🇪🇺 Built for US businesses selling to Europe

Selling to EU customers
from the US?
GDPR already applies to you.

Incorporation in Delaware doesn't exempt you from European data protection law. If EU residents buy from you, or you track their behavior on your site, three things are probably missing: an EU Representative, valid data-transfer safeguards, and a GDPR-compliant privacy notice. Find out exactly what, for free.

🇪🇺 GDPR 🇬🇧 UK GDPR 🇺🇸 CCPA / CPRA 🇺🇸 VCDPA 🇨🇭 nLPD + 7 more laws if you sell elsewhere too

What does your site actually expose?

Enter your URL — our AI checks it against GDPR and the other laws your visitors bring with them, for free.

A full report in 3 steps

No EU legal team required. Our AI reads the regulation so you don't have to.

1

Automatic detection

amalyon crawls your website: languages, currencies, hreflang tags, phone prefixes, cookie banners, legal notices — to confirm which markets you're actually selling into, EU included.

2

GDPR gap analysis

Claude AI checks your site against GDPR (and any other detected law): score out of 100, per-article findings, maximum fine exposure — 4% of global annual revenue under GDPR, not just EU revenue.

3

Report delivered by email

Compliance score, fine exposure, and the top 3 fixes to make first — all in your inbox within the hour.

The 3 obligations a French or German site doesn't have to think about

These aren't covered by a generic GDPR checklist written for EU companies — they only apply because you're outside the EU.

27

EU Representative

Article 27 GDPR

If you offer goods or services to people in the EU, or monitor their behavior, you likely need a representative established in the EU — a local point of contact for supervisory authorities and data subjects. Few US companies have appointed one.

SCC

Data Transfer Safeguards

Chapter V GDPR

Moving EU personal data to US servers or a US parent company needs a legal basis: Standard Contractual Clauses (SCCs) with your EU customers or vendors, or self-certification under the Data Privacy Framework.

DPF

EU-US Data Privacy Framework

Adequacy mechanism

A US Department of Commerce self-certification program that can replace SCCs for EU-US transfers — enforced by the FTC. Useful, but it doesn't cover the rest of GDPR (representative, notices, rights requests) on its own.

GDPR is the headline — your report checks what else applies too

Most US companies selling to Europe also have customers elsewhere. The same scan checks for that automatically.

🇪🇺 GDPRHigh priority
General Data Protection Regulation
Max fine: €20M or 4% of global revenue
🇬🇧 UK GDPRPriority
UK General Data Protection Regulation
Max fine: £17.5M or 4% of global revenue
🇨🇭 nLPDPriority
New Federal Act on Data Protection — Switzerland
Max fine: CHF 250,000 (personal liability)
Also selling back into the US? The same scan checks CCPA/CPRA (California) and VCDPA (Virginia) at the same time — no separate audit needed. See our dedicated US Privacy Audit if that's your primary market.

SELLING BEYOND THE EU AND US? THE SAME SCAN ALSO CHECKS:

🇺🇸 CCPA / CPRAHigh priority
California Consumer Privacy Act
Max fine: $7,500 per intentional violation
🇺🇸 VCDPAPriority
Virginia Consumer Data Protection Act
Max fine: $7,500 per violation
🇨🇦 PIPEDA / Law 25Priority
Personal Information Protection — Canada
Max fine: CAD $25M or 4% of revenue
🇧🇷 LGPDPriority
Lei Geral de Proteção de Dados
Max fine: R$50M or 2% of Brazil revenue
🇦🇺 Privacy ActStandard
Privacy Act 1988 — Australia
Max fine: AUD 50M

Choose your coverage

One-time payment, report delivered by email within the hour. No subscription.

Local

$49

1 jurisdiction (e.g. GDPR)

  • Full report for 1 law
  • Compliance score out of 100
  • 8 evaluated criteria
  • Top 3 urgent fixes
  • HTML report + email
Get started

Global

$299

All detected jurisdictions

  • EU + US + international coverage
  • Per-law report + global score
  • Total fine exposure
  • Priority recommendations
  • Executive summary included
  • HTML report + email
Get started

Everything you need to know

My company has no office in the EU — does GDPR still apply to us?
Yes. GDPR applies based on whose data you process, not where your company is incorporated. If you offer goods or services to people in the EU, or monitor their behavior (analytics, ad retargeting, cookies), Article 3(2) GDPR applies to you regardless of your US location.
What is an EU Representative and do I need one?
Article 27 GDPR requires most non-EU controllers and processors covered by GDPR to appoint a representative established in the EU, who acts as a local point of contact for supervisory authorities and data subjects. Narrow exemptions exist for occasional, low-risk processing — most e-commerce and SaaS businesses with recurring EU sales don't qualify for the exemption.
What are Standard Contractual Clauses (SCCs)?
SCCs are European Commission-approved contract templates that let you legally transfer personal data from the EU to the US. Since the US isn't automatically deemed "adequate" outside the Data Privacy Framework, most US companies need SCCs in place with their EU customers, vendors, or subsidiaries — or self-certify under the Data Privacy Framework instead.
What is the EU-US Data Privacy Framework?
The DPF is a self-certification program (administered by the US Department of Commerce) that lets US companies receive EU personal data without SCCs, by committing to a set of privacy principles enforced by the FTC. It's an alternative to SCCs, not a full GDPR compliance program on its own — you still need the rest of GDPR in place.
How does amalyon detect which laws apply?
Our service crawls your website and analyzes 8 types of signals: the <html lang> attribute, hreflang attributes, the Content-Language header, displayed currencies, phone number prefixes, mentions of laws or countries in your legal pages, cookie banners (OneTrust, Cookiebot…), and meta geo.region tags.
What exactly does the report contain?
For each detected law: 8 criteria evaluated from 0 to 10 (privacy notice, consent/opt-out mechanism, individual rights, controller identity, data transfer disclosures, retention periods, security measures, processor contracts). A global score out of 100 and the 3 urgent fixes to make. All in structured HTML format, delivered by email.
Does the report replace a privacy attorney?
No. This is an automated audit tool that identifies compliance gaps visible on your public website. For appointing an actual EU Representative, drafting SCCs, or complex cross-border transfer questions, we recommend consulting a privacy attorney with EU data protection experience.