Skip to content
Topic Contested in court

Territorial scope (GDPR)

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

When the GDPR applies geographically: establishment in the Union, targeting (offering goods or services), and behavioural monitoring by non-EU controllers (Article 3 GDPR).

96 linked items 19 Laws8 Case Law57 Guidance4 Enforcement1 News

Overview

24 sources · Aug 27, 2026

Legal Framework

Article 3 GDPR sets out three limbs of territorial application. Paragraph 1 captures the establishment-based trigger: any controller or processor with an establishment in the Union is subject to the GDPR for processing carried out in the context of that establishment's activities, wherever the data physically sits. Paragraph 2 extends the Regulation to non-EU controllers and processors through two targeting criteria — offering goods or services to data subjects in the Union, or monitoring their behaviour as it occurs within the Union. Paragraph 3 reaches controllers operating in territories subject to Member State law by virtue of public international law (for instance, embassies or consulates).

"This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not."
GDPR Art. 3(1)

When Article 3(2) applies, Article 27 obliges the non-EU controller or processor to designate a written EU representative, established in a Member State where the targeted data subjects are located. The representative acts as a point of contact for supervisory authorities and data subjects, though designation does not shield the controller from direct legal action.

Key Developments

The CJEU's landmark Google Spain ruling confirmed that a search engine's ad-selling subsidiary in Spain constituted an "establishment" for purposes of the predecessor Directive, even though the data processing occurred on servers in the United States. The Court framed the question around the material and territorial scope of data protection law in the context of internet search engines and establishment on Member State territory.

"Personal data — Protection of individuals with regard to the processing of such data — Directive 95/46/EC — Articles 2, 4, 12 and 14 — Material and territorial scope — Internet search engines — Processing of data contained on websites — Searching for, indexing and storage of such data — Responsibility of the operator of the search engine — Establishment on the territory of a Member State"
Google Spain, C-131/12, ¶0

Enforcement confirms that DPAs apply Article 3(2) aggressively against non-EU controllers. Italy's Garante fined Lusha Systems Inc. €2,000,000 for processing EU residents' professional contact data without an EU establishment, and Spain's AEPD opened proceedings against 23andMe, a US-based genomics company offering genetic testing services to EU consumers. Both cases turned on the Article 3(2)(a) "offering of goods or services" limb.

The EDPB's Guidelines 3/2018 on territorial scope remain the primary interpretive reference, supplemented by breach-notification guidance confirming that:

"Article 3 GDPR concerns the territorial scope of the GDPR, including when it applies to the processing of personal data by a controller or processor that is not established in the EU."
EDPB Guidelines 9/2022, §70

Status of the Debate

This topic is actively contested in court. The establishment limb was broadly settled by Google Spain, but the targeting and monitoring limbs under Article 3(2) remain in flux. Courts and DPAs diverge on what degree of intentionality is required to demonstrate "offering" services to EU data subjects versus merely being accessible from the EU. The behavioural monitoring limb raises unresolved questions about whether tracking technologies such as cookies or analytics scripts directed at EU IP addresses constitute monitoring "as far as their behaviour takes place within the Union." No definitive CJEU ruling under the GDPR has yet drawn these boundaries. A preliminary reference on Article 3(2)(b) — particularly distinguishing passive accessibility from active targeting — would resolve the core open question.

Practical Guidance

  • Map your establishment footprint first. If any entity in your corporate group has an EU establishment and processes personal data in the context of that establishment's activities, Article 3(1) applies regardless of where servers are located. Do not assume that hosting data outside the EU avoids the GDPR.
  • Assess targeting indicators under Article 3(2)(a). EU-facing websites, euro pricing, EU shipping options, and EU-language content all signal offering goods or services to EU data subjects. The absence of payment does not exclude application — the text expressly covers offerings "irrespective of whether a payment of the data subject is required."
  • Evaluate behavioural monitoring under Article 3(2)(b). Use of cookies, tracking pixels, or analytics tools that profile EU-based users triggers the monitoring limb. Document whether your tracking is directed at EU users specifically or operates indiscriminately.
  • Designate an Article 27 representative where required. Non-EU controllers caught by Article 3(2) must appoint a written representative in a relevant Member State, unless the processing is occasional and low-risk under the Article 27(2) exemption.
  • Document your territorial-scope analysis. Maintain a reasoned assessment of why the GDPR does or does not apply to each processing activity, referencing the three limbs of Article 3 and the EDPB Guidelines 3/2018 criteria.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 19
Art. 3(2) This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the U… GDPR Art. 3(2)(a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or GDPR Art. 3(2)(b) the monitoring of their behaviour as far as their behaviour takes place within the Union. GDPR Art. 3(3) This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies… GDPR art 3 Territorial scope GDPR Apr 2016 geographic applicability conditions
why this is here
This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union

The provision is the direct legal basis defining when the GDPR applies geographically, covering establishment, targeting, and monitoring as described in the topic.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

art 27 Representatives of controllers or processors not established in the Union GDPR Apr 2016 Obligation for non-EU controllers
why this is here
Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union.

The provision operationalizes the extraterritorial application under Article 3(2) by requiring a Union representative, directly supplementing the territorial-scope rule. It is not the primary source of the scope itself but implements it for non-EU controllers.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

rec 23 Recital 23 — extraterritorial scope non EU controllers GDPR Apr 2016 rec 24 Recital 24 — extraterritorial processing behaviour monitoring GDPR Apr 2016 rec 22 Recital 22 — extraterritorial application to non-EU operators AI Act Jun 2024 rec 36 Recital 36 — territorial scope of orders against illegal content DSA Oct 2022 rec 22 Recital 22 — Union establishment territorial scope GDPR Apr 2016 rec 115 Recital 115 — extraterritorial third country data disclosure GDPR Apr 2016 rec 80 Recital 80 — non-EU controller processor representative requirement GDPR Apr 2016 rec 25 Recital 25 — public international law applicable controllers GDPR Apr 2016 rec 82 Recital 82 — EU authorised representative for third-country providers AI Act Jun 2024 rec 116 Recital 116 — non-EU digital service provider EU representative NIS2 Dec 2022 rec 113 Recital 113 — member state jurisdiction over entities NIS2 Dec 2022 rec 114 Recital 114 — single Member State jurisdiction for digital service providers NIS2 Dec 2022 rec 8 Recital 8 — substantial connection to the Union DSA Oct 2022 rec 123 Recital 123 — supervision by member state of establishment DSA Oct 2022 rec 31 Recital 31 — cross-border orders for intermediary services DSA Oct 2022 rec 122 Recital 122 — supervisory authority territorial competence and tasks GDPR Apr 2016 rec 63 Recital 63 — ENISA European vulnerability database NIS2 Dec 2022
Case Law 8
¶110 In that context, the weighing of the interference resulting from the publication of personal data contained in the declarations of private interest ag… OT v Vyriausioji tarnybinės etikos komisija ¶5 Article 3 of that regulation defines its territorial scope. According to paragraph 1 thereof, the GDPR ‘applies to the processing of personal data in … Komisia za zashtita na lichnite danni and Tsentralna izbiratelna komisia v Koalitsia „Demokratichna Bulgaria - Obedinenie“ ¶1 #Google LLC, successor in law to Google Inc. #Case C-507/17. Judgment of the Court (Grand Chamber) of 24 September 2019. Google LLC, successor in law … Google LLC, venant aux droits de Google Inc. v Commission nationale de l’informatique et des libertés (CNIL) ¶1 20220627Mentioned in the tables of the Lebon collection10th - 9th chambers combinedMme Christelle Thomas, rapporteurMme Esther de Moustier, public rap… CE - 451423 306/21 Komisia za zashtita na lichnite danni and Tsentralna izbiratelna komisia v Koalitsia „Demokratichna Bulgaria - Obedinenie“ Court of Justice of the European Union Oct 2022 Supreme Administrative Court CE - 451423 Supreme Administrative Court Jun 2022 507/17 Google LLC v CNIL CJEU Sep 2019 CJEU Google LLC, venant aux droits de Google Inc. v Commission nationale de l’informatique et des libertés (CNIL) CJEU Sep 2019 establishment and single act of processing
why this is here
that search engine must, in view of, inter alia, the existence of gateways between its various national versions, be regarded as carrying out a single act of personal data processing

The entire judgment is about whether GDPR applies territorially, focusing on the establishment's activities and the single-processing-act doctrine.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

136/17 GC and Others v CNIL CJEU Sep 2019 131/12 Google Spain SL and Google Inc. v AEPD and Mario Costeja González CJEU May 2014 CJEU UNABHäNGIGES LANDESZENTRUM FüR DATENSCHUTZ SCHLESWIG-HOLSTEIN v. WIRTSCHAFTSAKADEMIE SCHLESWIG-HOLDSTEIN GmbH CJEU Jun 2018 Establishment and territorial application
why this is here
the activities of that establishment must be regarded as inextricably linked to the processing of personal data at issue

The entire judgment concerns whether the processing occurs in the context of the activities of an establishment in the EU, which is central to territorial scope.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

CJEU GOOGLE SPAIN SL V. AEPD (THE DPA) & MARIO COSTEJA GONZALEZ, 13.May.2014 (“GOOGLE v. Spain”) CJEU May 2014 territorial application and establishment
why this is here
Article 4(1)(a) of Directive 95/46 is to be interpreted as meaning that processing of personal data is carried out in the context of the activities of an establishment of the controller on the territory of a Member State, within the meaning of that provision, when the operator of a search engine sets up in a Member State a branch or subsidiary which is intended to promote and sell advertising space offered by that engine and which orientates its activity towards the inhabitants of that Member State.

The case is a landmark decision on the territorial scope of EU data protection law, clarifying that the presence of an establishment in a Member State suffices to trigger the Directive even if processing occurs outside.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidance 57
§70 Article 3 GDPR concerns the territorial scope of the GDPR, including when it applies to the processing of personal data by a controller or processor t… Guidelines 9/2022 on personal data breach notification under GDPR §71 Article 3(3) GDPR is also relevant and states 35 : “ This Regulation applies to the processing of personal data by a controller not established in the… Guidelines 9/2022 on personal data breach notification under GDPR §76 In its Opinion 03/2014 on breach notification 38 , WP29 explained that a confidentiality breach of personal data that were encrypted with a state of t… Guidelines 9/2022 on personal data breach notification under GDPR §138 Controllers should also be aware of any additional legal, medical, or professional notification duties under other applicable regimes. force, see http… Guidelines 9/2022 on personal data breach notification under GDPR guidelines on the territorial scope of the gdpr Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) EDPB Nov 2019 Article 3 territorial application
why this is here
The territorial scope of General Data Protection Regulation 1 ( the GDPR or the Regulation ) is determined by Article 3

This is the central subject of the document; it extensively interprets Article 3 GDPR.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

guidelines 022024 on article 48 gdpr Guidelines 02/2024 on Article 48 GDPR EDPB Jun 2025 GDPR applies to EU controllers/processors
why this is here
controllers or processors in the EU

The document discusses situations where controllers or processors in the EU receive requests, implicating territorial scope.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

guidelines 202402 article48 v2 Guidelines 02/2024 on Article 48 GDPR EDPB Jun 2025 guidelines on personal data breach notification under gdpr Guidelines 9/2022 on personal data breach notification under GDPR EDPB Apr 2023 052021 on the interplay between the application of article 3 and the Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR EDPB Feb 2023 guidelines on the concepts of controller and processor in the gdpr Guidelines 07/2020 on the concepts of controller and processor in the GDPR EDPB Jul 2021 22020 on articles 46 2 a and 46 3 b of regulation 2016679 for Guidelines 2/2020 on articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies EDPB Dec 2020 222024 on certain obligations following from the Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s) EDPB Oct 2024 122024 on the draft decision of the french Opinion 12/2024 on the draft decision of the French Supervisory Authority regarding the “Code of Conduct for Service Providers in Clinical Research” submitted by EUCROF EDPB Jun 2024 62024 on the draft list of the latvian sa on pro Opinion 6/2024 on the draft list of the Latvian SA on pro-cessing operations exempt from the data protection impact assessment requirement (Art. 35.5 GDPR) EDPB Apr 2024 042024 on the notion of main establishment of a Opinion 04/2024 on the notion of main establishment of a controller in the Union under Art. 4.16(a) GDPR EDPB Feb 2024 162021 on the draft decision of the belgian Opinion 16/2021 on the draft decision of the Belgian Supervisory Authority regarding the “EU Data Protection Code of Conduct for Cloud Service Providers” submitted by Scope Europe EDPB May 2021 172021 on the draft decision of the french Opinion 17/2021 on the draft decision of the French Supervisory Authority regarding the European code of conduct submitted by the Cloud Infrastructure Service Providers (CISPE) EDPB May 2021 72020 on the draft list of the competent supervisory Opinion 7/2020 on the draft list of the competent supervisory authority of France regarding the processing operations exempt from the requirement of a data protection impact assessment (Article 35(5) GDPR) EDPB Apr 2020 122019 on the draft list of the competent supervisory Opinion 12/2019 on the draft list of the competent supervisory authority of Spain regarding the processing operations exempt from the requirement of a data protection impact assessment (Article 35(5) GDPR) EDPB Jul 2019 132019 on the draft list of the competent supervisory Opinion 13/2019 on the draft list of the competent supervisory authority of France regarding the processing operations exempt from the requirement of a data protection impact assessment (Article 35(5) GDPR) EDPB Jul 2019 112019 on the draft list of the competent supervisory Opinion 11/2019 on the draft list of the competent supervisory authority of the Czech Republic regarding the processing operations exempt from the requirement of a data protection impact assessment (Article 35(5) GDPR) EDPB Jul 2019 102019 on the draft list of the competent supervisory Opinion 10/2019 on the draft list of the competent supervisory authority of Cyprus regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35(4) GDPR) EDPB Jul 2019 62019 on the draft list of the competent supervisory Opinion 6/2019 on the draft list of the competent supervisory authority of Spain regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) EDPB Mar 2019 72019 on the draft list of the competent supervisory Opinion 7/2019 on the draft list of the competent supervisory authority of Iceland regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) EDPB Mar 2019 Show 37 more →
Enforcement 4
AEPD (Spain) AEPD (Spain) - PS-00140-2025 AEPD (Spain) Oct 2025 HDPA (Greece) HDPA (Greece) - 54/2024 HDPA (Greece) Jun 2023 CNPD (Portugal) CNPD (Portugal) - Deliberação 2019/494 CNPD (Portugal) Sep 2019 Garante per la protezione dei dati personali (Italy) Garante per la protezione dei dati personali (Italy) - 9788429 Garante per la protezione dei dati personali (Italy) Jul 2022
News 1
IAPP Greek SA fines Clearview AI for EUR 20M IAPP Oct 2022 targeting criterion application
why this is here
the targeting criterion also establishes its competence to monitor GDPR compliance within its territory.

The HDPA directly addresses the extraterritorial application of the GDPR based on the targeting criterion, which is the heart of territorial scope.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Literature 7
SSRN Electronic Journal Territorial Scope and Data Transfer Rules in the GDPR: Realising the EU’s Ambition of Borderless Data Protection SSRN Electronic Journal Jan 2021 Pravo ta nauki IMPACT OF GDPR ON UKRAINIAN PERSONAL DATA PROTECTION LEGISLATION Pravo ta nauki Dec 2018 Comparative Law Review General Data Protection Regulation (GDPR) – Revolution Coming to European Data Protection Laws in 2018. What’s New for Ordinary Citizens? Comparative Law Review Feb 2018 Studies in Law and Justice The Path of Formulating the Basic Law of Artificial Intelligence in China — Analysis of the Desirability of the EU Artificial Intelligence Act Studies in Law and Justice Sep 2023 i-lex Perspectives for Open Source AI i-lex Jul 2026 International Journal of Law and Societal Studies Balancing Security and Privacy: Analyzing the Effectiveness of EU Digital Surveillance Laws in Criminal Proceedings International Journal of Law and Societal Studies Sep 2025 International Journal of Computer Applications A Comparative Analysis of the EU AI Act and the Colorado AI Act: Regulatory Approaches to Artificial Intelligence Governance International Journal of Computer Applications Sep 2024