed marketing. No ads aimed at EU countries, no EU trade shows, no EU lists.
  • No tracking of EU visitors. No pixels or profiling on European traffic.
  • No EU customer data in your systems. That includes data an EU client hands you to process.
  • No EU establishment. No entity, office, or staff on the ground.

Here is the trap. Most B2B firms fail this test the day one rep imports a list with @sap.com on it. Scope is not a company-wide switch. It attaches to each activity. One EU campaign is enough.

How does GDPR compare to US privacy laws?#

The two systems start from different places. GDPR is opt-in, and you need a lawful basis first. US law is mostly opt-out, with rules by sector. Here is how the frameworks that touch B2B outbound line up.

Attribute GDPR (EU/EEA) UK GDPR + PECR CCPA/CPRA (California) CAN-SPAM (US federal)
Applies to US company without local office Yes, via Art. 3(2) targeting/monitoring Yes, same extraterritorial test Yes, if thresholds met (>$26.6M revenue or 100k+ consumers) Yes, all commercial email
Covers B2B work emails Yes — personal data if it identifies a person Yes Yes (B2B exemption expired Jan 2023) Yes
Lawful basis needed before contact Yes — consent or legitimate interest Yes; PECR allows B2B soft opt-in No basis required; opt-out model No basis required
Prior consent for cold B2B email Country-dependent (DE/IT effectively yes) No, for corporate subscribers No No
Right to access / deletion Yes, 30-day response window Yes, 30 days Yes, 45 days No
Data subject notification at first contact Yes — Art. 14, within 30 days Yes Notice at collection Sender ID + physical address
Max penalty €20M or 4% global turnover £17.5M or 4% $7,988 per intentional violation $53,088 per email
Opt-out honoring window Without undue delay Without undue delay 15 business days 10 business days

The short version: CAN-SPAM lets you email first and drop people later. GDPR asks you to justify the send first. You also have to say where you got the address. That paperwork is the real change, not the fines.

Chart: how GDPR, UK PECR, CCPA and CAN-SPAM compare for US senders
Chart: how GDPR, UK PECR, CCPA and CAN-SPAM compare for US senders

What counts as personal data in B2B prospecting?#

More than you think. That is why "we only do B2B" is not a defense.

Does GDPR apply to US companies that only email work addresses? Yes. Under Article 4(1), personal data is any data that points to a person you can name. In a normal prospecting stack:

  1. Named work emails are personal data. maria.rossi@acme.it points to Maria Rossi. Every EU regulator agrees on this one.
  2. Role accounts usually are not. sales@acme.it, info@acme.it, and support@acme.it sit outside, unless one person clearly owns the box.
  3. Extra fields inherit the status. Job title, LinkedIn URL, direct dial, company size, and tech stack all count once tied to a name.
  4. IP addresses and device IDs count. The CJEU settled that in Breyer in 2016. Visitor ID tools need their own basis for EU traffic.
  5. Guesses count too. An intent score or a persona label about a named person is personal data. You must explain it and delete it on request.

So your tools matter as much as your list. A vendor that shows where each record came from lets you write the Article 14 notice. One that hands you a raw CSV does not. Tomba publishes its data sources for that reason. Provenance is what turns a list into a record you can defend.

Diagram: what counts as personal data in B2B prospecting
Diagram: what counts as personal data in B2B prospecting

Can US companies cold email EU prospects legally?#

Yes, in most member states. You run it on legitimate interest, and you keep the paperwork.

Does GDPR apply to US companies sending cold email into the EU? It does, and you can still send. Recital 47 says direct marketing may count as a legitimate interest. That is your basis. It is not automatic. You need a written Legitimate Interest Assessment (LIA) with three parts:

  • Purpose test. Why is this outreach a real business need? "More sales" is weak. "Reaching IT leads at logistics firms about a compliance tool they likely need" holds up.
  • Necessity test. Is email the lightest way to get there? Note why an ad campaign would not do the same job.
  • Balancing test. Do the person's rights outweigh your interest? A VP of Engineering, at work, about an engineering tool: low intrusion. A nurse, on a personal Gmail, about crypto: fails.

Then add the ePrivacy Directive. It governs the channel, not the data. This is where the map splits by country.

Country Cold B2B email without prior consent Notes for US senders
United Kingdom Allowed PECR permits corporate-subscriber marketing; opt-out required
Ireland Allowed Corporate subscribers exempt from consent rule
Netherlands Allowed B2B permitted with clear opt-out
France Allowed CNIL permits B2B if message relates to the recipient's role
Spain Allowed LSSI permits with relevance and opt-out
Germany Effectively no UWG requires prior consent; competitor lawsuits are common
Italy Effectively no Garante applies strict consent expectations
Austria Effectively no Consent expected under TKG

The UK ICO's direct marketing guidance explains the split in plain English. The lesson for you is simple. Split your EU list by country. That step is the line between a clean campaign and a German cease-and-desist letter.

Diagram: cold email rules by country for US senders in the EU
Diagram: cold email rules by country for US senders in the EU

What does a compliant US-to-EU outbound workflow look like?#

Does GDPR apply to US companies that run these six controls? Yes, and none of them stop you from selling. All of them survive an audit.

1. Source data you can trace. For every record, answer one question: where did this come from? Article 14(2)(f) makes that a duty when the person did not hand you the data. A scraped list with no origin fails on the spot. Tools with clear sourcing and a real email verifier step give you a chain you can show.

2. Verify before you send. Dead addresses raise bounce rates and hurt your sender reputation. They also mean you hold wrong data, which breaks the accuracy rule in Article 5(1)(d). Verification is a control, not just a deliverability trick.

Does GDPR apply to US companies buying scraped lists? A rep picks verified data
Does GDPR apply to US companies buying scraped lists? A rep picks verified data

3. Put the Article 14 notice in your first email. One or two lines. Who you are. What data you hold. Where you got it. Why you wrote. A link to your privacy policy. It costs you nothing in replies. It often helps, because it shows you are not spraying.

4. Make opt-out instant and honored. Use one-click unsubscribe, plus a suppression list shared by every sending tool. The standard is "without undue delay". Treat that as same-day. Keep the record forever, so you can prove you honored it.

5. Run the LIA and file it. One doc per campaign type, reviewed each quarter. Two pages is plenty. If a regulator asks, "we thought about it" is worth nothing. A dated PDF is gold.

6. Answer DSARs within 30 days. Access, fix, delete, and object requests all start a 30-day clock. An objection to marketing is absolute. You stop, with no balancing. Route these to a shared inbox, not to the rep who got the reply.

Which tools help US teams stay in scope?#

Provenance and process beat feature count. Here is how the options compare for a US team selling into Europe.

Requirement Scraper / bought list General B2B database Sourced email finder (e.g. Tomba)
Documented data origin No Partial Yes — published sourcing
Verification before send Rarely Sometimes Yes, built in
Deletion / suppression support No Varies Yes, via API and dashboard
Role vs. named email distinction No Sometimes Yes
Entry price Cheap or free $99–$500/mo Free tier, then $49/mo
Audit trail for Art. 14 notice None Limited Yes

Peers worth a look include BookYourData. It sells verified B2B contact data, bills pay-as-you-go, and publishes its accuracy numbers. That fits if you would rather buy a list than build one. Check vendor claims on G2 as well. Do not take one blog's word for it, this one included.

For a US team, the practical setup is simple. Build lists by country segment. Verify every address. Keep the sourcing records. Skip Germany, Italy, and Austria for cold email, and use LinkedIn or paid ads there. Tomba's pricing starts free at 25 searches a month, then moves to $49/mo on Starter. That is enough to test a country-split approach before you commit budget.

Tool comparison for US teams asking does GDPR apply to US companies
Tool comparison for US teams asking does GDPR apply to US companies

What happens if you ignore it?#

Does GDPR apply to US companies in practice, or only on paper? Ask Clearview AI.

Clearview is a US firm with no EU office. France, Italy, Greece, and the UK fined it between 2021 and 2022. The total ran past €60 million. The charge was scraping and processing EU residents' data. Clearview argued GDPR did not reach it. Every regulator disagreed. "We are American" is not a defense.

Your real risk is not a €20M fine on day one. It runs like this. Someone complains to a data protection authority. The authority asks questions. You cannot answer, because you have no LIA and no sourcing records. A corrective order follows. Worse, an EU buyer's procurement team kills your deal during the DPA review. The European Data Protection Board posts guidance and decisions if you want to watch the trend.

Compliance also sells. A European legal team asks how you got their CTO's email. You show the source, the date, the lawful basis, and the opt-out log in ten minutes. Friction turns into a trust signal.

Where should you start this week?#

Three steps, in order.

  1. Audit your campaigns. Does any of them target people in the EU? Check contact country in your CRM, not company HQ.
  2. If yes, split that list by country. Pause Germany, Italy, and Austria for email.
  3. Write one legitimate interest assessment for your main outbound motion. Add a two-line source note to your first-touch template.

Then fix the data layer, because everything above rests on it. If you cannot say where a contact came from, no policy document saves you.

So, does GDPR apply to US companies like yours? If you sell into Europe, assume yes, and build the paper trail. The Tomba Email Finder handles that layer. It finds work addresses by domain, name, or company. It verifies them before they hit your sequencer. It logs where each record came from. Your Article 14 notice becomes something you can write, not something you hope nobody asks about. Start on the free tier, run one country-split EU campaign with the full trail, and see if compliant outbound costs you any replies. Most teams find it does not.

Start your free trial

Ready to find emails that actually work?

Join 150,000+ professionals who stopped guessing and started sending. Free credits on signup — no credit card required.

Get the Tomba newsletter

Practical outbound tactics and product updates — once every two weeks.

Share
0 clapsEnjoyed it? Give a clap.
AU

About the author

Tomba Editorial Team

Was this helpful?

Start finding verified emails today

Join 150,000+ professionals who trust Tomba for accurate contact data. No credit card required.