Does GDPR Apply to US Companies? A 2026 Compliance Guide
GDPR doesn't stop at the EU border. If you sell into Europe, target EU-based buyers, or process EU personal data, the regulation reaches your US business. Here is exactly when it applies, when it doesn't, and how to keep outbound running.

TL;DR — does GDPR apply to US companies? Yes, in three cases.
- You offer goods or services to people in the EU or EEA.
- You track what those people do online.
- You handle EU personal data on behalf of someone else.
No EU office is needed. What you do matters. Where you sit does not.
- Cold B2B email counts as processing.
firstname.lastname@company.comis personal data. So isinfo@when one person owns the box. - Most legal EU outbound runs on legitimate interest (Article 6(1)(f)), not consent. You still need a written balancing test and a working opt-out.
- The ePrivacy Directive sits on top of GDPR. Germany and Italy want consent first, even for B2B. The UK and Ireland allow legitimate interest.
- Fines stop at €20 million or 4% of global turnover, whichever is higher. Regulators have chased non-EU firms since the 2021 Clearview AI rulings.
Does GDPR apply to US companies in your case? This guide walks you through it. It is written for revenue teams, not lawyers. You will see when the rule reaches you, what changes in your prospecting, and where the lines sit. It is not legal advice. Talk to counsel before you set policy.
Does GDPR apply to US companies at all?#
Yes. The trigger is behavior, not geography.
Think of it like a state sales-tax rule. You do not need a store in the state. You just need to sell into it. GDPR works the same way. Article 3 puts that reach in writing.
Two things pull you in under Article 3(2):
- You offer goods or services to people in the EU. Paid or free, both count. Prices in euros, a
.delanding page, EU ads, or an SDR sequence aimed at Berlin all show intent. - You track how people in the EU behave. That covers analytics cookies, retargeting pixels, session recording, intent scores, and visitor ID tools.
Article 3(1) is a separate case. Do you have an "establishment" in the EU? A branch, a sales office, sometimes one employee is enough. Then the rule covers that work, wherever your buyers live.
Here is what most US teams miss. GDPR protects people located in the EU, not EU citizens. A German who lives in Austin is usually out of scope. An American who works in Amsterdam is in it. What counts is where the person is at the time. Read the source text on gdpr.eu if you want the wording.
When does GDPR not apply to a US business?#
There is a real exemption. It is narrow.
Recital 23 is the one to know. A website Europeans can reach is not enough on its own. Say you sell in dollars. Your content targets US buyers. You run no EU-language pages. You do not ship to Europe. A German visitor lands from a Google search. That alone creates no duty.
So does GDPR apply to US companies that never aim at Europe? Often not, if all of this holds:
- No EU targeting signals. No euro prices, EU languages, country domains, EU phone numbers, or EU shipping.
- No EU-directed marketing. No ads aimed at EU countries, no EU trade shows, no EU lists.
- No tracking of EU visitors. No pixels or profiling on European traffic.
- No EU customer data in your systems. That includes data an EU client hands you to process.
- No EU establishment. No entity, office, or staff on the ground.
Here is the trap. Most B2B firms fail this test the day one rep imports a list with @sap.com on it. Scope is not a company-wide switch. It attaches to each activity. One EU campaign is enough.
How does GDPR compare to US privacy laws?#
The two systems start from different places. GDPR is opt-in, and you need a lawful basis first. US law is mostly opt-out, with rules by sector. Here is how the frameworks that touch B2B outbound line up.
| Attribute | GDPR (EU/EEA) | UK GDPR + PECR | CCPA/CPRA (California) | CAN-SPAM (US federal) |
|---|---|---|---|---|
| Applies to US company without local office | Yes, via Art. 3(2) targeting/monitoring | Yes, same extraterritorial test | Yes, if thresholds met (>$26.6M revenue or 100k+ consumers) | Yes, all commercial email |
| Covers B2B work emails | Yes — personal data if it identifies a person | Yes | Yes (B2B exemption expired Jan 2023) | Yes |
| Lawful basis needed before contact | Yes — consent or legitimate interest | Yes; PECR allows B2B soft opt-in | No basis required; opt-out model | No basis required |
| Prior consent for cold B2B email | Country-dependent (DE/IT effectively yes) | No, for corporate subscribers | No | No |
| Right to access / deletion | Yes, 30-day response window | Yes, 30 days | Yes, 45 days | No |
| Data subject notification at first contact | Yes — Art. 14, within 30 days | Yes | Notice at collection | Sender ID + physical address |
| Max penalty | €20M or 4% global turnover | £17.5M or 4% | $7,988 per intentional violation | $53,088 per email |
| Opt-out honoring window | Without undue delay | Without undue delay | 15 business days | 10 business days |
The short version: CAN-SPAM lets you email first and drop people later. GDPR asks you to justify the send first. You also have to say where you got the address. That paperwork is the real change, not the fines.
What counts as personal data in B2B prospecting?#
More than you think. That is why "we only do B2B" is not a defense.
Does GDPR apply to US companies that only email work addresses? Yes. Under Article 4(1), personal data is any data that points to a person you can name. In a normal prospecting stack:
- Named work emails are personal data.
maria.rossi@acme.itpoints to Maria Rossi. Every EU regulator agrees on this one. - Role accounts usually are not.
sales@acme.it,info@acme.it, andsupport@acme.itsit outside, unless one person clearly owns the box. - Extra fields inherit the status. Job title, LinkedIn URL, direct dial, company size, and tech stack all count once tied to a name.
- IP addresses and device IDs count. The CJEU settled that in Breyer in 2016. Visitor ID tools need their own basis for EU traffic.
- Guesses count too. An intent score or a persona label about a named person is personal data. You must explain it and delete it on request.
So your tools matter as much as your list. A vendor that shows where each record came from lets you write the Article 14 notice. One that hands you a raw CSV does not. Tomba publishes its data sources for that reason. Provenance is what turns a list into a record you can defend.
Can US companies cold email EU prospects legally?#
Yes, in most member states. You run it on legitimate interest, and you keep the paperwork.
Does GDPR apply to US companies sending cold email into the EU? It does, and you can still send. Recital 47 says direct marketing may count as a legitimate interest. That is your basis. It is not automatic. You need a written Legitimate Interest Assessment (LIA) with three parts:
- Purpose test. Why is this outreach a real business need? "More sales" is weak. "Reaching IT leads at logistics firms about a compliance tool they likely need" holds up.
- Necessity test. Is email the lightest way to get there? Note why an ad campaign would not do the same job.
- Balancing test. Do the person's rights outweigh your interest? A VP of Engineering, at work, about an engineering tool: low intrusion. A nurse, on a personal Gmail, about crypto: fails.
Then add the ePrivacy Directive. It governs the channel, not the data. This is where the map splits by country.
| Country | Cold B2B email without prior consent | Notes for US senders |
|---|---|---|
| United Kingdom | Allowed | PECR permits corporate-subscriber marketing; opt-out required |
| Ireland | Allowed | Corporate subscribers exempt from consent rule |
| Netherlands | Allowed | B2B permitted with clear opt-out |
| France | Allowed | CNIL permits B2B if message relates to the recipient's role |
| Spain | Allowed | LSSI permits with relevance and opt-out |
| Germany | Effectively no | UWG requires prior consent; competitor lawsuits are common |
| Italy | Effectively no | Garante applies strict consent expectations |
| Austria | Effectively no | Consent expected under TKG |
The UK ICO's direct marketing guidance explains the split in plain English. The lesson for you is simple. Split your EU list by country. That step is the line between a clean campaign and a German cease-and-desist letter.
What does a compliant US-to-EU outbound workflow look like?#
Does GDPR apply to US companies that run these six controls? Yes, and none of them stop you from selling. All of them survive an audit.
1. Source data you can trace. For every record, answer one question: where did this come from? Article 14(2)(f) makes that a duty when the person did not hand you the data. A scraped list with no origin fails on the spot. Tools with clear sourcing and a real email verifier step give you a chain you can show.
2. Verify before you send. Dead addresses raise bounce rates and hurt your sender reputation. They also mean you hold wrong data, which breaks the accuracy rule in Article 5(1)(d). Verification is a control, not just a deliverability trick.
3. Put the Article 14 notice in your first email. One or two lines. Who you are. What data you hold. Where you got it. Why you wrote. A link to your privacy policy. It costs you nothing in replies. It often helps, because it shows you are not spraying.
4. Make opt-out instant and honored. Use one-click unsubscribe, plus a suppression list shared by every sending tool. The standard is "without undue delay". Treat that as same-day. Keep the record forever, so you can prove you honored it.
5. Run the LIA and file it. One doc per campaign type, reviewed each quarter. Two pages is plenty. If a regulator asks, "we thought about it" is worth nothing. A dated PDF is gold.
6. Answer DSARs within 30 days. Access, fix, delete, and object requests all start a 30-day clock. An objection to marketing is absolute. You stop, with no balancing. Route these to a shared inbox, not to the rep who got the reply.
Which tools help US teams stay in scope?#
Provenance and process beat feature count. Here is how the options compare for a US team selling into Europe.
| Requirement | Scraper / bought list | General B2B database | Sourced email finder (e.g. Tomba) |
|---|---|---|---|
| Documented data origin | No | Partial | Yes — published sourcing |
| Verification before send | Rarely | Sometimes | Yes, built in |
| Deletion / suppression support | No | Varies | Yes, via API and dashboard |
| Role vs. named email distinction | No | Sometimes | Yes |
| Entry price | Cheap or free | $99–$500/mo | Free tier, then $49/mo |
| Audit trail for Art. 14 notice | None | Limited | Yes |
Peers worth a look include BookYourData. It sells verified B2B contact data, bills pay-as-you-go, and publishes its accuracy numbers. That fits if you would rather buy a list than build one. Check vendor claims on G2 as well. Do not take one blog's word for it, this one included.
For a US team, the practical setup is simple. Build lists by country segment. Verify every address. Keep the sourcing records. Skip Germany, Italy, and Austria for cold email, and use LinkedIn or paid ads there. Tomba's pricing starts free at 25 searches a month, then moves to $49/mo on Starter. That is enough to test a country-split approach before you commit budget.
What happens if you ignore it?#
Does GDPR apply to US companies in practice, or only on paper? Ask Clearview AI.
Clearview is a US firm with no EU office. France, Italy, Greece, and the UK fined it between 2021 and 2022. The total ran past €60 million. The charge was scraping and processing EU residents' data. Clearview argued GDPR did not reach it. Every regulator disagreed. "We are American" is not a defense.
Your real risk is not a €20M fine on day one. It runs like this. Someone complains to a data protection authority. The authority asks questions. You cannot answer, because you have no LIA and no sourcing records. A corrective order follows. Worse, an EU buyer's procurement team kills your deal during the DPA review. The European Data Protection Board posts guidance and decisions if you want to watch the trend.
Compliance also sells. A European legal team asks how you got their CTO's email. You show the source, the date, the lawful basis, and the opt-out log in ten minutes. Friction turns into a trust signal.
Where should you start this week?#
Three steps, in order.
- Audit your campaigns. Does any of them target people in the EU? Check contact country in your CRM, not company HQ.
- If yes, split that list by country. Pause Germany, Italy, and Austria for email.
- Write one legitimate interest assessment for your main outbound motion. Add a two-line source note to your first-touch template.
Then fix the data layer, because everything above rests on it. If you cannot say where a contact came from, no policy document saves you.
So, does GDPR apply to US companies like yours? If you sell into Europe, assume yes, and build the paper trail. The Tomba Email Finder handles that layer. It finds work addresses by domain, name, or company. It verifies them before they hit your sequencer. It logs where each record came from. Your Article 14 notice becomes something you can write, not something you hope nobody asks about. Start on the free tier, run one country-split EU campaign with the full trail, and see if compliant outbound costs you any replies. Most teams find it does not.
Related guides#
Ready to find emails that actually work?
Join 150,000+ professionals who stopped guessing and started sending. Free credits on signup — no credit card required.
Get the Tomba newsletter
Practical outbound tactics and product updates — once every two weeks.
About the author