Duty of Care for Schengen-to-US Business Travel: What EU Employers Must Know


TLDR;
- EU employers carry a legal duty of care for staff traveling to the US, grounded in Framework Directive 89/391/EEC.
- ISO 31030:2021 is the international travel risk management standard employers and insurers now benchmark against.
- The US has no universal healthcare, so an uninsured hospital day can top $3,000 and travel medical insurance is non-negotiable.
- Run the program in three phases: pre-trip risk assessment, in-trip tracking and support, and a post-trip debrief.
- Track travelers only with consent, because itineraries are personal data under GDPR.
When you send an employee from a Schengen country to the United States, your duty of care does not pause at passport control. As the employer you carry a legal obligation for that person's health and safety for the whole trip, and the US raises risks a European program rarely plans for, starting with a healthcare system that can turn a minor emergency into a five-figure bill. This guide covers what EU employers owe, why the US is a distinct risk, and how to build a program that holds up.
What EU employers legally owe traveling employees
Duty of care is not a nice-to-have for EU employers; it is a legal obligation. Framework Directive 89/391/EEC requires every employer to assess occupational risks and put preventive measures in place, and that duty follows the employee onto a business trip, not just around the office. National laws across the Schengen area build on that baseline, and a serious failure can bring liability, not only reputational damage.
The recognized way to meet that duty is ISO 31030:2021, the first international standard for travel risk management, which sets out how to build, run, and review a travel risk program. It is guidance rather than law, so it is not mandatory. In practice, though, courts, insurers, and works councils increasingly treat alignment with ISO 31030 as the benchmark for whether an employer took reasonable steps, which makes it the standard your program should map to.
Why the US is a distinct risk profile for Schengen travelers
The single biggest US-specific risk is medical cost, because there is no universal healthcare a European traveler can fall back on. An emergency-room visit without insurance runs roughly $1,500 to $3,000, and a serious hospital stay climbs into the tens of thousands. For a traveler used to an EHIC card or national coverage at home, that gap is easy to underestimate, which is why travel medical insurance with a high limit is non-negotiable for US trips.
Geography and weather add a second layer most European itineraries ignore. Hurricane season on the Gulf and East coasts runs June to November, wildfire risk peaks in the West through late summer, and distances between cities mean long drives or extra flights that a map of Europe never prepares you for. A duty-of-care program should flag these by destination and season before the trip is booked, not after a storm grounds flights.
Data and safety round out the picture. Traveler data crossing to a US platform is a GDPR transfer, and personal-safety expectations vary sharply by city and neighborhood in ways a risk briefing should name. The same standard you would apply to female business travelers' safety belongs in any US trip brief.
Building a Schengen-to-US duty-of-care program
A workable program runs in three phases, and the point is to make each one routine rather than heroic. The structure below maps to what ISO 31030 expects and to what a European works council will ask for after an incident.
Two of those steps trip European teams up most. On entry, most Schengen nationals travel under the Visa Waiver Program and need an ESTA, which now costs $40 after the September 2025 increase and covers business stays up to 90 days; build that ESTA check into pre-trip approval, which a platform like ITILITE surfaces automatically, so nobody is turned back at the gate. On tracking, location visibility is powerful but it is personal data, so run it on consent and a clear policy, since EU-to-US data transfer is governed by the EU-US Data Privacy Framework.
A travel manager evaluating platforms told us their number-one duty-of-care requirement was real-time traveler location, so the team could "know where our people are in real time.
How a travel platform operationalizes duty of care
The three phases only work if the data lives in one place, which is where a managed platform beats booking across consumer sites. ITILITE gives travel and HR teams real-time traveler visibility with consent, 24/7 human support the traveler can reach directly, and one record of who is where, which turns the ISO 31030 checklist into a live system rather than a binder. The broader mechanics, including a ready-to-use checklist, sit in the duty of care guide and the wider corporate travel risk management program.
One honest boundary: a travel platform is not an insurer. ITILITE handles booking, tracking, and 24/7 traveler support, but the travel medical insurance that covers a US hospital bill is a separate policy your finance or HR team arranges. The platform's job is to make sure the trip is visible and supported, and to keep the booking and traveler data in one place through a single corporate travel booking platform, so duty of care is enforced rather than assumed.
FAQ
What is duty of care in business travel?
Duty of care is an employer's legal obligation to take reasonable steps to protect the health and safety of employees while they travel for work. It covers transport, accommodation, and activity for the whole trip, and for EU employers it is grounded in Framework Directive 89/391/EEC, which requires risk assessment and preventive measures.
Do EU employers have a legal duty of care for employees traveling to the US?
Yes. Framework Directive 89/391/EEC and national laws across the Schengen area require employers to assess risks and protect employees on business trips, including trips to the US. A serious failure can bring legal liability, so a US itinerary needs a documented risk assessment, insurance, and support in place before departure.
Is ISO 31030 mandatory?
No. ISO 31030:2021 is guidance, not law, so it is not compulsory. In practice, though, insurers, courts, and works councils increasingly treat alignment with it as the benchmark for whether an employer met its duty of care, which is why most serious travel risk programs now map to the standard.
What are the biggest risks for European business travelers in the US?
Medical cost is the largest, because there is no universal healthcare and an uninsured hospital stay can run into the tens of thousands. Add seasonal severe weather (hurricanes, wildfires), long domestic distances, and safety that varies by city, and you have a risk profile most European itineraries underplan for.
Do employees need travel insurance for US business trips?
Yes, with a high medical limit. Because the US has no universal coverage a visitor can rely on, an emergency-room visit without insurance runs roughly $1,500 to $3,000 and a hospital stay far more. Travel medical insurance that covers US treatment and evacuation is the single most important thing to arrange before a trip.
How do you track travelers to the US under GDPR?
Track location on the basis of consent and a clear policy, and hold only what duty of care needs. Traveler data moving to a US platform is a GDPR transfer, lawful when the platform is certified under the EU-US Data Privacy Framework, so confirm certification and sign a data-processing agreement.
Meet your duty of care on every US business trip
A fully integrated corporate travel management software that dramatically reduces spends while improving user experience









.jpeg)





.jpeg)





.avif)


.avif)





.avif)

%20(1).avif)
%20(1).avif)





.avif)


.avif)
.avif)

.avif)

.avif)
.avif)

.avif)










.avif)


















































