GDPR Territorial Scope Beyond Europe

An organisation with no office in Europe can still be bound by the GDPR in full. No subsidiary, no staff on the continent, and still squarely in scope. Article 3 decides when that happens, and it uses two separate tests. GDPR territorial scope is the first thing to settle in any analysis. An organisation outside it owes nothing under the Regulation at all.

The Body of Knowledge is the IAPP document setting out what each exam covers. It places scope alongside accountability in Domain IV, European Data Protection: Scope and Accountability. The weighting is modest. Even so, every later answer about lawful bases, rights or transfers assumes the Regulation applies.

The two GDPR territorial scope criteria

Article 3 sets GDPR territorial scope. Paragraph 1 gives an establishment criterion. Paragraph 2 gives a targeting criterion. Meeting one of them is enough.

Paragraph 3 adds a third route. It covers processing in a place where Member State law applies by virtue of public international law. That is how the Regulation reaches embassies, consular posts and ships registered in a Member State.

One clarification in the EDPB guidelines on territorial scope reframes the whole analysis. Article 3 asks whether a particular processing activity falls within scope. It does not ask whether a company does. So one controller can have an activity inside the Regulation and another outside it.

What makes something an establishment

Recital 22 defines establishment loosely. It implies the effective and real exercise of activities through stable arrangements. The legal form of those arrangements does not settle the question. A branch, a subsidiary or something far less formal can all qualify.

The Court of Justice pushed the threshold low. In Weltimmo it held that establishment extends to any real and effective activity through stable arrangements, even a minimal one. Where a controller provides its services online, the EDPB accepts that one employee or agent in the Union may be enough. That person only has to act with a sufficient degree of stability.

Two limits that stop this swallowing everything

A website reaching people in the Union creates no establishment there. The Court confirmed that in the Amazon EU case.

An employee sitting in the Union does not trigger the Regulation on its own either. The processing also has to happen in the context of that person’s activities.

That phrase carries most of the weight. Google Spain settled the point. Processing by a non-EU entity falls in scope where it links inextricably to the activities of a local establishment. The local office need play no part in the processing itself.

The EDPB gives a worked example. A Chinese e-commerce company runs commercial prospection and marketing towards EU markets from a Berlin office. That office touches no data. The processing in China still falls inside GDPR territorial scope.

Targeting reaches organisations with no presence at all

Article 3(2) covers the personal data of people who are in the Union. It reaches a controller or processor with no establishment there. The processing has to relate to one of two things. Either the organisation offers goods or services to those people, or it monitors their behaviour as it takes place in the Union.

Location matters and citizenship does not. Recital 14 protects natural persons whatever their nationality or place of residence. The test applies at the moment of the offer or the monitoring. A service aimed only at users outside the EU stays outside the Regulation when one of those users travels into it.

What counts as offering goods or services

The offering limb turns on intention. Recital 23 rules out three things on their own: a website people can reach, an email address, and contact details. It also rules out a language generally used in the third country where the controller sits.

The EDPB draws on the Court’s reasoning in Pammer and Hotel Alpenhof. It lists factors that can combine to show intent:

  • naming the EU or a Member State in connection with the goods or service
  • paying a search engine for referencing that eases access for consumers in the Union
  • offering delivery of goods into Member States
  • using a currency or language of a Member State, or a Member State or .eu domain name
  • presenting accounts written by customers domiciled in Member States

What counts as monitoring

The monitoring limb of territorial scope works differently. Recital 24 points at tracking people on the internet. It covers later profiling that supports decisions about them, or that analyses or predicts their preferences, behaviours and attitudes.

The EDPB reads the provision more widely. Tracking through other technologies counts too, wearables and other smart devices among them. Its examples run from behavioural advertising and cookie or fingerprint tracking to CCTV, geolocation for marketing and personalised diet and health analytics.

The representative in the Union

Article 27 requires a representative in the Union, on a written mandate. It applies to any organisation that Article 3(2) reaches.

The exemptions are narrow. Processing escapes the duty on three conditions. It has to be occasional, it must involve no large-scale special category or criminal data, and it must be unlikely to result in a risk to people’s rights and freedoms. Public authorities also fall outside the duty. The representative sits in a Member State where the affected people are.

Three points decide questions here regularly. Appointing a representative creates no establishment, so it never pulls the organisation into Article 3(1). The representative cannot double as an external data protection officer, because such an officer takes no instructions on the exercise of their tasks. An organisation with no establishment in the Union also cannot use the one-stop-shop mechanism in Article 56.

Where territorial scope questions are lost

A scenario often plants an EU-based processor and waits. Instructing a processor in the Union does not bring a non-EU controller into scope. That controller is not processing in the context of the processor’s activities.

The processor falls in scope in its own right under Article 3(1). It owes the obligations the Regulation places on processors directly. Those include the security duty, the record of categories of processing and the transfer rules in Chapter V.

So read the facts for the connecting factor first, because that factor fixes GDPR territorial scope. Where the connecting factor is an establishment in the Union, work through the context test. Where there is none, ask what the organisation is doing to people who are in the Union.

If cross-border fact patterns cost you time, the walkthrough of hidden cross-border exam scenarios covers the neighbouring traps. The CIPP/E study guide sets out the order to work the domains.

Similar Posts