Guide

Who Must Comply With GDPR (Even Outside the EU)

GDPR's extraterritorial reach, when a company based outside the EU is still in scope, and the controller versus processor distinction.

6 min read

One of the most misunderstood things about GDPR is who it applies to. A common assumption is that it only affects European companies. It does not. GDPR was written to follow the data, so a company with no office in Europe can still be fully in scope.

The Two Triggers

GDPR applies to your organization if either is true:

  • You are established in the EU or UK. If you have operations there, processing personal data in that context is covered, wherever the data subjects are.
  • You target or monitor people in the EU or UK. Even with no EU presence, you are in scope if you offer goods or services to people there (for example, a website that sells to EU customers or prices in euros) or if you monitor their behavior (for example, tracking or profiling EU visitors).

That second trigger is why so many US companies are subject to GDPR: selling to or tracking EU users is enough.

Controller vs Processor

GDPR splits responsibility between two roles, and which one you are shapes your obligations:

  • A controller decides why and how personal data is processed. If it is your product and your customers, you are usually the controller of their data.
  • A processor processes data on a controller's behalf. A vendor that handles data for you, under your instructions, is typically a processor.

Most companies are controllers for their own customer data and processors for the data their customers put into their product. You can be both at once, for different data, which is why the distinction is worth getting right early.

What Being In Scope Means

If you are in scope, you need a legal basis for processing, you have to honor data subject rights, and, above a threshold or for certain processing, you may need records of processing and a data protection officer. The practical takeaway: if you handle the personal data of people in the EU or UK, assume you are in scope and build accordingly.

How Concord Fits

Concord Privacy is built for exactly this cross-border reality: geo-aware consent, configurable privacy request handling, and data mapping, so a company serving EU and non-EU users can meet each region's rules from one platform.

Get Started

Run Your Privacy Program on One Platform

Concord brings consent, privacy requests, data mapping, and policy management together, so a rights request is a workflow, not a fire drill.