β‘ Quick Facts
"I Am a Small US Business. Does GDPR Apply to Me?"
Probably yes. GDPR applies to any organization anywhere in the world if you:
- Sell goods or services to people in the EU/UK β even if they come to you. If your website accepts orders with a European shipping address, you are covered.
- Monitor the behavior of people in the EU/UK β which includes analytics cookies, tracking pixels, and any form of behavioral advertising targeting European visitors.
- Have a website accessible from Europe with analytics or cookies enabled β the "monitoring" threshold is very low.
The key distinction: GDPR does NOT apply just because someone in Europe can see your website. It applies when you are actively targeting or monitoring European individuals. If you price in euros, ship to Europe, have a .eu domain, or run ads targeting European countries, you are clearly covered. If you are a purely local US business with no European customers and no analytics, GDPR likely does not apply.
Need a Privacy Policy? Start With Our Toolkit
Our compliance toolkit includes a customizable privacy policy template that addresses GDPR requirements for small businesses.
View Compliance Toolkit βThe 7 Core GDPR Principles
1. Lawfulness, Fairness, and Transparency
You must have a legal basis for collecting and processing personal data. The most common for small businesses: consent (cookie banners, email signups), contractual necessity (processing an order), and legitimate interest (fraud prevention). You must be transparent about what you do with data β this is what privacy policies are for.
2. Purpose Limitation
Collect data for specified, explicit, and legitimate purposes only. If you collect email addresses for order confirmation, you cannot also add them to your marketing newsletter without separate consent.
3. Data Minimization
Only collect the data you actually need. You do not need someone's date of birth to send them a newsletter. Every extra data field increases your exposure if breached. Ask yourself: "Do I really need this?"
4. Accuracy
Take reasonable steps to ensure personal data is accurate and up to date. Provide a way for people to correct their information.
5. Storage Limitation
Do not keep personal data longer than necessary. If someone has not ordered from you in 5 years and is not subscribed to your newsletter, delete their data. This also reduces your exposure in a breach.
6. Integrity and Confidentiality (Security)
Use appropriate technical and organizational measures to protect personal data. Encryption, access controls, and regular security updates are not optional β they are legal requirements under GDPR.
7. Accountability
You must be able to demonstrate compliance. Maintain records of your processing activities, consent logs, and data protection impact assessments where required. If the regulator asks, "show me" β you need to be able to.
Cookie Consent Setup Guide
Learn how to set up a GDPR-compliant cookie banner with Google Consent Mode v2. Part of our compliance toolkit.
View Setup Guide βPractical Steps for Small Business GDPR Compliance
- 1 Post a clear, complete privacy policy.
Your policy must state: what data you collect, why, the legal basis, who you share it with, how long you keep it, and what rights people have. It must be written in plain language. Link it from every page of your website.
- 2 Implement a cookie consent banner.
If you use any non-essential cookies (analytics, advertising, social media embeds), you need a consent banner that blocks those cookies until the user agrees. Pre-checked boxes are not valid consent.
- 3 Know what to do in a data breach.
Under GDPR, you must notify the relevant data protection authority within 72 hours of becoming aware of a breach. If the breach poses a high risk to individuals, you must also notify the affected individuals without undue delay. Have a plan before you need it.
- 4 Be ready for Data Subject Access Requests (DSARs).
Anyone can ask what data you hold about them, request corrections, or demand deletion ("right to be forgotten"). You must respond within 30 days. Set up a process β even a simple one β before you receive a request.
- 5 Get consent right.
Consent must be freely given, specific, informed, and unambiguous. That means: no pre-checked boxes, separate consent for separate purposes, clear language, and easy withdrawal (unsubscribe links must work immediately).
UK GDPR: Same Rules, Different Regulator
Since Brexit, the UK has its own version of GDPR (the "UK GDPR") enforced by the Information Commissioner's Office (ICO). The requirements are nearly identical. If you deal with both EU and UK customers, you need to comply with both β but a single compliance program covers both frameworks since they are so similar. The main practical difference: you may need a UK representative if you have no UK presence but actively target UK customers.