
GDPR Compliance
GDPR Applies to Your Organization Whether You’re Based in Europe or Not. Most US Businesses Don’t Know That Until It’s Too Late.
The General Data Protection Regulation (GDPR) is the European Union’s comprehensive data protection law — and its reach extends significantly beyond the EU’s borders. Under GDPR Article 3, the regulation applies to any organization — regardless of where it is established — that processes the personal data of individuals located in the EU in connection with offering goods or services to them, or monitoring their behavior within the EU. A US-based company with European customers, a professional services firm with EU employees working remotely, a SaaS provider with European enterprise clients, a healthcare organization treating patients who are EU residents — all of these organizations are subject to GDPR whether or not they have a single office, employee, or server on European soil.
The consequences of GDPR non-compliance are substantial. Article 83 establishes two tiers of administrative fines — violations of the most serious provisions, including the lawful basis for processing, data subject rights, and cross-border data transfer requirements, carry fines of up to €20 million or 4% of global annual turnover, whichever is higher. For a US company with $50 million in annual revenue, that is up to $2 million in potential fines for a single violation — before considering the litigation costs, reputational damage, and operational disruption that significant GDPR enforcement actions consistently produce. Meta has been fined over €1.3 billion under GDPR. Amazon was fined €746 million. These are not enforcement actions limited to European companies — they apply to any organization subject to the regulation’s extraterritorial scope.
Lionhive builds GDPR compliance programs for US organizations with European operations, customers, employees, or data flows — providing the technical controls, data governance frameworks, processing documentation, and ongoing compliance management that satisfy GDPR requirements and withstand supervisory authority scrutiny.
Most US organizations’ GDPR exposure is not the result of malicious intent — it is the result of building data practices around US legal requirements and never systematically evaluating which of those practices conflict with GDPR obligations. The gap between “we don’t think we have a GDPR problem” and “we have a significant GDPR problem” is usually discovered during a data subject request, a supervisory authority inquiry, or a data breach — all of which are the wrong times to be starting the compliance analysis.
Does GDPR Apply to Your Organization?
The extraterritorial scope of GDPR catches US organizations by surprise more consistently than almost any other aspect of the regulation. The analysis starts with a straightforward question — does your organization process the personal data of individuals located in the EU? If yes, the next question is whether that processing is connected to offering goods or services to EU individuals (even free services), or monitoring EU individuals’ behavior. If either applies, GDPR applies to your organization.
Common scenarios where US organizations are subject to GDPR include:
European customers — Any US business that sells products or services to customers in EU member states processes EU personal data in connection with those transactions. Billing information, shipping addresses, account credentials, purchase history, and customer communications are all personal data under GDPR’s broad definition.
European employees and contractors — HR data for EU-based employees — payroll, performance records, health information, disciplinary records, monitoring data — is subject to GDPR. The employee relationship does not exempt an organization from GDPR obligations regarding employee personal data, and employment-related GDPR requirements are among the most strictly enforced by EU data protection authorities.
SaaS and technology platforms with EU users — Technology companies whose platforms are used by EU individuals — even if those individuals are employees of US companies using the platform — may be processing EU personal data subject to GDPR. The analysis depends on whether EU individuals’ data is being processed and the purpose of that processing.
Website analytics and behavioral tracking — US companies whose websites use cookies, analytics tools, or behavioral tracking that collects data from EU visitors may be subject to GDPR’s e-privacy requirements alongside the core regulation. Cookie consent requirements are one of the most commonly enforced GDPR obligations and one of the most commonly violated by US organizations that have simply never addressed them.
Healthcare organizations with EU patients — US healthcare organizations treating EU nationals, conducting clinical trials with EU participants, or sharing health information internationally may process special category personal data — health data — under GDPR, which carries significantly stricter requirements than standard personal data processing.
The Core GDPR Requirements
Lawful Basis for Processing
Every processing activity involving EU personal data must have a documented lawful basis under GDPR Article 6. The six lawful bases are consent, contract performance, legal obligation, vital interests, public task, and legitimate interests. US organizations frequently assume that consent is the appropriate basis for all processing — which is incorrect and creates significant compliance problems, because GDPR consent must be freely given, specific, informed, and unambiguous, and individuals have the right to withdraw it at any time. Many processing activities that US organizations run on consent would more appropriately rely on contract performance or legitimate interests — and the choice of lawful basis affects the data subject rights that apply, the documentation required, and the consequences of processing failures.
For special category personal data — health data, biometric data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, and data concerning sex life or sexual orientation — the lawful basis requirements under Article 9 are stricter and the list of applicable conditions is more limited. US healthcare organizations and employers handling health-related employee data face elevated scrutiny on special category processing.
Data Subject Rights
GDPR grants EU individuals a comprehensive set of rights regarding their personal data — and organizations must be operationally capable of responding to these rights within defined timeframes. Failing to respond to a data subject rights request within one month — or responding inaccurately or incompletely — is a commonly enforced GDPR violation. The rights include:
Right of Access (Article 15) — Individuals can request confirmation of whether their data is being processed and a copy of that data, along with information about the purposes, categories, recipients, retention periods, and the existence of their other rights. Responding to access requests requires knowing where personal data lives across all systems — which many organizations discover they cannot do without a data mapping exercise.
Right to Rectification (Article 16) — Individuals can request correction of inaccurate personal data and completion of incomplete data.
Right to Erasure — “Right to be Forgotten” (Article 17) — Individuals can request deletion of their personal data in defined circumstances, including when the data is no longer necessary for the purpose it was collected, when consent is withdrawn, or when the data has been unlawfully processed. Erasure requests create technical challenges for organizations with data in backups, third-party systems, and distributed storage environments.
Right to Restriction (Article 18) — Individuals can request that processing be restricted in defined circumstances while accuracy or lawfulness is contested.
Right to Data Portability (Article 20) — Individuals can request their personal data in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible.
Right to Object (Article 21) — Individuals can object to processing based on legitimate interests or for direct marketing purposes. Objections to direct marketing must be honored immediately and without exception.
Lionhive builds the technical and procedural infrastructure for responding to data subject rights — data mapping to identify where personal data lives, request intake and tracking workflows, response procedures within the one-month deadline, and integration with the systems holding personal data to execute erasure, portability, and restriction requests accurately.
Records of Processing Activities
Article 30 requires organizations to maintain detailed Records of Processing Activities (RoPA) — documentation of every processing activity involving EU personal data, including the purposes of processing, categories of data subjects and personal data, recipients, international transfer mechanisms, retention periods, and security measures. The RoPA is the foundational documentation artifact of GDPR compliance — supervisory authorities request it as a first step in investigations, and organizations that cannot produce a current, accurate RoPA cannot demonstrate compliance with the regulation’s accountability principle.
Lionhive conducts data mapping exercises that identify every processing activity involving EU personal data across the organization — every system, every vendor, every data flow — and builds the RoPA that documents this accurately. The RoPA is designed to be maintained as a living document as processing activities change, not created once and filed.
Data Protection Impact Assessments
Article 35 requires Data Protection Impact Assessments (DPIAs) for processing activities that are likely to result in high risk to individuals — including systematic and extensive profiling, large-scale processing of special category data, and systematic monitoring of publicly accessible areas. DPIAs assess the necessity and proportionality of the processing, evaluate the risks to data subject rights, and identify the measures to address those risks.
US organizations deploying AI systems that process EU personal data, implementing employee monitoring technologies, or expanding the scale of data processing involving EU individuals should evaluate whether a DPIA is required before deployment — not after. Lionhive conducts DPIAs for processing activities that meet the high-risk threshold and advises on the technical and organizational measures that mitigate identified risks to acceptable levels.
Data Breach Notification
Under Article 33, organizations must notify the relevant supervisory authority of a personal data breach within 72 hours of becoming aware of it — unless the breach is unlikely to result in risk to individuals’ rights and freedoms. Where the breach is likely to result in high risk to individuals, Article 34 requires notification to affected individuals without undue delay.
The 72-hour window is unforgiving — it begins when the organization becomes aware of the breach, not when it has completed its investigation. Organizations that discover a breach on a Friday afternoon have until Monday afternoon to notify the supervisory authority, regardless of weekends and regardless of whether the investigation is complete. GDPR permits notification with incomplete information followed by updates as investigation progresses — but the initial notification must occur within 72 hours of awareness.
Lionhive’s incident response program integrates GDPR notification obligations alongside the other notification requirements applicable to the organization — ensuring that the 72-hour clock is recognized immediately upon incident discovery, that the supervisory authority notification is drafted and submitted within the window, and that individual notifications are executed where required. The integration between Lionhive’s Incident Response practice and GDPR notification obligations is designed before an incident occurs, not assembled under 72-hour deadline pressure.
Controller and Processor Obligations
GDPR distinguishes between data controllers — organizations that determine the purposes and means of processing — and data processors — organizations that process personal data on behalf of controllers. US organizations are typically controllers with respect to their customers’ and employees’ data, and processors with respect to data they handle on behalf of clients.
Article 28 requires that processing by a processor be governed by a Data Processing Agreement (DPA) that specifies the subject matter, duration, nature, and purpose of the processing, the type of personal data, and the obligations and rights of the controller. US technology companies, SaaS providers, and managed service providers handling EU personal data on behalf of European or EU-data-holding clients must have Article 28-compliant DPAs in place with those clients — and must themselves execute DPAs with their subprocessors. Lionhive reviews and advises on DPA terms for technology vendors and service providers on both sides of the controller-processor relationship.
International Data Transfers
Transferring EU personal data to the United States — including routine transfers like syncing data to US-based cloud services, sending emails containing EU personal data to US recipients, or providing US-based customer support teams access to EU customer data — requires a valid transfer mechanism under GDPR Chapter V. The US is not considered a country with an adequate level of data protection under EU law by default — which means transfers to the US require specific legal mechanisms rather than simply being permitted.
The primary available transfer mechanisms for US-EU data flows are:
EU-US Data Privacy Framework (DPF) — The EU-US Data Privacy Framework, adopted in July 2023, allows US organizations certified under the DPF to receive EU personal data without additional transfer mechanisms. DPF certification requires self-certification with the US Department of Commerce, commitment to DPF principles covering notice, choice, accountability for onward transfer, security, data integrity and purpose limitation, access, and recourse, and annual recertification. The DPF replaced Privacy Shield following the Court of Justice of the EU’s Schrems II decision — but its long-term legal stability remains a subject of EU legal and political debate.
Standard Contractual Clauses (SCCs) — The European Commission’s Standard Contractual Clauses, updated in 2021, are the most widely used transfer mechanism for US organizations not certified under DPF. SCCs are pre-approved contractual terms that provide appropriate safeguards for data subjects — but following Schrems II, they must be accompanied by a Transfer Impact Assessment (TIA) that evaluates whether the law and practice of the destination country undermines the effectiveness of the SCCs. Lionhive conducts TIAs and implements SCCs for US organizations receiving EU personal data from European clients, partners, or group entities.
Binding Corporate Rules (BCRs) — Approved binding corporate rules allow multinational organizations to transfer personal data within the corporate group across borders. BCRs require supervisory authority approval and are typically pursued by larger multinational organizations with significant intragroup data flows.
Data Protection Officers
Article 37 requires designation of a Data Protection Officer (DPO) for organizations that are public authorities, that carry out large-scale systematic monitoring of data subjects as a core activity, or that carry out large-scale processing of special category data as a core activity. For organizations that don’t meet the mandatory DPO threshold, designating a voluntary DPO or an external privacy counsel in a DPO-equivalent role is considered best practice and demonstrates the accountability principle that runs throughout GDPR.
Lionhive provides DPO-as-a-Service for organizations that require a designated DPO but don’t have the internal capacity to staff the role — providing the independent privacy expertise, supervisory authority liaison capability, and ongoing compliance advisory that the DPO function requires under Article 38 and 39.
UK GDPR — Post-Brexit Considerations
Following Brexit, the United Kingdom enacted the UK GDPR — a domestic version of GDPR administered by the Information Commissioner’s Office (ICO). UK GDPR is substantially equivalent to EU GDPR but is a separate legal instrument with its own regulatory authority, its own adequacy decisions, and its own enforcement framework. US organizations with UK customers, employees, or data flows are subject to UK GDPR in addition to EU GDPR — requiring separate transfer mechanisms for UK-to-US data flows and compliance with ICO guidance that may diverge from EU supervisory authority positions over time. Lionhive addresses UK GDPR obligations alongside EU GDPR as an integrated compliance program rather than treating them as identical.
GDPR and US Privacy Regulations — The Overlap and the Gaps
US organizations subject to GDPR are often simultaneously subject to US privacy and data protection regulations — creating a compliance environment that requires careful coordination across multiple overlapping frameworks. Lionhive builds GDPR programs that are designed alongside applicable US requirements rather than as a separate compliance silo:
HIPAA — Healthcare organizations subject to both GDPR and HIPAA face requirements that overlap significantly in some areas — both require data breach notification, both require data processing agreements with vendors, both impose security requirements — but differ meaningfully in others. GDPR’s individual rights framework is broader than HIPAA’s, GDPR’s lawful basis requirements don’t map cleanly to HIPAA’s treatment disclosures, and GDPR’s 72-hour breach notification is more demanding than HIPAA’s 60-day window. Lionhive designs unified compliance programs for healthcare organizations that satisfy both frameworks through coordinated controls rather than parallel compliance programs.
CCPA/CPRA — California’s Consumer Privacy Act and its amendment, the Consumer Privacy Rights Act, share significant structural similarities with GDPR — individual rights including access, deletion, and portability; opt-out rights for data sales; and privacy notice requirements. Organizations that have built GDPR compliance programs find significant overlap with CCPA/CPRA requirements, though the specific rights, definitions, and enforcement mechanisms differ in important ways.
Illinois BIPA — Illinois organizations subject to both GDPR and BIPA face overlapping but distinct requirements for biometric data — GDPR classifies biometric data as special category personal data with elevated protections under Article 9, while BIPA establishes specific consent, retention, and destruction requirements under Illinois law. A unified approach to biometric data governance addresses both frameworks simultaneously.
Lionhive’s GDPR Compliance Approach
GDPR Applicability Assessment — Before building a compliance program, Lionhive conducts an honest assessment of whether and how GDPR applies to your organization — mapping EU data flows, identifying processing activities involving EU personal data, evaluating the controller-processor relationship for each activity, and determining which GDPR obligations apply at what priority. For organizations uncertain about their GDPR exposure, this assessment is the starting point.
Data Mapping & Records of Processing — Comprehensive inventory of every processing activity involving EU personal data — systems, vendors, data flows, purposes, legal bases, retention periods, and cross-border transfer mechanisms — producing the Article 30 RoPA that is the foundation of GDPR accountability.
Lawful Basis Analysis — Review of each processing activity against the six available lawful bases under Article 6, identification of activities relying on inappropriate bases, and remediation of the data collection and processing practices, consent mechanisms, and privacy notices that need to reflect accurate lawful basis documentation.
Technical Controls Implementation — Deployment of the technical controls that GDPR’s security requirements under Article 32 demand — encryption in transit and at rest, access controls and IAM through Microsoft Entra ID and Okta, pseudonymization where appropriate, data loss prevention through Microsoft Purview, and the monitoring and breach detection capability integrated with Lionhive’s Managed SOC.
Data Subject Rights Infrastructure — Intake processes, tracking workflows, and technical capabilities to respond to access, erasure, portability, rectification, restriction, and objection requests within GDPR’s one-month response window — across all systems holding EU personal data.
Transfer Mechanism Implementation — DPF certification support, SCC execution with Transfer Impact Assessments, and DPA review for vendor and client relationships involving EU personal data transfers to the US or other third countries.
Breach Response Integration — Integration of GDPR’s 72-hour notification obligation into the incident response program — ensuring the notification clock, supervisory authority contact, and individual notification requirements are operationalized before an incident occurs.
Ongoing Compliance Management — GDPR compliance is not a one-time project — it is an ongoing operational discipline that must keep pace with changes in data processing activities, regulatory guidance from EU supervisory authorities, and the evolving enforcement landscape. Lionhive provides ongoing GDPR compliance management including annual RoPA reviews, DPIA assessments for new processing activities, regulatory guidance monitoring, and privacy program maintenance.
🌐 Why Organizations Choose Lionhive for GDPR
- Extraterritorial scope analysis — honest assessment of whether and how GDPR applies before building a compliance program
- Data mapping and Article 30 RoPA development covering every processing activity, system, and vendor
- Lawful basis analysis and remediation — identifying activities relying on incorrect bases and fixing them
- Transfer mechanism implementation — DPF certification support, SCC execution with Transfer Impact Assessments
- Data subject rights infrastructure — intake, tracking, and technical response within one-month deadlines
- 72-hour breach notification integration with incident response program
- DPO-as-a-Service for organizations requiring a designated Data Protection Officer
- UK GDPR addressed alongside EU GDPR as an integrated program
- Unified compliance design across GDPR, HIPAA, CCPA/CPRA, and BIPA for organizations managing multiple frameworks
📞 Ready to Understand Your Real GDPR Exposure Before a Supervisory Authority Does?
Most US organizations with EU data flows are somewhere on the spectrum between “we know we have gaps and haven’t addressed them” and “we’re not sure whether GDPR applies to us.” Both are starting points Lionhive works from — the honest assessment of current exposure comes first, and the compliance program that closes the gaps follows. If your organization processes EU personal data and hasn’t done a systematic GDPR analysis, the risk is real and the right time to address it is before a data subject complaint, a supervisory authority inquiry, or a breach triggers the analysis under circumstances you can’t control.
Part of Lionhive’s Cybersecurity & Compliance practice — see also HIPAA Compliance, NIST CSF, Incident Response, Identity & Access Management, and SOC 2.