Territorial Scope of GDPR

When does the GDPR apply? This article explains the Regulation's territorial scope, including the establishment and targeting criteria, its extraterritorial reach, and why organizations outside the EU may still be subject to European data protection law.

Territorial Scope of GDPR
ChatGPT modified from - Image from page 215 of “Af-beeldinghe van d’eerste eeuwe der Societeyt Iesu : voor ooghen ghestelt door de Duyts-Nederlantsche provincie der selver societeyt” (1640) -IABI
Key Points: Article 3 gives the GDPR a broad extraterritorial reach, ensuring that organizations with meaningful links to the EU or that target or monitor individuals in the EU remain subject to its requirements. GDPR applies (1) where a controller or processor has a real and effective establishment in the EU and the processing is carried out in the context of that establishment’s activities, regardless of where the processing takes place or where the individuals are located ("establishment criterion") ; (2) to non-EU organizations that process personal data of individuals located in the EU when the processing relates to offering goods or services to individuals in the EU or monitoring behaviour within the EU ("targeting criterion"); and (3) where Member State law applies by virtue of public international law.
Article 3 of the GDPR:
  1. This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or processor in the Union, regardless of whether the processing takes place in the Union or not.
  2. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:
    a. the offering of goods or services, irrespective of whether payment is required, to such data subjects in the Union; or
    b. the monitoring of their behaviour, insofar as that behaviour takes place within the Union.
  3. This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.

Establishment Criterion

If an entity is subject to the GDPR under the establishment criterion, neither the location of the processing nor the location of the data subject is relevant. The only two considerations are:

The existence of an establishment in the EU.

  1. The existence of processing carried out in the context of the activities of such an establishment.

An establishment exists where there is real and effective activity exercised through stable arrangements. A non-EU entity without a branch or subsidiary in a Member State may still qualify as an establishment if it operates in that Member State in a “real and effective” manner. The degree of stability of the arrangements and the effective exercise of activities must be considered in light of the specific nature of the economic activities and the services provided.

The GDPR does not provide a definition of “establishment,” but Recital 225 clarifies that an establishment “implies the effective and real exercise of activities through stable arrangements. The legal form of such arrangements, whether through a branch or a subsidiary with a legal personality, is not the determining factor.” This wording mirrors Recital 19 of Directive 95/46/EC, which has been cited in several CJEU rulings.

Controllers and processors are subject to GDPR obligations whenever processing is carried out “in the context of the activities” of their establishments, even if not carried out by the establishment itself. Whether processing meets this test must be decided case by case, based on facts and relevant case law.

The European Data Protection Board (EDPB) has noted that the threshold for a “stable arrangement” is low: even one employee or agent of a non-EU entity in the Union may be sufficient, provided their work is stable and ongoing.

Non-EU organizations processing personal data must assess potential links between their processing and any EU establishment, considering factors such as:

  • The relationship between a non-EU controller or processor and its EU establishment.
  • Revenue generated in the EU.

Although geographical location matters in defining an establishment, it does not affect whether processing activities themselves fall under GDPR. Any processing carried out “in the context of the activities of an establishment” in the Union falls within GDPR, regardless of the data subject’s location or nationality.

Obligations of Organizations Established in the EU: Controllers and processors within EU establishments must be considered separately, since different obligations apply. A processor established in the Union is required to comply with GDPR obligations even if the controller itself is not subject to the GDPR. If a processor handles data on behalf of a non-EU controller, the data may or may not fall under the GDPR. However, the processor must still comply with its own GDPR obligations. These obligations do not extend to the non-EU controller, which remains outside the scope of the GDPR’s controller requirements.

Relevant obligations include:

  • Entering into data processing agreements (Art. 28).
  • Processing data only on the controller’s instructions (Arts. 29, 32(4)).
  • Maintaining records of processing activities (Art. 30(2)).
  • Cooperating with supervisory authorities (Art. 31).
  • Implementing appropriate security measures (Art. 32).
  • Notifying the controller of breaches without undue delay (Art. 33).
  • Appointing a Data Protection Officer, if required (Arts. 37–38).
  • Complying with restrictions on international transfers (Chapter V).

Targeting Criterion

Controllers or processors not established in the EU may still fall under GDPR if:

  1. Data subjects are located in the Union.
  2. Processing involves offering goods/services or monitoring their behaviour.

Application of this criterion is not limited by nationality or residence of the data subject. What matters is that the individual is in the Union at the time of the relevant activity.

The “processing activities” are to be considered on a case-by-case basis. Controllers and processors under the territorial scope of EU data protection law under the ‘targeting criterion’ are required to appoint a representative.

The application of the targeting criteria is not limited by the citizenship, residency or other type of legal status of the data subject. The requirement that the data subject be located in the Union is assessed at the moment when the relevant trigger activity takes place (i.e. at the moment of offering of goods or services or the moment when the behavior is being monitored) regardless of the duration of the offer made or monitoring undertaken.

In regards to offering goods or services, the key is whether the conduct on the part of the controller or processor demonstrates its intention to offer goods or a services to a data subject located in the Union (Recital 23 of the GDPR). Factors to be taken into consideration include:

  • The EU or at least one Member State is designated by name with reference to the good or service offered;
  • The data controller or processor pays a search engine operator for an internet referencing service in order to facilitate access to its site by consumers in the Union; or the controller or processor has launched marketing and advertising campaigns directed at an EU country audience;
  • The international nature of the activity at issue, such as certain tourist activities;
  • The mention of dedicated addresses or phone numbers to be reached from an EU country;
  • The use of a top-level domain name other than that of the third country in which the controller or processor is established, for example “.de”, or the use of neutral top-level domain names such as “.eu”;
  • The description of travel instructions from one or more other EU Member States to the place where the service is provided;
  • The mention of an international clientele composed of customers domiciled in various EU Member States, in particular by presentation of accounts written by such customers;
  • The use of a language or a currency other than that generally used in the trader’s country, especially a language or currency of one or more EU Member states;
  • The data controller offers the delivery of goods in EU Member States.

Whether the activity of a controller or processor not established in the Union is to be considered as an offer of a good or a service is not dependent on whether payment is made in exchange for the goods or services provided.

With regards to the monitoring of data subject behavior that takes place within the EU.

  • The behavior monitored must relate to a data subject in the Union and the monitored behavior must take place within the territory of the Union.
  • As opposed ‘offering of good and services’ (Article 3(2)(a) GDPR), there is no expressed requirement for the tracking to include a degree of intent. However, EDPB has taken the position that the use of the word “monitoring” implies a specific purpose ant that, therefore, not all online collection or analysis of personal data of individuals in the EU would automatically count as “monitoring”.

A broad range of activities can constitute monitoring including:

  • Behavioral advertisement
  • Geo-localization activities, in particular for marketing purposes
  • Online tracking through the use of cookies or other tracking techniques such as fingerprinting
  • Personalized diet and health analytic services online
  • CCTV
  • Market surveys and other behavioral studies based on individual profiles
  • Monitoring or regular reporting on an individual’s health status

Applicability Through International Law

In addition, the GDPR applies to personal data processing carried out by EU Member States’ embassies and consulates. A Member State’s diplomatic or consular post, acting as a controller or processor, is subject to all relevant provisions of the GDPR — including the rights of data subjects, the general obligations of controllers and processors, and the rules governing transfers of personal data to third countries or international organizations.


Resources

  • EDPB Guidelines 3/2018 on the territorial scope of GDPR (Article 3).
  • GDPR Article 3 and Recitals (14), (22)–(25).

Subscribe to The de la Torre Review

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe