Regulation · Filed · London · 7 min read

GDPR Readiness for US Companies Serving European Customers

A concise operating framework covering lawful basis, data-transfer mechanics post-Schrems II, DPO thresholds, and the records US firms must produce on request.

By Cyber Inspect Editorial Board

When GDPR reaches across the Atlantic

A US company falls in scope of GDPR under Article 3(2) when it offers goods or services to individuals in the EU or monitors their behavior. Language, currency, and top-level domain are all relevant indicators regulators consider.

Six work-streams to run in parallel

  • Article 30 records of processing activities — the regulator's first document request.
  • Lawful basis mapping and, where consent is used, a verifiable capture mechanism.
  • Data Protection Impact Assessments for high-risk processing.
  • EU-US Data Privacy Framework certification or Standard Contractual Clauses with transfer risk assessments.
  • Appointment of an EU representative under Article 27 where applicable.
  • Data subject rights workflow with 30-day response SLA and audit trail.

The Schrems II reality

Standard Contractual Clauses alone are insufficient. Transfer Impact Assessments must document supplementary technical measures — typically encryption with keys held outside the destination jurisdiction — for transfers to the United States and other third countries.