Comprehensive Privacy Law
General Data Protection Regulation
European Union · May 25, 2018
Applies to any organization established in the EU (regardless of where processing actually happens), OR to a non-EU organization that either offers goods/services to people in the EU (paid or free) or monitors their behavior (analytics, ad targeting, profiling) — no revenue or headcount threshold triggers or excuses this. Nonprofits and public authorities are generally covered, not exempt (unlike most US comprehensive laws). A narrow exemption from Article 30 record-keeping exists for organizations under 250 employees, but only for that specific paperwork duty — it doesn't exempt them from GDPR's substantive rules.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.