GDPR compliance software and GDPR software for US companies inside Article 3(2)
GDPR compliance software keeps a company inside the General Data Protection Regulation: lawful bases documented, data subject requests answered on time, processors under contract, breaches notified within 72 hours, and evidence for all of it. Complianceofficer adds the piece the checklist tools skip: it watches what the EDPB, the DPAs and the courts actually publish, and re-checks your policies when the interpretation moves.
Most of the companies buying this in the US have no EU office at all. They are in scope through Article 3(2), because they sell to people in the Union or track their behaviour, and the practical problem is that the obligations shift through guidance rather than through amendments they could subscribe to.
Check your GDPR obligations now
Pick your sector below. The scan returns the register of GDPR and related privacy obligations that apply to you, with recent regulatory movement and sources linked. No signup, nothing stored.
§ Live · Compliance scan
No signup. Nothing you pick is stored.
Sample register · fintech, US · what a scan returns
- § 01 Written AML program with a named officer
- § 02 KYC and customer due diligence
- § 03 Sanctions screening lists Changed
- § 04 PCI DSS v4.0 validation
The GDPR register: what gets watched for you
- § 01 Lawful bases and processing records Art. 6, 30
- § 02 Data subject rights, one-month clock Art. 12-22
- § 03 Processor DPAs and transfers Art. 28, 44-49
- § 04 Breach notification readiness Art. 33-34 · 72 hours
- § 05 DPIAs, incl. new AI features Art. 35
- § 06 Security of processing Art. 32
Each line maps to your privacy notice, DPAs, retention schedule and security policies. When the EDPB adopts new guidelines or a DPA decision shifts practice, the affected lines flag seal-red, the alert explains the change in plain language, and the policy update is drafted for your review. That loop is described step by step on how it works.
GDPR moves through guidance, not amendments
The regulation's text has barely changed since 2018; what changes is how it is enforced. EDPB guidelines, DPA decisions, adequacy rulings and court judgments keep redefining what compliant looks like, and fines run up to 4 percent of global turnover. A static checklist certified last year cannot tell you that this year's guidance just invalidated your transfer mechanism. A watcher can. The same engine covers your other regimes too, from SOC 2 to regulatory change management generally.
Try it now: pick B2B SaaS and GDPR in the scan and it returns this register with the last 12 months of movement, sources linked.
Run the compliance scan- § 01 Art. 83 fines up to 4% of global turnover
- § 02 Breach clock 72 hours, weekends count
- § 03 EDPB and DPA output watched at the source
- § 04 Your policy updates drafted for review
Does GDPR apply to a US company with no EU office?
Often, yes. Article 3(2) extends the regulation to controllers and processors with no establishment in the Union when they process personal data of people who are in the Union, and the processing relates to either offering goods or services to them, irrespective of whether payment is required, or monitoring their behaviour as far as that behaviour takes place within the Union.
Two words in there do most of the work. Irrespective of whether payment is required means a free tier, a free trial and a newsletter all count. Monitoring behaviour covers analytics, session recording, ad retargeting and profiling, which is why companies that have never knowingly sold into Europe still land in scope through their marketing stack. The test is about people who are in the Union at the time, not about citizenship, so an American customer working from Lisbon for three months is inside it and an EU citizen living in Ohio is not.
Being in scope through Article 3(2) also triggers Article 27, which requires designating a representative in the Union in writing. The exemption in Article 27(2) is narrower than most people assume: occasional processing, not large-scale special category or criminal conviction data, and unlikely to result in a risk. A SaaS product with continuous EU signups is not occasional processing.
The GDPR clocks that actually run against you
Most of the regulation is principles. A small part of it is deadlines, and those are what turn a bad week into a reportable failure. These are the ones worth writing into your incident and request procedures verbatim.
| Obligation | Clock | Starts when | Article |
|---|---|---|---|
| Breach notification to the DPA | 72 hours, weekends included | You become aware of the breach | Art. 33 |
| Breach notice to individuals | Without undue delay, if high risk | You assess the risk as high | Art. 34 |
| Data subject request response | One month, extendable by two | Receipt of the request | Art. 12(3) |
| Telling the requester about an extension | Within the original month | Receipt of the request | Art. 12(3) |
| DPIA before processing begins | Prior to the processing | High risk is likely | Art. 35 |
The 72 hour clock is the one teams get wrong most often, because it starts at awareness rather than at confirmation. If your security team has reasonable certainty a breach occurred on Friday evening, the clock is running through the weekend whether or not the investigation has concluded. Article 33(4) exists precisely for this: you may provide information in phases rather than wait until you have everything.
Transfers to the US: where the Data Privacy Framework stands in August 2026
This is the part of GDPR that has been invalidated twice, and it is the part US buyers most need dated correctly. Safe Harbor fell in 2015. Privacy Shield fell in 2020. The current mechanism is the European Commission's adequacy decision (EU) 2023/1795 of 10 July 2023, establishing the EU-US Data Privacy Framework, which lets a self-certified US organization receive personal data from the EU without additional safeguards.
That decision faced its first direct judicial challenge in Latombe, and on 3 September 2025 the EU General Court dismissed the action, upholding the adequacy decision. The matter is not closed: an appeal is pending before the Court of Justice as Case C-703/25 P. So the accurate position today is that the framework is valid law and under appeal.
The practical consequence for a US company is unglamorous but specific. Do not build your transfer posture on the framework alone. Keep standard contractual clauses executed and a transfer impact assessment on file as a fallback, so that a future adverse ruling is a document swap rather than a re-papering exercise across every EU customer. Two invalidations in ten years is a pattern, and the companies that handled 2020 well were the ones that already had SCCs signed.
The two fine tiers, and which failures sit in each
Article 83 sets two maxima, and both are expressed as whichever is higher between a fixed euro amount and a percentage of total worldwide annual turnover for the preceding financial year. Worldwide turnover, not EU revenue, is the base. That is why the ceiling is meaningful for US companies whose European business is small.
| Tier | Maximum | What lands here |
|---|---|---|
| Lower, Art. 83(4) | 10 million euro or 2 percent of worldwide turnover | Controller and processor obligations: records of processing, security of processing, breach notification, DPIAs, data protection by design, DPO duties |
| Upper, Art. 83(5) | 20 million euro or 4 percent of worldwide turnover | Basic principles including consent, lawful basis, data subject rights, and transfers to third countries |
Note where the transfer rules sit. Getting your US transfer mechanism wrong is an upper tier exposure, in the same bracket as processing without a lawful basis. That asymmetry is worth knowing when you are deciding how much effort to put into the SCC fallback described above. The same watch loop covers your other regimes, from SOC 2 to ISO 27001.
GDPR compliance software questions, answered
Do US companies need to comply with GDPR?
Yes, if Article 3(2) catches you. A company with no establishment in the EU is still in scope when it processes personal data of people who are in the Union and the processing relates to offering them goods or services, whether or not payment is required, or to monitoring their behaviour within the Union. Having EU customers, or analytics that reaches EU visitors, is usually enough.
What is GDPR compliance software?
GDPR compliance software documents and operates the obligations the regulation imposes: lawful bases, Article 30 records of processing, data subject requests inside the one-month deadline, processor contracts, transfer mechanisms, DPIAs and 72 hour breach notification. Better tools also track how regulators interpret those obligations, since the text rarely changes but the interpretation does.
How much are GDPR fines?
Article 83 sets two tiers. The lower is up to 10 million euro or 2 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. The upper is up to 20 million euro or 4 percent, and covers the basic principles, lawful basis, data subject rights and transfers to third countries.
Is the EU-US Data Privacy Framework still valid in 2026?
Yes as of August 2026. Adequacy decision (EU) 2023/1795 of 10 July 2023 stands, and the EU General Court dismissed the first direct challenge to it in Latombe on 3 September 2025. An appeal is pending at the Court of Justice as Case C-703/25 P, so a US company relying on the framework should keep standard contractual clauses ready as a fallback.
How long do you have to respond to a data subject access request?
Article 12(3) requires a response without undue delay and in any event within one month of receipt. That period can be extended by two further months where necessary given the complexity and number of requests, but you have to tell the data subject about the extension and the reasons for it within the original month.
Does a US company need an EU representative?
Usually yes. Article 27 requires controllers and processors caught by Article 3(2) to designate a representative in the Union in writing. The Article 27(2) exemption is narrow: occasional processing, no large-scale special category or criminal conviction data, and unlikely to result in a risk to individuals. Most SaaS companies do not qualify.
When do you have to report a data breach under GDPR?
Article 33 requires notification to the supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to individuals. Article 34 separately requires telling affected individuals without undue delay where the breach is likely to result in a high risk to them.
Is GDPR compliance software the same as a consent management platform?
No. A consent management platform handles one obligation, collecting and recording consent at the point of interaction, usually for cookies and trackers. GDPR compliance software covers the whole register: lawful bases across all processing, records, rights handling, processors, transfers and breach. Most companies need both, and a CMP alone is a common reason a first audit goes badly.
Related registers
- Continuous Compliance Monitoring
- Compliance Monitoring Software
- Compliance Software Cost
- Enterprise Compliance Software for CCOs and CISOs
- GRC Software and Governance Risk Compliance Software
- Compliance Automation Software
- AML Transaction Monitoring Plus Regulatory Watch
- SOC 2 Compliance Software Beyond Audit Readiness
- Policy Compliance Software and Policy Compliance Tracking
- Policy Attestation Software and Acknowledgement Tracking
- Regulatory Change Management Software, Tools and Platform
- HIPAA Compliance Software with Security Risk Analysis
- ISO 27001 Software for ISMS Compliance and Audit Evidence
- Vendor Risk Management Software for Third Party Risk
- PCI Compliance Software Tied to PCI DSS 4.0.1
- Audit Management Software for Continuous Readiness
- SOX Compliance
- Segregation of Duties Software
- Financial Services Compliance Software for RIAs and BDs
- 21 CFR Part 11 Compliant Software, GxP Compliance Software
- ITGC Controls Software for SOX IT General Controls Audits
- Compliance Reporting Software and Compliance Dashboards
- SOX Compliance Software for SOX 404 Controls
- Best Compliance Software in 2026, Compared
- CMMC Compliance Software for DoD Contractors
- Enterprise Risk Management Software
- Compliance Software Pricing Comparison
- Healthcare Compliance Software for OIG Compliance Programs
- Bank Compliance Software for Financial Institutions, BSA/AML
- AI Compliance Software
- AML Compliance Software with KYC and Sanctions Screening
- Regulatory Compliance Software with Compliance Tracking
- CCPA Compliance Software, Data Privacy Management Software
- Enterprise Risk Assessment Software, Risk Assessment Tools
- AI Governance Tool, Platform and Software for US Teams
- Business Continuity Plan Software, BCM and Disaster Recovery
- SOX 404(b) Compliance Software, Requirements and Threshold
- Integrated Risk Management Software, IRM Platform and Tools
- Vanta Alternative for Regulatory Change Monitoring
- Drata Alternative Focused on Regulatory Change
- Secureframe Alternative for Regulatory Change
- Sprinto Alternative for Regulatory Change
- AuditBoard Alternative (Now Optro) for Regulatory Change
- OneTrust Competitors
- Workiva Competitors and Alternatives
§ 99 · Final entry
Get on the early-access list
Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.