The United States has no single, all-encompassing privacy law like the GDPR. That does not mean American businesses are off the hook when it comes to data protection. As global data flows increase and state-level privacy laws multiply, US companies face a growing set of regulations that, taken together, resemble a GDPR equivalent in scope if not in structure.
• There’s no single US law that mirrors the GDPR. The US relies on a patchwork of sector-specific federal rules (HIPAA, Gramm-Leach-Bliley) and state laws instead of one comprehensive framework, and California’s CCPA/CPRA is the closest thing to a GDPR equivalent, though it’s narrower in scope, uses an opt-out rather than opt-in consent model, and carries far smaller penalties ($7,500 per intentional violation versus GDPR’s up to €20 million or 4% of global turnover).
• Location doesn’t exempt US businesses from GDPR. Any US company that offers goods or services to EU individuals or monitors their behaviour falls under GDPR’s extraterritorial reach, regardless of size or physical presence in the EU, and fines are calculated on worldwide revenue, not just EU operations.
• Federal privacy legislation isn’t coming soon. The ADPPA stalled in Congress, and more states keep passing their own laws with different thresholds and requirements, so the article’s recommended strategy is to build compliance around GDPR as the benchmark, since meeting the highest standard tends to satisfy the lower ones too.
No comprehensive federal law matches the scope and requirements of the GDPR. The US takes a fundamentally different approach to data privacy, relying on sector-specific regulations and state-level legislation rather than a single overarching framework.
The California Consumer Privacy Act and the California Privacy Rights Act are the closest equivalents to the GDPR within US borders. These laws grant California residents rights over their personal data, including access, deletion, and opt-out mechanisms for data collection.
At the federal level, US businesses face regulations such as the Health Insurance Portability and Accountability Act (HIPAA) for healthcare providers handling protected health information and the Gramm-Leach-Bliley Act for financial institutions managing customer data. The Federal Trade Commission has enforcement authority over most commercial entities but lacks a comprehensive data privacy law to enforce.

The California Consumer Privacy Act applies specifically to California residents, creating a much narrower geographic scope than GDPR, which covers all EU citizens regardless of where their data is processed.
CCPA uses an opt-out model: businesses can collect data without prior explicit consent, provided they provide adequate privacy notices and offer consumers the opportunity to opt out.
Penalty structures differ significantly:
• GDPR: fines up to €20 million or 4% of annual global turnover, whichever is higher.
• CCPA: $7,500 per intentional violation, $2,500 per unintentional violation.
Both frameworks grant data subjects fundamental rights, including the right to access their personal data, the right to have it deleted, and the right to know what information businesses collect. GDPR grants the right to correct inaccurate personal data, a right that the CCPA did not originally include until the CPRA amendments.
California residents have a private right of action for certain data breaches under CCPA, allowing individuals to pursue legal claims and statutory damages. This enforcement mechanism remains unique among US state data protection laws.
The European Union treats privacy as a fundamental right, embedded in the EU Charter of Fundamental Rights. US law balances privacy interests with business needs and free-market principles, resulting in distinct regulatory philosophies.
GDPR applies extraterritorially to any organisation that processes personal data of EU citizens, regardless of where the business is located. If your US company processes EU personal data, GDPR applies to your operations. US state laws typically apply based on where consumers reside and where businesses operating within certain thresholds conduct activities.
Legal bases for data processing differ markedly:
• GDPR requires one of six legal bases, including consent, contract performance, or legal obligation.
• US laws generally permit processing with adequate notice and opt-out opportunities.
GDPR mandates data protection impact assessments for high-risk processing activities, requires data minimisation, and imposes strict storage limitations. Most US state laws focus on transparency and consumer choice rather than limiting how businesses collect data.
Cross-border data transfers are subject to strict GDPR requirements, including adequacy decisions or specific safeguards such as Standard Contractual Clauses. US data privacy laws contain no comparable restrictions on international data transfers.
California maintains the most comprehensive framework through the CCPA and the CPRA. Unlike other states, California’s law covers personal information collected in employment and B2B contexts. The state requires businesses to honour Global Privacy Control signals from browsers.
Virginia, Colorado, Utah, and Connecticut enacted Consumer Data Protection Acts with substantially similar structures. These laws define “consumers” as individuals acting in personal capacities, excluding employment and commercial contexts from protection.
Texas, Florida, Montana, Oregon, Delaware, Iowa, Nebraska, New Hampshire, and New Jersey have all passed comprehensive state laws. Each law varies in:
• Revenue and data processing thresholds for applicability.
• Definitions of sensitive personal information.
• Requirements for explicit consent versus opt-out mechanisms.
• Enforcement authority and penalties.
Most states, other than California, Florida, Iowa, and Utah, require explicit consent to collect sensitive data, including biometric data and health information. California requires businesses to provide a right to limit the use of sensitive data rather than obtain prior consent.
None of these states, other than California, provides for a private right of action. Enforcement depends on state attorneys general and, in some states such as Colorado, district attorneys.
US companies that process EU personal data must comply with GDPR regardless of what US law requires. A small e-commerce business in Texas selling products to EU customers faces the same GDPR requirements as a multinational corporation.
The compliance challenge compounds for businesses operating across multiple jurisdictions. A company with customers in California, Virginia, and Colorado must track different thresholds, definitions, and requirements across each state’s laws.
Non-compliance carries serious risks:
• GDPR fines calculated on global revenue, not just EU operations.
• Reputational damage affecting customer trust.
• Private litigation exposure in California for data breaches.
• Enforcement actions from data protection authorities.
Numerous additional states are actively considering new data protection legislation. The patchwork approach shows no signs of consolidating into federal law soon, meaning compliance efforts must account for continued regulatory expansion.
The American Data Privacy and Protection Act (ADPPA) represented the most serious Congressional attempt at a comprehensive federal law, but stalled without passage. No current timeline exists for the enactment of comprehensive federal privacy legislation.
Federal agencies continue to develop sector-specific regulations rather than pursue comprehensive reform. Businesses must prepare for the patchwork of state laws continuing indefinitely.
The practical consequences are:
• No preemption of stricter state laws.
• Continued variation in requirements across states.
• Ongoing compliance burden for national businesses.
• More states are likely to enact different standards over time.
GDPR applies if your business:
• Has an establishment in an EU member state.
• Offers goods or services to EU citizens.
• Monitors the behaviour of individuals within the EU.
Processing EU personal data through a website accessible in EU countries may trigger compliance obligations, even without a physical presence in the EU. Mere accessibility from the EU is not sufficient; there must be targeted or monitored access to individuals in the EU.
Identify which state laws apply based on:
• Where your customers reside.
• Your annual revenue thresholds.
• Volume of personal data processed.
• Types of data collected, especially sensitive personal information.
Meeting the highest applicable standard (typically GDPR) often satisfies requirements across jurisdictions. Key principles in GDPR implementation include:
• Data minimisation: collect only necessary personal information.
• Purpose limitation: process data only for specified purposes.
• Storage limitation: retain data only as long as needed.
• Security measures: protect against data breaches.
GDPR requires organisations that regularly monitor data subjects at scale or process sensitive data extensively to appoint a Data Protection Officer. Even when not legally required, an outsourced Data Protection Officer service can coordinate regulatory compliance across jurisdictions and provide a single point of accountability.

Map all data processing activities:
• What personal data do you collect?
• Where does it come from?
• How is it stored and protected?
• Who has access?
• How long is it retained?
This audit identifies IP addresses, customer data, and other information that qualifies as personal data under GDPR’s broad definition, which covers any identifiable natural person.
GDPR transparency requirements demand clear disclosure of:
• Legal bases for processing.
• Data subject rights, including data portability and the right to restrict processing.
• Data controller identity and contact information.
• Any data processors involved in handling personal information.
• Retention periods and criteria.
Under GDPR, consent is required for:
• Non-essential cookies (ePrivacy Directive interaction).
• Certain marketing activities.
• Processing where no other lawful basis applies.
Many processing activities rely instead on contract, legitimate interests, or legal obligation. Identifying the correct basis for each processing activity before configuring a consent management platform prevents over-reliance on consent where it is not needed, and under-reliance where it is.
If you process EU personal data but do not have an EU establishment, you likely need an EU representative under Article 27 of the GDPR. The representative must be established in one of the member states where the data subjects whose data are processed are located, not necessarily all member states, just one relevant member state.
Privacy regulations change continuously. The European Data Protection Board issues guidance, states amend their laws, and enforcement priorities shift. Expert services track these changes and update compliance programmes accordingly, so businesses do not need to monitor every regulatory development independently.
Appointing a proper EU representative satisfies GDPR requirements and establishes your point of contact within the European Union. This representative must be established in a member state where your data subjects are located and must be reachable by supervisory authorities on your behalf.
Periodic compliance audits identify gaps before they become enforcement issues. Audits should cover:
• Data collection practices against stated purposes.
• Security measures protecting against breaches.
• Consent records and privacy notice accuracy.
• Third-party data processor agreements.
• Risk assessments for new processing activities.
Rather than building internal expertise across multiple regulatory frameworks, outsourced services provide immediate access to specialists who can help implement GDPR requirements, manage subject access requests, and respond to incidents.
The United States has no true GDPR equivalent, but the reality for American businesses is clear: data protection obligations are growing, not shrinking. State privacy laws continue to expand, enforcement is increasing, and any organisation that touches EU personal data must meet GDPR standards regardless of its location.
For most businesses, the most practical path forward is to treat GDPR as the benchmark and build privacy programmes around its principles. Doing so reduces regulatory risk across jurisdictions and builds customer trust.

It depends on whether you process EU personal data. There must be targeting of EU individuals (for example, EU currency, EU shipping, or EU language adaptation) or monitoring of behaviour in the EU (for example, tracking for profiling or behavioural advertising). Collecting IP addresses alone does not automatically trigger GDPR unless the conditions in Article 3(2) are met.
The same penalties apply regardless of location: up to €20 million or 4% of annual global turnover, whichever is higher. Data protection authorities in EU member states can pursue enforcement against US companies, and GDPR fines are calculated on worldwide revenue, not just European operations.
Blocking EU traffic can avoid some compliance obligations, but it comes with significant downsides. You lose customers and revenue from the entire EU. VPNs can bypass geo-blocking, creating ongoing compliance risks. And any EU data collected before blocking remains subject to GDPR obligations.
About the Author
Ana Mishova
Sales and Business Development Consultant — GDPRLocal
Ana focuses on helping organisations understand their compliance obligations and find the right data protection solutions. At GDPRLocal she works closely with businesses of all sizes, making GDPR and privacy compliance clear, practical, and accessible.