If all your customers are in the US, do you actually need to care about GDPR?
Comes up constantly and the answers are all over the place, so curious how this sub reads it. If a business is US-based and its customers are all in the US, does GDPR actually apply?
The nuance I keep seeing missed: it's not about where your company is, it's about whose data you process. An EU visitor hitting your US site, an EU customer buying, EU traffic you're running analytics on – any of those can pull you in, even with no EU entity. But "we occasionally get EU visitors" isn't the same as "targeting the EU market" either.
(We work on the consent side, so we hit this question a lot. We're genuinely curious to know where people draw the line.)
Where do you all land: does incidental EU traffic trigger it, or only actually targeting the EU market?