Business Travel Management

Duty of Care for Schengen-to-US Business Travel: What EU Employers Must Know

Ardra M B
August 14, 2026
Reading Time 14 mins
Duty of Care for Schengen-to-US Business Travel What EU Employers Must Know
Business Travel at its smartest
ITILITE offers modern UX, real human support, pricing built to save money.
Get Started

TLDR;

  • EU employers carry a legal duty of care for staff traveling to the US, grounded in Framework Directive 89/391/EEC.
  • ISO 31030:2021 is the international travel risk management standard employers and insurers now benchmark against.
  • The US has no universal healthcare, so an uninsured hospital day can top $3,000 and travel medical insurance is non-negotiable.
  • Run the program in three phases: pre-trip risk assessment, in-trip tracking and support, and a post-trip debrief.
  • Track travelers only with consent, because itineraries are personal data under GDPR.
Summarize the article  with

When you send an employee from a Schengen country to the United States, your duty of care does not pause at passport control. As the employer you carry a legal obligation for that person's health and safety for the whole trip, and the US raises risks a European program rarely plans for, starting with a healthcare system that can turn a minor emergency into a five-figure bill. This guide covers what EU employers owe, why the US is a distinct risk, and how to build a program that holds up.

What EU employers legally owe traveling employees

Duty of care is not a nice-to-have for EU employers; it is a legal obligation. Framework Directive 89/391/EEC requires every employer to assess occupational risks and put preventive measures in place, and that duty follows the employee onto a business trip, not just around the office. National laws across the Schengen area build on that baseline, and a serious failure can bring liability, not only reputational damage.

The recognized way to meet that duty is ISO 31030:2021, the first international standard for travel risk management, which sets out how to build, run, and review a travel risk program. It is guidance rather than law, so it is not mandatory. In practice, though, courts, insurers, and works councils increasingly treat alignment with ISO 31030 as the benchmark for whether an employer took reasonable steps, which makes it the standard your program should map to.

Why the US is a distinct risk profile for Schengen travelers

The single biggest US-specific risk is medical cost, because there is no universal healthcare a European traveler can fall back on. An emergency-room visit without insurance runs roughly $1,500 to $3,000, and a serious hospital stay climbs into the tens of thousands. For a traveler used to an EHIC card or national coverage at home, that gap is easy to underestimate, which is why travel medical insurance with a high limit is non-negotiable for US trips.

Geography and weather add a second layer most European itineraries ignore. Hurricane season on the Gulf and East coasts runs June to November, wildfire risk peaks in the West through late summer, and distances between cities mean long drives or extra flights that a map of Europe never prepares you for. A duty-of-care program should flag these by destination and season before the trip is booked, not after a storm grounds flights.

Data and safety round out the picture. Traveler data crossing to a US platform is a GDPR transfer, and personal-safety expectations vary sharply by city and neighborhood in ways a risk briefing should name. The same standard you would apply to female business travelers' safety belongs in any US trip brief.

Building a Schengen-to-US duty-of-care program

A workable program runs in three phases, and the point is to make each one routine rather than heroic. The structure below maps to what ISO 31030 expects and to what a European works council will ask for after an incident.

PhaseWhat the employer must do
Before the tripAssess destination risk by city and season, arrange travel medical insurance, brief the traveler, and confirm the ESTA and entry documents
During the tripTrack location with consent, run a check-in schedule, provide 24/7 human support, and escalate incidents fast
After the tripDebrief the traveler, log any incident, and feed it back into the next risk assessment

Two of those steps trip European teams up most. On entry, most Schengen nationals travel under the Visa Waiver Program and need an ESTA, which now costs $40 after the September 2025 increase and covers business stays up to 90 days; build that ESTA check into pre-trip approval, which a platform like ITILITE surfaces automatically, so nobody is turned back at the gate. On tracking, location visibility is powerful but it is personal data, so run it on consent and a clear policy, since EU-to-US data transfer is governed by the EU-US Data Privacy Framework. 

A travel manager evaluating platforms told us their number-one duty-of-care requirement was real-time traveler location, so the team could "know where our people are in real time.

How a travel platform operationalizes duty of care

The three phases only work if the data lives in one place, which is where a managed platform beats booking across consumer sites. ITILITE gives travel and HR teams real-time traveler visibility with consent, 24/7 human support the traveler can reach directly, and one record of who is where, which turns the ISO 31030 checklist into a live system rather than a binder. The broader mechanics, including a ready-to-use checklist, sit in the duty of care guide and the wider corporate travel risk management program.

One honest boundary: a travel platform is not an insurer. ITILITE handles booking, tracking, and 24/7 traveler support, but the travel medical insurance that covers a US hospital bill is a separate policy your finance or HR team arranges. The platform's job is to make sure the trip is visible and supported, and to keep the booking and traveler data in one place through a single corporate travel booking platform, so duty of care is enforced rather than assumed.

FAQ

What is duty of care in business travel?

Duty of care is an employer's legal obligation to take reasonable steps to protect the health and safety of employees while they travel for work. It covers transport, accommodation, and activity for the whole trip, and for EU employers it is grounded in Framework Directive 89/391/EEC, which requires risk assessment and preventive measures.

Do EU employers have a legal duty of care for employees traveling to the US?

Yes. Framework Directive 89/391/EEC and national laws across the Schengen area require employers to assess risks and protect employees on business trips, including trips to the US. A serious failure can bring legal liability, so a US itinerary needs a documented risk assessment, insurance, and support in place before departure.

Is ISO 31030 mandatory?

No. ISO 31030:2021 is guidance, not law, so it is not compulsory. In practice, though, insurers, courts, and works councils increasingly treat alignment with it as the benchmark for whether an employer met its duty of care, which is why most serious travel risk programs now map to the standard.

What are the biggest risks for European business travelers in the US?

Medical cost is the largest, because there is no universal healthcare and an uninsured hospital stay can run into the tens of thousands. Add seasonal severe weather (hurricanes, wildfires), long domestic distances, and safety that varies by city, and you have a risk profile most European itineraries underplan for.

Do employees need travel insurance for US business trips?

Yes, with a high medical limit. Because the US has no universal coverage a visitor can rely on, an emergency-room visit without insurance runs roughly $1,500 to $3,000 and a hospital stay far more. Travel medical insurance that covers US treatment and evacuation is the single most important thing to arrange before a trip.

How do you track travelers to the US under GDPR?

Track location on the basis of consent and a clear policy, and hold only what duty of care needs. Traveler data moving to a US platform is a GDPR transfer, lawful when the platform is certified under the EU-US Data Privacy Framework, so confirm certification and sign a data-processing agreement.

Ardra M B
Content Strategist

Ardra is a Content Strategy Manager at ITILITE with 6+ years of experience in travel and SaaS content. She holds a Master’s degree in Political Science from Lady Shri Ram College for Women and transitioned from academic research and travel content into SaaS content strategy.

She previously worked with JustWravel, where she focused on travel storytelling and digital content. Today, she specializes in SEO and AEO-driven content strategies that help businesses simplify complex travel and expense workflows into search-optimized narratives.

When she’s not working, Ardra is usually reading or watching films.

Read more
CTA Download File
Share this article
Track, insure, support, comply

Meet your duty of care on every US business trip

A fully integrated corporate travel management software that dramatically reduces spends while improving user experience

Read More Blogs