GDPR does not apply to every American business with a website. It applies if you deliberately offer goods or services to people in the EU, or monitor their behaviour. A site that a European can reach is not the same as a site aimed at Europeans. If you do fall in scope, the obligations are real but manageable for a small business.
Every few years a wave of panic goes through American small business about GDPR, usually triggered by a consultant quoting the maximum fine. The maximum fine is real. It is also almost entirely irrelevant to a plumbing company in Tampa.
The useful question is narrow: does the regulation reach you at all? For most US small businesses the answer is no. For some it is clearly yes, and those businesses are often the ones not worrying about it.

The short answer on GDPR for US small business
For the majority of US small businesses, GDPR does not apply. The regulation reaches a company established outside the EU only where that company deliberately offers goods or services to people in the EU, or monitors their behaviour there. Being reachable from Europe is not the same as targeting Europe, and the distinction is the whole game. What follows is where the line actually falls, and what to do if you find yourself on the wrong side of it.
The test is targeting, not geography
GDPR reaches a business outside the EU in two situations. The first is offering goods or services to people in the EU. The second is monitoring the behaviour of people in the EU.
The word doing the work is offering. Having a website that a European can load is not offering them anything, any more than a shop in Ohio is targeting Belgium because a Belgian could theoretically walk in.
Regulators look at intent, and the signals are practical: do you price in euros, do you translate the site into European languages, do you ship to EU addresses, do you mention EU customers in your marketing, do you run ads targeted at EU countries, is there an EU phone number.
One or two of those may mean nothing. Several together mean you are targeting.
The monitoring limb catches more people
This is the part that surprises businesses, and it is where a genuinely US-focused company can still find itself in scope.
Monitoring means tracking people in the EU to profile or analyse them. Behavioural advertising pixels and cross-site tracking are the clearest examples.
Plain server logs or basic aggregate analytics are a weaker case. Remarketing pixels that follow an EU visitor around the internet are a much stronger one, and most small business sites are carrying at least one without anybody having decided to.
If you have never audited what scripts your website loads, that is the most useful hour you could spend on this whole subject — and it will probably also make your site faster.
Who is genuinely in scope
A few clear cases. If you ship physical products to EU addresses, you are offering goods there. If you sell software or digital services to EU customers, same. If you employ or contract people in the EU, their employee data is personal data and you are processing it. If you run EU-targeted advertising, you are both targeting and usually monitoring.
And a few clear non-cases. A local service business whose customers are all within driving distance is not in scope because a European loaded the homepage. Nor is a US-only e-commerce store that does not ship internationally. Nor is a business whose only EU contact is one customer who found them and asked to buy.
What compliance actually involves
If you are in scope, the work is more mundane than the headlines suggest.
Know what you hold. Write down what personal data you collect, where it lives, who can see it, and how long you keep it. Most small businesses have never done this, and it is the foundation for everything else.
Have a lawful basis. Consent is one of six, and it is not always the right one. Fulfilling a contract, complying with a legal obligation and legitimate interests cover a great deal of ordinary business activity.
Get consent properly where you need it. Freely given, specific, informed, unambiguous, and as easy to withdraw as to give. Pre-ticked boxes and cookie walls that only offer “accept” do not qualify.
Publish a privacy notice people can read. Plain language, saying what you collect, why, who you share it with and what rights people have.
Be able to answer requests. People can ask for a copy of their data, ask you to correct it, and in many cases ask you to delete it. You generally have a month. This is much easier if you did the first step.
Have a breach plan. Serious breaches must be reported to a supervisory authority within 72 hours of becoming aware. That deadline is the single hardest one to meet without having thought about it in advance.
The vendor question
Your obligations follow your data to everyone you hand it to: your host, your email provider, your CRM, your email marketing platform.
You need a data processing agreement with each of them, and you need to know where they store the data. This is a real reason to keep your stack small. Four vendors means four agreements to obtain, review and keep current; one vendor means one.
LiberationTek publishes a data processing addendum and a GDPR page, and our infrastructure is in the United States, which is itself a fact you have to disclose and document rather than hide.
What about US state privacy laws
Here is the part most GDPR articles leave out, and for an American small business it usually matters more.
California, Virginia, Colorado, Connecticut, Utah, Texas and a growing list of other states have their own consumer privacy laws. Their thresholds differ, and many are based on revenue or the number of consumers whose data you process, which means a purely domestic business can be in scope without any European dimension at all.
The practical consequence is encouraging: the work overlaps heavily. Knowing what data you hold, having a readable privacy notice, honouring deletion requests and keeping vendor agreements serves all of them. Do the groundwork once and you are most of the way to compliance with laws you have not read yet.
What not to do
Three common mistakes, in rough order of how often we see them.
Do not paste a cookie banner on and call it done. A banner that sets tracking cookies before anyone clicks anything is worse than none: it documents that you knew consent was required and collected it improperly.
Do not copy another company’s privacy policy. It describes their data practices, not yours. A policy that does not match reality is evidence against you rather than protection.
Do not assume you are exempt because you are small. GDPR has no small business exemption. What it has is a proportionality principle: what is expected of a six-person firm is not what is expected of a bank. That is a much better argument than pretending the rules do not exist.

Frequently asked questions
Does GDPR apply to my US small business?
Only if you deliberately offer goods or services to people in the EU, or monitor their behaviour. Simply having a website a European can load does not put you in scope. The signals regulators look at are practical: pricing in euros, translating the site, shipping to EU addresses, running EU-targeted ads, listing an EU phone number. One of those on its own may mean nothing; several together mean you are targeting.
What counts as monitoring EU visitors?
Tracking people in order to profile or analyse them — behavioural advertising pixels and cross-site tracking are the clearest cases. Plain server logs and basic aggregate analytics are a much weaker case. The practical risk for small businesses is carrying a remarketing pixel nobody remembers installing, which is why auditing what scripts your site loads is worth an hour of anyone’s time.
Do I need a cookie banner?
Only if you are in scope and you set non-essential cookies. And if you do use one, it has to work properly: no cookies set before consent, a refuse option as easy as accept, and no pre-ticked boxes. A banner that sets tracking cookies the moment the page loads is worse than having none, because it documents that you knew consent was required and collected it improperly.
What are the actual fines for a small business?
The headline maximum is the figure consultants quote, and it is not what a small business faces. Enforcement against small companies is usually corrective rather than punitive: an order to change practice, sometimes a modest fine, and it typically starts with a complaint from an individual rather than a regulator sweep. The realistic risk is the cost of responding, not the theoretical ceiling.
Do I need an EU representative?
Organisations outside the EU that are in scope generally have to appoint a representative in the EU, with limited exemptions for occasional, low-risk processing that does not involve sensitive data. If you are seriously in scope — shipping there, employing there, advertising there — this is worth a conversation with a lawyer rather than a blog post.
Does using a US host break GDPR?
No. Transferring data outside the EU is permitted with appropriate safeguards, and this is a documentation question rather than a prohibition. What you must do is know where the data sits, disclose it, and have the right agreements in place with your provider. Pretending your data is somewhere it is not is the problem, not the location itself.
What about California and other state laws?
For most American small businesses these matter more than GDPR. California, Virginia, Colorado, Connecticut, Utah, Texas and others have their own consumer privacy laws with their own thresholds, and a purely domestic business can be in scope. The good news is the groundwork overlaps almost entirely: know what you hold, publish an accurate privacy notice, honour deletion requests, keep vendor agreements.
What actually happens if you get it wrong
The number quoted in every GDPR scare piece is 20 million euro or 4% of global annual turnover, whichever is higher. It is a real ceiling written into Article 83. It is also the ceiling, and ceilings are not averages.
Article 83 requires that a fine be effective, proportionate and dissuasive, and it lists what a supervisory authority must weigh: the nature and gravity of the infringement, whether it was negligent or deliberate, what you did to mitigate it, your degree of responsibility, whether you have previous infringements, how well you cooperated, and how the authority found out. A six-person company that responded quickly to a complaint is not in the same position as a data broker that ignored one.
For a US company with no EU establishment, there is also a practical question of reach. A European supervisory authority can issue a decision against a non-EU controller, and under Article 27 most in-scope non-EU controllers are required to appoint a representative in the Union. Enforcing a monetary penalty against a company with no EU assets, no EU entity and no EU bank account is a slower and less certain matter, and authorities have limited appetite for that fight against very small businesses.
None of that is a reason to ignore the regulation, and it is emphatically not legal advice. It is a reason to keep the risk in proportion. For a genuinely small US business, the realistic exposure is not a headline fine. It is an individual complaint that produces a letter, a period of correspondence you are not equipped for, and a demand to delete data you cannot easily locate. The work described above is mostly about being able to answer that letter in a week rather than a quarter.
The second realistic exposure is commercial rather than regulatory. If you sell to European businesses, their procurement process will ask how you handle personal data long before any regulator does. Being unable to answer loses the deal. That happens far more often than enforcement does.
A practical checklist for GDPR for US small business owners
If you have worked through the scope test and concluded the regulation reaches you, this is the order to do things in. It is deliberately short.
Write down what you collect and why. Not a formal record of processing activities to begin with, just an honest list: form submissions, email marketing, analytics, support tickets, invoices, whatever a CRM holds. Most small businesses discover two or three collection points nobody remembered. You cannot honour a deletion request for data you have forgotten you hold.
Decide your lawful basis for each one, once. Contract covers what you need to deliver what someone bought. Legitimate interest covers a good deal of ordinary business operation, provided you can articulate the interest and show you considered the other person. Consent is the right basis for marketing email and for non-essential cookies, and it has to be a positive action rather than a pre-ticked box or an implied agreement from continued browsing.
Rewrite the privacy notice so it is true. The most common defect is not an absent notice, it is an inherited template describing tools the business does not use and omitting the ones it does. Name the actual categories of data, the actual purposes, the actual third parties, and the actual retention periods. If you cannot say how long you keep something, that is the finding, not the notice.
Build the deletion path before anyone asks. Work out, concretely, how you would remove one person from every system you listed in step one. Write the steps down. One month is the response deadline and it passes quickly when the answer involves a tool nobody has the login for.
Get processing terms from your vendors. Your email platform, CRM, analytics, helpdesk and host are all processors acting on your instructions. Reputable providers publish a data processing addendum you can accept without negotiation. Collect them in one folder. Our own data processing addendum is published for exactly this reason.
Fix the cookie banner. Non-essential cookies and trackers require consent before they load, not after. A banner that sets analytics on page load and then asks permission is worse than no banner, because it documents the violation.
Decide who handles a breach, today. Seventy-two hours from awareness is not long enough to also be deciding who is in charge. One named person, one written sequence, one list of who to call.
That is the whole programme for a small business. It is a few days of work, most of it writing things down rather than buying anything, and nearly all of it is equally useful for the US state privacy laws that are far more likely to apply to you than GDPR is.
Sources
The territorial-scope test described above is set out in the regulation itself and elaborated by the EU’s own supervisory body. If you are assessing your exposure, read the primary material rather than a vendor summary of it.
- Regulation (EU) 2016/679 (GDPR), official consolidated text — EUR-Lex. Article 3 is the scope provision.
- Guidelines 3/2018 on the territorial scope of the GDPR — European Data Protection Board. The targeting and monitoring criteria in detail.