Compliance & regulations
Does GDPR apply to my business if we're outside Europe?
Reviewed by the Privacy Horizon team · Last reviewed
Quick answer
Yes, the GDPR can apply to your business even if you have no presence in Europe. Its reach is extraterritorial: it applies to any organization that offers goods or services to people in the EU or EEA, or that monitors their behaviour, regardless of where the company is located. If EU residents are among your customers or website users in a targeted way, you likely have GDPR obligations — including a lawful basis for processing, honouring individual rights, and in many cases appointing an EU representative.
On this page
How the GDPR reaches outside the EU
The GDPR applies based on whose data you process and what you do with it, not just where you are. Article 3 extends it to organizations outside the EU/EEA in two main situations: when you offer goods or services to individuals in the EU (even for free), and when you monitor the behaviour of individuals in the EU (for example, tracking and profiling website visitors).
Simply having a website that EU residents can reach is not automatically enough — the question is whether you target or intentionally serve people in the EU. Accepting EU currencies, shipping there, using EU languages, or running EU-focused marketing are signals that you do.
What you need to do if it applies
- Establish a lawful basis for each processing activity (such as consent or legitimate interests).
- Provide clear privacy information and honour individuals' rights (access, deletion, objection, portability, and more).
- Keep records of processing and apply data-protection-by-design and by-default.
- Appoint an EU/EEA representative where required, and a Data Protection Officer if your processing meets the threshold.
- Ensure a valid transfer mechanism for moving EU personal data outside the EEA.
Why it matters
The GDPR is enforced with significant penalties, and it has shaped privacy laws worldwide. Even where it does not strictly apply, aligning with its principles is a strong baseline that helps you meet other regimes — including Canada's PIPEDA — and signals trustworthiness to customers.
Frequently asked questions
Not automatically. The test is whether you target or intentionally offer goods or services to people in the EU, or monitor their behaviour. Incidental access by an EU visitor is different from marketing to, selling to, or tracking EU residents.
Compliance with PIPEDA does not automatically equal GDPR compliance — the GDPR imposes additional and sometimes stricter requirements. If both apply, you need to meet each; fortunately, much of the underlying work overlaps.
Keep exploring
All Compliance & regulationsDoes HIPAA apply to my software or business?
HIPAA applies to covered entities and the business associates that handle protected health information (PHI) on their behalf. Find out whether that includes your business.
ReadCybersecurity basicsWhat's the difference between data privacy and cybersecurity?
Data privacy governs how personal information is collected, used, and shared; cybersecurity protects information and systems from threats. Here's how they differ and overlap.
ReadCompliance & regulationsWhat is a HIPAA security risk assessment, and do you need one?
What is a HIPAA security risk assessment, and do you need one? Learn what the assessment covers, who must do it, what's involved, and how to scope it.
ReadCompliance & regulationsWhat is PIPEDA, and does it apply to my business?
What is PIPEDA, and does it apply to my business? A plain-language guide to Canada's federal private-sector privacy law: who it covers, exemptions, and what you must do.
ReadCompliance & regulationsHow do we prepare for a customer security questionnaire?
Customer security questionnaires (SIG, CAIQ, and custom) gate enterprise deals. Prepare with a control framework, ready evidence, a reusable answer library, and an owner.
ReadCompliance & regulationsWhat is a cybersecurity risk assessment, and how often should we do one?
A cybersecurity risk assessment identifies threats to your data and systems and how to manage them. Do one at least annually and after any significant change.
Read