6.3 GDPR Requirements and Multinational Conflicts
Key Takeaways
- A U.S. company is in GDPR territorial scope under Article 3(1) if it has an EU/EEA establishment whose processing is in the context of that establishment, or under Article 3(2) if it targets people in the Union by offering goods or services or monitoring their behavior
- GDPR processing needs an Article 6 lawful basis (and Article 9 for special-category data); U.S. notice-and-choice is not a substitute lawful basis
- Targeting without an establishment can trigger a Data Protection Officer, a Data Protection Impact Assessment, and an Article 27 EU representative even when the company never opened a Dublin office
- Classic conflicts include EU data minimization versus a U.S. litigation hold, GDPR erasure versus SEC or tax retention, and EU limits on employee monitoring versus U.S. workplace-notice practice
- APEC CBPR and PRP are BoK-listed certification systems built on the APEC Privacy Framework; they are not an EU adequacy decision and do not waive Chapter V
GDPR Requirements and Multinational Conflicts
International-transfer tools answer how EU personal data may leave the EEA. This section answers a prior question the CIPP/US BoK still expects a U.S. professional to get right: when does the GDPR apply to the U.S. company at all, and what happens when EU duties collide with U.S. litigation, securities, tax, and workplace practice.
Article 3: establishment and targeting
Article 3 is territorial scope, not a citizenship test and not a "we have no EU office" escape hatch.
Article 3(1) — establishment. The GDPR applies to processing in the context of the activities of an establishment of a controller or processor in the Union, whether or not the processing itself occurs in the Union. A stable arrangement in a Member State — a subsidiary, a branch, or sometimes a one-person sales office that behaves like an establishment — is enough. If the U.S. parent’s processing is inextricably linked to that EU establishment's activities (the Google Spain / establishment case law the GDPR absorbed), Article 3(1) reaches the parent’s processing too. "The servers are in Virginia" does not defeat 3(1).
Article 3(2) — targeting. A controller or processor not established in the Union is still in scope when the processing relates to (a) offering goods or services to data subjects in the Union, whether paid or free, or (b) monitoring their behavior insofar as that behavior takes place in the Union. Recital 23 looks for an intention to target: Union languages and currencies, the ability to order in those languages, dedicated country sites, or marketing aimed at Member States. Recital 24 treats tracking on the internet, including profiling for decisions or for analyzing personal preferences, as monitoring. A U.S. app that geo-prices in euros, ships to France, and runs behavioral ads at French users is in Article 3(2) even if every employee sits in Austin.
Article 3 is not triggered merely because an EU person happens to use a purely U.S.-oriented site while on vacation, and it is not limited to EU citizens. The test is establishment or targeting of people in the Union.
Lawful bases versus U.S. notice-and-choice
Once the GDPR applies, Article 6 requires a lawful basis before processing: consent, contract, legal obligation, vital interests, public task, or legitimate interests (balanced against the data subject's interests and rights). Article 9 adds a separate condition for special-category data (health, biometrics for identification, racial or ethnic origin, and the rest of the list). Transparency (Articles 13–14) is a parallel duty, not the basis.
Classic U.S. notice-and-choice — publish a privacy notice, offer an opt-out for some secondary uses, keep processing unless the consumer objects — is not an Article 6 basis. A U.S. notice that says "by using this site you agree" is rarely valid consent under Article 4(11) and Article 7 (freely given, specific, informed, unambiguous, and as easy to withdraw as to give). Contract covers what is necessary to perform the requested service, not a bundle of analytics and advertising. Legitimate interests can support some B2B and security processing, but the balancing test and the right to object (Article 21) still apply, and legitimate interests is a weak story for large-scale special-category or children's data.
The exam contrast is therefore conceptual: the United States often asks "did you disclose it and offer a choice?" The GDPR asks "which Article 6 box did you tick, and can you prove it?" A multinational that copies its California notice into an EU product flow has not finished the analysis.
DPIA, DPO, and the EU representative
Three operational duties appear constantly in U.S. multinational fact patterns.
A Data Protection Impact Assessment (DPIA) (Article 35) is required when processing is likely to result in a high risk to rights and freedoms — especially systematic and extensive profiling that produces legal or similarly significant effects, large-scale special-category or criminal-data processing, or systematic monitoring of a publicly accessible area. A U.S. retailer that scores EU customers for automated credit or that rolls out always-on workplace cameras in an EU warehouse should expect a DPIA before go-live, not a memo after the first complaint.
A Data Protection Officer (DPO) (Articles 37–39) is required when the controller or processor is a public authority, when core activities consist of regular and systematic monitoring on a large scale, or when core activities consist of large-scale processing of special-category or criminal data. The DPO must be independent, resourced, and reachable. Naming the U.S. general counsel as DPO while that lawyer also defends the company against data-subject claims is the independence trap.
An Article 27 representative is required when Article 3(2) applies and no exception fits (the processing is occasional, does not include large-scale special-category or criminal data, and is unlikely to result in a risk — a narrow out). The representative is established in a Member State where some of the targeted data subjects are, and is the supervisory authority's and data subjects' local addressee. Article 27 is not the same as appointing a DPO, and DPF certification does not erase the representative duty for a non-established targeting controller.
| Duty | Typical U.S. trigger | Common miss |
|---|---|---|
| Article 6 / 9 lawful basis | Any in-scope processing | Treating the U.S. privacy notice as the basis |
| DPIA (Art. 35) | High-risk profiling, large-scale special-category data, systematic monitoring | Writing the assessment after launch |
| DPO (Art. 37) | Large-scale regular monitoring or special-category core activities | Combining the role with a conflicted legal-defense job |
| EU representative (Art. 27) | Article 3(2) targeting without an establishment | Assuming DPF or SCCs replace the representative |
Conflict examples the exam actually uses
Data minimization versus a U.S. litigation hold. Article 5(1)(c) limits personal data to what is necessary. A U.S. parent in active federal litigation issues a legal hold that freezes EU employee mailboxes "in place," including years of unnecessary HR notes. EU law does not make the hold disappear — establishing, exercising, or defending legal claims is a recognized GDPR theme (including an Article 17(3)(e) limit on erasure and a possible Article 6(1)(f) or 6(1)(c) story). The conflict is scoped: hold what the claim requires, document the U.S. legal obligation or legitimate interest, restrict access, and resume minimization when the hold lifts. "Litigation in Delaware, keep everything forever" fails both systems.
Erasure versus SEC or tax retention. Article 17's right to erasure yields where processing is necessary for compliance with a legal obligation in Union or Member State law (Article 17(3)(b)) or for legal claims. A U.S. securities or tax retention rule is not automatically "Union or Member State law." The practical reconciliation is to identify whether an EU/Member State obligation also requires the keep, whether a claims or accounting necessity still applies, and whether the U.S. retention can be met with minimized, access-restricted, non-production archives rather than a live marketing profile. Do not tell an examiner that the Securities and Exchange Commission silently preempts Article 17 worldwide. Do not delete a required broker-dealer or tax record because a marketing data subject asked.
Employee monitoring. EU workplace monitoring is typically necessary and proportionate, preceded by notice (and often works-council or labor consultation), and hard to rest on consent because of the imbalance of power. U.S. private-sector practice is often notice plus a workplace-privacy policy, with broader employer latitude under the Electronic Communications Privacy Act's provider and consent exceptions (Domain IV). A U.S. company that silently deploys keystroke logging on EU laptops because "our U.S. handbook allows it" is answering the wrong legal system. Run the GDPR lawful-basis and DPIA analysis for the EU population; do not import the U.S. handbook as an Article 6 basis.
APEC CBPR and PRP — describe, do not overclaim
The Asia-Pacific Economic Cooperation (APEC) Cross-Border Privacy Rules (CBPR) system and Privacy Recognition for Processors (PRP) operationalize the APEC Privacy Framework principles (preventing harm, notice, collection limitation, use limitation, choice, integrity, security safeguards, access and correction, and accountability). CBPR is the controller-facing certification; PRP is the processor-facing recognition. A participating economy (the United States is one) designates accountability agents; a company that certifies can transfer personal information among participating CBPR economies under that system's rules. The Global CBPR Forum is a related, later effort to carry those certifications beyond APEC; it is still not an EU adequacy decision.
The BoK lists these principles because a U.S. multinational that sells into Asia will meet them. They are not:
- an Article 45 adequacy decision for the United States,
- a substitute for SCCs or DPF on an EU-to-U.S. flow,
- a waiver of Article 3, Article 6, DPIA, DPO, or Article 27,
- a finding that U.S. federal law is "adequate" in the GDPR sense.
Scenario. A Boston health-tech vendor has no EU office. It localizes its checkout in German, prices in euros, and profiles German users for wellness scores. Article 3(2) applies. It needs an Article 6/9 basis (consent or another Article 9 condition for health data — not a U.S. notice), a DPIA, likely a DPO if this scoring is a core activity on a large scale, an Article 27 representative, and a Chapter V tool for any EU-to-U.S. hosting. Its APEC CBPR seal helps Asia-Pacific customers. It does not move the German profiles to Virginia by itself.
Exam traps
- Do not say the GDPR applies only to EU-headquartered companies or only to EU citizens.
- Do not treat U.S. notice-and-choice as Article 6 consent.
- Do not let a U.S. litigation hold or SEC calendar erase minimization and erasure without a scoped legal analysis.
- Do not promote CBPR/PRP into EU adequacy.
When is a U.S.-incorporated company in the territorial scope of the GDPR?
Which example is a genuine multinational conflict a CIPP/US candidate should be ready to reconcile?
How should a CIPP/US candidate describe APEC Cross-Border Privacy Rules and Privacy Recognition for Processors?