GDPR for US Companies: When It Applies and How to Answer Data Subject Requests on Time
A US company does not need an office in Europe to fall under the GDPR. If you sell to or track people in the EU, the regulation reaches you, and a data subject access request can land in your inbox with a one-month clock attached. Obtainer finds where that person's data lives across your US systems, compiles it into one reviewable manifest, drafts the response, and tracks the deadline, so a request from an EU resident does not catch your team flat-footed.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
Yes, the GDPR can apply to a US company that has no office, staff, or servers in Europe. Article 3(2) extends the regulation to any business outside the EU that either offers goods or services to people in the EU, whether or not payment is required, or monitors the behavior of people in the EU, for example through analytics or advertising pixels. Physical presence is not the test; targeting is. Merely having a website that Europeans can reach, or writing it in English, is not enough on its own, but taking EU currency, shipping to EU countries, translating for an EU market, or running ad campaigns aimed at EU users is. Once you are in scope, three things follow. First, you generally must appoint a representative in the EU under Article 27. Second, EU residents can exercise the eight data subject rights against you, including access, erasure, and portability, and you must answer within one month, extendable by two months for complex requests with notice. Third, the penalties are real: up to 20 million euros or 4 percent of total worldwide annual turnover, whichever is higher, for the most serious violations. Obtainer handles the operational side of a request: it discovers where an EU resident's data lives across your CRM, warehouse, help desk, billing, and files, compiles a source-system manifest, drafts a deadline-safe response, and tracks the one-month clock. Nothing is disclosed automatically; a human reviews, redacts, and approves. Obtainer helps you comply. It is not legal advice, so whether Article 3 applies to your business, and whether you need an EU representative, stay decisions for your team or counsel. Self-serve from $49/mo.
Why it fits
US companies, SaaS, ecommerce, agencies, and B2B firms, that market to or track EU residents and want the discovery, drafting, and deadline tracking for a GDPR data subject request handled in one place, without buying an enterprise governance suite.
Scope turns on targeting, not location
The GDPR reaches a US company when it offers goods or services to people in the EU or monitors their behavior, no European office required. If you take EU currency, ship to the EU, translate for an EU market, or run analytics and ad pixels on EU visitors, assume you are in scope and be ready to answer a data subject request.
One month to respond, eight rights to honor
EU residents can ask to access, correct, delete, port, restrict, or object to the data you hold, and the GDPR gives you one calendar month from a valid request. The clock does not care that you are in another time zone. Obtainer starts the countdown, finds the data across your US stack, and drafts the reply so the deadline is workable.
Discovery across a US stack, priced for you
A single EU user's data is spread across your production database, warehouse, Stripe, support desk, and email. Obtainer surfaces where it lives and compiles one manifest, instead of leaving an engineer to hunt it down. Self-serve from $49/mo, with no five-figure floor to clear before you can answer your first request.
More use cases
Related features
Questions
Common questions about this
Does GDPR apply to US companies?
Yes, it can, even with no office or servers in Europe. Under Article 3(2), the GDPR applies to a US company that offers goods or services to people in the EU or monitors their behavior, such as through analytics or ad pixels. The test is whether you target EU residents, not where your business sits. A US-only customer base is out of scope.
What are the GDPR requirements for US companies?
A US company in scope must generally appoint an EU representative under Article 27, provide a compliant privacy notice, have a lawful basis for processing, honor the eight data subject rights within one month, and report qualifying breaches within 72 hours. In practice the operational load is answering access, deletion, and portability requests on time, which is where discovery and deadline tracking earn their keep.
What are the GDPR penalties for US companies?
The same tiers apply as to EU firms. The most serious violations, such as ignoring data subject rights or lacking a lawful basis, can draw fines up to 20 million euros or 4 percent of total worldwide annual turnover, whichever is higher. Lesser violations cap at 10 million euros or 2 percent. Regulators can also order you to stop processing. Enforcement against US firms is uncommon but not theoretical.
Do US companies need an EU representative under GDPR?
Usually, yes, if Article 3(2) brings you into scope. Article 27 requires most non-EU companies subject to the GDPR to designate, in writing, a representative established in an EU member state where their data subjects are located. Narrow exemptions exist for occasional, low-risk processing. The representative is a point of contact for regulators and individuals, not a shield from liability.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.