{"id":469,"date":"2024-03-29T11:34:31","date_gmt":"2024-03-29T10:34:31","guid":{"rendered":"https:\/\/stage.usercentrics.com\/?post_type=knowledge&#038;p=13591"},"modified":"2025-06-25T09:21:08","modified_gmt":"2025-06-25T07:21:08","slug":"gdpr-compliance-checklist-for-us-companies","status":"publish","type":"knowledge","link":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/gdpr-compliance-checklist-for-us-companies\/","title":{"rendered":"Comprehensive GDPR compliance checklist for U.S. companies"},"content":{"rendered":"<p>The <a href=\"https:\/\/usercentrics-poc.psapp.devgdpr\/\">General Data Protection Regulation (GDPR)<\/a> has been in effect in the European Union since May 2018. Any organization that handles the consumer data of EU residents needs to take GDPR compliance seriously.<\/p>\n<p>GDPR compliance is also valuable for those doing business in the United States, among other countries that have since introduced data privacy laws. California, for example, borrowed heavily from the GDPR when drafting its data privacy regulations. This has since influenced data privacy legislation drafted by other states.<\/p>\n<p>Achieving GDPR compliance puts U.S. companies ahead of the game in ensuring state-by-state compliance at home. By adopting its more stringent best practices, you\u2019re set up to avoid future disruptions as more regulations are passed in the U.S. and other countries.<\/p>\n<p>The following information will help clarify your company\u2019s GDPR compliance requirements. Please note that due to differences in implementation and enforcement among EU countries, we strongly recommend that you consult with a lawyer specializing in data protection and privacy.<\/p>\n<p>\u00a0<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-gdpr-in-the-u-s-does-your-company-need-to-be-compliant\">GDPR in the U.S.: Does your company need to be compliant?<\/h2>\n\n\n<p>One of the first questions asked by U.S. companies is, \u201cDoes the GDPR apply to us?\u201d If your company does business in the EU that involves collecting and processing user data, then yes, you do need to be GDPR-compliant.<\/p>\n<p>This can mean you sell products or services in the EU, work with partners or customers there, or receive web traffic from visitors located there.<\/p>\n<p>Note that the GDPR is extraterritorial. This means it applies to organizations that process EU residents\u2019 personal data whether or not those entities are actually located in the EU. It only matters that the personal data being used belongs to people in the EU.<\/p>\n<p>In July 2023, the <a href=\"https:\/\/usercentrics-poc.psapp.devknowledge-hub\/eu-us-data-privacy-framework\/\">EU-U.S. Data Privacy Framework<\/a> introduced a new adequacy agreement between the two regions, which had been without one since the Schrems II decision struck down the previous EU\u2013U.S. Privacy Shield framework in 2020.<\/p>\n<p>The EU-U.S. Data Privacy Framework does not apply GDPR requirements to the U.S., though it is a legal agreement and does apply certain standards to data protection and international transfers. The framework also outlines data subjects\u2019 rights, responsibilities and requirements for certified companies, redress mechanisms for complaints, and requirements and restrictions on US intelligence services.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-gdpr-requirements-for-u-s-companies\">GDPR requirements for U.S. companies<\/h2>\n\n\n\n<p>The GDPR\u2019s requirements differ from data privacy regulations in the U.S., so you need to understand the distinctions. These include the following.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Scope of jurisdiction<\/h4>\n\n\n\n<p>Data privacy laws passed to date in the U.S. are all at the state level, each one only applies in the state where it was enacted. The U.S. does not yet have a federal data privacy regulation, so companies need to check if there\u2019s a law for each state where they do business, and what its requirements are.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Scope of protection<\/h4>\n\n\n\n<p>Privacy laws in the U.S., like the <a href=\"https:\/\/usercentrics-poc.psapp.devccpa\/\">California Consumer Privacy Act (CCPA)<\/a>, are centered around consumer protection, whereas the GDPR regulates data protection more comprehensively. That includes the B2C and B2B sectors.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Dedicated roles<\/h4>\n\n\n\n<p>In many instances, the GDPR requires organizations to appoint a data protection officer. This isn\u2019t the case under the majority of U.S. state-level laws passed to date.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Opting in and opting out<\/h4>\n\n\n\n<p>Under the GDPR, individuals must provide explicit opt-in consent prior to having their personal data collected and processed. The U.S. uses an opt-out model in all privacy laws passed to date, meaning you can collect and use data in many cases without obtaining consent (with the common exception of children\u2019s data or that categorized as \u201csensitive\u201d), You do have to provide a way for people to opt out of data collection and\/or processing for various purposes (these vary by state law).<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Terms and definitions<\/h4>\n\n\n\n<p>While the GDPR refers to \u201cpersonal data,\u201d the term \u201cpersonally identifiable information\u201d (PII) is more common in the U.S. The specific requirements for data to be \u201csensitive\u201d also vary. We explain these differences in depth: <a href=\"https:\/\/usercentrics-poc.psapp.devknowledge-hub\/personally-identifiable-information-vs-personal-data\/\">Personally Identifiable Information (PII) vs. Personal Data \u2014 What\u2019s the difference?<\/a><\/p>\n\n\n\n<p>Under the GDPR, you need a legal reason that can be proven to collect and process customer data. Valid consent is one of the six legal bases listed in <a href=\"https:\/\/gdpr.eu\/article-6-how-to-process-personal-data-legally\/\" target=\"_blank\" rel=\"noopener\">Art. 6 GDPR<\/a>. The conditions for consent to be valid are outlined in <a href=\"https:\/\/gdpr.eu\/article-7-how-to-get-consent-to-collect-personal-data\/\" target=\"_blank\" rel=\"noopener\">Art. 7 GDPR<\/a>.<\/p>\n\n\n\n<p>You need to document and clearly communicate to site visitors, customers, app users, etc. what personal data you want to collect, for what purpose(s), who may have access to it, and several other requirements. If the purpose for processing user data changes, you must obtain new consent from users.<\/p>\n\n\n\n<p>Data controllers (e.g. companies collecting data from visitors to its website), can use any of the legal bases for data processing if they can prove the necessity of doing so. You can\u2019t simply choose or change a legal basis because a business need a change or one method (like obtaining valid consent) is more work.<\/p>\n\n\n<div class=\"uc-notice\">\n    <div class=\"uc-notice__icon\">\n        <svg width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M10.8177 17.0093H12.8177V11.0093H10.8177V17.0093ZM11.8177 9.00928C12.1011 9.00928 12.3386 8.91344 12.5302 8.72178C12.7219 8.53011 12.8177 8.29261 12.8177 8.00928C12.8177 7.72594 12.7219 7.48844 12.5302 7.29678C12.3386 7.10511 12.1011 7.00928 11.8177 7.00928C11.5344 7.00928 11.2969 7.10511 11.1052 7.29678C10.9136 7.48844 10.8177 7.72594 10.8177 8.00928C10.8177 8.29261 10.9136 8.53011 11.1052 8.72178C11.2969 8.91344 11.5344 9.00928 11.8177 9.00928ZM11.8177 22.0093C10.4344 22.0093 9.13442 21.7468 7.91775 21.2218C6.70108 20.6968 5.64275 19.9843 4.74275 19.0843C3.84275 18.1843 3.13025 17.1259 2.60525 15.9093C2.08025 14.6926 1.81775 13.3926 1.81775 12.0093C1.81775 10.6259 2.08025 9.32594 2.60525 8.10928C3.13025 6.89261 3.84275 5.83428 4.74275 4.93428C5.64275 4.03428 6.70108 3.32178 7.91775 2.79678C9.13442 2.27178 10.4344 2.00928 11.8177 2.00928C13.2011 2.00928 14.5011 2.27178 15.7177 2.79678C16.9344 3.32178 17.9928 4.03428 18.8927 4.93428C19.7927 5.83428 20.5052 6.89261 21.0302 8.10928C21.5552 9.32594 21.8177 10.6259 21.8177 12.0093C21.8177 13.3926 21.5552 14.6926 21.0302 15.9093C20.5052 17.1259 19.7927 18.1843 18.8927 19.0843C17.9928 19.9843 16.9344 20.6968 15.7177 21.2218C14.5011 21.7468 13.2011 22.0093 11.8177 22.0093Z\" fill=\"black\"\/>\n<\/svg>\n    <\/div>\n    <div class=\"uc-notice__content\">\n                <p>Read about <a href=\"https:\/\/usercentrics-poc.psapp.devguides\/social-media-email-marketing-compliance\/gdpr-email-marketing\/\">marketing data strategy in alignment with GDPR<\/a> now<\/p>\n            <\/div>\n<\/div>\n\n\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-u-s-gdpr-compliance-checklist\">U.S. GDPR compliance checklist<\/h2>\n\n\n<p>\u2705 Keep data privacy and protection top of mind in all aspects of your business, especially the customer-facing parts. It\u2019s cheaper, more efficient, and less resource-intensive to build compliance into your system from the beginning using a <a href=\"https:\/\/usercentrics-poc.psapp.devknowledge-hub\/what-is-privacy-by-design\/\">privacy by design<\/a> approach, rather than retrofitting it. Especially when considering the risks of violations if efforts are not comprehensive enough.<\/p>\n<p>\u2705 Create an <a href=\"https:\/\/gdpr.eu\/recital-78-appropriate-technical-and-organisational-measures\/\" target=\"_blank\" rel=\"noopener\">internal security policy<\/a> for employees, partners and contractors to ensure security measures are adequate, and keep it updated. Ensure it\u2019s clear and covers all operations and specific roles within the organization where accessing personal data is necessary.<\/p>\n<p>\u2705 Know what a <a href=\"https:\/\/gdpr.eu\/article-35-impact-assessment\/\" target=\"_blank\" rel=\"noopener\">data protection impact assessment<\/a> is and have a process to carry it out. These are legally required under some regulations, but a good idea regardless.<\/p>\n<p>\u2705 Wherever possible, when personal data is collected, <a href=\"https:\/\/usercentrics-poc.psapp.devknowledge-hub\/data-anonymization\/\">anonymize, pseudonymize, and encrypt it<\/a>.<\/p>\n<p>\u2705 In the event of a data breach, have a process in place to <a href=\"https:\/\/gdpr.eu\/article-33-notification-of-a-personal-data-breach\/\" target=\"_blank\" rel=\"noopener\">notify data subjects and the correct authorities<\/a> within the required time frame. Where possible, act as quickly and thoroughly as possible to provide information, cooperate with authorities, protect affected users, and mitigate and repair damage from the breach.<\/p>\n<h4>Data subjects\u2019 privacy rights<\/h4>\n<p>It must be clear and easy for customers, users, and visitors to:<\/p>\n<ul style=\"list-style-type: none;\">\n<li>\u2705 object to collection and\/or processing of their personal data<\/li>\n<li>\u2705 request and receive all the data you have about them in a timely manner<\/li>\n<li>\u2705 request a correction or update to inaccurate or incomplete data<\/li>\n<li>\u2705 request that their personal data be deleted in a timely manner (with some exceptions)<\/li>\n<li>\u2705 have you stop collecting and processing their data if they withdraw previous consent<\/li>\n<li>\u2705 receive a copy of all of their personal data to be transferred to another entity<\/li>\n<li>\u2705 have processes and policies in place (and user access to them) to protect their rights if you make decisions about them based on automated decision-making processes<\/li>\n<\/ul>\n<h4>Operations<\/h4>\n<table>\n<tbody>\n<tr>\n<th>Requirement<\/th>\n<th>Key actions<\/th>\n<th>Details<\/th>\n<\/tr>\n<tr>\n<td><img loading=\"lazy\" decoding=\"async\" style=\"width: 24px;\" src=\"\/wp-content\/themes\/usercentrics\/img\/table\/CheckCircleFilled.svg\" alt=\"\" width=\"24\" height=\"24\" \/> Know what data you collect, store, and use<\/td>\n<td>\n<ul>\n<li>Conduct an information audit to learn and document:\n<ul>\n<li>what data you collect<\/li>\n<li>why it\u2019s collected<\/li>\n<li>who has access to it (including third parties)<\/li>\n<li>how and where it\u2019s stored\/protected<\/li>\n<li>how long it\u2019s kept<\/li>\n<li>how it\u2019s expunged or returned<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/td>\n<td>\n<ul>\n<li>Organizations with 250+ employees, or that conduct higher-risk data processing, must keep an up to date and detailed <a href=\"https:\/\/gdpr.eu\/article-30-records-of-processing-activities\/\" target=\"_blank\" rel=\"noopener\">list of their processing activities<\/a>, which can be shown to regulators on request.<\/li>\n<li>Companies with fewer than 250 employees should still do these audits and maintain this information.<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td><img loading=\"lazy\" decoding=\"async\" style=\"width: 24px;\" src=\"\/wp-content\/themes\/usercentrics\/img\/table\/CheckCircleFilled.svg\" alt=\"\" width=\"24\" height=\"24\" \/> Have a legal basis for data processing activities<\/td>\n<td>\n<ul>\n<li>Determine which legal basis you process data under<\/li>\n<li>Determine what additional conditions may apply<\/li>\n<li>Document the rationale for your organization\u2019s chosen legal basis and be prepared to present it to regulators<\/li>\n<\/ul>\n<\/td>\n<td>\n<ul>\n<li>Legal basis is determined based on the six conditions under <a href=\"https:\/\/gdpr.eu\/article-6-how-to-process-personal-data-legally\/\" target=\"_blank\" rel=\"noopener\">Art. 6<\/a>.<\/li>\n<li>There are additional provisions relating to children and special categories of personal data in <a href=\"https:\/\/gdpr.eu\/tag\/chapter-2\/\" target=\"_blank\" rel=\"noopener\">Arts. 7\u201311<\/a>.<\/li>\n<li>Be aware of the <a href=\"https:\/\/gdpr.eu\/gdpr-consent-requirements\/\" target=\"_blank\" rel=\"noopener\">extra obligations<\/a> if consent is your chosen legal basis.<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td><img loading=\"lazy\" decoding=\"async\" style=\"width: 24px;\" src=\"\/wp-content\/themes\/usercentrics\/img\/table\/CheckCircleFilled.svg\" alt=\"\" width=\"24\" height=\"24\" \/> Appoint appropriate officers and representatives to manage data privacy and protection initiatives.<\/td>\n<td>\n<ul>\n<li>Designate a privacy\/compliance officer in your organization<\/li>\n<li>Appoint a representative within the EU if your organization is outside (e.g. United States)<\/li>\n<li>Determine if your organization needs a <a href=\"https:\/\/gdpr.eu\/data-protection-officer\/\" target=\"_blank\" rel=\"noopener\">data protection officer<\/a>, and appoint one if required<\/li>\n<\/ul>\n<\/td>\n<td>\n<ul>\n<li>The internal data protection officer needs to be able to <a href=\"https:\/\/gdpr.eu\/article-25-data-protection-by-design\/\" target=\"_blank\" rel=\"noopener\">understand the needs<\/a> of ongoing compliance, work on drafting, reviewing, implementing and enforcing the policies.<\/li>\n<li>EU member states require <a href=\"https:\/\/gdpr.eu\/article-27-representatives-of-controllers-not-in-union\/\" target=\"_blank\" rel=\"noopener\">a representative in each country<\/a> who can communicate on your behalf with data protection authorities.<\/li>\n<li>A data protection officer is needed if the organization:\n<ul>\n<li>&#8211; is a public authority<\/li>\n<li>&#8211; has large-scale data processing as a core activity<\/li>\n<li>&#8211; has large-scale data processing of special categories of data as a core activity<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td><img loading=\"lazy\" decoding=\"async\" style=\"width: 24px;\" src=\"\/wp-content\/themes\/usercentrics\/img\/table\/CheckCircleFilled.svg\" alt=\"\" width=\"24\" height=\"24\" \/> Create and use a data processing agreement with third parties.<\/td>\n<td>\n<ul>\n<li>Any third parties that process data on your behalf need to sign a <a href=\"https:\/\/gdpr.eu\/data-processing-agreement\/\" target=\"_blank\" rel=\"noopener\">data processing agreement<\/a> that clearly outlines how data is to be transferred, stored, protected, used, and erased.<\/li>\n<\/ul>\n<\/td>\n<td>\n<ul>\n<li>This can include email hosting, cloud services, advertising or marketing partnerships, analytics software, etc.<\/li>\n<li>Ensure the rights and obligations of both parties are clear.<\/li>\n<li>Reputable services should have a data processing agreement for review on their websites.<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h4>Users and customers<\/h4>\n<table>\n<tbody>\n<tr>\n<th>Requirement<\/th>\n<th>Key actions<\/th>\n<th>Details<\/th>\n<\/tr>\n<tr>\n<td><img loading=\"lazy\" decoding=\"async\" style=\"width: 24px;\" src=\"\/wp-content\/themes\/usercentrics\/img\/table\/CheckCircleFilled.svg\" alt=\"\" width=\"24\" height=\"24\" \/> Duty to provide information<\/td>\n<td>\n<ul>\n<li>Provide clear notification that you are using cookies or other tracking technologies on your website.<\/li>\n<li>Explain what the tracking technologies are doing and why, and what data they collect.<\/li>\n<li>Include this information in a Privacy Policy that\u2019s easy to find, read, and understand.<\/li>\n<li>Review and update the Privacy Policy at least every 12 months.<\/li>\n<\/ul>\n<\/td>\n<td>\n<ul>\n<li>Include the following information in the Privacy Policy:<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Name and contact of data controller<\/li>\n<li>Purpose of data processing\/tracking technologies<\/li>\n<li>Categories of people and personal data processed<\/li>\n<li>Transfers of personal data to third countries<\/li>\n<li>Time limit for deletion of personal data<\/li>\n<li>General description of security measures<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td><img loading=\"lazy\" decoding=\"async\" style=\"width: 24px;\" src=\"\/wp-content\/themes\/usercentrics\/img\/table\/CheckCircleFilled.svg\" alt=\"\" width=\"24\" height=\"24\" \/> Obtain explicit user consent<\/td>\n<td>\n<ul>\n<li>Obtain individuals\u2019 informed and explicit consent to use tracking technologies and to store cookies on their device(s).<\/li>\n<\/ul>\n<\/td>\n<td>Consent must be:\n<ul>\n<li><strong>Explicit:<\/strong> Active acceptance, e.g. ticking a box or clicking a link<\/li>\n<li><strong>Informed: <\/strong>Communicate the who, what, why, and for how long of data collection<\/li>\n<li><strong>Documented:<\/strong> You have the burden of proof in the case of an audit<\/li>\n<li><strong>In advance:<\/strong> No data is to be collected before opt-in, e.g. cookies cannot be set on your website before an individual has consented to them<\/li>\n<li><strong>Granular:<\/strong> Individual consent for individual purpose, i.e. consent cannot be bundled with other purposes or activities<\/li>\n<li><strong>Freely given:<\/strong> E.g. the \u201cAccept\u201d and \u201cReject\u201d options are equal size, prominence, and accessibility<\/li>\n<li><strong>Easy to withdraw:<\/strong> Opt out is available and is as easily accessible as opt in later if the person changes their mind<\/li>\n<li><strong>Exception<\/strong>: These rules don\u2019t apply to strictly necessary cookies (aka essential cookies), but there are restrictions regarding which kinds of cookies can be categorized as essential.<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td><img loading=\"lazy\" decoding=\"async\" style=\"width: 24px;\" src=\"\/wp-content\/themes\/usercentrics\/img\/table\/CheckCircleFilled.svg\" alt=\"\" width=\"24\" height=\"24\" \/> Setting cookies<\/td>\n<td>\n<ul>\n<li>Collect and process personal data via cookies only with valid consent.<\/li>\n<\/ul>\n<\/td>\n<td>\n<ul>\n<li><strong>Loading:<\/strong> Ensure cookies are not loaded until the person has given consent<\/li>\n<li><strong>User refusal:<\/strong> If someone rejects cookies, no cookies can be set. But the user must still be able to use your website\/access your service as much as possible without the cookie use.<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td><img loading=\"lazy\" decoding=\"async\" style=\"width: 24px;\" src=\"\/wp-content\/themes\/usercentrics\/img\/table\/CheckCircleFilled.svg\" alt=\"\" width=\"24\" height=\"24\" \/> Legally compliant documentation<\/td>\n<td>\n<ul>\n<li>Document and store consents received from users whose data you\u2019re processing.<\/li>\n<\/ul>\n<\/td>\n<td>\n<ul>\n<li><strong>Data protection authority (DPA) audit: <\/strong>Comply with documentation obligations and store evidence of consent in case of an audit by data protection authorities or a data subject access request in accordance with users\u2019 legal rights.<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td><img loading=\"lazy\" decoding=\"async\" style=\"width: 24px;\" src=\"\/wp-content\/themes\/usercentrics\/img\/table\/CheckCircleFilled.svg\" alt=\"\" width=\"24\" height=\"24\" \/> Opt out<\/td>\n<td>\n<ul>\n<li>Rejecting the use of cookies or other tracking technologies must be as easy to access and use as consenting.<\/li>\n<\/ul>\n<\/td>\n<td>\n<ul>\n<li><strong>Easy access:<\/strong> It must be as easy for individuals to withdraw their consent \u2014 at any time \u2014 as it is for them to give it.<\/li>\n<li><strong>External links: <\/strong>Linking to a separate page for opt-out is not sufficient.<\/li>\n<li><strong>After opt-out:<\/strong> Ensure no further data is collected, processed, or forwarded from the moment the consent request is rejected or rescinded, i.e. the opt-out must also be technically linked to the cookie and, ideally, documented.<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-ensuring-consent-is-gdpr-compliant\">Ensuring consent is GDPR-compliant<\/h2>\n\n\n<p>For an individual\u2019s consent to be GDPR-compliant, you need to meet seven criteria. See our article <a href=\"https:\/\/usercentrics-poc.psapp.devknowledge-hub\/7-criteria-for-a-gdpr-compliant-consent\/\">7 criteria for GDPR-compliant consent<\/a> for detailed information on those criteria and what that means for consent banners on your website.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-data-protection-and-regulation-of-children-s-data\">Data protection and regulation of children\u2019s data<\/h2>\n\n\n<p>Under the GDPR, you\u2019re generally only able to process personal data for children aged 16 and older. Parental or guardian consent must be obtained for data processing requests for children under 16.<\/p>\n<p>Some EU member states reduce the age limit to 13, but not all of them do. As confirming an individual\u2019s age can be ambiguous on some websites, we recommend obtaining explicit consent from all users.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-kickstart-gdpr-compliance-with-a-data-privacy-audit\">Kickstart GDPR compliance with a data privacy audit<\/h2>\n\n\n<p>As mentioned, the precise implementations and interpretations of GDPR vary among member states. But you\u2019ll need to complete a full data audit before you\u2019ll know exactly how GDPR requirements apply to your organization and customers.<\/p>\n<p>Start with Usercentrics\u2019 <a href=\"https:\/\/usercentrics-poc.psapp.devdata-privacy-audit\/\">free data privacy audit<\/a> that detects the cookies and trackers in use on your website, and can help you to see where your website might fall short of GDPR compliance.<\/p>\n<p>While this audit will support your compliance efforts, it does not replace legal advice. To ensure your company\u2019s GDPR compliance efforts are robust and compliant, we strongly recommend working with legal counsel that specializes in data protection and privacy, and appointing a Data Protection Officer.<\/p>\n<p>Still have questions about data privacy requirements under the GDPR and how to achieve and maintain compliance? We\u2019re here to help.<\/p>\n\n<a id=\"c3d02bdf-27f2-4703-9a52-035bf55546f5\" class=\"uc-button uc-button-size-m uc-button-contained  no-default-link-decoration\" href=\"https:\/\/usercentrics-poc.psapp.devbook-a-consultation\/\" target=\"\"><span>Contact sales<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>This GDPR Compliance Checklist for US companies helps American companies navigate GDPR compliance so that they can focus on doing business in the EU and avoid fines<\/p>\n","protected":false},"featured_media":8876,"template":"","meta":{"_acf_changed":false,"editor_notices":[],"footnotes":""},"tags":[],"magazine_issue":[],"magazine_tag":[],"resource_tag":[13],"class_list":["post-469","knowledge","type-knowledge","status-publish","has-post-thumbnail","hentry","resource_tag-regulations"],"acf":[],"yoast_head":"<title>Download GDPR Compliance Checklist for US Companies<\/title>\n<meta name=\"description\" content=\"Our GDPR compliance checklist helps navigate GDPR requirements for US companies. Build trust, protect data, and address GDPR for US companies effectively.\" \/>\n<meta name=\"robots\" content=\"noindex, follow\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Download GDPR Compliance Checklist for US Companies\" \/>\n<meta property=\"og:description\" content=\"Our GDPR compliance checklist helps navigate GDPR requirements for US companies. Build trust, protect data, and address GDPR for US companies effectively\" \/>\n<meta property=\"og:url\" content=\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/gdpr-compliance-checklist-for-us-companies\/\" \/>\n<meta property=\"og:site_name\" content=\"Usercentrics - US\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/usercentrics\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-25T07:21:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2024\/03\/45.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"GDPR Compliance Checklist For US Companies\" \/>\n<meta name=\"twitter:description\" content=\"This GDPR Compliance Checklist for US companies helps American companies navigate GDPR compliance so that they can focus on doing business in the EU and avoid fines\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/usercentrics-poc.psapp.devwp-content\/uploads\/2021\/09\/GDPR_checklist-1.jpg\" \/>\n<meta name=\"twitter:site\" content=\"@usercentrics\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/gdpr-compliance-checklist-for-us-companies\/\",\"url\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/gdpr-compliance-checklist-for-us-companies\/\",\"name\":\"Download GDPR Compliance Checklist for US Companies\",\"isPartOf\":{\"@id\":\"https:\/\/test-usercentrics-poc.pantheonsite.io\/us\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/gdpr-compliance-checklist-for-us-companies\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/gdpr-compliance-checklist-for-us-companies\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2024\/03\/Comprehensive-GDPR-compliance-checklist-for-U.S.-companies-1.jpg\",\"datePublished\":\"2024-03-29T10:34:31+00:00\",\"dateModified\":\"2025-06-25T07:21:08+00:00\",\"description\":\"Our GDPR compliance checklist helps navigate GDPR requirements for US companies. Build trust, protect data, and address GDPR for US companies effectively.\",\"breadcrumb\":{\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/gdpr-compliance-checklist-for-us-companies\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/gdpr-compliance-checklist-for-us-companies\/\"}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/gdpr-compliance-checklist-for-us-companies\/#primaryimage\",\"url\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2024\/03\/Comprehensive-GDPR-compliance-checklist-for-U.S.-companies-1.jpg\",\"contentUrl\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2024\/03\/Comprehensive-GDPR-compliance-checklist-for-U.S.-companies-1.jpg\",\"width\":1000,\"height\":1000,\"copyrightNotice\":\"\u00a9 Copyright 2026 Usercentrics GmbH\",\"creator\":{\"@type\":\"Organization\",\"name\":\"Usercentrics GmbH\"},\"creditText\":\"Image: Usercentrics GmbH\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/gdpr-compliance-checklist-for-us-companies\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Resources\",\"item\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/resources\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Blog\",\"item\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Comprehensive GDPR compliance checklist for U.S. companies\",\"item\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/gdpr-compliance-checklist-for-us-companies\/\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/test-usercentrics-poc.pantheonsite.io\/us\/#website\",\"url\":\"https:\/\/test-usercentrics-poc.pantheonsite.io\/us\/\",\"name\":\"Usercentrics - US\",\"description\":\"Consent Management Platform (CMP) Usercentrics\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/test-usercentrics-poc.pantheonsite.io\/us\/?s={search_term_string}\"}}],\"inLanguage\":\"en-US\"}]}<\/script>","yoast_head_json":{"title":"Download GDPR Compliance Checklist for US Companies","description":"Our GDPR compliance checklist helps navigate GDPR requirements for US companies. Build trust, protect data, and address GDPR for US companies effectively.","robots":{"index":"noindex","follow":"follow"},"og_locale":"en_US","og_type":"article","og_title":"Download GDPR Compliance Checklist for US Companies","og_description":"Our GDPR compliance checklist helps navigate GDPR requirements for US companies. Build trust, protect data, and address GDPR for US companies effectively","og_url":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/gdpr-compliance-checklist-for-us-companies\/","og_site_name":"Usercentrics - US","article_publisher":"https:\/\/www.facebook.com\/usercentrics","article_modified_time":"2025-06-25T07:21:08+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2024\/03\/45.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_title":"GDPR Compliance Checklist For US Companies","twitter_description":"This GDPR Compliance Checklist for US companies helps American companies navigate GDPR compliance so that they can focus on doing business in the EU and avoid fines","twitter_image":"https:\/\/usercentrics-poc.psapp.devwp-content\/uploads\/2021\/09\/GDPR_checklist-1.jpg","twitter_site":"@usercentrics","twitter_misc":{"Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/gdpr-compliance-checklist-for-us-companies\/","url":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/gdpr-compliance-checklist-for-us-companies\/","name":"Download GDPR Compliance Checklist for US Companies","isPartOf":{"@id":"https:\/\/test-usercentrics-poc.pantheonsite.io\/us\/#website"},"primaryImageOfPage":{"@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/gdpr-compliance-checklist-for-us-companies\/#primaryimage"},"image":{"@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/gdpr-compliance-checklist-for-us-companies\/#primaryimage"},"thumbnailUrl":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2024\/03\/Comprehensive-GDPR-compliance-checklist-for-U.S.-companies-1.jpg","datePublished":"2024-03-29T10:34:31+00:00","dateModified":"2025-06-25T07:21:08+00:00","description":"Our GDPR compliance checklist helps navigate GDPR requirements for US companies. Build trust, protect data, and address GDPR for US companies effectively.","breadcrumb":{"@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/gdpr-compliance-checklist-for-us-companies\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/gdpr-compliance-checklist-for-us-companies\/"}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/gdpr-compliance-checklist-for-us-companies\/#primaryimage","url":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2024\/03\/Comprehensive-GDPR-compliance-checklist-for-U.S.-companies-1.jpg","contentUrl":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2024\/03\/Comprehensive-GDPR-compliance-checklist-for-U.S.-companies-1.jpg","width":1000,"height":1000,"copyrightNotice":"\u00a9 Copyright 2026 Usercentrics GmbH","creator":{"@type":"Organization","name":"Usercentrics GmbH"},"creditText":"Image: Usercentrics GmbH"},{"@type":"BreadcrumbList","@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/gdpr-compliance-checklist-for-us-companies\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https:\/\/usercentrics-poc.psapp.dev\/us\/resources\/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/"},{"@type":"ListItem","position":3,"name":"Comprehensive GDPR compliance checklist for U.S. companies","item":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/gdpr-compliance-checklist-for-us-companies\/"}]},{"@type":"WebSite","@id":"https:\/\/test-usercentrics-poc.pantheonsite.io\/us\/#website","url":"https:\/\/test-usercentrics-poc.pantheonsite.io\/us\/","name":"Usercentrics - US","description":"Consent Management Platform (CMP) Usercentrics","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/test-usercentrics-poc.pantheonsite.io\/us\/?s={search_term_string}"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/knowledge\/469","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/knowledge"}],"about":[{"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/types\/knowledge"}],"version-history":[{"count":0,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/knowledge\/469\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/media\/8876"}],"wp:attachment":[{"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/media?parent=469"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/tags?post=469"},{"taxonomy":"magazine_issue","embeddable":true,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/magazine_issue?post=469"},{"taxonomy":"magazine_tag","embeddable":true,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/magazine_tag?post=469"},{"taxonomy":"resource_tag","embeddable":true,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/resource_tag?post=469"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}