All Blog Posts

How Does GDPR Affect U.S. Companies? Real-World Impact on Marketing and Analytics

Close
Read time
12 mins
Published
Aug 27, 2026
Share

  • The GDPR is the EU's data protection law, in effect since 2018. The UK adopted the UK GDPR post-Brexit, which mirrors the EU GDPR, but with its own amendments.
  • The GDPR applies to U.S. companies that offer goods or services to, or monitor the behavior of, people in the EU. Having a physical European presence is not required.
  • Requirements for U.S. companies include establishing a lawful basis for processing personal data, obtaining opt-in consent, responding to data subject access requests, following breach notification and DPO/EU representative rules, and using a valid EU–U.S. data transfer mechanism.
  • For marketing and analytics, this means adjusting opt-in consent settings for tools such as GA4, Meta Pixel, Google Ads, and email marketing platforms when targeting EU residents.
  • Cookiebot CMP's geolocation rules can adjust the consent method and banner visibility based on a visitor's location, helping align with GDPR, U.S. state laws, and other jurisdictions.
  • Penalties reach up to EUR 10 million or 2% of annual worldwide turnover for lower-tier GDPR violations, and up to EUR 20 million or 4% for higher-tier violations; the largest fine to date for unlawful international data transfers was Meta's EUR 1.2 billion penalty in 2023.

The EU’s General Data Protection Regulation (GDPR) has been protecting personal data of EU/EEA residents since May 2018. It applies to businesses that have an EU headquarters or subsidiary, offer goods or services to EU residents, or monitor their behavior. This includes U.S. companies that are not physically present in the EU, but have EU-based e-commerce customers or website visitors, for example.

Misunderstanding or ignoring GDPR compliance requirements can come at a steep price. Ireland’s Data Protection Commission (DPC) imposed EUR 1.2 billion on Meta in 2023 for mishandling user data transfers between the EU and U.S. 

France’s CNIL penalized Google EUR 325 million in 2025 for inserting unconsented ads and cookies in Gmail inboxes. 

Luxembourg's National Commission for Data Protection (CNPD) issued a EUR 746 million fine on Amazon in 2021 for unlawful behavioral advertising practices, though the Luxembourg Administrative Court annulled the fine on procedural grounds in March 2026, sending it back to the regulator for reassessment. The underlying GDPR violation findings were upheld.

Facing the risk of GDPR fines, U.S. marketers may choose to geo-block European users, finance continuous legal defenses, or do nothing and hope to avoid the penalty. However, understanding how to comply with GDPR and proactively introducing GDPR-compliant mechanisms in business operations can help you save customers, money, and reputation in the long run. 

This article has been reviewed by Cookiebot's data protection experts and reflects requirements in force as of August 2026.

Based on Art. 3 GDPR, the territorial scope includes all the processing activities that are related to offering goods and services or monitoring the behavior of individuals in the EU. The law applies based on whether the individuals are in the EU when your processing relates to them, notwithstanding their passport and whether any of your employees or servers are in the EU. 

The table below describes the details of how and in which cases GDPR applies to U.S. companies.

CaseGDPR appliesReason
A U.S. company offering goods and services to customers in the EU/EEAYesArt. 3.2(a) GDPR
A US-based marketing campaign targeting EU marketsYesArt. 3.2(b) GDPR
A U.S. citizen on vacation in an EU country viewing Netflix in their hotelYesAn individual in the EU is protected by the GDPR.
An EU citizen on vacation in California viewing Netflix in their hotelNoAn individual physically in the U.S., outside GDPR's territorial reach, but also not a 'California resident' under CCPA/CPRA (18 CCR § 17014), since a brief vacation doesn't establish residency. This person would generally fall outside both regimes' protections.
A U.S. bakery serving EU tourist customersNo No intentional targeting of the EU market, as an incidental sale to a visiting tourist doesn't meet the Art. 3(2)(a) 'offering goods/services' test .
U.S. federal and state agencies processing EU’s residents’ dataDepends on the activityArt. 3(2) only applies if the specific processing involves offering goods/services to, or monitoring the behavior of, people in the EU. Most routine government functions (visa processing, tax administration, benefits, law enforcement) don't meet that test and fall outside GDPR's scope regardless. 
Where an agency does run something like a public-facing service or tracking tool aimed at EU residents, Art. 3(2) can apply, except where Art. 2(2) separately excludes the activity (e.g., law enforcement and national-security processing, which fall under the EU Law Enforcement Directive instead).

U.S. website operators that target EU markets in their marketing and analytics activities should note that supervisory authorities check a range of triggers to identify non-compliance with the GDPR. 

If you have an EU-language version of your website and display prices in euros, this is a likely indicator that the website offers goods and services to individuals in the EU.

Accepting payments, shipping to EU countries, and using Google Analytics, social media pixels, and other tools with tracking cookies are stronger and clearer indicators that you should comply with GDPR.

GDPR vs CCPA and Other U.S. State Laws: Key Differences

Beyond their jurisdiction, GDPR compliance and state-level laws in the United States, like the California Consumer Privacy Act (CCPA) have different practical implications for website owners in the U.S., including an opt-in vs opt-out consent model, privacy policy requirements, and personal data definitions.

The table below provides more details on the GDPR vs CCPA differences for marketers and website owners.

CriterionGDPRCCPA
Consent modelOpt-in: Businesses must obtain freely given, specific, informed, and unambiguous consent before collecting and processing personal dataOpt-out: No prior consent required, but customers must have the right to opt out with a “Do Not Sell or Share My Personal Information” link
Privacy policyShould include how you collect and use data and for what purposes, who you sell and share it with, how long will you store it, explain individuals’ rights and legal basis for processing, whether it’s transferred from EU and how it’ll be protected, DPO contact information Should include how you collect and use data and for what purposes, who you sell and share it with, explain consumers’ rights, and provide accessible options to exercise them
Enforcement bodyNational data protection authorities (DPAs) in EU Member States and UK, coordinated by the European Data Protection Board (EDPB)- California Privacy Protection Agency (primary administrative enforcement)- California Attorney General (concurrent civil enforcement authority)
Who needs to complyAny organization offering goods and services or monitoring behavior of individuals in EU- For-profit organizations with annual gross revenue exceeding USD 26,625,000 (the 2025 CPI-adjusted figure- Or with 50% or more of annual revenue derived from selling or sharing personal information- Or processing personal information of 100,000 or more California consumers or households
How marketers can complyAsk for consent for use of cookies and trackers, have a detailed privacy policy and revise it regularly, respect GDPR principles (Art. 5 GDPR)Provide "Do Not Sell or Share My Personal Information" link as opt-out option, regularly update privacy policy, rely on first-party and zero-party data

Both EU and U.S. data protection laws protect individuals’ rights over their personal data, require privacy notices, and impose data security obligations. However, while CCPA applies only to businesses that meet specific revenue and data‑volume thresholds, GDPR is more prescriptive. It applies to organizations of any size that meet the territorial scope requirements in Art. 3 GDPR.

Achieving GDPR compliance requires U.S. companies to shift from ad-hoc data handling to a structured, privacy-first operating model. Beyond mere legal necessity, implementing these measures strengthens consumer trust and mitigates significant operational risks. 

The following requirements outline the core pillars your organization needs to address to align its data protection practices with GDPR standards.

What do U.S. companies need to do to work toward GDPR compliance?

Establish a lawful basis for each data processing activity

Introduce opt-in consent (whenever relevant)

Update the privacy policy and establish a process for fulfilling DSARs

Establish data breach procedures, including notification within 72 hours

Implement DPIAs as preventive risk assessments

Appoint a DPO and EU representative (if relevant)

Have an eligible international data transfer mechanism in place

Sign Data Processing Agreements with vendors and processors

Establish a Lawful Basis for Data Processing

Art. 6 GDPR sets out six lawful bases for collecting and processing personal data. Of these, consent and legitimate interests are the two most relevant for U.S. companies offering goods or services to, or monitoring the behavior of, individuals in the EU:

  • Consent: Freely given, specific, informed, and unambiguous agreement, typically collected via a cookie banner.
  • Legitimate interests: Cases where a business's needs outweigh, without overriding, individuals' privacy rights, such as fraud prevention and security. Relying on this basis requires passing the purpose, necessity, and balancing tests.

Businesses in the U.S. should determine and document a lawful basis for every data processing activity before it begins. Those with fewer than 250 employees are exempt from keeping written records of processing activities, unless the processing is likely to be risky, is more than occasional, or involves special categories of data.

Establish a Process for Fulfilling DSARs

Similar to the CCPA, GDPR compliance requires honoring requests from individuals to access, correct, object to processing, or completely delete their personal data. But the standard response period is shorter under GDPR (one calendar month vs. 45 days under the CCPA), the privacy policy requirements are more detailed, and these requests are commonly referred to as data subject access requests (DSARs).

To be ready to respond, you should establish a process for fulfilling DSARs. This includes having email contact information or web forms available for individuals, an organized database for storing requests, verification checks, and request-processing and confirmation tools in place. Failure to establish a smooth DSAR fulfillment process risks triggering a complaint to a supervisory authority.

Follow Breach Notification Rules

Under Art. 33 GDPR, organizations have 72 hours to notify the relevant supervisory authority of a personal data breach caused by cyberattacks, employee errors, third‑party incidents, or any other cause. U.S. businesses that need to comply with GDPR should also be ready to notify affected individuals directly where the breach poses a high risk to their rights and freedoms.

To prepare for this scenario, you should have the contact details of your supervisory authority on hand and develop a notification template to use within 72 hours of an identified breach, covering:

  • Nature of the breach
  • Categories and approximate number of affected individuals (with a way to contact them directly)
  • Likely consequences of the breach
  • Measures already taken and planned in response

Additionally, Art. 35 GDPR requires implementing a Data Protection Impact Assessment (DPIA) to identify risks to the rights and freedoms of EU individuals at an early stage and reduce those risks before processing begins.

Meet the Requirements for Appointing Roles

Under Art. 27 GDPR, businesses outside the EU (including U.S. companies) generally must appoint an EU representative in writing, unless the processing is occasional, does not involve special category data, and does not pose a risk to the rights and freedoms of EU individuals.

Art. 37 GDPR requires appointing a Data Protection Officer (DPO) for activities that involve large-scale, systematic monitoring of individuals, or large-scale processing of special category data (such as health, biometric, or religious data).

The DPO is responsible for:

  • Informing and advising the organization and its employees about GDPR obligations
  • Monitoring compliance (including training and audits)
  • Assisting with DPIAs
  • Acting as the contact point for supervisory authorities and data subjects, including for DSARs and data breach coordination

Every case is different, but if your business actively markets goods and services to EU residents, you most likely need to appoint an EU representative, since that's a regular activity, though you may not need a DPO unless you systematically monitor individuals' activity at scale.

International Data Transfers: Rules to Consider

Under Art. 45 GDPR, transferring EU individuals' personal data to a third country requires an "adequate level of protection," meaning protection essentially equivalent to the GDPR's, upheld by independent supervisory authorities.

For U.S. companies, the EU-U.S. Data Privacy Framework (DPF) self-certification program has long served as an eligible transfer mechanism. However, the U.S. Supreme Court's ruling in Trump v. Slaughter on June 29, 2026, limited the independence of the Federal Trade Commission (FTC) — the DPF's primary U.S. enforcement authority — and U.S. businesses should be prepared to introduce additional transfer mechanisms, such as Standard Contractual Clauses (SCCs), to maintain GDPR compliance.

GDPR Penalties for U.S. Companies

Some of the biggest U.S. companies, including Meta, Amazon, Google, and Microsoft-owned LinkedIn, have already been fined by EU data protection authorities for GDPR violations involving cross-border data transfers, opt-in consent, and transparency around individual rights. 

For non-compliance, European regulators can block a business from operating or transferring data, and can seize assets within their market, particularly where a cooperation agreement with the U.S. facilitates enforcement.

Art. 83 GDPR sets two tiers of penalties for non-compliance:

  • Up to EUR 10 million or two percent of annual global turnover: typically applies to failing to conduct DPIAs or appoint a DPO, incomplete data records, or violating the 72-hour data breach notification rule.
  • Up to EUR 20 million or four percent of annual global turnover: typically applies to violating data subject rights, failing to establish a valid lawful basis for data collection, failing to obtain GDPR-compliant consent, or violating international data transfer rules.

U.S. businesses of all sizes should take lawful basis requirements, opt-in consent obligations, and EU-U.S. data transfer rules seriously to avoid substantial GDPR penalties. 

A consent management platform (CMP) can help automate this work, supporting compliance efforts across different data protection laws and adjusting cookie consent banner design and data processing based on the geolocation of your website visitors.

How GDPR Compliance Affects Marketing and Analytics Channels

Marketing and analytics tools like GA4, Meta Pixel, Google Ads, and email platforms need reconfiguration to support GDPR compliance. Third-party tools you use for marketing act as data processors under Art. 4 GDPR, so under Art. 28 GDPR you need to sign a Data Processing Agreement (DPA) with them. 

You should also verify that these providers meet GDPR requirements for security measures, EU-U.S. data transfer mechanisms, and data breach notification processes.

How GDPR Affects U.S. Companies: Channel-by-Channel Changes for Marketers

How GDPR Affects U.S. Companies: Channel-by-Channel Changes for Marketers

GA4 and Google Ads

  • Sign a DPA with Google
  • Enable opt-in consent
  • Use Google Consent Mode v2
  • Update privacy policy

Meta Pixel

  • Sign a DPA with Meta
  • Enable opt-in consent
  • Update privacy policy
  • Configure Meta Business Tools

Email Marketing

  • Determine legal basis
  • Sign a DPA with vendor and check transfer mechanism
  • Build opt-in consent flow (with clear Unsubscribe option)
  • Set internal processes

Here are practical recommendations for configuring consent mechanisms in marketing and analytics channels:

GA4 and Google Ads

Use a CMP like Cookiebot™ to wire up Google Consent Mode v2 and opt-in consent in Google Tag Manager, sign a DPA with Google for GDPR-compliant data transfer, and disclose the use of third-party tools like this in your privacy policy.

Meta Pixel

Consider whether you still need this tool, given the additional scrutiny it has attracted in the EU due to the data transfer mechanism it uses. If you need it, wire up this tag and its logic manually with a CMP like Cookiebot™ in Google Tag Manager after signing a DPA.

Email Marketing

Consider switching to EU-hosted services for lower transfer risk, or sign DPAs and verify that your existing service's transfer mechanisms are GDPR-compliant. Configure opt-in consent with a CMP like Cookiebot™ to tie form submissions to your website consent banner, and establish internal processes for fulfilling DSARs.

Why GDPR Compliance Matters in 2026

After the Trump v. Slaughter ruling reduced the FTC's independence on June 29, 2026, the risks increased for U.S. companies that need a reliable EU–U.S. transfer mechanism. As a third attempt to regulate transatlantic data flows, following the Court of Justice of the European Union's (CJEU) invalidation of the EU–U.S. Safe Harbor framework in 2015 and the EU–U.S. Privacy Shield in 2020, the DPF is likely to face greater scrutiny from EU counterparts going forward.

U.S. companies with GDPR-compliant mechanisms in place are advised to plan contingencies for the DPF, including being ready to switch to Standard Contractual Clauses, reinforce current measures, and monitor EU regulatory signals.

On July 31, 2026, the European Data Protection Board formally asked the European Commission to review the DPF's adequacy in light of the Trump v. Slaughter ruling. The framework remains in force for now, but the request signals that scrutiny is building.

For U.S. companies just considering GDPR compliance, it's a good moment to build stronger data protection architecture from the start.

Cookiebot CMP can serve as the bridge between your legal obligations and operational reality, supporting your compliance efforts across both GDPR and U.S. state regulations. With automated support, you can adjust your marketing and analytics operations as the legal environment changes.

Frequently asked questions

Yes, if they meet GDPR's territorial scope criteria under Art. 3 GDPR, for example, offering goods or services to, or monitoring the behavior of, individuals in the EU.

This applies regardless of whether the company has any physical presence, subsidiary, or servers in the EU: GDPR protects individuals based on their location at the time of processing, not their nationality or the company's location.

(Note: this covers EU GDPR specifically. The UK GDPR is a separate, though near-identical regime with its own territorial scope provision.)

Yes, if they meet the same territorial scope test. Unlike the CCPA, GDPR has no revenue or company-size threshold. A small U.S. business with a handful of EU customers, or one that runs analytics or advertising cookies tracking EU visitors, can fall within GDPR's scope just as much as a large enterprise. Company size only affects narrower obligations, such as the reduced record-keeping requirements available to businesses with fewer than 250 employees.

It depends on the specific activity. Art. 3(2) only brings a non-EU processor into GDPR's scope if the processing involves offering goods or services to, or monitoring the behavior of, individuals in the EU. Most routine government functions (visa processing, tax administration, benefits) don't meet that test.

Where an agency does run something like a public-facing service aimed at EU residents, Art. 3(2) can apply, except that Art. 2(2) GDPR separately excludes law-enforcement and national-security processing, which falls under the EU Law Enforcement Directive instead.

Yes. EU regulators can act against any EU-based assets, subsidiaries, or local operations, and can restrict a company's ability to process EU data or operate in the EU market.

As of August 2026, the DPF remains a valid EU-U.S. transfer mechanism, but its footing has weakened. Following the U.S. Supreme Court's Trump v. Slaughter ruling, the reduced independence of the FTC — the DPF's primary U.S. enforcement authority — undercuts the "essentially equivalent protection" the framework was built on, and the European Data Protection Board formally asked the European Commission to review the DPF's adequacy on July 31, 2026.

U.S. companies should be prepared to switch to Standard Contractual Clauses if the mechanism is suspended, which is possible given the precedents set when the CJEU invalidated both the EU-U.S. Safe Harbor framework (2015) and the EU-U.S. Privacy Shield (2020).