Skip to content
Patrick Webby

Insights

May 18, 2026

GDPR Basics for U.S. Small Businesses with EU Customers

GDPR isn't just a European problem. If your site collects data from EU or UK visitors, here's what actually applies to a US-based small business.

GDPR Basics for U.S. Small Businesses with EU Customers

A lot of US small business owners assume GDPR doesn’t apply to them because they’re not based in Europe. That’s not quite how it works — GDPR applies based on whose data you’re collecting, not where your business is registered. If you have visitors, customers, or newsletter subscribers in the EU or UK, some of it likely applies to you.

When GDPR applies to a US business

Generally, GDPR is relevant if your site:

  • Is reasonably accessible to and used by people in the EU/UK, and
  • Collects personal data from them — through a contact form, account creation, email signup, or e-commerce checkout

It doesn’t take much. A single EU customer who places an order counts. A newsletter signup form open to any visitor counts.

The parts that matter most for a small business

You don’t need an enterprise compliance program, but a few basics cover most of the real risk:

  • A real privacy policy that says what you collect, why, and who you share it with — not a boilerplate page copied from another site
  • Cookie and tracking disclosure, especially for analytics and advertising tools that set cookies before the visitor has made a choice
  • A way to honor deletion requests — if someone in the EU asks you to delete their data, you need a process, even if that process is “email us and we handle it manually”
  • Basic vendor awareness — knowing which third-party tools (email platforms, analytics, payment processors) also touch that data

What this looks like in practice

For most small businesses, GDPR readiness is less about legal drafting and more about configuration: making sure your cookie consent tool actually blocks tracking scripts until consent is given, making sure your privacy policy reflects the tools you actually run (not a generic template), and having an honest answer if a customer ever asks what you do with their information.

If you’re also thinking about California’s CIPA exposure, the two overlap more than people expect — both usually start with the same audit of what’s actually running on your site. That’s the starting point for our compliance work with clients.

There are plenty of DIY tools, services, and plugins that can get a site compliant with a few hours of work — or you can contact us and let us do the heavy lifting for you. Either way, don't wait: another day out of compliance can end up costing a lot more than the fix itself.

Not legal advice. This post is general information, not legal advice — GDPR obligations vary by business, and an attorney should review your specific compliance posture.