AI & Privacy · guide
GDPR Enforcement Basics for US Companies: How EDPB Decisions and DPA Fines Work
Updated
A US company can be fined under the GDPR without an EU office, and the largest fines to date have been imposed on US-headquartered groups. What confuses many teams is not the substantive rules but the machinery: which regulator leads, how other regulators can force a bigger penalty, and how fine amounts are set. This guide explains that machinery in plain terms. Details are current at time of writing (September 2026).
Who is caught: Article 3(2)
The GDPR applies to a controller or processor with no EU establishment when its processing relates to offering goods or services to people in the Union, whether or not payment is required, or to monitoring their behavior within the Union (Article 3(2)). Shipping to EU addresses, pricing in euros, EU-language marketing and behavioral analytics on EU visitors are all classic indicators. Merely having a website reachable from Europe is not.
Article 27: the EU representative
A company caught by Article 3(2) must designate in writing a representative established in one of the Member States where its EU data subjects are, unless the processing is occasional, does not include large-scale processing of special-category or criminal data, and is unlikely to result in risk to individuals (Article 27). The representative is the point of contact for supervisory authorities and data subjects and must be named in the privacy notice. Public authorities are exempt. Not appointing one is itself a fineable breach.
Who leads: Article 56 and the one-stop-shop
For cross-border processing, the supervisory authority (DPA) of the company's main establishment in the EU acts as lead supervisory authority and sole interlocutor (Article 56). That is why Ireland's Data Protection Commission (DPC) handles Meta, TikTok and others headquartered in Dublin. A company with no EU establishment has no lead authority: each DPA where its data subjects are located can act independently, which is a reason some US companies establish an EU entity. A local DPA can also handle a matter that affects only its own Member State.
Article 60 cooperation and Article 65 binding decisions
The lead DPA investigates and circulates a draft decision to every concerned DPA. Those authorities have four weeks to raise a relevant and reasoned objection; if the lead accepts it, a revised draft goes round for two more weeks (Article 60). If the lead rejects the objection, the dispute goes to the European Data Protection Board (EDPB), which adopts a binding decision by two-thirds majority within one month, extendable by another month (Article 65). The lead must then issue a final decision within one month that follows the Board's ruling.
This is how the largest fine on record was produced. The DPC's draft decision on Meta's transfers of Facebook data to the US did not include a fine. Other DPAs objected, the EDPB adopted Binding Decision 1/2023 on April 13, 2023 instructing the DPC to impose one, and on May 12, 2023 the DPC issued its final decision: a 1.2 billion euro fine, an order to suspend transfers within five months, and an order to cease unlawful processing and storage of already-transferred data within six months.
Article 83: the fine tiers
| Tier | Maximum | Covers |
|---|---|---|
| Article 83(4) | 10 million euros or 2 percent of worldwide annual turnover, whichever is higher | Controller and processor obligations such as records, security, breach notification, DPIAs and DPOs |
| Article 83(5) and (6) | 20 million euros or 4 percent of worldwide annual turnover, whichever is higher | Processing principles and lawful basis, data subject rights, international transfers, and non-compliance with a DPA order |
The turnover figure is that of the undertaking, which the EDPB reads as the whole corporate group, not the EU subsidiary. See Article 83.
How the number is calculated
The EDPB's Guidelines 04/2022 on the calculation of administrative fines, finalized in 2023, set a five-step method: identify the processing and whether several infringements are linked; pick a starting point based on the seriousness of the infringement, expressed as a band of the legal maximum (low seriousness 0 to 10 percent, medium 10 to 20 percent, high 20 to 100 percent), adjusted for turnover; apply aggravating and mitigating factors; check the legal maximum; and test whether the result is effective, proportionate and dissuasive. Courts increasingly hold DPAs to this reasoning. In March 2026 a Luxembourg appeals court annulled the 746 million euro fine imposed on Amazon in 2021 because the regulator had not established whether the breach was intentional or negligent or considered lesser measures, and sent the case back, as reported by The Record. The finding of infringement stood.
Other fines to know
The DPC fined TikTok 530 million euros on May 2, 2025: 485 million for transfers to China without essentially equivalent protection (Article 46) and 45 million for transparency failures (Article 13), with an order to comply within six months; no other DPA objected under Article 60, per the DPC announcement. Fines are routinely appealed, so treat headline figures as provisional until the courts are done.
The EU-US Data Privacy Framework
The Commission's adequacy decision for the EU-US Data Privacy Framework was adopted on July 10, 2023, allowing transfers to certified US companies without further safeguards. The General Court dismissed the Latombe challenge on September 3, 2025 (press release); an appeal to the Court of Justice was filed on October 31, 2025 and is pending at time of writing. Companies relying on the framework should keep standard contractual clauses ready as a fallback.
How to monitor
- The EDPB news page carries Board decisions, guidelines and notable national fines.
- The register of final one-stop-shop decisions lists Article 60 outcomes, filterable by lead authority, article and outcome type.
- The EDPB's binding decisions page lists every Article 65 ruling.
- Each national DPA publishes its own decisions; Ireland, France, Italy, Spain and the Netherlands are the most active against US companies.
RegPing's AI and privacy bot posts EDPB and DPA decision announcements like these into Discord as they appear.
Where to verify
- Regulation (EU) 2016/679 on EUR-Lex
- EDPB Guidelines 04/2022 on calculating fines
- EDPB Binding Decision 1/2023 (Meta transfers)
- DPC final decision on Meta Ireland transfers
- DPC TikTok decision announcement
- EDPB register of one-stop-shop decisions
- General Court press release in Latombe v Commission
This guide is general information, not legal advice. Verify against the primary source and consult counsel before acting.
Questions people ask
Does the GDPR apply to a US company with no EU office?
Yes, if it offers goods or services to people in the EU or monitors their behavior there (Article 3(2)). Such companies usually must also appoint an EU representative under Article 27.
What are the maximum GDPR fines?
Two tiers: up to 10 million euros or 2 percent of worldwide annual turnover for most controller and processor obligations, and up to 20 million euros or 4 percent for breaches of processing principles, data subject rights, transfer rules or DPA orders, whichever is higher.
How did Meta end up with a 1.2 billion euro fine?
The Irish DPC's draft decision proposed no fine, but other DPAs objected, and the EDPB's Article 65 binding decision of April 2023 required one. The DPC issued the 1.2 billion euro fine and transfer suspension order in May 2023.