GDPR can apply to companies outside Europe when they offer goods or services to people in the EU/EEA, monitor their behaviour in the EU/EEA, or process data through an EU/EEA establishment.
Kobalt helps tech companies build a defensible, procurement-ready privacy program without hiring a full-time DPO. Whether you're in scope through the targeting test, the monitoring test, or an EU/EEA establishment, the obligations are real, and enterprise buyers increasingly require documented compliance before signing.
GDPR scope is not based only on where your company is incorporated or where your servers are hosted. For non-EEA companies, the key questions are whether you target people in the EEA, provide goods or services to them, or monitor their behaviour there through analytics, profiling, advertising, or similar tracking. A scope assessment is the right starting point before drawing conclusions.
Your company is incorporated in Delaware and your servers are in us-east-1. EU GDPR may still apply if you actively offer goods or services to people in the EEA, for example by accepting EEA customers, pricing in euros, or running campaigns targeting EEA markets, or if you monitor their behaviour through analytics, retargeting, or behavioural profiling. Accessibility alone, without targeting, is generally not enough to trigger scope.
PIPEDA governs how you handle Canadian personal data. EU GDPR is a separate, parallel obligation if you target or monitor people in the EEA. The two frameworks overlap significantly on documentation and consent requirements. Kobalt's CIPP/C and CIPP/E designations cover both simultaneously.
Australia's Privacy Act and EU GDPR are distinct obligations that can both apply at once. GDPR's extraterritorial scope is triggered when you target people in the EEA, through active marketing, EEA-facing features, or behavioural tracking, not simply by being technically accessible there. Availability alone, without targeting, is unlikely to bring you in scope under Article 3(2).
B2B does not exempt you. The contact data of EU-based employees at your client companies is personal data under GDPR: names, work email addresses, and job titles all qualify. So is the data of your own EU employees, contractors, or prospects in your CRM.
GDPR governs data processing, not commercial transactions. A free tier still requires a lawful basis for processing, a compliant privacy notice, and the operational capacity to fulfill Data Subject Access Requests within one month. "We don't charge them" is not a legal basis.
GDPR has no blanket startup exemption. Some obligations scale with risk and company size: certain organisations with fewer than 250 employees may be exempt from some Article 30 records requirements, but early-stage SaaS companies can still need privacy notices, lawful-basis analysis, vendor DPAs, DSAR workflows, breach procedures, and processing records, especially where processing is regular or enterprise buyers require evidence.
Whether EU GDPR applies depends on whether you target or monitor people in the EEA, not simply on whether any EEA resident has ever used your product. The answer requires a proper scope assessment, not a blanket assumption either way. A free 30-minute call is the right starting point.
Get a free scope assessmentChoose the path that matches where you are. Most clients start with FullStart, then move to ongoing Fractional DPO management.
EU/EEA data protection authorities, including the CNIL in France, the DPC in Ireland, and the APD in Belgium, enforce EU GDPR actively against non-EEA companies. The UK's ICO enforces UK GDPR under a separate regime. Regulators have issued fines against US, Australian, and Canadian organizations for the same violations they pursue domestically. Geographic distance is not a mitigating factor.
Enterprise procurement teams now routinely require GDPR compliance documentation before signing contracts. A missing Data Processing Agreement or an incomplete Record of Processing Activities can stall a six-figure deal indefinitely. Compliance is increasingly a revenue requirement, not just a legal one.
The good news: if you are already working toward SOC 2 or ISO 27001, the evidence collection overlaps significantly. Kobalt's GDPR program layers privacy controls on top of your existing security posture, avoiding duplicate effort across frameworks.
Every GDPR FullStart and ongoing program covers six core workstreams. No deliverables left to the client's interpretation.
A 360-degree review of your current data handling practices against the 99 Articles of GDPR.
Article 30 requires a documented Record of Processing Activities. We build the Data Map and keep it current.
Legally-vetted policies tailored to your actual tech stack. Not templates.
Mandatory for high-risk processing. Common in AI, FinTech, and HealthTech. Proves Privacy by Design to enterprise buyers.
A senior privacy expert on call. DSAR management, breach response, vendor DPA reviews, and regulatory liaison.
GDPR controls mapped directly to your GRC platform. Real-time audit evidence, not a static compliance binder.
Kobalt's privacy team holds both CIPP/C (Canadian privacy law) and CIPP/E (European GDPR) certifications, and includes practicing lawyers with direct experience engaging EU and UK data protection authorities. No other DPO-as-a-service provider in our segment brings this combination.
What that means for you: real legal judgment on privacy decisions. When a regulator contacts you, when a data breach happens, when an enterprise prospect's legal team sends a 40-question DPA, you want a team that can give you a definitive answer.
Many tech companies confuse GDPR with security frameworks like SOC 2 or ISO 27001. They serve different purposes. They share significant evidence. Kobalt runs both programs in parallel.
| GDPR | SOC 2 | ISO 27001 | |
|---|---|---|---|
| What it governs | Privacy rights of EU data subjects | Security controls for client data | Information security management |
| Who requires it | Companies targeting or monitoring people in the EU/EEA | Enterprise B2B buyers | Global enterprise, EU public sector |
| Regulatory body | EU/EEA DPAs (CNIL, DPC, etc.); ICO for UK GDPR separately | AICPA (via licensed CPA auditor) | ISO (via accredited certification body) |
| Fines / consequences | Up to €20M or 4% of global revenue | Loss of enterprise deals | Loss of enterprise deals |
| Kobalt's role | Managed privacy program + Fractional DPO | Audit prep and managed compliance | Certification pathway |
Clients combining GDPR with SOC 2 or ISO 27001 benefit from shared evidence collection and shared policy documentation, cutting total effort and cost by up to 40%. Kobalt runs both programs in parallel from day one.
Post-Brexit, the UK operates under its own data protection regime: UK GDPR, embedded in the Data Protection Act 2018 and further updated by the Data (Use and Access) Act 2025 (DUAA). UK GDPR is supervised exclusively by the ICO (Information Commissioner's Office), which is independent of EU/EEA supervisory authorities; the ICO is not an EU DPA.
Companies operating in both the EEA and UK markets face separate but parallel compliance obligations. You may need both an EU/EEA Article 27 representative and a UK representative appointed in writing where required. Transfer mechanisms diverge: EU transfers rely on Standard Contractual Clauses (SCCs); UK transfers use the IDTA or the UK Addendum to the EU SCCs. Adequacy decisions are managed independently. The DUAA introduced further UK-specific updates in 2025, including adjustments to legitimate interests, DSARs, and automated decision-making rules.
Kobalt's privacy team covers both EU GDPR and UK GDPR in a single engagement. If you operate in the UK market, scope should be set separately from the outset.
A structured sequence from first call to fully defensible program. No ambiguity on what happens when.
Free consultation. We review your technology stack, data flows, and existing controls to scope the engagement accurately before any work begins.
Every processing activity mapped against the 99 articles of GDPR. Deliverable: a prioritized remediation roadmap with effort estimates for each finding.
Complete data flow mapping across your cloud infrastructure and SaaS stack. Deliverable: an Article 30-compliant Record of Processing Activities ready for auditor and enterprise buyer review.
Legally-vetted privacy policies, data handling procedures, and Data Protection Impact Assessments for high-risk processing. Tailored to your stack, not generic templates.
GDPR controls mapped directly into your GRC platform. Evidence collection automated from day one. Your compliance posture visible in a single dashboard.
Monthly retainer for DSAR management, breach response, vendor DPA reviews, and regulatory liaison. The program stays current as your product and regulatory environment evolve.
Clients combining GDPR with SOC 2 or ISO 27001 complete shared deliverables once, not twice. Kobalt's multi-framework programs reduce total effort by up to 40% compared to running engagements separately.
It depends on what your company does, not where it is incorporated or where its servers are hosted. EU GDPR applies to non-EEA companies under Article 3(2) when they offer goods or services to people in the EU/EEA, or monitor their behaviour in the EU/EEA through analytics, profiling, advertising, or similar tracking. Simply being accessible to EEA residents is not enough on its own to trigger scope. The right answer requires a proper scope assessment against the Article 3 targeting and monitoring tests, and Kobalt's free consultation is the starting point for that.
Personal data under GDPR (Article 4(1)) is any information that relates to an identified or identifiable natural person. This is broader than most companies expect. Names, email addresses, IP addresses, device identifiers, cookie IDs, location data, and behavioral data all qualify. So does any data that can be combined with other information to identify someone. If your product collects analytics, runs cookies, stores user accounts, or processes payment information, you are processing personal data under GDPR.
GDPR grants data subjects in the EU/EEA eight rights: the right to be informed (Articles 13-14), the right of access (Article 15), the right to rectification (Article 16), the right to erasure (Article 17), the right to restrict processing (Article 18), the right to data portability (Article 20), the right to object (Article 21), and rights related to automated decision-making (Article 22). Practically, this means your product must be able to fulfil Data Subject Access Requests within one month (extendable by a further two months in complex cases), delete user data on request, and export personal data in a machine-readable format. Most SaaS products require product and engineering work to implement this correctly.
A DPIA (Article 35) is a structured risk assessment required when processing is likely to result in high risk to individuals' rights and freedoms. It is mandatory for AI systems that profile individuals, large-scale processing of special category data (health, biometric, genetic, or similar sensitive categories), systematic monitoring, and new technologies with uncertain privacy implications. "Financial data" is not itself a special category under Article 9 GDPR. A DPIA documents the processing purpose, necessity and proportionality, risks identified, and measures taken to mitigate those risks. Enterprise procurement teams increasingly request DPIA documentation as part of vendor security reviews, making this a commercial requirement as well as a legal one.
With Kobalt's FullStart process: a Privacy Gap Assessment followed by remediation and policy implementation means most clients are enterprise-ready in a matter of weeks. If you are already working on SOC 2 or ISO 27001, the timeline is often shorter because evidence collection overlaps significantly across frameworks.
Most SMBs are not legally required to appoint a formal DPO unless they perform large-scale systematic monitoring or process special category data at scale (such as health data). However, GDPR still requires that someone is accountable for privacy decisions. Kobalt's Fractional DPO service covers all of the same functions: privacy expertise on demand, DSAR management, breach response, and regulatory liaison. At $7,500 per month, it is a fraction of the cost of a $180,000+ full-time hire.
EU GDPR covers personal data of data subjects in the EU/EEA where the regulation's territorial scope applies. CCPA (California Consumer Privacy Act) covers California residents. Both require privacy notices and data subject rights mechanisms, but GDPR has significantly stricter breach notification requirements (72-hour window to notify regulators) and substantially higher fines. Most companies Kobalt works with address both regulations in a single compliance program, since the policy infrastructure overlaps significantly.
EU/EEA regulators can impose fines up to €20 million or 4% of global annual revenue, whichever is higher. Recent confirmed examples: Meta was fined €1.2 billion by the Irish DPC in 2023, TikTok was fined €345 million by the Irish DPC in 2023, and LinkedIn was fined €310 million by the Irish DPC in 2024. Beyond fines, non-compliance creates direct business risk: enterprise buyers increasingly require GDPR compliance documentation as part of procurement, and a data breach without a compliant program dramatically increases legal exposure.
UK GDPR is the post-Brexit version of the EU GDPR, embedded in the Data Protection Act 2018 and further updated by the Data (Use and Access) Act 2025 (DUAA). It is supervised exclusively by the ICO (Information Commissioner's Office), which is independent of EU/EEA supervisory authorities; the ICO is not an EU DPA. Core requirements are largely aligned with EU GDPR, but specific differences apply: data transfers use the IDTA or the UK Addendum to the EU SCCs rather than SCCs alone; representative requirements are separate (a UK representative appointed in writing where required); and adequacy decisions are managed independently. If your company operates in both the EEA and UK markets, both frameworks apply and must be scoped separately.