A US business with no office in Europe can still be covered by European privacy law. It depends on who you sell to and what your website does with their data.

Plenty of US sites get real traffic from the UK and the EU: customers, prospects, people comparing suppliers. What the site does in the first second of their visit is where the rules bite.

When European law reaches a US business.

The GDPR applies to businesses outside the EU when they either:

  • offer goods or services to people in the EU, for example by shipping there, pricing in euros or marketing to European customers
  • monitor the behaviour of people in the EU, which includes tracking and profiling them online

The UK GDPR works the same way for people in the UK. Tracking with analytics and advertising pixels can count as monitoring, which is why the question comes up for websites at all.

The cookie rules sit alongside the GDPR: the ePrivacy rules in the EU, and PECR in the UK. They cover storing or reading anything on a visitor's device, whoever runs the site.

What they require.

  • EU visitors: consent before analytics or advertising cookies are set. Tags wait for a "yes".
  • UK visitors: consent before advertising cookies. Since the Data (Use and Access) Act 2025, some analytics can run without consent, as long as visitors are told and can object easily.

Both are stricter than the opt-out model of most US state privacy laws. One banner that suits your US visitors won't meet either.

Google has its own requirement.

Separately from the law, Google's EU user consent policy covers visitors in the EEA and the UK. If you use Google Ads, it expects consent for those visitors, passed to its tags through Consent Mode. Without the signals, Google Ads loses remarketing audiences and conversion measurement for that traffic.

So even a business that decides the law doesn't reach it may still need consent for European visitors to keep its Google Ads working properly.

Will anyone enforce it?

Enforcement against businesses with no European presence is less common, and harder. It isn't unknown, and the risk grows with the size of your European audience. Your lawyers will weigh that.

There's also a practical point: European buyers, especially larger companies, often check a supplier's own site before signing, and a banner that ignores their choices is a poor first impression.

You don't have to change anything for US visitors.

This is the part most US businesses don't realise. Consent can be set by region. Visitors from the EU and the UK get a banner that asks first. Visitors from the US keep the setup they have now, with the opt-outs US law asks for.

It's one Tag Manager container and one banner that changes by location. The setup is covered in region-specific consent in Tag Manager.

A quick check of your site.

  1. Visit your site from the UK or an EU country, with a VPN if you need one, in a private window.
  2. Before touching the banner, open the developer tools and look at cookies and network requests.
  3. If GA4, Meta or Google Ads have already loaded and set cookies, the site isn't waiting for European visitors.
  4. Reject everything, reload, and check the requests stop.

The free tracking checker runs a version of this check for any page.

Whether European law applies to your business is a question for your lawyers. Marc Alexander, a London GA4 consultant, makes the tracking do what they decide, for US businesses with UK and EU visitors, without changing anything for your US audience.