{"id":975,"date":"2022-04-27T12:25:00","date_gmt":"2022-04-27T12:25:00","guid":{"rendered":"https:\/\/www.cookiebot.com\/en\/?p=975"},"modified":"2026-03-12T09:15:43","modified_gmt":"2026-03-12T08:15:43","slug":"gdpr-usa","status":"publish","type":"post","link":"https:\/\/www.cookiebot.com\/en\/gdpr-usa\/","title":{"rendered":"GDPR USA"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-gdpr-in-usa\">GDPR in USA<\/h2>\n\n\n\n<p>The <a href=\"\/en\/gdpr\/\">General Data Protection Regulation<\/a>&nbsp;(or GDPR) is an EU-wide law that protects Europeans in regard to to the processing of their personal data, as well as laying down the rules relating to the free movement of personal data.<\/p>\n\n\n\n<p>It was enforced in <strong>May 2018<\/strong>.<\/p>\n\n\n\n<p>You might ask what an EU law has to do with you, if you and your website is based in the US?<\/p>\n\n\n\n<p>The truth is a lot.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-does-the-gdpr-affect-the-us\">Does the GDPR affect the US?<\/h3>\n\n\n\n<p>Yes!<\/p>\n\n\n\n<p>The GDPR has <strong>extra-territorial scope<\/strong>, which means that websites outside the EU that process data of people inside the EU are obligated to comply with the GDPR.<\/p>\n\n\n\n<p>So, if you have a website in the US and you have visitors from the EU, the GDPR applies to your domain. Therefore, if that is the case, you need to meet the GDPR requirements and conditions for processing data.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img decoding=\"async\" src=\"\/media\/3731\/skaermbillede-2019-10-15-kl-134758.png?width=400&amp;\" alt=\"Planet Earth - Cookiebot\" width=\"770px\" height=\"527px\"\/><figcaption class=\"wp-element-caption\">GDPR and USA: America is covered by the scope of the EU data law.<\/figcaption><\/figure>\n\n\n\n<p>In doubt whether your website is GDPR-compliant? <a href=\"\/en\/cookie-checker\/\">Test with the free Cookiebot CMP compliance test<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-gdpr-and-pii\">GDPR and PII<\/h3>\n\n\n\n<p>PII stands for&nbsp;<em>personally identifiable information<\/em>, i.e. any kind of data that can be linked to an individual and thereby&nbsp;<em>identify<\/em>&nbsp;them.<\/p>\n\n\n\n<p>This can be anything from <strong>first<\/strong>&nbsp;and <strong>last names<\/strong>, <strong>e-mail addresses<\/strong>, <strong>geolocation<\/strong>, and <strong>browser history<\/strong>, among many others.<\/p>\n\n\n\n<p>Important to know is that in the GDPR, PII is not mentioned as such. That is because <strong>personally identifiable information<\/strong>&nbsp;is a term primarily used in the US, whereas the European equivalent that is found in the GDPR is <strong>personal data<\/strong>.<\/p>\n\n\n\n<p>However, in this blogpost, when we talk about the GDPR, PII is used instead of \u201cpersonal data\u201d.<\/p>\n\n\n\n<p>So, in the GDPR, PII processing is determined by strict rules and conditions. These are in place to protect users from having their data collected and abused without their knowledge or consent.<\/p>\n\n\n\n<p>In the GDPR, PII is protected namely because it has the potential to infringe on an individual\u2019s private life, and even do harm, when combined with other data.<\/p>\n\n\n\n<p>If your website processes personally identifiable information of individuals in the EU (known in the GDPR as \u201cdata subjects\u201d), it has to be done on one of the following legal grounds:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>With the consent of the data subject,<\/li>\n\n\n\n<li>Processing necessary for the performance of a contract,<\/li>\n\n\n\n<li>Processing necessary for compliance with legal obligations,<\/li>\n\n\n\n<li>Processing necessary to protect \u201cvital interests\u201d of the data subject,<\/li>\n\n\n\n<li>Processing necessary for tasks carried out in public interest,<\/li>\n\n\n\n<li>Processing necessary for purposes of legitimate interests pursued by the controller or by a third party.<\/li>\n<\/ul>\n\n\n\n<p>Of the lawful grounds for processing PII, <strong>obtaining the consent of the data subject<\/strong>&nbsp;is the most widely used for websites who process, in accordance with the GDPR, PII on individuals in the EU.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-gdpr-for-us-companies-and-websites\">GDPR for US companies and websites<\/h3>\n\n\n\n<p>So, <strong>if your US website has EU visitors<\/strong>&nbsp;and consent is the legal ground that you base your PII processing on, the GDPR has specific requirements as to how you must obtain the consent and what constitutes valid consent.<\/p>\n\n\n\n<p>For a website to achieve <strong>GDPR compliance in the US<\/strong>, these conditions for consent must be met.<\/p>\n\n\n\n<p>Your website, when engaging with visitors from inside the EU, and so processing their PII, must:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>obtain clear and unambiguous <strong>consent<\/strong>&nbsp;from its users,<\/li>\n\n\n\n<li><strong>prior to<\/strong>&nbsp;any processing of personal data,<\/li>\n\n\n\n<li>after <strong>specifying all types of cookies and other tracking technology<\/strong>&nbsp;present and operating on its pages,<\/li>\n\n\n\n<li>in easy-to-understand ways that enable users <strong>to consent<\/strong>&nbsp;and <strong>to revoke consent<\/strong>&nbsp;on each specific category of cookies,<\/li>\n\n\n\n<li>to then be able to safely and confidentially <strong>document<\/strong>&nbsp;each user consent,<\/li>\n\n\n\n<li>and to ask for <strong>renewed consent regularly<\/strong>.<\/li>\n<\/ul>\n\n\n\n<p>A consent management platform (known as a CMP) can help your website become GDPR-compliant with minimum effort on your behalf.<\/p>\n\n\n\n<p>Cookiebot CMP specializes in exactly this niche area. Our scanning technology finds all cookies and trackers on your website, pauses them all until your end-users have given their consent, after which each consent is stored for legal documentation.<\/p>\n\n\n\n<p>Read more about the <a href=\"\/en\/cookie-consent-solution\/\">functions of our consent management platform<\/a>.<\/p>\n\n\n\n<p>Choosing a consent management platform like Cookiebot CMP means peace of mind for you and your end-users \u2013 we\u2019ve taken the hard work out of protecting your users\u2019 privacy, so you can focus on running your website and business.<\/p>\n\n\n\n<p>We are European-based with a strong knowledge of consent management that enables compliance with the GDPR in the US. We also have a sharp eye on the emerging privacy laws across the world, including the <a href=\"\/en\/ccpa\/\">California Consumer Privacy Act<\/a>&nbsp;(CCPA) and minor privacy laws such as the new <a href=\"\/en\/nevada-privacy-law\/\">Nevada privacy amendment<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-gdpr-eu-vs-us\">GDPR - EU vs US<\/h2>\n\n\n\n<p>Next question might be whether there is a GDPR US equivalent, a sort of \u201cGDPR USA version\u201d that from a federal level lays down the law of the land when it comes to cookies and website tracking and user privacy?<\/p>\n\n\n\n<p>The answer is <strong>no<\/strong>.<\/p>\n\n\n\n<p>There is nothing close to the GDPR (or any other cookie law) in the US. When processing European PII, GDPR is in effect. When processing American PII in the US, no broad federal law applies.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-gdpr-vs-us-privacy-law\">GDPR vs US privacy law<\/h3>\n\n\n\n<p>In fact, in the absence of such a federal data privacy regulation, many US states have begun to legislate locally on their own, to secure consumers the rights to opt out of having their data sold to third parties.<\/p>\n\n\n\n<p>These include the <a href=\"\/en\/ccpa\/\">California Consumer Privacy Act&nbsp;<\/a>(known as CCPA) that&nbsp;took effect January 1, 2020, and the <a href=\"\/en\/nevada-privacy-law\/\">Nevada privacy law<\/a>&nbsp;that was enforced on October 1, 2019.<\/p>\n\n\n\n<p>The <a href=\"\/en\/ccpa\/\">CCPA<\/a>&nbsp;secures Californian citizens the right to opt out of data sales, as well as the rights to access their data and request deletion. The <a href=\"\/en\/nevada-privacy-law\/\">Nevada privacy law<\/a>&nbsp;isn\u2019t nearly as ambitious as the CCPA but does empower Nevada residents with the right to opt out of third-party data sales as well.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img decoding=\"async\" src=\"\/media\/3733\/skaermbillede-2019-10-15-kl-135302.png?width=410&amp;\" alt=\"Map of USA - Cookiebot\" width=\"770px\" height=\"461px\"\/><\/figure>\n\n\n\n<p>GDPR in the USA - state-wide regulations emerging as GDPR US equivalents.<\/p>\n\n\n\n<p>Cookiebot CMP&nbsp;offers CCPA and GDPR compliance.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-who-enforces-the-gdpr-in-the-usa\">Who enforces the GDPR in the USA?<\/h3>\n\n\n\n<p>The GDPR is enforced by the national data protection authorities in the EU, even if the fine or penalty is levied against a US company.<\/p>\n\n\n\n<p>In fact, the <a href=\"https:\/\/www.jlt.com\/en-dk\/insurance-risk\/cyber-insurance\/insights\/regulator-issues-first-gdpr-enforcement-notice\/\" target=\"_blank\" rel=\"noreferrer noopener\">very first GDPR enforcement<\/a>&nbsp;was against a Canadian company, and the biggest GDPR enforced to date is the <a href=\"https:\/\/www.cnil.fr\/en\/cnils-restricted-committee-imposes-financial-penalty-50-million-euros-against-google-llc\/\" target=\"_blank\" rel=\"noreferrer noopener\">$50 million fine against Google<\/a>&nbsp;issued by the French data protection authority CNIL for three separate violations of the GDPR, including not having obtained valid consent for processing PII of Europeans.<\/p>\n\n\n\n<p>So, being a website in the US does not exempt you from GPDR compliance and the territorial distance will not protect you from its enforcement either.<\/p>\n\n\n\n<p>That\u2019s why a <a href=\"\/\">consent management provider<\/a>&nbsp;is a smart choice for websites of all shapes and sizes, regardless of where in the world they\u2019re based, to enable GDPR compliance, avoid heavy fines and protect the privacy of their users.<\/p>\n\n\n\n<p>Try <a href=\"https:\/\/admin.cookiebot.com\/signup\">Cookiebot CMP for free today<\/a>&nbsp;to enable GDPR compliance in US.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-gdpr-and-sharing-data-between-the-us-and-eu\">GDPR and sharing data between the US and EU<\/h3>\n\n\n\n<p>The <a href=\"https:\/\/www.privacyshield.gov\/welcome\/\" target=\"_blank\" rel=\"noreferrer noopener\">US Privacy Shield<\/a>&nbsp;is a way for US companies and organizations to obtain an <a href=\"https:\/\/ec.europa.eu\/info\/law\/law-topic\/data-protection\/international-dimension-data-protection\/adequacy-decisions_en\/\" target=\"_blank\" rel=\"noreferrer noopener\">adequacy agreement<\/a>&nbsp;with the EU, allowing for free data transfers between the US and EU.<\/p>\n\n\n\n<p>The GDPR orders \u2013 <a href=\"https:\/\/gdpr-info.eu\/art-45-gdpr\/\" target=\"_blank\" rel=\"noreferrer noopener\">in its Article 45<\/a>&nbsp;\u2013 how data is allowed to be transferred outside the European Union. Data transfers outside the EU, the GDPR rules, are allowed if:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>the country receiving the data has an adequacy agreement&nbsp;with the EU,<\/li>\n\n\n\n<li><strong><em>or<\/em><\/strong><\/li>\n\n\n\n<li>the data processor or controller demonstrates an adequate level of data privacy safeguards (such as the US Privacy Shield).<\/li>\n<\/ul>\n\n\n\n<p>The <a href=\"https:\/\/www.privacyshield.gov\/welcome\/\" target=\"_blank\" rel=\"noreferrer noopener\">US Privacy Shield program&nbsp;<\/a>enables US-based companies \u201cto join the Privacy Shield Framework in order to benefit from the adequacy determinations\u201d, which means that certified US companies are empowered to transfer and process data without restrictions with the EU.<\/p>\n\n\n\n<p>Even though the <a href=\"https:\/\/www.privacyshield.gov\/welcome\/\" target=\"_blank\" rel=\"noreferrer noopener\">US Privacy Shield program<\/a>&nbsp;is recognized as an adequate way to transfer data to the US from EU and vice versa, the US in its entirety does not figure on the list of countries that the EU has deemed to have an adequate level of data protection law.<\/p>\n\n\n\n<p>An obvious reason for the exemption of the US on the list of adequate countries is the lack of a uniform, federal data privacy law (a GDPR US equivalent) that guarantees the same rights to Americans as the GDPR does to Europeans.<\/p>\n\n\n\n<p>However, in these times of great privacy awakenings, many eyes are on the tech industry and Washington D.C. as talks of federal privacy legislations are spurring.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-gdpr-and-silicon-valley\">GDPR and Silicon Valley<\/h2>\n\n\n\n<p>Privacy is a hot topic in the age of Silicon Valley, and it has become even hotter after the privacy scandal surrounding Cambridge Analytica. It has evidently reached a boiling point, as <a href=\"https:\/\/www.nbcnews.com\/politics\/meet-the-press\/poll-americans-give-social-media-clear-thumbs-down-n991086\/\" target=\"_blank\" rel=\"noreferrer noopener\">public sentiment<\/a>&nbsp;towards tech companies is souring and a major political candidate is <a href=\"https:\/\/www.forbes.com\/sites\/jackkelly\/2019\/10\/02\/senator-elizabeth-warren-says-its-time-to-break-up-amazon-google-and-facebook-and-facebook-ceo-mark-zuckerberg-fights-back\/#54b4352b6791\/\" target=\"_blank\" rel=\"noreferrer noopener\">calling for the breaking up<\/a>&nbsp;of Google and Facebook on anti-competition grounds.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-tech-lobbying-and-data-privacy-in-the-us\">Tech lobbying and data privacy in the US<\/h3>\n\n\n\n<p>Google, Facebook, Apple, Amazon and Microsoft <a href=\"https:\/\/www.forbes.com\/sites\/ajdellinger\/2019\/04\/30\/how-the-biggest-tech-companies-spent-half-a-billion-dollars-lobbying-congress\/\" target=\"_blank\" rel=\"noreferrer noopener\">spent $582 million on political lobbying<\/a>&nbsp;from 2005 to 2018. Google mentioned privacy in 64% of its lobbying reports, while Facebook mentioned the topic in 61% of its reports.<\/p>\n\n\n\n<p>Overall, the topic of privacy is by far the most lobbied about topic, with more than 3.240 mentions in all filed reports by the above-mentioned tech giants.<\/p>\n\n\n\n<p>The prevalent narrative of Silicon Valley \u2013 of tech companies like Google, Facebook and Amazon \u2013 is that privacy is an inevitable trade-off in the technological evolution that is propelling human progress.<\/p>\n\n\n\n<p>This is worrying, because it diminishes the dangers of the erosion of privacy through technological development.<\/p>\n\n\n\n<p>It suggests that political regulation of the ad tech practices of Google and Facebook \u2013 <a href=\"http:\/\/www.shoshanazuboff.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">what Harvard prof. emerita Shoshana Zuboff has famously coined \u201csurveillance capitalism\u201d<\/a>&nbsp;\u2013 is impossible from the start: that the tech giants are too big to be tethered to any privacy protecting legislation.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-surveillance-is-not-the-inevitable-end-of-technology\">Surveillance is not the inevitable end of technology<\/h2>\n\n\n\n<p>\u201cEvolution is a terrible metaphor for technology\u201d, <a href=\"https:\/\/www.vox.com\/the-highlight\/2019\/10\/1\/20887003\/tech-technology-evolution-natural-inevitable-ethics\/\" target=\"_blank\" rel=\"noreferrer noopener\">argues tech writer Rose Eveleth for the American news site Vox<\/a>, and argues that talking about the growth and development of technology in the terms of evolution pushes the question of regulation and control to the fringes of public conversation.<\/p>\n\n\n\n<p>The assertion that tech companies can\u2019t be shaped or regulated with the public\u2019s interest in mind, Eveleth writes, is to argue that they are fundamentally different from any other industry.<\/p>\n\n\n\n<p>They are not.<\/p>\n\n\n\n<p>They are industries like any other, whether it\u2019s Oil or Coal or Pharma. Privacy at the cost of technological progress is a false narrative. The EU\u2019s General Data Protection Regulation is a sterling example that legislation and regulation can empower citizens with enforceable rights to privacy, without halting technological development or worsening the products.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img decoding=\"async\" src=\"\/media\/3734\/eu_us_0.jpg?width=402&amp;\" alt=\"Flag of the United States &amp; the European Union - Cookiebot\" width=\"770px\" height=\"511px\"\/><figcaption class=\"wp-element-caption\">GDPR and USA: Cookiebot CMP enables GDPR PII compliant processing across the Atlantic.<\/figcaption><\/figure>\n\n\n\n<p>On the contrary, the GDPR specifically mandates<a href=\"https:\/\/gdpr-info.eu\/issues\/privacy-by-design\/\" target=\"_blank\" rel=\"noreferrer noopener\">&nbsp;privacy by design<\/a>&nbsp;in its Article 25, which means \u201cdata protection through technology design\u201d, i.e. that privacy has to be thought into and built into the very development of technology.<\/p>\n\n\n\n<p>That is why we see US companies like <a href=\"https:\/\/brave.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Brave<\/a>&nbsp;\u2013 the privacy enhancing browser \u2013 publicly pushing for stronger privacy laws, both in the US and in the EU.<\/p>\n\n\n\n<p>In fact, in October 2019, <a href=\"https:\/\/brave.com\/eprivacy-october2019\/\" target=\"_blank\" rel=\"noreferrer noopener\">Brave submitted a letter to all twenty-eight EU governments<\/a>&nbsp;urging them to strengthen the draft of the coming European law called the ePrivacy Regulation, which is meant to up the European data privacy game even further from the GDPR.&nbsp;<\/p>\n\n\n\n<p>The narrative that promotes a tech evolution where privacy is an inevitable trade-off also frames opposition to privacy-invasive products and services as a resistance to human progress itself.<\/p>\n\n\n\n<p>This is of course wrong.<\/p>\n\n\n\n<p>We find it of paramount importance to secure privacy in all aspects of human existence, especially in the digital lands, where it is endangered by illicit tech industry practices.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-gdpr-as-a-road-map\">GDPR as a road map<\/h3>\n\n\n\n<p>The <a href=\"\/en\/gdpr\/\">GDPR<\/a>&nbsp;is an example of taking back the control of run-amok tech industries. The GDPR is an example that privacy is not a natural trade-off in the evolution of technology.<\/p>\n\n\n\n<p>Democracy is the system that enshrines privacy as a right of the people. It is through democratic process \u2013 not technological progress \u2013 that we reign in surveillance capitalism and secure a private, free future for the generations to come.<\/p>\n\n\n\n<p>That is why legislations like the <a href=\"\/en\/gdpr\/\">GDPR<\/a>&nbsp;and the coming <a href=\"\/en\/eprivacy-regulation\/\">ePrivacy Regulation<\/a>&nbsp;in the EU are milestones of regulatory achievements, which hopefully will inspire American equivalents.<\/p>\n\n\n\n<p>These are on the horizon, with the <a href=\"\/en\/ccpa\/\">California Consumer Privacy Act<\/a>&nbsp;(CCPA) as a lodestar for future US privacy legislation, and hopefully, eventually, a strong federal law that enshrines privacy for American citizens as the GDPR does for Europeans.<\/p>\n\n\n\n<p>Until then, using Cookiebot CMP&nbsp;guarantees your users the best privacy protection against third-party cookies and trackers, and enables GDPR compliance for your website.<\/p>\n\n\n\n\n\n\n","protected":false},"excerpt":{"rendered":"<p>GDPR in USA The General Data Protection Regulation&nbsp;(or GDPR) is an EU-wide law that protects Europeans in regard to to the processing of their personal data, as well as laying down the rules relating to the free movement of personal data. It was enforced in May 2018. You might ask what an EU law has [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":12607,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":true,"editor_notices":[],"footnotes":""},"categories":[1],"tags":[],"class_list":["post-975","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"acf":[],"thumbnail_status":"The image is too white. Please, check the original image for faulty SVGs. If the original image is in SVG format, try to upload the PNG or JPEG version instead.","thumbnail_url":"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/04\/GDPR-USA_1200x630_ffffff.png","_links":{"self":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/975","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/comments?post=975"}],"version-history":[{"count":0,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/975\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media\/12607"}],"wp:attachment":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media?parent=975"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/categories?post=975"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/tags?post=975"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}