Does GDPR Apply to My Business If I'm Not Based in the EU?
GDPR's territorial scope is based on your visitors and customers, not your company's address. Here's how to tell whether your non-EU business is actually in scope.
This is one of the most common GDPR questions, and the most common wrong assumption: that being headquartered outside the EU automatically puts you outside GDPR’s reach. It doesn’t. GDPR’s Article 3 defines territorial scope based on whose data you’re processing and why, not where your company is incorporated or where your servers sit.
The actual test: Article 3(2)
GDPR applies to a business with no EU establishment if it processes personal data of people in the EU in connection with either:
- Offering goods or services to those individuals, whether or not payment is required, or
- Monitoring their behavior, as far as that behavior takes place within the EU (this covers most web analytics, advertising tracking, and profiling).
Neither branch of this test cares where your business is based. A company in Canada, Brazil, Australia, or anywhere else can be squarely in scope if either condition is met.
“Offering goods or services”: what actually counts
The GDPR (and the guidance from the European Data Protection Board) looks at whether you’re targeting EU individuals, not just whether an EU visitor can technically reach your site. Indicators that you’re targeting the EU include:
- Pricing displayed in euros or other EU currencies
- Language options specific to EU countries (beyond just offering English, which many non-EU-targeting sites do anyway)
- Shipping to EU addresses
- EU-specific marketing, domain extensions (
.de,.fr, etc.), or testimonials - Explicitly mentioning EU customers in your marketing
A US site that happens to be accessible from Germany, with no EU-specific pricing, shipping, or marketing, generally isn’t “offering” to EU individuals just because the traffic exists. A US site that ships internationally, prices in EUR for EU visitors, and runs EU-targeted ad campaigns is a different story.
“Monitoring behavior”: the one that catches analytics-heavy sites
This is the branch that surprises non-EU businesses most. If you run Google Analytics, retargeting pixels, or any behavioral tracking, and EU visitors show up in that data, you’re likely monitoring their behavior within the meaning of Article 3(2)(b), regardless of whether you ever intended to “target” the EU commercially. This is the same underlying issue covered in our GA4 and GDPR guide, worth reading if analytics is your main EU touchpoint.
Usercentrics
If EU visitors show up in your analytics at all, meaningfully or not, the safest and lowest-effort path is gating tracking behind proper opt-in consent for that traffic rather than litigating whether you're 'really' targeting the EU. Usercentrics handles the geo-detection and opt-in logic for you.
What if you’re US-based specifically?
If your business is based in the United States, we cover the US-specific version of this question, including how it interacts with CCPA and other state laws, in more depth in our dedicated US-based website guide.
What to do if you’re on the edge
- Audit your actual EU traffic volume and behavior, not just whether it’s theoretically possible for someone in the EU to visit.
- Check whether you meet either Article 3(2) branch, targeting or monitoring, independently; you only need to meet one.
- If you’re close to either threshold, treat GDPR as applicable and configure consent accordingly, the cost of doing so is far lower than the cost of getting the applicability call wrong.
- Revisit this periodically as your marketing, shipping, and analytics setup changes, scope isn’t a one-time determination.
This guide is educational and not legal advice. Whether GDPR applies to your specific business depends on facts a privacy attorney should review.