CHAPTER IGENERAL PROVISIONS

Article 3Territorial scope

Official text

(1)This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.

(2)This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:

(a)the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or

(b)the monitoring of their behaviour as far as their behaviour takes place within the Union.

(3)This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.

Commentary

Article 3 determines the territorial scope of the General Data Protection Regulation (GDPR). It is one of the Regulation's most significant provisions because it establishes when the GDPR applies geographically, including in situations where a controller or processor is located outside the European Union. Consequently, Article 3 gives the GDPR an extensive extraterritorial reach and plays a central role in regulating international processing activities.

Article 3 must be interpreted together with Recitals 14, 22, 23, 24, 25, 80 and 122, as well as the European Data Protection Board (EDPB) Guidelines 3/2018 on the Territorial Scope of the GDPR and EDPB Guidelines 05/2021 on the interaction between Article 3 and Chapter V on international transfers. These interpretative instruments provide essential guidance on concepts such as establishment, targeting, monitoring, and the relationship between territorial scope and cross-border data transfers.

Three Bases for GDPR Applicability Article 3 establishes three independent bases upon which the GDPR may apply:

  1. Processing in the context of the activities of an establishment in the Union (Article 3(1));
  2. Processing by a controller or processor outside the Union that targets or monitors individuals in the Union (Article 3(2)); and
  3. Processing carried out in places where Member State law applies by virtue of public international law (Article 3(3)).

Each basis operates independently. Satisfaction of any one of these jurisdictional connections is sufficient to bring the relevant processing activity within the scope of the GDPR.

Article 3(1): Processing in the Context of an EU Establishment

Article 3(1) provides that the GDPR applies where personal data is processed in the context of the activities of an establishment of a controller or processor in the Union, irrespective of whether the processing itself takes place within or outside the European Union. Accordingly, the physical location of the servers, databases, or processing infrastructure is not determinative. The decisive question is whether the processing is sufficiently connected with the activities of an EU establishment.

Meaning of "Establishment"

The concept of an establishment is explained in Recital 22, which provides that an establishment exists where an organisation carries out effective and real activity through stable arrangements. The legal form of the entity is not decisive. Accordingly, an establishment may consist of:

  • a branch;
  • a subsidiary;
  • a representative office;
  • an employee; or
  • an authorised agent,

provided that the activities demonstrate sufficient permanence and organisational stability.

The EDPB Guidelines 3/2018 emphasise that the threshold for establishing a "stable arrangement" is relatively low, particularly in the digital economy. Even a single employee or representative may constitute an establishment where that individual carries out genuine and continuous activities connected with the organisation's business in the European Union. Consequently, organisations cannot avoid GDPR applicability merely because they have adopted a minimal physical presence within the Union.

Illustration

The EDPB similarly explains that supervisory authorities should examine whether there is an "inextricable link" between the activities of the EU establishment and the processing, and whether those activities contribute to the economic objectives of the controller or processor. The assessment therefore focuses on the commercial and functional relationship between the establishment and the processing activity, rather than on the location where technical processing takes place. Illustration A US-based online advertising platform maintains a German office responsible for selling advertising services to European businesses. Although user tracking and data analytics are performed outside Germany, those activities directly support the advertising business generated through the German office. The processing may therefore be regarded as occurring in the context of the activities of the EU establishment. However, Article 3(1) is not without limits. A purely incidental or remote connection with an EU establishment is insufficient. There must be a genuine relationship between the establishment's activities and the specific processing operation. Where the EU establishment performs functions entirely unrelated to the processing under consideration, Article 3(1) should not apply merely because the organisation happens to maintain some presence within the Union.


Article 3(2): Processing by Non-EU Organisations Targeting Individuals in the Union

Article 3(2) extends the GDPR beyond the European Union by applying to controllers and processors that are not established in the Union where they process personal data relating to individuals who are in the Union, provided that the processing relates to either:

  • the offering of goods or services to such individuals; or
  • the monitoring of their behaviour within the Union. This provision reflects the GDPR's objective of ensuring that individuals located within the European Union receive a consistent level of protection, irrespective of where the organisation processing their personal data is established. Article 3(2) must be interpreted alongside Recitals 14, 23 and 24, which clarify the concepts of targeting and monitoring. Notably, nationality is irrelevant. The decisive factor is whether the individual is physically present within the Union at the time the relevant processing occurs. Consequently, an Indian tourist visiting Italy may fall within the protection of the GDPR, whereas a French citizen permanently residing outside the European Union does not automatically benefit from Article 3(2) merely by virtue of nationality. The EDPB further explains that an individual's location must be assessed at the time of the activity giving rise to GDPR applicability, such as when goods or services are offered or when behavioural monitoring takes place. Accordingly, organisations should assess territorial scope based upon the factual circumstances existing at the relevant point in time rather than upon the individual's habitual residence or citizenship.

Article 3(2)(a): Offering Goods or Services

Article 3(2)(a) applies where a controller or processor established outside the European Union offers goods or services to individuals located within the Union. The GDPR expressly provides that this applies irrespective of whether payment is required, meaning that both commercial and free digital services may fall within its scope. The critical consideration is intentional targeting. As explained in Recital 23, the mere accessibility of a website from within the European Union is insufficient. Instead, it must be apparent that the organisation envisages offering goods or services to individuals in one or more Member States. Consequently, territorial scope depends upon objective evidence demonstrating a deliberate commercial orientation towards the European market rather than on the technical possibility that EU residents may access an online service. Objective indicators of targeting may include:

  • websites available in EU languages;
  • pricing in euros or other EU currencies;
  • delivery of goods to EU Member States;
  • EU customer support services;
  • advertisements specifically directed at EU consumers;
  • EU-specific domain names;
  • references to EU customers; and
  • mobile applications marketed specifically to EU users. A single factor is rarely determinative. Rather, supervisory authorities assess the overall factual circumstances to determine whether the organisation has demonstrated an intention to engage with the European market.

Illustration

Illustration

Illustration

Article 3(2)(b): Monitoring Behaviour in the Union

Article 3(2)(b) applies where a controller or processor established outside the European Union monitors the behaviour of individuals while they are in the Union. This provision reflects the increasing use of digital technologies capable of observing, analysing and predicting human behaviour across borders. Recital 24 explains that monitoring occurs where individuals are tracked on the internet or through other technologies in order to analyse or predict their personal preferences, behaviours, attitudes or movements. The focus is therefore not merely on the collection of personal data but on the systematic observation and evaluation of behaviour.

The EDPB Guidelines 3/2018 emphasise that behavioural monitoring extends well beyond traditional internet tracking. It may include monitoring through:

  • mobile applications;
  • wearable devices;
  • connected vehicles;
  • smart home devices;
  • geolocation technologies; and
  • other technologies capable of analysing individual behaviour over time.

Illustration

Illustration

Illustration

  • Article 23, Restrictions on data subject rights;
  • Article 85, Processing for freedom of expression and journalism;
  • Article 88, Processing in the employment context; and
  • Article 89, Processing for archiving, scientific research and statistical purposes. Accordingly, once Article 3 establishes that the GDPR applies, organisations must also consider whether any relevant Member State legislation supplements, modifies or particularises the GDPR in relation to the specific processing activity. Similarly, where the GDPR refers to concepts such as legal obligations, contracts, or public interest, the content of those concepts frequently depends upon applicable national law. Consequently, territorial applicability under Article 3 often represents only the first stage of the legal analysis.