The short answer
The General Data Protection Regulation applies to US companies that process personal data of individuals in the European Union, regardless of where the company is located. This article explains the territorial scope, core obligations, leadership accountability and practical steps for compliance.
The General Data Protection Regulation (GDPR) imposes binding obligations on US companies that process personal data of individuals in the European Union, even when those companies have no physical presence in Europe. The regulation applies based on data subjects' location and the nature of processing activities, not corporate domicile. Leadership must determine whether the organization falls within scope, assign clear accountability for compliance, and establish governance adequate to the regulation's substantive requirements.
1When GDPR Applies to US Organizations
GDPR applies extraterritorially to any organization that offers goods or services to individuals in the EU or monitors their behavior, regardless of whether the organization has a European establishment. A US company triggers GDPR obligations when it targets EU residents through websites in European languages, accepts payment in euros, serves EU-based customers, employs workers located in the EU, or tracks EU residents' online activity for profiling or behavioral analysis.
The regulation does not require a physical office, subsidiary or revenue threshold. Processing personal data of a single EU resident in the course of offering services or monitoring behavior brings the organization within scope. Personal data is defined broadly to include any information relating to an identified or identifiable individual, including names, email addresses, IP addresses, location data and online identifiers.
2Core Obligations Under GDPR
Organizations subject to GDPR must establish a lawful basis for each processing activity, implement technical and organizational measures appropriate to the risk, maintain detailed records of processing activities, conduct data protection impact assessments for high-risk processing, report certain personal data breaches to supervisory authorities within 72 hours, and honor individual rights including access, rectification, erasure and data portability.
Controllers must appoint a data protection officer when core activities consist of processing requiring regular and systematic monitoring of individuals on a large scale or processing special categories of data on a large scale. The regulation imposes obligations on both controllers, who determine the purposes and means of processing, and processors, who process data on behalf of controllers. US companies engaging third-party service providers must execute compliant data processing agreements.
Transfers of personal data from the EU to the United States require an adequacy mechanism. Following the invalidation of Privacy Shield and subsequent legal challenges, organizations rely on standard contractual clauses supplemented by additional safeguards, binding corporate rules for intra-group transfers, or specific derogations for particular situations. The legal framework governing transatlantic data flows has evolved through successive court decisions and regulatory guidance.
3Enforcement and Material Consequences
European supervisory authorities can impose administrative fines up to €20 million or 4% of annual worldwide turnover, whichever is higher, for the most serious infringements. Fines up to €10 million or 2% of turnover apply to certain other violations. Enforcement actions against US technology companies have resulted in fines exceeding €1 billion in individual cases. Beyond financial penalties, supervisory authorities may issue warnings, reprimands, temporary or permanent processing bans, and orders to suspend data flows to third countries.
Individuals have the right to lodge complaints with supervisory authorities and to seek judicial remedies. The regulation establishes a right to compensation for material or non-material damage resulting from GDPR violations. US companies defending cross-border enforcement actions face procedural complexity, extended timelines and reputational exposure in addition to potential penalties.
4Leadership Accountability and Governance
GDPR compliance is fundamentally a governance challenge requiring executive ownership, not solely a technology or legal project. The regulation's accountability principle requires organizations to demonstrate compliance through documented policies, procedures, training, vendor management, breach response capabilities and regular review. Compliance cannot be delegated to technical staff alone. General counsel, compliance officers and executive leadership must establish who is accountable for risk decisions, regulatory positions and ongoing governance.
Many US companies lack clarity on which executive owns GDPR risk. Privacy may fall between legal, information security, compliance, operations and product teams without a single point of executive accountability. This fragmentation creates gaps in risk assessment, delayed breach notification, inconsistent vendor oversight and poorly documented transfer mechanisms. Effective governance requires a designated executive who can make binding decisions on data processing, assess third-party risk, authorize controls and represent the organization's position to regulators.
For organizations without a chief information security officer or data protection officer, virtual CISO leadership provides the executive-level accountability necessary to establish defensible governance. A vCISO brings strategic oversight, regulatory interpretation, documented decision-making and board-level reporting to organizations that need governance maturity without expanding permanent headcount. This model aligns particularly well with growing US companies that trigger GDPR obligations through European expansion but lack dedicated privacy infrastructure.
5Practical Steps Toward Compliance
Leadership should begin with a documented assessment of whether the organization processes personal data of EU residents and, if so, in what capacity. Map data flows to identify what personal data is collected, from whom, for what purpose, where it is stored, who has access, how long it is retained, and with whom it is shared. This mapping exercise typically reveals processing activities leadership was unaware of, particularly in marketing technology, analytics platforms and third-party integrations.
Establish and document a lawful basis for each processing activity. Review and revise privacy notices to meet GDPR's transparency requirements. Implement processes to honor individual rights requests within required timeframes. Assess whether a data protection officer appointment is mandatory and, if so, designate a qualified individual with appropriate independence and resources. Inventory all vendors that process personal data and confirm that compliant data processing agreements are in place.
Evaluate cross-border data transfers and implement valid transfer mechanisms. Build incident response capabilities to detect, assess, contain and report personal data breaches within regulatory deadlines. Establish a governance rhythm with defined ownership, regular review and board-level reporting. Document everything. The regulation's accountability principle makes documentation a substantive compliance requirement, not an administrative formality.
6How This Relates to Regulatory and Framework Readiness
GDPR is one element within a broader landscape of privacy and security regulations affecting US companies. Organizations processing health information face HIPAA obligations, those handling payment card data must comply with PCI DSS, and companies across sectors increasingly navigate state privacy laws modeled partly on GDPR. Regulatory readiness means building governance structures that address multiple frameworks through integrated controls rather than treating each regulation as an isolated project.
The skills and governance required for GDPR readiness translate directly to other regulatory domains. A documented approach to data mapping supports both GDPR and the California Consumer Privacy Act. Breach notification procedures developed for GDPR align substantively with requirements under state breach notification laws. Vendor risk assessments conducted for GDPR provide a foundation for broader third-party risk management. Building regulatory readiness as a capability, rather than achieving compliance as a one-time milestone, positions the organization to adapt as the regulatory environment evolves.
7Next Steps for Leadership
Executive leadership should designate a single accountable owner for GDPR governance and data protection risk. This individual must have authority to make binding decisions on processing activities, access to relevant business units, and a direct reporting line to general counsel or the chief executive. Without clear executive ownership, compliance efforts fragment across departments and critical gaps persist.
Commission a documented assessment of current processing activities, lawful bases, transfer mechanisms and control gaps. This assessment should identify specific risks, assign remediation owners and establish a prioritized timeline. For organizations that have triggered GDPR obligations but lack dedicated privacy leadership, consider whether a fractional or virtual CISO engagement would provide the necessary governance without permanent headcount expansion.
If your organization processes EU residents' data and current accountability for GDPR compliance is unclear or distributed across multiple roles without executive synthesis, a confidential consultation can clarify your regulatory position, governance gaps and practical options. Heights Consulting Group provides virtual CISO leadership to establish the executive ownership, documented decision-making and regulatory readiness that boards and general counsel require. To discuss your situation in confidence, contact Heights Consulting Group directly through the firm's website.
Related service: Regulatory and Framework Readiness
Readiness for the frameworks and regulations that genuinely apply to you, NIST CSF, ISO 27001, SOC 2, CMMC, HIPAA, PCI DSS and SOX-related IT controls, with the evidence maintained between assessments.