Does GDPR apply to my company?
GDPR reaches far beyond Europe. Answer six questions about where you operate, who you sell to and what you track, and see whether the EU GDPR or UK GDPR applies, in what role, and which duties follow. Nothing you enter leaves your browser.
GDPR applies to your company if you have an establishment in the EU, or if you are based elsewhere, such as the US, UK or India, and offer goods or services to people in the EU or monitor their behaviour there. Company size and server location do not matter. Processing EU customers' data as their vendor brings GDPR terms in by contract. UK users bring in UK GDPR too.
Result
Article 3(2)(a) reaches companies with no EU presence at all, including US, UK and Indian start-ups, when they offer goods or services to people in the EU, paid or free. Selling in euros, shipping to the EU, EU-language marketing or naming EU customers all show the intent. UK GDPR, which the UK kept after Brexit as a separate law, applies to your UK activity too.
- Notice: publish a privacy notice that names your purposes, lawful bases, recipients and retention. The privacy policy generator gives you a first draft.
- Records: start the record of processing from the RoPA template; most other duties depend on it.
- Processors: list every vendor that touches personal data and put a data processing agreement in place with each.
- Representative: appoint one by written mandate in an EU country where people whose data you process are located, and name it in your privacy notice. It does not take your liability away.
- UK: appoint a UK representative too if you have no UK office; one EU representative does not cover the UK.
- Read: the GDPR guide explains each duty; the DPDP to GDPR mapping shows what carries over if you also serve India.
Who GDPR applies to: the two tests in Article 3
Article 3 of the GDPR has two routes in. Establishment (Art. 3(1)): if you have an establishment in the EU, the GDPR covers processing in the context of its activities, wherever that processing happens. The bar is low; the EDPB says one employee or agent acting with enough stability can be an establishment for an online business. Targeting (Art. 3(2)): with no EU establishment, the GDPR still applies when you offer goods or services to people in the EU, paid or free, or monitor their behaviour while they are in the EU.
Neither test asks about nationality, company size or where your servers are. A US start-up with European customers, a UK company tracking EU visitors and an Indian app with users in Germany are all in scope for that processing. The EDPB's Guidelines 3/2018 list the signs of targeting: an EU country named in the offer, EU-targeted ads, an EU language or currency, delivery to the EU, EU phone numbers or domains. A site that can merely be reached from the EU is not enough on its own.
Controller or processor
The controller decides why and how personal data is processed; a processor handles it on the controller's behalf (Art. 4(7) and 4(8)). Most SaaS companies are both: controller for their own accounts, billing and marketing data, processor for the data customers put into the product. The role matters because most duties, such as the lawful basis, notices and rights, sit with the controller. Processors must act on documented instructions, keep data secure, get approval for sub-processors and report breaches to the controller (Art. 28 to 33).
A processor outside the EU working only for EU business customers is not directly caught by Article 3, but its customers must bind it to the Article 28 terms and use transfer safeguards under Chapter V. In practice the obligations arrive in the contract.
The EU representative, records and the DPO
Representative (Art. 27). A controller or processor caught by Article 3(2) must appoint a representative in the EU in writing, in a country where people whose data it processes are located. The exemption is narrow: processing that is occasional, does not involve large-scale special-category or criminal data, and is unlikely to be risky. A representative does not take on your liability. UK GDPR has its own UK representative rule, so one EU representative does not cover the UK.
Records (Art. 30). Every controller and processor keeps a record of processing. Article 30(5) exempts organisations with fewer than 250 staff, but only where the processing is occasional, unlikely to be risky and includes no special-category or criminal data. A product that processes customer data every day is not occasional, so most start-ups still need the record. An EU simplification package that changes this exemption (procedure 2025/0130(COD)) was agreed between the institutions in June 2026 but had not been adopted as of October 2026. Until it is published, the current text applies.
Data Protection Officer (Art. 37). A DPO is required only for public bodies, and where your core activities are regular and systematic monitoring of people on a large scale, or large-scale processing of special-category or criminal-offence data. Most B2B start-ups do not need one, but must still name a contact for privacy questions.
UK GDPR after Brexit
The UK kept the GDPR as its own law, UK GDPR, alongside the Data Protection Act 2018. It uses the same establishment and targeting tests for the UK, and the ICO enforces it. A company outside the UK that offers goods or services to people in the UK or monitors them must comply and appoint a UK representative, with the same narrow exemption (see the ICO's guidance). Fines go up to £17.5 million or 4% of worldwide turnover. The Data (Use and Access) Act 2025 is changing parts of the UK regime, and the ICO marks some guidance as under review, so check the ICO before you rely on a detail.
Fines
Article 83 sets two caps. Up to €10 million or 2% of total worldwide annual turnover, whichever is higher, applies to failures in controller and processor duties such as records, security, breach notification, processor contracts and the DPO. Up to €20 million or 4% applies to the principles, lawful basis, consent, data subject rights and international transfers. The authority weighs the nature, gravity and duration of the breach, intent or negligence, mitigation and cooperation in each case. These are maximums, not tariffs.
Sources
- EUR-Lex: Regulation (EU) 2016/679 (GDPR), Articles 3, 4, 27, 28, 30, 33, 37 and 83
- EDPB: Guidelines 3/2018 on the territorial scope of the GDPR (Article 3), final version of 12 November 2019
- ICO: Receiving personal information from the EEA (EU and UK representatives)
- ICO: Who needs to document their processing activities?
- ICO: The maximum amount of a fine under UK GDPR and DPA 2018
- European Parliament Legislative Observatory: procedure 2025/0130(COD) (Omnibus IV)
Facts checked against these sources in October 2026. Laws, thresholds and guidance change: check the source before you rely on a figure.
The things people ask us
Does GDPR apply to US companies?
Yes, when a US company offers goods or services to people in the EU or monitors their behaviour there, or has an EU establishment. Being incorporated and hosted in the US changes nothing. A US company with no EU users, customers or tracking is outside it.
Does GDPR apply to Indian companies?
It applies to an Indian company that targets or monitors people in the EU, or has an EU office. Indian IT and SaaS vendors that only process data for EU business customers are usually reached through the customer's data processing agreement and standard contractual clauses rather than directly.
Does GDPR still apply to UK companies after Brexit?
UK companies follow UK GDPR at home, enforced by the ICO. A UK company that offers goods or services to people in the EU or monitors them is also subject to the EU GDPR and, with no EU establishment, needs an EU representative.
Does GDPR apply to small businesses?
Yes. There is no size threshold for scope. Size matters only for the Article 30(5) records exemption for organisations under 250 staff, and that exemption is lost when processing is regular, risky or involves special-category data.
Does GDPR apply to B2B companies?
Yes. Business contacts are people, so names, work emails and phone numbers of EU contacts are personal data. A B2B SaaS company is usually a controller for its own sales and account data and a processor for the data customers load into the product.
Do I need an EU representative under GDPR?
You need one if the GDPR applies to you through Article 3(2) and you have no EU establishment, unless your processing is occasional, low-risk and involves no large-scale special-category or criminal data. UK GDPR has a separate UK representative rule.
Do I need a Data Protection Officer?
Only if you are a public body, or your core activities involve regular and systematic monitoring of people on a large scale, or large-scale processing of special-category or criminal data (Art. 37(1)). Most start-ups do not.
What are the GDPR fines?
Up to €10 million or 2% of worldwide annual turnover for failures in duties such as security and records, and up to €20 million or 4% for breaches of the principles, rights and transfer rules, whichever is higher in each case (Art. 83). Under UK GDPR the caps are £8.7 million and £17.5 million.
See what applies to you, and track it.
TryTrustable maps your controls to every framework you need and keeps the evidence current.