Does GDPR apply to a US company with EU employees or customers?

GDPR applies to a US company in two ways under Article 3: when it processes personal data in the context of an EU establishment, such as a subsidiary or branch, or when it offers goods or services to people in the EU or monitors their behavior there. A US-only business with no EU presence or targeting is generally outside it.

The short answer: establishment and targeting decide it

GDPR does not follow a company's nationality. It follows where the company operates and whose personal data it handles. Under Article 3 of the General Data Protection Regulation, a US company is covered for processing carried out in the context of an EU establishment, and for processing linked to offering goods or services to people in the EU or monitoring their behavior there.

Illustrative examples: a Texas freight broker with a subsidiary in Rotterdam is inside the regulation for that subsidiary's activities. A Colorado software firm, by contrast, that sells only to US customers, has no EU office and runs no EU-directed marketing is generally outside it, even if some European visitors reach its website.

For an owner weighing a data license, the useful question is narrower: which systems hold personal data about people in the EU or the UK, and can that slice be excluded or anonymized before a scope is agreed? Usually it can, and the US operational records continue through the normal review.

What Article 3 actually says

Article 3 sets the territorial reach in three paragraphs. Paraphrased from the official text:

  1. Establishment, Article 3(1). The regulation applies to processing of personal data in the context of the activities of an establishment of a controller or processor in the EU, whether or not the processing itself takes place in the EU.
  2. Targeting and monitoring, Article 3(2). It applies to a controller or processor not established in the EU when it processes personal data of people who are in the EU and the processing relates to (a) offering them goods or services, whether or not payment is required, or (b) monitoring their behavior, as far as that behavior takes place within the EU.
  3. Public international law, Article 3(3). It applies where member state law applies by virtue of public international law. This rarely matters for a private US business.

Two recitals do much of the interpretive work. Recital 23 says the mere accessibility of a website, an email address or other contact details in the EU is not enough to show an intention to offer goods or services there, while factors such as an EU language or currency with the option to order in it, or references to customers in the EU, can show it. Recital 24 ties monitoring to tracking people on the internet, including profiling used to analyze or predict their preferences, behaviors and attitudes.

A company caught by Article 3(2) generally also has to designate a representative in the EU under Article 27, with narrow exceptions for occasional, lower-risk processing.

Does GDPR apply if you have EU employees?

Often yes, but the route matters. Employee files, payroll, email and chat are personal data, and the answer turns on how those people are engaged.

  • Staff employed by an EU subsidiary or branch. Processing in the context of that entity's activities falls under Article 3(1). This is the clearest case, and it covers the entity's HR system, mailboxes and chat workspaces.
  • Remote individuals hired directly by the US company, with no EU entity. Whether one or a few remote workers amount to an establishment, or bring their records within Article 3(2), is fact-specific. Counsel will look at how stable the arrangement is, what the person does and how they are managed. Employer-of-record arrangements add another party with its own role.
  • US-based staff travelling in the EU. Short trips raise fewer questions, but tracking those employees while they are in the EU, such as device location, is monitoring behavior that takes place in the EU and is worth raising with counsel.

The page on whether employers can use employee emails to train AI covers the US side of employee records; colleagues in Europe whose messages sit in the same archive are a separate GDPR question.

Does GDPR apply if you have EU customers?

It can, through Article 3(2)(a), when the company intends to offer goods or services to people in the EU. A US distributor that ships to Lyon from a French-language storefront priced in euros is targeting the EU. A US engineering consultancy that occasionally serves a European client who found it unprompted is a much weaker case.

Selling business to business does not take a company outside the regulation. Names, work email addresses and call notes about identifiable contacts at European customers are personal data.

Common situations and what to check

SituationWhat to checkTypical outcome to confirm with counsel
EU subsidiary or branch with its own staffWhich systems the EU entity uses and whether the US parent shares themGDPR applies to the entity's processing; its records need separate handling
A few remote employees in the EU, no local entityEmployment contracts, employer-of-record terms, how work is directedFact-specific; often treated cautiously as in scope
EU-language storefront, euro pricing, EU shippingSite localization, checkout settings, orders by countryTargeting under Article 3(2)(a) is likely
Analytics, ad pixels or app tracking of EU visitorsTag manager, consent tool, ad audiences by regionMonitoring under Article 3(2)(b) may apply to that data
Occasional EU clients who found the company on their ownShare of revenue, any EU-directed sales activityWeaker case for targeting; document the facts
US-only staff and customers, no EU marketingConfirm no EU entity and no EU-directed trackingGenerally outside Article 3; US privacy laws still apply

What this means for a data licensing scope

GDPR scope and licensing scope are separate questions, but they meet in the archive. A mostly US company can still hold EU personal data in its CRM (European contacts), help desk (tickets from EU users), email (threads with European partners) or HR system (EU staff).

The cleanest approach is to deal with that slice before the scope is set:

  1. Map where EU and UK records sit. List the systems first, then the fields, queues or folders that hold data about people in Europe: country fields in the CRM, EU support queues, the EU entity's mailboxes.
  2. Choose carve-out or anonymization. Carving out is usually simpler: leave the EU entity's systems, EU accounts and EU queues out of the dataset. UK records raise parallel questions under UK data protection law, so treat them the same way unless counsel says otherwise.
  3. Know the anonymization bar. Recital 26 says the regulation does not apply to anonymous information, but pseudonymized data that could be attributed to a person with additional information is still personal data. Replacing names with tokens is not enough on its own.
  4. Write the rules down before work starts. SourceX settles de-identification and redaction requirements with the company up front, and delivery happens only under a signed agreement the company has authorized.
  5. Run the US records through the normal review. US-only operational records still go through the usual checks on ownership, client contracts, employee notices and state privacy law.

Transfers matter as well. Chapter V of the regulation restricts transfers of personal data to countries outside the EU unless one of its transfer mechanisms applies, so records held by an EU subsidiary should not be pulled into a US dataset without counsel's sign-off.

The how it works page shows where the data inventory and rights review sit in the process, and PE teams can use the portfolio company data monetization legal checklist to put GDPR alongside the other legal checks.

A five-question EU exposure screen

  • Does the company have an EU or UK subsidiary, branch, office or employees?
  • Has it marketed to people in the EU in an EU language or currency, or shipped goods to them?
  • Does it track EU website or app users through analytics, pixels or profiling?
  • Which systems hold data about people in the EU or UK, and can that data be filtered by country, entity or queue?
  • Can someone at the company run filtered exports that leave that data out?

If the first three answers are no, GDPR is less likely to reach the archive at all. The last two questions still tell you how easily any European records can be left out. If any of the first three is yes, bring in privacy counsel before the data inventory starts.

Questions to ask your counsel

The stakes justify the call: Article 83 allows fines of up to 20 million euros or 4% of total worldwide annual turnover, whichever is higher, for the most serious infringements.

  • Do we have an EU establishment for Article 3(1) purposes, and which processing happens in its context?
  • Does any of our processing fall under Article 3(2), and do we need an Article 27 representative?
  • Which systems should be excluded or anonymized for a licensing scope, and to what standard?
  • Do our privacy notices or employee notices promise anything that limits new uses of the data? The page on privacy policies that say 'we do not sell data' covers how US promises are read.
  • How should UK personal data be treated alongside EU data?

This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.

Next step

Owners can run a preliminary, non-binding screen with the company fit checker and then apply at sourcex.si/apply. If you advise US companies with deep operational records, register as a partner and make the introduction; SourceX handles qualification, the data inventory and the rights review with the company.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Does a website that EU visitors can reach bring a US company under GDPR?

Not by itself. Recital 23 of the regulation says the mere accessibility of a website, email address or contact details in the EU is not enough to show an intention to offer goods or services there. Signals such as an EU language or currency with the ability to order in it, or references to customers in the EU, point the other way. Tracking EU visitors with analytics or advertising tools can separately count as monitoring.

If an EU subsidiary handles data about US customers, does GDPR cover that data?

It can. Article 3(1) applies to processing in the context of an EU establishment's activities regardless of where the processing happens, and it is not limited to data about people in the EU. If the subsidiary runs the support desk or CRM for US customers, ask counsel how that affects the systems you plan to license and whether those systems should be carved out entirely.

Is pseudonymized data outside GDPR?

No. Recital 26 says pseudonymized data that could be attributed to a person by using additional information is still personal data. Only information that is truly anonymous, where people are no longer identifiable taking into account the means reasonably likely to be used, falls outside the regulation. That is why leaving EU records out of a licensing scope is often simpler than trying to anonymize them.

Will EU or UK records in the archive stop a company from licensing its data?

Usually not. The common approach is to exclude the EU or UK slice, or anonymize it to the regulation's standard, and assess the US operational records on their own merits. The company still needs to meet the baseline: 50+ full-time employees at peak (contractors excluded), several years of documented operations, rights to license the data and an authorized sponsor who can sign.

Do B2B contact details count as personal data under GDPR?

Yes. Names, work email addresses, direct phone numbers and notes about identifiable people at customer or supplier companies are personal data, even when collected in a business context. A US company that targets European businesses can therefore hold GDPR-covered data in its CRM and email, which is why sales and account-management systems deserve a close look when mapping EU records.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment