United StatesDenmark

Article 3 · Article 27 · Chapter V

Does GDPR apply to a B2B SaaS provider based in the United States handling B2B SaaS customer accounts in Denmark?

A deliberate EU offering is likely to bring this processing into scope. This route separately identifies the transfer position for the United States and the supervisory context in Denmark.

Business based inUnited States
People located inDenmark
ActivityB2B SaaS customer accounts
EU or EEA connectiongoods or services intentionally offered in the EU
Processing roleorganisation acts as controller
Frequency and riskregular or continuing processing
LIKELYART. 3

Result on the selected facts

Likely within Article 3(2)(a)

Article 3(2)(a) can apply to an organisation outside the EEA when the relevant processing relates to intentionally offering goods or services to people in the Union. Payment is not required. The conclusion should be tied to concrete targeting signals and the particular processing activity.

Result applies toB2B SaaS customer accountsNot automatically to every activity run by the organisation

How the result was reached

Five separate questions, kept separate.

The two countries provide context. The territorial conclusion changes because the connection, processing role, and risk facts change.

01 · Connection

A deliberate EU offering is likely to bring this processing into scope.

Article 3(2)(a) can apply to an organisation outside the EEA when the relevant processing relates to intentionally offering goods or services to people in the Union. Payment is not required. The conclusion should be tied to concrete targeting signals and the particular processing activity.

02 · Processing situation

B2B SaaS customer accounts

This scenario concerns administrators and business users and work identity, account permissions, product usage, support conversations, and billing-contact data. Separate customer-controller instructions from the provider’s own account, security, billing, and product-analytics purposes.

03 · Organisational role

organisation acts as controller

The organisation outside the EEA determines why and how this processing occurs. If Article 3 applies, it must map its own controller duties rather than relying on a customer or vendor to absorb them. For this B2B SaaS scenario, separate customer-controller instructions from the provider’s own account, security, billing, and product-analytics purposes.

04 · EU or EEA representation

Likely required

The occasional-processing exception is unlikely to fit regular operations. If Article 3(2) applies and no EU establishment covers the activity, an Article 27 representative is likely required. For this Denmark scenario, confirm placement in an EU or EEA state where affected people are located and make the representative reachable to people and authorities.

05 · National context

Datatilsynet

Danish product journeys, Denmark-specific campaigns, local delivery, local customer references, or deliberate onboarding of people in Denmark can support a targeting analysis. No single signal decides the question. Datatilsynet is the national data-protection authority for Denmark. Which authority is competent still depends on the processing, establishments, and cross-border cooperation rules.

Evidence file

What should be preserved for this exact scenario?

A territorial-scope conclusion should be reproducible from recorded facts. It should not depend on an unrecorded impression that a business “feels European” or “feels foreign.”

  1. 01

    Record the country-facing product, campaign, delivery, contract, language, onboarding, and customer evidence that demonstrates intentional direction.

  2. 02

    Country-specific sales activity, EU contracts, local onboarding, and product access intentionally supplied to users in the selected Member State

  3. 03

    Inventory work identity, account permissions, product usage, support conversations, and billing-contact data and identify which purposes belong to the controller.

  4. 04

    Preserve the evidence supporting the “regular or continuing processing” classification and review it when scale, data, or purpose changes.

  5. 05

    Record Denmark-specific contacts, complaints, campaigns, users, contracts, and language choices relevant to the territorial analysis.

  6. 06

    Record whether the transfer to the United States uses adequacy, a qualifying certification, Standard Contractual Clauses, Binding Corporate Rules, or another valid Chapter V route.

Operating plan

Turn this result into controlled work.

1

Fix the territorial-scope finding to this activity

Treat the directed offer finding as processing-specific, not as a blanket answer for the entire business.

2

Map the B2B SaaS processing

Separate customer-controller instructions from the provider’s own account, security, billing, and product-analytics purposes.

3

Document the controller position

Document purposes, lawful bases, transparency, rights handling, retention, security, recipients, and any automated decisions for this controller activity.

4

Resolve EU or EEA representation

Choose and mandate an EU representative where required, publish its contact details, and connect it to rights and authority-response procedures.

5

Resolve the transfer route separately

Verify and record that the specific recipient in the United States satisfies the adequacy conditions. If it does not, select and document another lawful transfer mechanism.

Article 3Chapter V

Separate transfer result · Adequacy is conditional

The recipient in the United States must qualify for adequacy

The EU–US Data Privacy Framework adequacy decision covers transfers only to US organisations that participate in the Framework for the relevant data. A US recipient outside that coverage needs another Chapter V mechanism, commonly the Standard Contractual Clauses, where a qualifying transfer occurs.

Territorial scope and an EU or EEA transfer to the United States are separate tests. Direct collection by a B2B SaaS provider based in the United States is not automatically the same event as an EU or EEA exporter disclosing data to a separate recipient there. Map every exporter, importer, controller role, and transfer mechanism separately.

Questions raised by these facts

Answers for this scenario.

Does a company in the United States automatically fall under GDPR because people in Denmark can open its service?+

No. Mere accessibility is not enough by itself. An EU establishment, an intentional offering of goods or services, or relevant monitoring can change the result.

Does the controller label settle territorial scope?+

No. The organisation outside the EEA determines why and how this processing occurs. If Article 3 applies, it must map its own controller duties rather than relying on a customer or vendor to absorb them.

Would this organisation in the United States need an EU or EEA representative?+

The occasional-processing exception is unlikely to fit regular operations. If Article 3(2) applies and no EU establishment covers the activity, an Article 27 representative is likely required. For this Denmark scenario, confirm placement in an EU or EEA state where affected people are located and make the representative reachable to people and authorities.

Does GDPR applicability automatically answer a transfer to United States?+

Territorial scope and an EU or EEA transfer to the United States are separate tests. Direct collection by a B2B SaaS provider based in the United States is not automatically the same event as an EU or EEA exporter disclosing data to a separate recipient there. Map every exporter, importer, controller role, and transfer mechanism separately.

Primary material

Check the law and guidance behind the route.

This page is general information based on the selected facts. It cannot account for unselected establishments, processing activities, contracts, or national-law questions.

Use your complete facts

Turn the analysis into a repeatable workflow.

ProseID lets legal and compliance teams publish fixed interpretations, run them as guided workflows, and retain a version-bound record of each completed path.