GDPR
How does GDPR affect US companies?
GDPR can apply to a US company when its processing is connected with an EU/EEA establishment, or when it targets people there with goods or services or monitors their behaviour there. A US website’s mere accessibility in Europe is not enough. These conditions come from Article 3 of the GDPR.
For affected companies, GDPR compliance includes obligations appropriate to their role, such as:
Using an appropriate lawful basis and providing clear privacy information.
Respecting individual rights and applying security, retention and data minimisation rules.
Putting compliant contracts in place with processors.
Meeting breach notification duties. Controllers must notify the supervisory authority without undue delay and, where feasible, within 72 hours of awareness, unless the breach is unlikely to risk individuals’ rights and freedoms.
Appointing an EU representative where Article 27 requires one, and a data protection officer where the relevant criteria apply.
Transfers from the EU/EEA to a US company also need a valid transfer mechanism. The EU–US Data Privacy Framework covers participating commercial organisations; other transfers may require safeguards such as standard contractual clauses and the necessary assessments. Participation in the framework does not replace other GDPR obligations.
Türkçe
English