These Laws Don't Care Where Your Office Is — Only Where Your Visitor Is
GDPR and California's privacy laws are both triggered by where your visitor is standing, not where your business is registered. A Long Island company can be fully in scope for either one without ever shipping a product outside Suffolk County — because the trigger is who lands on the site, not who you sell to.
GDPR has no revenue threshold and no exemption for small businesses. If your site sets a tracking or analytics cookie on a visitor physically located in the EU, that interaction falls under GDPR's "monitoring" provision — regardless of your company's size, industry, or where you're incorporated. Serious violations carry fines up to €20 million or 4% of global annual revenue.
CCPA/CPRA itself only applies once a business crosses a size threshold (roughly $26.6M in revenue, or personal data on 100,000+ California residents/devices a year — easier to hit than it sounds once ad-tech data-sharing counts toward it). The bigger current risk is a separate, older law: the California Invasion of Privacy Act. Courts have found that tracking a visitor's activity before they've consented can qualify as illegal wiretapping under CIPA — a law with no size threshold, that lets any individual visitor sue directly. Nearly 4,000 CIPA lawsuits were filed in California through 2026, most involving ordinary tools like Google Analytics, Meta Pixel, and chat widgets.
This is general background on how these laws are structured, not legal advice about your specific exposure. For guidance on your business's own risk, consult an attorney.
What is your website quietly tracking?
A straightforward audit of every cookie and tracker your site sets, a compliant consent banner installed correctly, and ongoing monitoring so it stays that way. A few quick questions so we can scope your scan accurately.
- Creates your assessment in Command Center
- Confirms your CMS and current tracking setup up front
- We follow up within one business day
