-
Foreign Company Scope: If a foreign company targets EU customers—by offering products and services in euros, using local languages, or shipping to the EU—they are legally bound to comply with the GDPR.
-
Key points regarding the application of UK GDPR to foreign websites:
-
Targeting UK Users: Offering goods/services (even free) or monitoring user behavior (e.g., tracking cookies, analytics) within the UK triggers compliance.
-
Definition of Services: This includes websites allowing registration, newsletter subscriptions, or handling user data from the UK.
-
as an examples
Key examples of foreign companies fined or targeted by the ICO include:
-
Clearview AI Inc. (USA): In May 2022, the ICO fined the American facial recognition company £7,552,800 (approx. 9 million euros at the time) for breaching GDPR by scraping biometric data from the internet.
-
23andMe (USA): In June 2025, the genetic testing company was fined £2.31 million by the ICO for violating the UK GDPR.
-
TikTok (China/Ireland): In 2023, the ICO fined TikTok £12.7 million for misusing the data of UK children.
-
Marriott International, Inc. (USA): Following a 2018 data breach, the ICO issued a notice of intent to fine the American hotel group £99 million in 2019.
-
Ticketmaster (USA/International): The ICO fined Ticketmaster UK Limited, a subsidiary of the US-based parent company, £1.25 million for a data breach in 2018.