Skip to main content
Category: Scope & Exemptions

Material Scope

Also known as: Material Scope of the GDPR, Article 2 Scope
Simply put

Material scope describes the kinds of activities the GDPR actually covers, in other words what the law applies to rather than where or to whom. It generally covers the processing of personal data done by computer or other automated means, and certain manual processing where the data forms part of a structured filing system. It is one of two applicability tests under the GDPR; the other, territorial scope, addresses geographic reach and is set out separately.

Formal definition

Material scope is the applicability criterion set out in Article 2 GDPR, determining whether a given processing activity falls within the Regulation's substantive reach. Under Article 2, the GDPR applies to the processing of personal data wholly or partly by automated means, and to non-automated processing of personal data that forms part of, or is intended to form part of, a filing system. It operates alongside the territorial scope criterion in Article 3, and both must be satisfied for the Regulation to apply. Article 2 also contains exclusions (for example, certain activities outside the scope of Union law and purely personal or household activity), and practitioners should note that the UK GDPR and national implementing laws, such as the UK Data Protection Act 2018, apply their own material scope provisions that may diverge; readers should verify the precise excluded categories and any member state derogations against the current official text.

Why it matters

Material scope is the threshold question that determines whether the GDPR's obligations bite on a given activity at all. Before assessing legal bases, data subject rights, or transfer mechanisms, an organisation must establish that what it is doing amounts to processing of personal data within Article 2's reach. Getting this wrong in either direction is costly: treating in-scope processing as excluded can leave an organisation without the safeguards, records, and lawful basis the Regulation requires, while treating clearly out-of-scope activity as covered can waste compliance effort on matters the law does not reach.

Because material scope generally turns on whether processing is automated, or whether manual records form part of a structured filing system, it directs attention to the practical realities of how data is held rather than abstract labels. It also works in tandem with territorial scope under Article 3; both criteria must be satisfied for the Regulation to apply, so a material scope assessment on its own does not settle whether the GDPR governs a particular operation. Practitioners should treat the two as a paired analysis.

Material scope also matters because its exclusions and their boundaries are not uniform. Article 2 carves out certain activities, and the UK GDPR and national implementing laws such as the UK Data Protection Act 2018 apply their own material scope provisions that may diverge. Any conclusion about whether an activity falls inside or outside the law should be checked against the current official text and relevant national derogations rather than assumed from the EU Regulation alone.

Who it's relevant to

Data Protection Officers and compliance leads
DPOs and compliance teams rely on material scope as the entry point for any compliance assessment, using it to determine whether a processing activity engages GDPR obligations before mapping legal bases, records, and rights. They also need to track how exclusions and national implementing provisions may vary the analysis across jurisdictions.
Privacy and data protection lawyers
Lawyers advising on whether a client's activities fall within the Regulation must apply the Article 2 criteria alongside the Article 3 territorial test, and identify where exclusions such as purely personal or household activity may apply. They should note where the UK GDPR and national laws diverge and confirm the position against the current official text.
Engineers and systems architects
Because material scope generally turns on whether processing is automated and, for manual records, whether data forms part of a structured filing system, technical teams designing systems and data stores help determine which activities fall within the Regulation. How records are organised can affect whether manual processing is caught.
Records and information management professionals
Those responsible for manual and paper-based records are directly affected, since non-automated processing is typically within scope only where the data forms part of, or is intended to form part of, a filing system. Their filing structures can therefore influence whether a given set of records falls inside material scope.

Inside Material Scope

Processing of personal data
Material scope generally covers the processing of personal data, meaning information relating to an identified or identifiable natural person. Processing includes operations such as collection, storage, use, disclosure, and erasure, whether wholly or partly by automated means, and non-automated processing where the data forms part of, or is intended to form part of, a filing system.
Automated and structured manual processing
The scope typically extends to fully or partly automated processing and to manual processing of data held or intended to be held in a structured filing system. Unstructured manual records that do not form part of a filing system generally fall outside this scope, though national implementing law may vary the position.
Excluded activities
Certain activities are generally outside material scope, including processing that falls outside the scope of EU law, processing by a natural person in the course of a purely personal or household activity, and processing by competent authorities for law enforcement purposes that is instead governed by separate legislation. The precise boundaries of these exclusions can be subject to interpretation and guidance.
Personal data as the trigger
Material scope is engaged only where personal data is involved. Anonymous data that does not relate to an identifiable person generally falls outside scope, though whether data is truly anonymous rather than pseudonymous is a fact-specific assessment. Data of deceased persons and of legal entities is generally not covered, subject to member state derogations.

Common questions

Answers to the questions practitioners most commonly ask about Material Scope.

Does the GDPR apply to all data an organisation holds?
No. The GDPR's material scope covers the processing of personal data, meaning information relating to an identified or identifiable living individual. It does not apply to genuinely anonymous data, and it generally does not cover the data of deceased persons or of legal entities, though member state law may address some of these areas differently. Whether data falls within scope should be assessed case by case, particularly where pseudonymised or aggregated data may still permit identification.
Is the GDPR limited only to automated or computerised processing?
Not entirely. The material scope covers processing of personal data wholly or partly by automated means, and also non-automated processing of personal data that forms part of, or is intended to form part of, a filing system. Manual records held in a structured filing system can therefore fall within scope, so organisations should not assume that paper-based or non-digital handling is automatically excluded.
How should an organisation determine whether a given activity falls within the GDPR's material scope?
Start by asking whether the activity involves personal data as defined by the Regulation, and whether the processing is by automated means or forms part of a filing system. Then consider whether any of the recognised exclusions apply, such as purely personal or household activity. Because identifiability can be context-dependent, this assessment should be documented and revisited when data, technology, or purposes change.
What steps help confirm that data has been placed outside material scope through anonymisation?
Anonymisation must be genuine, meaning individuals can no longer be identified by any means reasonably likely to be used, taking account of available techniques and re-identification risk. Organisations typically assess and document the anonymisation method, the risk of singling out, linkability, and inference, and monitor whether advances in technology could later undermine it. Where the process only reduces but does not eliminate identifiability, the data is generally pseudonymised rather than anonymised and remains within scope. Regulator guidance in this area continues to evolve and should be checked against current sources.
How does the material scope interact with the territorial scope when deciding if the GDPR applies?
Material scope and territorial scope are separate tests that both need to be satisfied. Material scope asks whether the activity involves processing of personal data of the relevant kind; territorial scope asks whether that processing is connected to the EU in the ways the Regulation sets out. An organisation should confirm both before concluding that the GDPR governs a particular activity, and note that the UK GDPR and national implementing laws may apply their own equivalent tests.
What should teams record to demonstrate their material scope analysis for accountability purposes?
It is generally advisable to document the categories of data involved, the reasoning for treating data as personal, anonymous, or pseudonymised, the processing methods, and any exclusions relied upon. Retaining this analysis supports the accountability principle and helps demonstrate a considered position if questioned. Because scope determinations are context and risk dependent, records should be reviewed periodically and verified against the current official text and applicable guidance.

Common misconceptions

Material scope covers all data an organization holds.
Material scope generally applies only to personal data relating to identifiable living individuals. Anonymous data, and generally data about deceased persons or legal entities, falls outside it, subject to national law variations. Whether data qualifies as personal or anonymous requires a case-by-case assessment.
Only computerized or digital processing is within scope.
Material scope typically includes both automated processing and non-automated processing where the data forms part of, or is intended to form part of, a structured filing system. Paper records held in a structured filing system can therefore be in scope.
Material scope and territorial scope are the same test.
Material scope concerns what kind of processing and data are covered, while territorial scope concerns where and to whom the rules apply. Both must generally be satisfied for the Regulation to apply, and they are assessed separately.

Best practices

Assess at the outset whether the data you process is personal data, distinguishing genuinely anonymous data from pseudonymous data, and document the reasoning behind that determination.
Map both automated processing and any manual records held in structured filing systems, since both may fall within material scope.
Identify whether any recognized exclusions apply, such as purely personal or household activity or law enforcement processing under separate legislation, and record why an exclusion is or is not relied upon.
Analyze material scope separately from territorial scope, confirming both are engaged before concluding the Regulation applies.
Check relevant national implementing law and member state derogations, as the treatment of manual records, deceased persons, and other edge cases can vary.
Verify article references and any exclusion criteria against the current official text of the applicable Regulation, since boundaries may be refined by guidance and case law.