US SaaS companies selling into the EU face a compliance stack that applies regardless of where they are incorporated. EU regulations use the "targeting criterion" — if you are offering services to EU users, the relevant regulation applies to you. This article covers the minimum viable compliance requirements for a US company with EU customers.
The Extraterritorial Reach Principle
The following EU regulations apply to non-EU companies based on activity, not location:
GDPR: Applies to any organisation processing personal data of EU individuals where the organisation offers goods/services to EU individuals or monitors their behaviour (Article 3(2)).
EU AI Act: Applies to providers and deployers of AI systems when outputs are used in the EU, or where users are located in the EU.
NIS2: Applies to digital service providers (online marketplaces, search engines, cloud providers) that target EU customers, even if established outside the EU.
Data Act: Applies to manufacturers placing connected products on the EU market and cloud providers serving EU customers.
CSRD (Wave 4): Applies to non-EU companies with €150M+ EU turnover and a large EU subsidiary or branch.
GDPR: The Non-Negotiable Starting Point
For any US SaaS company with EU customers or EU-based users: GDPR applies. The compliance requirements are the same as for EU-based companies, with additional obligations:
EU Representative
If you are not established in the EU and process EU personal data on a non-occasional basis, you need an EU Representative (Article 27). This is an individual or company in an EU member state who acts as the contact point for EU data protection authorities.
Services providing EU Representative services are widely available at €500–€2,000/year.
International Data Transfers
Personal data processed by your US-based infrastructure is a transfer from the EU to the US (or is initially collected in the US from EU users). The transfer mechanism must be in place:
EU-US Data Privacy Framework (DPF): If your company is DPF-certified, EU-to-US transfers are covered by the adequacy decision. DPF certification is managed by the US Department of Commerce.
Standard Contractual Clauses (2021): If not DPF-certified, use the 2021 SCCs in your DPA. Module 1 (controller-to-controller) for your relationship with EU business customers; Module 2 (controller-to-processor) for customer data processed by you as a processor.
Transfer Impact Assessment (TIA): Following Schrems II, the SCCs require a TIA — assessing whether the laws in the recipient country (the US) offer sufficient protection. A documented TIA demonstrating that your contractual safeguards are effective must accompany the SCCs.
Sub-Processors
If you use US-based sub-processors (AWS, Stripe, Intercom, etc.): each sub-processor relationship must have an appropriate transfer mechanism. Most major US SaaS tools are DPF-certified or execute SCCs with customers.
EU AI Act: Provider Obligations
If your SaaS includes AI features (chatbots, recommendations, automated decisions):
As a provider of AI systems used in the EU: The EU AI Act applies.
GPAI providers (foundation model providers): Article 53 obligations apply — training data documentation, copyright compliance summary publicly available.
High-risk AI providers: Technical documentation, conformity assessment, EU AI database registration — all apply regardless of where your company is incorporated.
Article 50 transparency: If your product includes chatbots interacting with EU users, you must disclose the AI nature of the interaction. This cannot be geofenced away — it applies when the user is in the EU.
Practical approach: Complete an AI risk assessment to determine which tier your AI falls into. Most B2B SaaS AI features are minimal-risk or limited-risk — the Article 50 transparency requirement is manageable.
NIS2: Digital Service Providers Targeting the EU
If your company provides cloud computing services, online marketplaces, or online search engines to EU customers above certain scale thresholds — NIS2 Section 2 digital service providers applies, even if you are established in the US.
Required:
- Designate a legal representative in the EU
- Register with the NIS2 competent authority in the member state where your EU representative is established
- Implement NIS2 Article 21 security measures
- Report significant incidents to EU authorities within 24/72 hours
Data Act: Cloud Providers with EU Customers
If you provide IaaS, PaaS, or SaaS to EU customers and hold their data: the Data Act's cloud switching provisions apply.
By September 2025:
- Remove lock-in contractual provisions from EU customer agreements
- Provide data portability in standard formats
- Implement a switching support process
- Reduce egress fees to cost-only for switching scenarios
By September 2027:
- Eliminate switching egress fees entirely
Practical Priority Order for US SaaS Entering EU
Step 1: GDPR compliance pack (essential, immediate)
- Privacy notice for EU users
- Cookie consent management (no non-essential cookies without consent)
- GDPR-compliant DPA for EU business customers
- DPF certification or SCCs with TIA for data transfers
- EU Representative appointed
Step 2: AI Act assessment (if you have AI features)
- Risk classification of AI systems used in EU
- Article 50 transparency disclosure for chatbots/AI interactions
- High-risk AI documentation if applicable
Step 3: NIS2 assessment (if digital service provider above thresholds)
- EU legal representative
- NIS2 registration
- Article 21 security measures
Step 4: Data Act (if cloud provider)
- Contract review for EU customers
- Data portability assessment
The Business Case for EU Compliance
US SaaS companies that achieve EU compliance early gain:
- Access to EU enterprise deals: Financial services, healthcare, and public sector enterprises will not sign with non-compliant vendors
- GDPR as a sales differentiator: "GDPR compliant, DPF certified, EU data residency available" is a commercial advantage in EU B2B
- Faster deal cycles: Compliance documentation in place reduces legal review time by weeks
The cost of basic EU compliance for a US SaaS company is €10,000–€30,000 for initial setup and €5,000–€15,000/year ongoing — a fraction of the lost revenue from deals blocked by compliance requirements.