GDPR is not CCPA
Opt-in consent, strict purpose limitation, data subject rights within one month and fines of up to 4% of global annual turnover.
For US companies entering Germany & EMEA
Launching in Germany or EMEA means GDPR, the EU AI Act and German IT law from day one. As a German attorney (Rechtsanwältin) for IT law and data protection and certified AI Officer, I help US companies enter the market compliant, fast and pragmatically – in English.
GDPR is not CCPA
Opt-in consent, strict purpose limitation, data subject rights within one month and fines of up to 4% of global annual turnover.
EU–US data transfers
Data Privacy Framework certification, Standard Contractual Clauses and transfer impact assessments for every US tool in your stack.
German specifics
Mandatory DPO from 20 employees processing personal data, works council co-determination for HR tools, whistleblowing channels and strict cookie rules (TDDDG).
EU AI Act
If your teams use AI tools in the EU, you are a “deployer” – AI literacy obligations already apply, more follow from August 2026.
External Data Protection Officer
German-qualified DPO for your EU entity – registered with the supervisory authority, available in English.
Market-entry compliance check
Gap analysis of your US setup against GDPR, German law and the EU AI Act – with a prioritized, budget-friendly roadmap.
Contracts & documentation
Data processing agreements, SCCs, transfer impact assessments, privacy notices, records of processing, and SaaS terms adapted for the EU market.
EU AI Act & AI governance
AI inventory, risk classification, AI policies and AI literacy training – by a certified AI Officer.
Employment & HR data
Employee data, monitoring tools, works council agreements and whistleblowing systems under the German Whistleblower Protection Act.
Interim / fractional counsel
Your part-time EU legal & privacy counsel – bridging the gap until you build an in-house legal team in Europe.
1. Free intro call
30 minutes, in English, scheduled for your US time zone.
2. Compliance snapshot
We review your products, data flows and US vendors against EU requirements.
3. Roadmap
Clear priorities, fixed-fee packages, no surprises.
4. Ongoing support
DPO mandate, interim counsel or project-based – as you scale across EMEA.
Companies without an EU establishment that target EU customers usually need an EU representative (Art. 27 GDPR). Once you have a German entity with 20+ people regularly processing personal data, appointing a DPO is mandatory. We help you assess both.
If your US recipient is certified, it covers transfers to that recipient. For non-certified vendors you still need SCCs and a transfer assessment – and you should plan for legal challenges to the framework.
Yes. All advice, documents and calls are available in English, with flexible scheduling for East and West Coast teams.
The focus is Germany and the EU/EEA under GDPR. For other EMEA jurisdictions I coordinate with trusted local counsel, including Poland.
Tell me where you are in your expansion – I will get back to you within one business day with a clear next step.
Book a free intro callThis page provides general information and does not replace individual legal advice. Last updated: October 2026.