Application Scope: Temporal and Territorial Dimensions
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This topic is needed to capture the specific provisions regarding when (temporal) and where (territorial) the AI Act applies, which are distinct from general scope and definitions.
Overview
24 sources · Jul 23, 2026Legal Framework
The territorial scope of EU data protection law is governed primarily by Article 3 GDPR, which establishes two main pathways for application. Under Article 3(1), the Regulation applies to processing carried out in the context of the activities of an establishment of a controller or processor in the Union, regardless of whether the actual processing takes place in the EU. The establishment concept requires effective and actual exercise of activities through stable arrangements, even if those activities are limited in scale. A commercial agent collecting payments for an internet service can constitute an establishment. The critical nexus is that the processing occurs "in the context of" the establishment's activities — not merely that an establishment exists somewhere in the EU.
Article 3(2) extends application to non-EU controllers and processors that either offer goods or services to data subjects in the Union or monitor their behavior occurring within the Union. The GDPR does not displace the E-commerce Directive (2000/31/EC), particularly the intermediary liability limitations in Articles 12–15, which are implemented nationally.
For law enforcement processing, Directive (EU) 2016/680 governs, covering not only public authorities but any entity authorized under Member State law to exercise public powers. The AI Act introduces specific temporal constraints in Recital 95 for post-remote biometric identification systems, requiring that use be proportionate, legitimate, strictly necessary, and targeted as to individuals, location, and temporal scope, using closed datasets of legally acquired footage.
Key Developments
The CJEU's establishment jurisprudence has set a deliberately broad threshold. In Google Spain v AEPD (C-131/12), the Court held that the EU legislature intended to prevent circumvention of protection through a particularly broad territorial scope. A subsidiary's advertising and commercial activities were deemed inextricably linked to the parent company's search engine data processing, bringing the entire operation within Article 3(1).
In Google v CNIL, the Court reaffirmed that Google's French establishment conducted commercial and advertising activities inextricably linked to search engine processing, and that the various national versions of the search engine constituted a single act of processing. This means that once the establishment nexus is established, all linked processing falls within scope.
Weltimmo clarified that supervisory authorities may exercise powers only within their own territory but may investigate complaints irrespective of which national law ultimately applies, facilitating cross-border cooperation under Article 28(6) of Directive 95/46.
The EDPB's Guidelines 3/2018 further elaborate the establishment and targeting tests, providing structured criteria for assessing whether activities fall within Article 3(1) or 3(2).
Practical Guidance
- Conduct a structured establishment analysis: identify any EU presence — including agents, subsidiaries, or stable commercial relationships — and map whether data processing is inextricably linked to that establishment's activities under the Google Spain and Google v CNIL standards.
- For non-EU entities, assess Article 3(2) exposure by evaluating whether you intentionally offer services to EU data subjects or systematically monitor behavior within the Union, using the EDPB Guidelines 3/2018 criteria.
- If deploying post-remote biometric identification systems under the AI Act, implement hard temporal and locational limits, restrict to closed datasets, and document proportionality and strict necessity assessments.
- Preserve any intermediary service provider status under the E-commerce Directive (Articles 12–15) where applicable, as the GDPR does not override these liability limitations.
- For law enforcement-related processing, determine whether your entity qualifies under Directive (EU) 2016/680 by assessing whether you exercise public authority under Member State law.