GDPR

When the GDPR Reaches a US Company, and What It Requires Once It Does

Key Takeaways

  • Article 3 applies the GDPR to companies outside the EU that offer goods or services to, or monitor the behaviour of, people in the Union
  • Every processing operation needs one of six lawful bases; consent is one option among several, not the default
  • Controllers face a 72-hour deadline to notify a supervisory authority of a personal data breach
  • Companies caught by Article 3(2) generally have to designate a representative in the Union under Article 27
  • The upper fine tier reaches 20 million euro or 4 percent of total worldwide annual turnover, whichever is higher

When the GDPR Reaches a US Company

Article 3 sets territorial scope, and it does so in two ways. Article 3(1) applies the Regulation to processing in the context of the activities of an establishment of a controller or processor in the Union, regardless of where the processing itself occurs. Establishment is read functionally rather than formally: it turns on stable arrangements and effective, real exercise of activity, not on whether a subsidiary was incorporated.

Article 3(2) is the provision that reaches companies with no European presence at all. It applies where processing relates to data subjects in the Union and concerns either the offering of goods or services to them, whether or not payment is required, or the monitoring of their behaviour as far as that behaviour takes place within the Union.

Neither trigger depends on the data subject's nationality or residence. What matters is that the person is in the Union at the relevant time. Recital 23 makes clear that mere accessibility of a website is not enough for the offering limb; there must be evidence of an intention to offer, such as use of a language or currency of a member state, mention of European customers, or the ability to order in a European language. The monitoring limb has been read broadly, covering behavioural advertising, profiling and tracking of online activity.

Controller and Processor Roles

The Regulation allocates obligations by role. A controller determines the purposes and means of processing. A processor processes on the controller's behalf. The distinction is factual rather than contractual: a party that decides why data is processed is a controller whatever the agreement calls it.

Article 28 requires a written contract between controller and processor containing prescribed terms: the subject matter and duration, the nature and purpose, the types of data and categories of data subject, and specific processor obligations covering confidentiality, security, sub-processor engagement, assistance with data subject rights, breach notification, deletion or return at the end of the relationship, and making information available for audits.

Processors carry direct obligations of their own under the Regulation, including security under Article 32 and records of processing under Article 30. Joint controllership under Article 26 arises where two parties jointly determine purposes and means, and requires an arrangement setting out their respective responsibilities.

The Six Lawful Bases

Article 6 requires at least one lawful basis for every processing operation. They are alternatives of equal standing; consent carries no priority.

  • Consent. Freely given, specific, informed and unambiguous, by a statement or clear affirmative action. Withdrawable at any time, and as easy to withdraw as to give
  • Contract. Necessary for performance of a contract with the data subject, or to take steps at their request before entering one
  • Legal obligation. Necessary for compliance with a legal obligation of the controller under Union or member state law
  • Vital interests. Necessary to protect the vital interests of the data subject or another person
  • Public task. Necessary for a task carried out in the public interest or in the exercise of official authority
  • Legitimate interests. Necessary for legitimate interests of the controller or a third party, except where overridden by the interests or fundamental rights of the data subject

Legitimate interests requires a documented balancing exercise weighing the interest pursued, the necessity of the processing, and the impact on the data subject. It is unavailable to public authorities acting in performance of their tasks.

Article 9 adds a separate layer for special categories: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic and biometric data processed for identification, health data, and data concerning sex life or sexual orientation. Processing is prohibited unless one of the Article 9(2) conditions applies, and an Article 6 basis is still needed alongside it.

Data Subject Rights

Chapter III gives data subjects a set of rights exercisable against the controller. Responses are due without undue delay and in any event within one month of receipt, extendable by two further months where necessary given complexity and number of requests, provided the data subject is informed within the first month.

RightArticleNote
Information13, 14Owed proactively at collection, not on request
Access15Confirmation, a copy of the data, and prescribed contextual information
Rectification16Correction of inaccurate data, completion of incomplete data
Erasure17Available on enumerated grounds; not unconditional
Restriction18Processing paused rather than deleted, in defined circumstances
Portability20Applies where processing rests on consent or contract and is automated
Object21Absolute for direct marketing; balanced elsewhere
Automated decisions22Right not to be subject to solely automated decisions with legal or similarly significant effects

Information can generally not be charged for. A controller may charge a reasonable fee or refuse to act where requests are manifestly unfounded or excessive, and bears the burden of showing that character.

Transfers Out of the EEA

Chapter V restricts transfers of personal data to third countries. Article 45 permits transfers to a country the Commission has found to provide an adequate level of protection. Article 46 permits transfers subject to appropriate safeguards, of which standard contractual clauses adopted by the Commission and binding corporate rules are the most used. Article 49 provides derogations for specific situations, which the EDPB has consistently read as exceptions for occasional and non-repetitive transfers rather than a routine route.

Following Schrems II, reliance on Article 46 safeguards carries an accompanying obligation to assess whether the law and practice of the destination country undermines those safeguards, and to adopt supplementary measures where it does. For US recipients, the EU-US Data Privacy Framework provides an adequacy route for organizations that self-certify and remain on the list.

Representatives and Data Protection Officers

These are separate requirements and are frequently conflated. Article 27 requires a controller or processor caught by Article 3(2) to designate in writing a representative established in a member state where the relevant data subjects are, to act as the addressee for supervisory authorities and data subjects. Narrow exemptions apply for occasional processing that is low risk and does not involve special category data at scale.

Article 37 requires a data protection officer in three cases: where processing is carried out by a public authority or body; where the core activities consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale; or where the core activities consist of large-scale processing of special category data or data relating to criminal convictions. A DPO must be appointed on the basis of professional qualities and expert knowledge, must report to the highest management level, and cannot be dismissed or penalised for performing the role.

Breach Notification

Article 33 requires a controller to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Notification made later than 72 hours must be accompanied by reasons for the delay.

Article 34 adds notification to affected data subjects, without undue delay, where the breach is likely to result in a high risk to their rights and freedoms. Exceptions apply where the data was rendered unintelligible, such as by encryption, where subsequent measures ensure the high risk is no longer likely to materialise, or where individual notification would involve disproportionate effort, in which case a public communication is required instead.

Processors have a separate duty: notify the controller without undue delay after becoming aware. The 72-hour clock runs against the controller.

Accountability and Records

Article 5(2) makes the controller responsible for, and required to be able to demonstrate compliance with, the principles in Article 5(1). That is the accountability principle, and it converts several obligations from matters of substance into matters of documented substance: doing the right thing without a record of having done it does not discharge it.

Article 30 requires controllers and processors to maintain records of processing activities in writing, including electronic form, and to make them available to a supervisory authority on request. Controller records cover the purposes of processing, categories of data subjects and personal data, categories of recipients including those in third countries, transfers and their safeguards, retention periods where possible, and a general description of security measures. Processor records are narrower, covering the categories of processing carried out for each controller.

The Article 30(5) derogation for organisations with fewer than 250 employees is far narrower than its headline suggests. It falls away where processing is likely to result in a risk to rights and freedoms, where processing is not occasional, or where it includes special category data or data relating to criminal convictions. Ordinary employee or customer data processing is not occasional, so most organisations relying on the exemption do not qualify for it.

Article 24 requires technical and organisational measures appropriate to the risk, reviewed and updated where necessary, and Article 25 requires data protection by design and by default, meaning that only personal data necessary for each specific purpose is processed by default, without the data subject having to intervene.

Data Protection Impact Assessments

Article 35 requires a data protection impact assessment before processing that is likely to result in a high risk to the rights and freedoms of natural persons, taking account of the nature, scope, context and purposes of the processing. The Regulation identifies three cases in particular: systematic and extensive evaluation of personal aspects based on automated processing including profiling, where decisions produce legal or similarly significant effects; processing of special category data on a large scale; and systematic monitoring of a publicly accessible area on a large scale.

Supervisory authorities publish lists of processing operations requiring an assessment, and those lists differ between member states, so an organisation operating across several may face different triggers in each. The assessment itself has prescribed content: a systematic description of the operations and purposes, an assessment of necessity and proportionality, an assessment of risks to data subjects, and the measures envisaged to address those risks.

Where an assessment indicates high residual risk that the controller cannot mitigate, Article 36 requires prior consultation with the supervisory authority before processing begins. The authority may give written advice and may exercise its corrective powers, including a ban on the processing.

Fine Structure and Enforcement

Article 83 sets two tiers. The lower tier reaches 10 million euro or 2 percent of total worldwide annual turnover of the preceding financial year, whichever is higher, and covers obligations such as records, security and DPO requirements. The upper tier reaches 20 million euro or 4 percent on the same basis, and covers the basic principles including lawful basis and consent conditions, data subject rights, and transfer rules.

Turnover is measured against the undertaking rather than the legal entity, which in group structures can produce a figure far larger than the revenue of the entity that carried out the processing. Article 83(2) lists the factors bearing on whether to impose a fine and its amount, including the nature and gravity of the infringement, intent or negligence, mitigation, and cooperation with the authority.

Enforcement runs through national supervisory authorities. Where processing is cross-border, the one-stop-shop mechanism designates a lead authority, with the consistency mechanism and the European Data Protection Board resolving disagreement between concerned authorities. That structure means the identity of the lead authority can materially affect how a case proceeds.

Fines are also not the only, or always the most consequential, outcome. Article 58 gives supervisory authorities corrective powers including warnings, reprimands, orders to bring processing into compliance, orders to comply with data subject requests, and a temporary or definitive limitation including a ban on processing. An order to stop a processing operation can affect a business more than a monetary penalty, since it reaches the activity itself rather than the balance sheet. Authorities may also order the suspension of data flows to a recipient in a third country.

Article 82 adds a separate route: any person who has suffered material or non-material damage as a result of an infringement has a right to compensation from the controller or processor. Non-material damage has been the subject of significant litigation, with the Court of Justice holding that a mere infringement does not by itself give rise to compensation, while also declining to impose a threshold of seriousness on damage that is established.

Background

For the underlying law rather than this development: Technology & SaaS privacy law.

Frequently Asked Questions

Does the GDPR apply to a US company with no European entity?
It can, under Article 3(2), where the company offers goods or services to people in the Union or monitors their behaviour there. Neither limb requires an establishment, a European entity or European staff. Mere accessibility of a website is not sufficient for the offering limb; evidence of an intention to offer is needed.
Is consent required for every processing operation under the GDPR?
No. Consent is one of six lawful bases in Article 6 and carries no priority over the others. Contract, legal obligation, vital interests, public task and legitimate interests are equally available, and the appropriate basis depends on the purpose of the processing.
What is the difference between an Article 27 representative and a DPO?
A representative is a point of contact in the Union required of controllers and processors caught by Article 3(2). A DPO is an internal advisory and monitoring role required under Article 37 in three defined cases, regardless of where the organisation sits. They are separate requirements and one does not satisfy the other.
When does the 72-hour breach clock start?
On the controller becoming aware of the personal data breach. Processors notify the controller without undue delay; the 72-hour deadline runs against the controller, and a later notification requires reasons for the delay.
How is a GDPR fine calculated against turnover?
The percentage tiers are applied to total worldwide annual turnover of the preceding financial year, measured against the undertaking rather than the individual legal entity. In group structures this can produce a maximum far above the revenue of the entity that carried out the processing.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.