Jurisdiction Guide
European Union Privacy & Data Protection Laws
Every regime below can apply to a business handling European Union residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Applies to any organization established in the EU (regardless of where processing actually happens), OR to a non-EU organization that either offers goods/services to people in the EU (paid or free) or monitors their behavior (analytics, ad targeting, profiling) — no revenue or headcount threshold triggers or excuses this. Nonprofits and public authorities are generally covered, not exempt (unlike most US comprehensive laws). A narrow exemption from Article 30 record-keeping exists for organizations under 250 employees, but only for that specific paperwork duty — it doesn't exempt them from GDPR's substantive rules.