If I don't sell to the EU, can I ignore GDPR?

If I don't sell to the EU, can I ignore GDPR?

Many UK businesses assume that, since Brexit, the EU GDPR is no longer their problem, especially if they don't sell into the EU. That assumption is risky. The EU GDPR can still apply to a UK business in certain situations, even without any EU sales. Here is how to tell whether it reaches you, in plain English.

First: the UK GDPR always applies to you

Whatever you do with the EU, if you are established in the UK and process personal data, the UK GDPR and Data Protection Act 2018 apply. So "ignoring GDPR" is never an option, the only question is whether the EU version also applies on top of the UK rules.

When the EU GDPR can reach a UK business

The EU GDPR has extraterritorial reach (Article 3). It can apply to a business outside the EU where it processes the personal data of people in the EU in connection with either:

  • offering goods or services to individuals in the EU (whether or not for payment); or
  • monitoring the behaviour of individuals in the EU (for example, tracking and profiling EU website visitors).

Crucially, "offering goods or services" is about whether you target people in the EU, not just whether a sale happens. And monitoring can apply even if you never sell anything.

So "no EU sales" is not the test

You could fall within the EU GDPR without making EU sales if, for example, you:

  • run a website that targets EU customers (EU languages, EU currencies, EU shipping, EU-focused marketing);
  • use analytics, cookies or ad-tracking that monitor the behaviour of visitors located in the EU; or
  • otherwise deliberately direct your services at people in the EU.

By contrast, simply having a website that is accessible from the EU, with no targeting or monitoring of EU individuals, generally does not by itself trigger the EU GDPR.

What you must do if the EU GDPR applies

If you are caught, you have to comply with the EU GDPR as well as the UK rules, and you may also need to appoint an EU representative (Article 27) as a point of contact in the EU, unless an exemption applies. (Likewise, EU businesses targeting or monitoring people in the UK may need a UK representative.)

Practical guidance

  • Don't assume "no EU sales" means "no EU GDPR", check targeting and monitoring.
  • Review your website, marketing and analytics: are you deliberately reaching, or tracking, people in the EU?
  • If the EU GDPR applies, comply with it and consider whether you need an EU representative.
  • Either way, you must always comply with the UK GDPR.

Key takeaways

  • The UK GDPR always applies to a UK business, you can never simply ignore data protection.
  • The EU GDPR can also apply if you target (offer goods/services to) or monitor people in the EU, even with no EU sales (Article 3).
  • Mere accessibility of your site from the EU is generally not enough; targeting or monitoring is the test.
  • If caught, comply with the EU GDPR and consider an EU representative (Article 27).

Sources

  • EU GDPR, Article 3 (territorial scope) and Article 27 (representatives)
  • UK GDPR and Data Protection Act 2018 (always applicable to UK establishments)
  • ICO/EDPB guidance on targeting and monitoring

--- This article is general information about the law of England & Wales as at 2026, not legal advice. For advice on your circumstances, consult a qualified solicitor.

Back to the blog