Does GDPR apply to my business if I'm not in the EU? (It depends on behaviour, not address)
Possibly — and it depends on your behaviour, not your address. Article 3 of the GDPR gives it extraterritorial reach: it applies to a business anywhere in the world that either targets EU customers or monitors the behaviour of people in the EU, with no EU office required. A company in Canada, Latin America or the United States can be fully in scope while never touching Europe. Merely being accessible from the EU isn’t enough — a local business serving locals probably isn’t targeting anyone — but two things pull you in. The first is targeting: offering your site in an EU language, pricing in euros, shipping or selling to the EU, running EU-aimed ads, or using a .eu or .de domain. The second, and the one that quietly catches ordinary small businesses, is monitoring: running analytics, cookies or behavioural tracking that observes EU visitors, because that counts as monitoring their behaviour whether you intended it or not. Enforcement against non-EU companies is real and accelerating — a €530 million TikTok fine, €30.5 million against the US firm Clearview, and now smaller fines against non-EU app makers for a missed EU representative. If you’re in scope you owe the core GDPR duties and, often forgotten, an EU representative under Article 27. The liberating flip side, and the thread through this whole cluster, is that the biggest trigger is the one you control: a site with no third-party tracking and cookieless analytics doesn’t monitor anyone, so it sidesteps the trigger that catches most small businesses. That’s how the sites we build reduce your exposure by construction. But we’re not lawyers, scope is fact-specific, and if you genuinely target or serve the EU you should get proper advice and, in most cases, appoint that representative.
It follows the visitor, not your address
The feature of the GDPR that surprises non-EU businesses is that it was written to reach them. Article 3 ties the law’s application not to where a company is established but to where the people it processes data about are located, so a controller or processor with no EU presence at all can be fully bound by it (GDPR.eu, 2026). The concept of “establishment” — an office, a subsidiary, staff — becomes essentially irrelevant for a foreign business; what matters is its relationship to people who are physically in the EU, and that includes anyone in the EU at the time, whether a citizen, a resident, or a visiting tourist (Wiley, 2026).
Article 3(2) sets out two ways a non-EU business is caught: offering goods or services to people in the EU, or monitoring their behaviour (Legiscope, 2026). Either one is enough on its own, and neither requires you to have wanted the regulation to apply. This is the detailed answer to the question our pillar on respecting visitor privacy raises — that privacy law follows the person — and it’s worth understanding both triggers precisely, because they behave very differently in practice. As always here, this is orientation rather than legal advice; your specific exposure is a question for a qualified professional.
The targeting test: are you courting the EU?
The first trigger, offering goods or services, turns on intent, and the key relief is that mere accessibility doesn’t count. A website being reachable from Europe is not, by itself, “offering” anything to Europe; regulators look for evidence that you set out to reach EU customers (Prighter, 2026). The recognised signs of that intent are concrete: presenting your site in an EU language beyond your own, displaying prices in euros or other EU currencies, shipping goods or offering services to EU locations, running marketing aimed at EU users, or using EU country-code domains such as .de, .fr or .eu (Prighter, 2026).
The classic illustration is a small local business. A golf course in Manitoba focused entirely on its own area, which EU residents only occasionally stumble across, is not realistically in European regulators’ crosshairs under the targeting test — it isn’t courting anyone in the EU (GDPR.eu, 2026). The GDPR also excludes purely personal or household activity, applying only to professional or commercial processing (GDPR.eu, 2026). So if your commerce and marketing genuinely point at your own region, the targeting trigger probably doesn’t reach you — but the moment you price in euros, ship to Berlin, or advertise into France, it does.
The monitoring trigger catches everyone — and how to dodge it
The second trigger is the one that quietly pulls in businesses that would never consider themselves “European.” Article 3(2)(b) applies whenever you monitor the behaviour of people in the EU, and monitoring is defined broadly: tracking users through cookies or device fingerprinting, profiling people for personalised ads, and — critically — using analytics tools to observe how EU visitors interact with your site all qualify (Prighter, 2026). That means an otherwise-local business can be dragged into GDPR’s scope for nothing more than running behavioural analytics on a site that EU residents happen to visit (Pandectes, 2026).
Here’s the useful part, and it’s the through-line of this entire cluster: monitoring is the trigger you have the most direct control over. A site that sets no tracking cookies and uses cookieless analytics — which measures traffic in aggregate without profiling anyone — is not monitoring individuals in the Article 3(2)(b) sense, so it doesn’t trip the trigger that catches most small businesses in the first place. The same architectural choice that lets you skip the cookie banner also narrows your GDPR exposure, because you can’t be caught for monitoring behaviour you never collect. You can’t as easily switch off the targeting trigger if your business genuinely sells into Europe — but you can almost always switch off the monitoring one.
If you’re in scope: the duties, including the one everyone forgets
Falling within GDPR’s scope brings the full set of substantive obligations: a lawful basis for processing, clear privacy notices, honouring data-subject rights such as access, rectification and erasure, data minimisation and purpose limitation, and a breach-response plan (Pandectes, 2026). Those are the duties most businesses expect. The one they routinely miss sits in Article 27: a non-EU business in scope, with no EU establishment, generally must appoint an EU representative — a person or company in an EU member state who serves as the contact point for regulators and data subjects, with their details published in your privacy policy (GDPR Info, 2026).
There’s a narrow exemption where your EU processing is only occasional, small-scale and low-risk, but continuous or core processing of EU data usually requires the representative regardless of whether you’re a controller or a processor (GDPR Info, 2026). One structural point sharpens why this matters: a non-EU business without an EU establishment falls outside the GDPR’s “one-stop-shop”, so it isn’t answerable to a single lead authority but is exposed to enforcement by any of the 27 member-state regulators whose residents it touches (Captain Compliance, 2026). Appointing a representative doesn’t shield you from enforcement, but failing to appoint one is now its own violation.
Enforcement is real, and accelerating
The assumption that distance provides safety has been tested and found wanting. EU authorities have levied major penalties on non-EU companies with no European establishment: a €530 million fine on TikTok in 2025 over data transfers, and €30.5 million on the US firm Clearview AI for collecting biometric data without a lawful basis (Legiscope, 2026). France’s CNIL has fined a US company purely over cookie practices affecting EU visitors, confirming that Article 3(2) bites without any EU office (GDPR Info, 2026).
The trend below the headlines matters more for a small business. Regional authorities have started issuing smaller, documented fines against non-EU companies — including app makers — specifically for failing to appoint an Article 27 representative, creating precedent that similar operators can no longer plead ignorance of (Captain Compliance, 2026). The EU logged more than 1,200 formal enforcement decisions in the first quarter of 2026 alone, with non-EU organisations squarely among the targets and maximum penalties reaching €20 million or 4% of global turnover (Legiscope, 2026). Enforcement is no longer aspirational; it’s operational.
The Canadian and Latin American angle
For a business in Canada or Latin America, the headline is simply that your location doesn’t decide the question — your behaviour does, and the same logic recurs closer to home. Canada’s own PIPEDA governs commercial handling of personal data, and Canada holds only limited EU adequacy, recognised for private-sector organisations under PIPEDA, which is what lets EU data flow to those Canadian businesses without extra safeguards (ComplyJet, 2026). Brazil’s LGPD mirrors much of the GDPR’s structure, and the broader pattern is convergence: more countries are adopting GDPR-style laws, so the habits that satisfy one increasingly satisfy the others (Legiscope, 2026).
The practical upshot is that “we’re an ocean away, so we’re fine” is a weaker assumption every year, on two fronts at once. If you court EU customers you can be reached under the targeting trigger; if you track any visitors you can be reached under the monitoring trigger; and even setting the EU aside, your own jurisdiction’s law and your customers’ expectations point the same direction. A privacy-minimal posture is the one bet that pays off under every regime simultaneously, which is exactly why our pillar frames collecting less as the move that reduces risk everywhere at once.
Why our builds reduce your exposure — and when to get a lawyer
Stated plainly as our position: the sites we build reduce your GDPR exposure by construction, without pretending to be legal advice. Because we build with no third-party tracking and cookieless analytics, a site we deliver doesn’t monitor visitors in the Article 3(2)(b) sense, which removes the single trigger most likely to pull an otherwise-local business into scope. That’s a genuine, architectural reduction in risk — not a certificate of compliance, but one large category of exposure closed off at the source, alongside the faster pages and absent cookie banner that the same choices produce.
The honest gate is firm and has two parts. First, we’re not lawyers, and territorial scope is genuinely fact-specific — whether you target the EU, whether an exemption applies, whether you need an Article 27 representative are questions a qualified professional should answer for your situation, not ones an architecture can settle. Second, if your business does target or serve the EU, minimising tracking narrows but doesn’t erase your obligations: you’ll still owe privacy notices, data-subject rights and, in most cases, that representative, and we’ll tell you so rather than imply a clean build covers the legal work. What a good build does is shrink the surface you have to defend; what a lawyer does is confirm what’s left. Both are worth having.
Scope follows behaviour; shrink the behaviour
Step back and the whole question resolves into a principle you can act on: GDPR’s reach is a function of what you do, so the way to reduce it is to do less of what triggers it. You can’t easily stop targeting the EU if selling there is your business — but you can almost always stop monitoring, and monitoring is the trigger that catches the businesses least prepared for it. Removing third-party tracking and choosing cookieless analytics does more than tidy up a site; it closes the most common door through which a Canadian or Latin American business walks, unaware, into European regulatory scope.
So the useful sequence is: work out honestly whether you target the EU, audit whether you monitor anyone, remove the tracking you don’t need, and then get professional advice on whatever genuine exposure remains — including an EU representative if you’re in scope. Do that and “does GDPR apply to me” stops being a source of low-grade dread and becomes a manageable, mostly-answered question — the same “do it right once” logic that runs through our pillar on respecting visitor privacy and the rest of this cluster, where the cheapest compliance is always the data you never collected.
Frequently asked
- Does GDPR apply to my business if I'm based outside the EU?
- It can, and it depends on what you do rather than where you're registered. Article 3 of the GDPR gives it extraterritorial scope: it applies to a business anywhere in the world if that business either offers goods or services to people in the EU, or monitors the behaviour of people in the EU. No EU office, employees or physical presence is required. So a company in Canada, Brazil or the United States can be fully within GDPR's scope while never setting foot in Europe. Merely having a website that EU residents happen to visit isn't enough on its own — but targeting EU customers, or tracking EU visitors, is. This is general orientation, not legal advice.
- What is the 'targeting' test under GDPR?
- It's the standard for whether you're 'offering goods or services' to people in the EU under Article 3(2)(a). Simply being accessible from Europe doesn't count; regulators look for evidence that you intended to reach EU customers. Signs include offering your site in an EU language, displaying prices in euros or other EU currencies, shipping products or providing services to EU locations, running ad campaigns aimed at EU users, or using EU country domains like .de, .fr or .eu. A genuinely local business that happens to be visible worldwide but serves only its own region is usually not targeting the EU — but the moment your marketing or commerce reaches toward Europe, you likely are.
- What counts as 'monitoring' EU visitors?
- Tracking or profiling the online behaviour of people in the EU, under Article 3(2)(b). This is broader and easier to trigger than most owners expect: using analytics that observe how EU visitors interact with your site, setting tracking cookies, fingerprinting devices, profiling people for personalised ads, or recording browsing habits for fraud or risk scoring all qualify. The practical consequence is that an otherwise-local business can be pulled into GDPR's scope simply by running behavioural analytics on a site that EU residents visit. It's also the trigger you have the most direct control over — a site that doesn't track visitors doesn't monitor them.
- Do non-EU businesses need an EU representative?
- Often, yes, and it's the most overlooked obligation. Under Article 27, a business that falls within GDPR's scope but has no establishment in the EU generally must appoint an EU representative — a person or company based in an EU member state who acts as a contact point for regulators and for the people whose data you process, with their details listed in your privacy policy. There's an exemption for processing that's only occasional, small-scale and low-risk, but continuous or core processing of EU data usually requires one. Regulators have begun issuing fines specifically for failing to appoint a representative, so it shouldn't be treated as optional if you're in scope.
- Is GDPR actually enforced against companies outside the EU?
- Yes, and increasingly so. EU regulators have imposed major penalties on non-EU companies with no European establishment — a €530 million fine on TikTok in 2025 and €30.5 million on the US firm Clearview AI, among others — and France's CNIL has penalised a US company purely over cookie practices affecting EU visitors. Beyond the headlines, regional authorities are now issuing smaller, documented fines against non-EU app makers for missing an EU representative, and the EU reported over 1,200 formal enforcement decisions in the first quarter of 2026 alone. Because there's no single lead authority for a non-EU business, any of the 27 member-state regulators can act.