If you work remotely for a US company that has customers, clients, or users in Europe, there’s a good chance GDPR applies to your daily work — even if you’ve never heard about it from your employer. The regulation doesn’t care where you’re sitting. It follows the data.
Most American remote workers I talk to are surprised by this. GDPR feels like a European law, and technically it is. But its reach extends to any organization that processes personal data of people in the European Economic Area, regardless of where that organization is based. That includes US companies with European customers, and by extension, the remote employees handling that data from home offices in Ohio or Texas or anywhere else.
Legal Compliance
Remote Work
GDPR
This post contains affiliate links.
The Regulation That Follows the Data, Not Your Location
GDPR’s extraterritorial scope is one of its most consequential features. Article 3 applies the regulation to any organization processing personal data of data subjects in the EU, regardless of where the organization is established. For a remote worker in the US, this means every time you open a spreadsheet with European customer names, respond to a support ticket from a user in France, or process an invoice for a client in Germany, you’re handling data that GDPR protects.
What makes this tricky for remote workers is that many US companies completed their initial GDPR compliance work in 2018 with office-based workflows in mind. The compliance documentation, the data maps, the vendor assessments — they often assumed everyone worked from a centralized location. When the workforce went remote, those assumptions broke down.
GDPR’s core principles — lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability — all apply regardless of whether the data is processed in a corporate office or a spare bedroom. The standard doesn’t change just because the location does.
What Remote Work Exposes That Office Work Didn’t
The shift to remote work created data security challenges that directly affect GDPR compliance. In the Apricorn 2021 Global IT Security Survey, 60% of IT security practitioners said the move to remote work introduced data security issues, and 38% reported that data control became very hard to manage. These aren’t minor operational headaches — they speak to whether an organization can meet its obligation under Article 32 to implement appropriate technical and organizational measures.
That figure matters because GDPR doesn’t make exceptions for home environments. If a family member uses a work laptop for personal browsing, streaming, or schoolwork, the organization is still responsible for any personal data stored on or accessible from that device. The same goes for unsecured home Wi-Fi networks, personal devices used for work without security tools, and physical privacy — whether other people in the house can see sensitive information on screen.
A 2020 article in the journal Patterns noted that organizations must evaluate each individual home environment, including whether employees have a dedicated lockable space and whether household members are present. These are questions most US companies haven’t systematically asked their remote workforce.
The Risk Assessment Step That Often Gets Skipped
Under GDPR, organizations are required to conduct a Data Protection Impact Assessment when processing operations present specific risks to individuals’ privacy rights. The same Patterns article outlined a five-step plan for revisiting compliance in a remote context, starting with reopening the DPIA to understand how the remote environment changes risk levels.
The Swedish healthcare provider Capio St. Göran was fined €2.9 million for lacking proper risk assessments and effective access controls — not for a data breach, but for failing to put the right safeguards in place from the start. The enforcement tracker record shows that regulators are paying attention to whether organizations have done the assessment work, not just whether they’ve had an incident.
For remote workers, this has a practical implication: if your employer hasn’t asked you about your home workspace, your network setup, or who else has access to your devices, there may be a DPIA gap that leaves both of you exposed. A simple question like “Has the company updated its data protection risk assessment to include remote work arrangements?” can start a useful conversation with your manager or privacy officer. You don’t need to become a GDPR expert, but knowing whether your company has assessed the risk of remote work is a reasonable concern to raise.
The Everyday Measures That Add Up to Compliance
Article 32 of GDPR requires organizations to implement measures appropriate to the risk level, including encryption, access controls, and the ability to ensure ongoing confidentiality and integrity of processing systems. For remote workers, several practices matter more than most people realize.
Multi-factor authentication is near the top of the list. When you’re logging into company systems from a home network, a password alone doesn’t provide enough protection. GDPR guidance on remote work consistently emphasizes MFA as a baseline requirement, not an optional enhancement.
Encryption is another area where the standard is clear. GDPR’s Recital 83 specifies that personal data must be protected both in transit and at rest. For a remote worker, this means data on your laptop should be encrypted (not just password-protected), and any data you send over the internet should go through encrypted channels — typically via a VPN or a zero-trust remote access solution.
Some remote access tools now offer zero-trust architectures that don’t rely on traditional VPNs, which can be vulnerable to exploitation. The key principle is that the organization needs to verify each access request based on user identity, device posture, and context — not just network location.
- Is multi-factor authentication enabled on every system you use that holds personal data?
- Is your work device encrypted (full-disk encryption is the standard)?
- Do you use a VPN or zero-trust access when connecting to company networks?
- Can other people in your home see your screen or access your devices?
- Do you know who to contact if you suspect a data breach?
The 72-Hour Notification Requirement
One of GDPR’s most operationally significant rules is the breach notification requirement under Article 33. Organizations must report certain data breaches to the supervisory authority within 72 hours of becoming aware. For remote workers, this creates a specific chain of responsibility.
If your laptop is lost or stolen, if you accidentally email customer data to the wrong recipient, if you fall for a phishing attempt that exposes your credentials — the organization’s 72-hour clock may start ticking from the moment someone internally becomes aware. That means you need to know exactly how to report an incident internally, and you need to do it promptly.
Data protection guidance for remote teams emphasizes that employees must be trained to recognize potential breaches and understand internal notification procedures. Asking your IT department “What’s the process for reporting a suspected data breach from a remote location?” is a practical step that clarifies your responsibility. If you haven’t received that training, it’s worth requesting — not because you’re trying to be difficult, but because the regulation expects it.
What a Good Remote Work Privacy Policy Looks Like
A comprehensive remote work policy under GDPR should cover several areas that directly affect how you do your job. Legal guidance from Jackson Lewis notes that companies need to address device management, data handling, monitoring practices, and employee privacy expectations.
For remote workers, the practical takeaways are straightforward. Your employer should have a clear policy on whether personal devices are allowed for work, what security software is required, how data should be stored and shared, and what to do in case of a breach. If those policies exist but you’ve never seen them, or if they were written for office workers and never updated, there’s work to be done.
I’ve written before about data monitoring practices for remote teams and strategies for remote team data privacy that go into more detail on what effective policies look like.
None of this is meant to suggest that every American remote worker needs to become a GDPR specialist. But the regulation applies whether you know about it or not, and the practical measures that support compliance — encryption, access controls, awareness training, clear policies — are good security practices regardless of which law governs the data. If you’re working remotely and handling data that might involve EU residents, the question isn’t whether GDPR applies. It’s whether your setup meets the standard.