Territorial Scope
Territorial scope describes when the GDPR applies to an organisation's processing of personal data, based on where the organisation operates and whom it targets rather than solely where it is located. In general, the GDPR can apply to businesses established in the EU and, in certain cases, to businesses outside the EU that offer goods or services to, or monitor the behaviour of, individuals in the EU. Because this can extend the Regulation beyond EU borders, it is often described as having 'extra-territorial' effect.
Territorial scope is governed by Article 3 GDPR and determines the Regulation's applicability along two principal limbs. The 'establishment' limb (generally associated with Article 3(1)) applies to processing carried out in the context of the activities of an establishment of a controller or processor in the Union, regardless of whether the processing itself takes place in the Union. The 'targeting' limb (generally associated with Article 3(2)) extends application to controllers or processors not established in the Union where processing relates to the offering of goods or services to data subjects in the Union, or to the monitoring of their behaviour insofar as that behaviour takes place within the Union. The European Data Protection Board's Guidelines 3/2018 provide interpretive guidance on applying these limbs, including on the meaning of establishment, offering, and monitoring; practitioners should note that assessment is fact-specific, that a similar territorial-scope provision exists under the UK GDPR following the UK's post-Brexit framework, and that the precise wording and article references should be verified against the current official text.
Why it matters
Territorial scope determines whether the GDPR applies to an organisation at all, making it the threshold question in most compliance assessments. Because the Regulation can reach beyond EU borders, an organisation established outside the EU cannot assume it is exempt: where it offers goods or services to individuals in the EU, or monitors their behaviour within the EU, the GDPR may still apply. Misjudging this question can lead an organisation to overlook obligations it is in fact subject to, or conversely to apply the Regulation where it does not strictly govern.
The extra-territorial dimension is particularly significant for businesses with cross-border operations or online services that reach EU-based individuals. The European Data Protection Board's Guidelines 3/2018, adopted after public consultation in November 2019, were issued specifically to provide a common interpretation of Article 3 and to clarify how the establishment and targeting limbs operate. The existence of dedicated guidance reflects that these determinations are often not obvious and turn on fact-specific analysis of an organisation's activities and intentions toward individuals in the EU.
Scope questions have also become more complex following the UK's departure from the EU, since a similar territorial-scope provision exists under the UK GDPR. Organisations operating across EU and UK borders may therefore need to assess their position under both frameworks. Because the boundaries of establishment, offering, and monitoring are subject to interpretation and continuing guidance, practitioners should treat each assessment as context-dependent and verify their conclusions against the current official text and applicable regulator guidance.
Who it's relevant to
Inside Territorial Scope
Common questions
Answers to the questions practitioners most commonly ask about Territorial Scope.