GDPR for companies with EU users

GDPR applies based on whose data you process, not where your company is incorporated. If you have EU customers or EU employees, the regulation reaches you whether you're based in Champaign or California.

Book a GDPR Snapshot Assessment

Who this applies to

Any organization, anywhere, that processes the personal data of people located in the EU, whether that's customers, employees, or website visitors. Fines scale with global revenue, which is why GDPR gets board-level attention even at companies with no EU office.

What GDPR actually requires

Lawful basis & consent

Every use of personal data needs a documented lawful basis, and consent (where that's the basis) has to be specific, informed, and easy to withdraw.

Data subject rights

Access, correction, deletion, and portability requests have real deadlines. You need a working process, not just a privacy policy that promises one.

Records & DPIAs

A record of processing activities (ROPA), and a Data Protection Impact Assessment for anything high-risk, including most AI systems that process personal data.

Breach notification

72 hours to notify your supervisory authority once you're aware of a qualifying breach. That clock starts whether or not you're ready.

How we help

Snapshot Assessment

Data mapping and gap analysis against your actual processing activities, with a prioritized remediation plan. $9,500, 2 to 3 weeks.

Program build-out

ROPA documentation, DPIA templates, consent flows, and international transfer mechanisms (Standard Contractual Clauses) that match how your systems actually move data.

Breach readiness

A tested incident response plan that hits the 72-hour window without a scramble to figure out who has authority to notify.

We provide technical and operational compliance support. For a Data Protection Officer designation or formal legal opinions, we work alongside your privacy counsel.

Frequently asked questions

We're a US company with a few EU customers. Does GDPR still apply?

Yes. GDPR is triggered by processing the data of people in the EU, not by where your company is based or how many EU customers you have.

Do we need a Data Protection Officer?

It depends on your scale and the type of data you process. We'll help you determine whether a formal DPO is required or whether a documented privacy program without one is sufficient.

How does GDPR intersect with our AI governance work?

Most AI systems that touch personal data trigger a DPIA requirement, and the EU AI Act adds its own layer on top for higher-risk systems. We handle both together so you're not building two separate paper trails.

Find out what GDPR actually requires of you

A short conversation covers your data flows, current exposure, and the fastest path to a defensible program.

Schedule a consultation