Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Compliance & regulations

Does GDPR apply to my business if we're outside Europe?

Reviewed by the Privacy Horizon team · Last reviewed

Quick answer

Yes, the GDPR can apply to your business even if you have no presence in Europe. Its reach is extraterritorial: it applies to any organization that offers goods or services to people in the EU or EEA, or that monitors their behaviour, regardless of where the company is located. If EU residents are among your customers or website users in a targeted way, you likely have GDPR obligations — including a lawful basis for processing, honouring individual rights, and in many cases appointing an EU representative.

On this page

How the GDPR reaches outside the EU

The GDPR applies based on whose data you process and what you do with it, not just where you are. Article 3 extends it to organizations outside the EU/EEA in two main situations: when you offer goods or services to individuals in the EU (even for free), and when you monitor the behaviour of individuals in the EU (for example, tracking and profiling website visitors).

Simply having a website that EU residents can reach is not automatically enough — the question is whether you target or intentionally serve people in the EU. Accepting EU currencies, shipping there, using EU languages, or running EU-focused marketing are signals that you do.

What you need to do if it applies

  • Establish a lawful basis for each processing activity (such as consent or legitimate interests).
  • Provide clear privacy information and honour individuals' rights (access, deletion, objection, portability, and more).
  • Keep records of processing and apply data-protection-by-design and by-default.
  • Appoint an EU/EEA representative where required, and a Data Protection Officer if your processing meets the threshold.
  • Ensure a valid transfer mechanism for moving EU personal data outside the EEA.

Why it matters

The GDPR is enforced with significant penalties, and it has shaped privacy laws worldwide. Even where it does not strictly apply, aligning with its principles is a strong baseline that helps you meet other regimes — including Canada's PIPEDA — and signals trustworthiness to customers.

Frequently asked questions

Not automatically. The test is whether you target or intentionally offer goods or services to people in the EU, or monitor their behaviour. Incidental access by an EU visitor is different from marketing to, selling to, or tracking EU residents.

Compliance with PIPEDA does not automatically equal GDPR compliance — the GDPR imposes additional and sometimes stricter requirements. If both apply, you need to meet each; fortunately, much of the underlying work overlaps.

How Privacy Horizon can help

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.