Territorial scope (GDPR)
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.When the GDPR applies geographically: establishment in the Union, targeting (offering goods or services), and behavioural monitoring by non-EU controllers (Article 3 GDPR).
Overview
24 sources · Aug 27, 2026Legal Framework
Article 3 GDPR sets out three limbs of territorial application. Paragraph 1 captures the establishment-based trigger: any controller or processor with an establishment in the Union is subject to the GDPR for processing carried out in the context of that establishment's activities, wherever the data physically sits. Paragraph 2 extends the Regulation to non-EU controllers and processors through two targeting criteria — offering goods or services to data subjects in the Union, or monitoring their behaviour as it occurs within the Union. Paragraph 3 reaches controllers operating in territories subject to Member State law by virtue of public international law (for instance, embassies or consulates).
"This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not."
— GDPR Art. 3(1)
When Article 3(2) applies, Article 27 obliges the non-EU controller or processor to designate a written EU representative, established in a Member State where the targeted data subjects are located. The representative acts as a point of contact for supervisory authorities and data subjects, though designation does not shield the controller from direct legal action.
Key Developments
The CJEU's landmark Google Spain ruling confirmed that a search engine's ad-selling subsidiary in Spain constituted an "establishment" for purposes of the predecessor Directive, even though the data processing occurred on servers in the United States. The Court framed the question around the material and territorial scope of data protection law in the context of internet search engines and establishment on Member State territory.
"Personal data — Protection of individuals with regard to the processing of such data — Directive 95/46/EC — Articles 2, 4, 12 and 14 — Material and territorial scope — Internet search engines — Processing of data contained on websites — Searching for, indexing and storage of such data — Responsibility of the operator of the search engine — Establishment on the territory of a Member State"
— Google Spain, C-131/12, ¶0
Enforcement confirms that DPAs apply Article 3(2) aggressively against non-EU controllers. Italy's Garante fined Lusha Systems Inc. €2,000,000 for processing EU residents' professional contact data without an EU establishment, and Spain's AEPD opened proceedings against 23andMe, a US-based genomics company offering genetic testing services to EU consumers. Both cases turned on the Article 3(2)(a) "offering of goods or services" limb.
The EDPB's Guidelines 3/2018 on territorial scope remain the primary interpretive reference, supplemented by breach-notification guidance confirming that:
"Article 3 GDPR concerns the territorial scope of the GDPR, including when it applies to the processing of personal data by a controller or processor that is not established in the EU."
— EDPB Guidelines 9/2022, §70
Status of the Debate
This topic is actively contested in court. The establishment limb was broadly settled by Google Spain, but the targeting and monitoring limbs under Article 3(2) remain in flux. Courts and DPAs diverge on what degree of intentionality is required to demonstrate "offering" services to EU data subjects versus merely being accessible from the EU. The behavioural monitoring limb raises unresolved questions about whether tracking technologies such as cookies or analytics scripts directed at EU IP addresses constitute monitoring "as far as their behaviour takes place within the Union." No definitive CJEU ruling under the GDPR has yet drawn these boundaries. A preliminary reference on Article 3(2)(b) — particularly distinguishing passive accessibility from active targeting — would resolve the core open question.
Practical Guidance
- Map your establishment footprint first. If any entity in your corporate group has an EU establishment and processes personal data in the context of that establishment's activities, Article 3(1) applies regardless of where servers are located. Do not assume that hosting data outside the EU avoids the GDPR.
- Assess targeting indicators under Article 3(2)(a). EU-facing websites, euro pricing, EU shipping options, and EU-language content all signal offering goods or services to EU data subjects. The absence of payment does not exclude application — the text expressly covers offerings "irrespective of whether a payment of the data subject is required."
- Evaluate behavioural monitoring under Article 3(2)(b). Use of cookies, tracking pixels, or analytics tools that profile EU-based users triggers the monitoring limb. Document whether your tracking is directed at EU users specifically or operates indiscriminately.
- Designate an Article 27 representative where required. Non-EU controllers caught by Article 3(2) must appoint a written representative in a relevant Member State, unless the processing is occasional and low-risk under the Article 27(2) exemption.
- Document your territorial-scope analysis. Maintain a reasoned assessment of why the GDPR does or does not apply to each processing activity, referencing the three limbs of Article 3 and the EDPB Guidelines 3/2018 criteria.
why this is here
This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union
The provision is the direct legal basis defining when the GDPR applies geographically, covering establishment, targeting, and monitoring as described in the topic.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union.
The provision operationalizes the extraterritorial application under Article 3(2) by requiring a Union representative, directly supplementing the territorial-scope rule. It is not the primary source of the scope itself but implements it for non-EU controllers.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
that search engine must, in view of, inter alia, the existence of gateways between its various national versions, be regarded as carrying out a single act of personal data processing
The entire judgment is about whether GDPR applies territorially, focusing on the establishment's activities and the single-processing-act doctrine.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
the activities of that establishment must be regarded as inextricably linked to the processing of personal data at issue
The entire judgment concerns whether the processing occurs in the context of the activities of an establishment in the EU, which is central to territorial scope.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
Article 4(1)(a) of Directive 95/46 is to be interpreted as meaning that processing of personal data is carried out in the context of the activities of an establishment of the controller on the territory of a Member State, within the meaning of that provision, when the operator of a search engine sets up in a Member State a branch or subsidiary which is intended to promote and sell advertising space offered by that engine and which orientates its activity towards the inhabitants of that Member State.
The case is a landmark decision on the territorial scope of EU data protection law, clarifying that the presence of an establishment in a Member State suffices to trigger the Directive even if processing occurs outside.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
The territorial scope of General Data Protection Regulation 1 ( the GDPR or the Regulation ) is determined by Article 3
This is the central subject of the document; it extensively interprets Article 3 GDPR.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
controllers or processors in the EU
The document discusses situations where controllers or processors in the EU receive requests, implicating territorial scope.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
the targeting criterion also establishes its competence to monitor GDPR compliance within its territory.
The HDPA directly addresses the extraterritorial application of the GDPR based on the targeting criterion, which is the heart of territorial scope.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026