Regulation · Filed · London · 7 min read
GDPR Readiness for US Companies Serving European Customers
A concise operating framework covering lawful basis, data-transfer mechanics post-Schrems II, DPO thresholds, and the records US firms must produce on request.
By Cyber Inspect Editorial Board
When GDPR reaches across the Atlantic
A US company falls in scope of GDPR under Article 3(2) when it offers goods or services to individuals in the EU or monitors their behavior. Language, currency, and top-level domain are all relevant indicators regulators consider.
Six work-streams to run in parallel
- Article 30 records of processing activities — the regulator's first document request.
- Lawful basis mapping and, where consent is used, a verifiable capture mechanism.
- Data Protection Impact Assessments for high-risk processing.
- EU-US Data Privacy Framework certification or Standard Contractual Clauses with transfer risk assessments.
- Appointment of an EU representative under Article 27 where applicable.
- Data subject rights workflow with 30-day response SLA and audit trail.
The Schrems II reality
Standard Contractual Clauses alone are insufficient. Transfer Impact Assessments must document supplementary technical measures — typically encryption with keys held outside the destination jurisdiction — for transfers to the United States and other third countries.