Meaning of "Establishment"
The concept of an establishment is explained in Recital 22, which provides that an establishment exists where an organisation carries out effective and real activity through stable arrangements. The legal form of the entity is not decisive. Accordingly, an establishment may consist of:
- a branch;
- a subsidiary;
- a representative office;
- an employee; or
- an authorised agent,
provided that the activities demonstrate sufficient permanence and organisational stability.
The EDPB Guidelines 3/2018 emphasise that the threshold for establishing a "stable arrangement" is relatively low, particularly in the digital economy. Even a single employee or representative may constitute an establishment where that individual carries out genuine and continuous activities connected with the organisation's business in the European Union. Consequently, organisations cannot avoid GDPR applicability merely because they have adopted a minimal physical presence within the Union.
Illustration
The EDPB similarly explains that supervisory authorities should examine whether there is an "inextricable link" between the activities of the EU establishment and the processing, and whether those activities contribute to the economic objectives of the controller or processor. The assessment therefore focuses on the commercial and functional relationship between the establishment and the processing activity, rather than on the location where technical processing takes place.
Illustration
A US-based online advertising platform maintains a German office responsible for selling advertising services to European businesses. Although user tracking and data analytics are performed outside Germany, those activities directly support the advertising business generated through the German office. The processing may therefore be regarded as occurring in the context of the activities of the EU establishment.
However, Article 3(1) is not without limits. A purely incidental or remote connection with an EU establishment is insufficient. There must be a genuine relationship between the establishment's activities and the specific processing operation. Where the EU establishment performs functions entirely unrelated to the processing under consideration, Article 3(1) should not apply merely because the organisation happens to maintain some presence within the Union.
Article 3(2): Processing by Non-EU Organisations Targeting Individuals in the Union
Article 3(2) extends the GDPR beyond the European Union by applying to controllers and processors that are not established in the Union where they process personal data relating to individuals who are in the Union, provided that the processing relates to either:
- the offering of goods or services to such individuals; or
- the monitoring of their behaviour within the Union.
This provision reflects the GDPR's objective of ensuring that individuals located within the European Union receive a consistent level of protection, irrespective of where the organisation processing their personal data is established.
Article 3(2) must be interpreted alongside Recitals 14, 23 and 24, which clarify the concepts of targeting and monitoring. Notably, nationality is irrelevant. The decisive factor is whether the individual is physically present within the Union at the time the relevant processing occurs. Consequently, an Indian tourist visiting Italy may fall within the protection of the GDPR, whereas a French citizen permanently residing outside the European Union does not automatically benefit from Article 3(2) merely by virtue of nationality.
The EDPB further explains that an individual's location must be assessed at the time of the activity giving rise to GDPR applicability, such as when goods or services are offered or when behavioural monitoring takes place. Accordingly, organisations should assess territorial scope based upon the factual circumstances existing at the relevant point in time rather than upon the individual's habitual residence or citizenship.
Article 3(2)(a): Offering Goods or Services
Article 3(2)(a) applies where a controller or processor established outside the European Union offers goods or services to individuals located within the Union. The GDPR expressly provides that this applies irrespective of whether payment is required, meaning that both commercial and free digital services may fall within its scope.
The critical consideration is intentional targeting. As explained in Recital 23, the mere accessibility of a website from within the European Union is insufficient. Instead, it must be apparent that the organisation envisages offering goods or services to individuals in one or more Member States. Consequently, territorial scope depends upon objective evidence demonstrating a deliberate commercial orientation towards the European market rather than on the technical possibility that EU residents may access an online service.
Objective indicators of targeting may include:
- websites available in EU languages;
- pricing in euros or other EU currencies;
- delivery of goods to EU Member States;
- EU customer support services;
- advertisements specifically directed at EU consumers;
- EU-specific domain names;
- references to EU customers; and
- mobile applications marketed specifically to EU users.
A single factor is rarely determinative. Rather, supervisory authorities assess the overall factual circumstances to determine whether the organisation has demonstrated an intention to engage with the European market.
Illustration
Illustration
Illustration