Guide

Does GDPR Apply to My US-Based Website?

GDPR applies based on your visitors' location, not your business's. Here's how to actually determine whether a US-based site is in scope.

Published May 11, 2026·Last updated August 18, 2026

This is one of the most common misconceptions about GDPR: that it’s an EU law for EU companies, and a US business is automatically outside its reach. That’s not how the regulation defines its own scope. GDPR applies based on whose data you’re processing, not where your company is incorporated.

The actual scope rule

GDPR applies to organizations, regardless of location, that process personal data of people in the EU/EEA in connection with either:

  • Offering goods or services to those individuals (even for free), or
  • Monitoring their behavior, which includes standard web analytics and tracking.

A US-based ecommerce site that ships to Europe is offering goods to EU residents. A US-based blog running Google Analytics on EU visitors is monitoring their behavior. Both can fall under GDPR’s scope, incorporation location aside.

What actually determines whether you’re in scope

  • Do you have EU/EEA visitors at all? Check your analytics by country, not just assume based on where you market.
  • Do you specifically target EU customers, pricing in euros, EU-specific marketing, shipping to EU addresses? This strengthens the “offering goods or services” trigger.
  • Do you track EU visitor behavior via analytics, ad pixels, or similar tools? This alone can trigger the “monitoring” prong, even without any deliberate EU targeting.
Our recommendation

Usercentrics

If EU traffic is a meaningful share of your visitors, Usercentrics' EU-first design handles the regional consent nuance more precisely than tools built primarily around US frameworks.

Try Usercentrics

The most common mistake

Assuming “we’re a US company, this doesn’t apply to us” without ever checking the actual traffic data. Plenty of small US businesses have meaningful EU traffic they never deliberately pursued, picked up through search, social sharing, or general online visibility, and that traffic alone can be enough to bring standard tracking tools into GDPR’s scope, independent of any EU-specific marketing effort.

If you have negligible EU traffic

If your analytics show effectively no EU visitors, GDPR’s practical relevance to you is low, even though the statute technically has broad extraterritorial language. Compliance effort should scale with actual exposure, see our general framework for deciding whether you need a banner at all, and our interactive privacy law checker if you want a fast read across GDPR, UK GDPR, CCPA, and US state laws together based on your specific traffic mix.

If you do have EU traffic

Treat GDPR as genuinely applicable and start with the basics: a compliant, opt-in cookie banner that blocks tracking pre-consent, and a privacy policy that accurately describes what you collect. Our GDPR compliance checklist walks through the rest.

This guide is educational and not legal advice. GDPR’s territorial scope involves fact-specific analysis. For your specific situation, consult a privacy attorney.