Skip to main content
Category: Scope & Exemptions

Territorial Scope

Also known as: Extra-territorial scope, Scope of application (Article 3)
Simply put

Territorial scope describes when the GDPR applies to an organisation's processing of personal data, based on where the organisation operates and whom it targets rather than solely where it is located. In general, the GDPR can apply to businesses established in the EU and, in certain cases, to businesses outside the EU that offer goods or services to, or monitor the behaviour of, individuals in the EU. Because this can extend the Regulation beyond EU borders, it is often described as having 'extra-territorial' effect.

Formal definition

Territorial scope is governed by Article 3 GDPR and determines the Regulation's applicability along two principal limbs. The 'establishment' limb (generally associated with Article 3(1)) applies to processing carried out in the context of the activities of an establishment of a controller or processor in the Union, regardless of whether the processing itself takes place in the Union. The 'targeting' limb (generally associated with Article 3(2)) extends application to controllers or processors not established in the Union where processing relates to the offering of goods or services to data subjects in the Union, or to the monitoring of their behaviour insofar as that behaviour takes place within the Union. The European Data Protection Board's Guidelines 3/2018 provide interpretive guidance on applying these limbs, including on the meaning of establishment, offering, and monitoring; practitioners should note that assessment is fact-specific, that a similar territorial-scope provision exists under the UK GDPR following the UK's post-Brexit framework, and that the precise wording and article references should be verified against the current official text.

Why it matters

Territorial scope determines whether the GDPR applies to an organisation at all, making it the threshold question in most compliance assessments. Because the Regulation can reach beyond EU borders, an organisation established outside the EU cannot assume it is exempt: where it offers goods or services to individuals in the EU, or monitors their behaviour within the EU, the GDPR may still apply. Misjudging this question can lead an organisation to overlook obligations it is in fact subject to, or conversely to apply the Regulation where it does not strictly govern.

The extra-territorial dimension is particularly significant for businesses with cross-border operations or online services that reach EU-based individuals. The European Data Protection Board's Guidelines 3/2018, adopted after public consultation in November 2019, were issued specifically to provide a common interpretation of Article 3 and to clarify how the establishment and targeting limbs operate. The existence of dedicated guidance reflects that these determinations are often not obvious and turn on fact-specific analysis of an organisation's activities and intentions toward individuals in the EU.

Scope questions have also become more complex following the UK's departure from the EU, since a similar territorial-scope provision exists under the UK GDPR. Organisations operating across EU and UK borders may therefore need to assess their position under both frameworks. Because the boundaries of establishment, offering, and monitoring are subject to interpretation and continuing guidance, practitioners should treat each assessment as context-dependent and verify their conclusions against the current official text and applicable regulator guidance.

Who it's relevant to

Non-EU businesses serving EU individuals
Organisations established outside the EU that offer goods or services to, or monitor the behaviour of, individuals in the EU may fall within the GDPR's targeting limb even without an EU establishment. Such businesses should assess their activities against Article 3(2) and the EDPB's Guidelines 3/2018 rather than assuming their location places them outside scope.
Cross-border and UK-EU operators
Businesses operating across EU and UK borders may need to assess their position under both the EU GDPR and the UK GDPR, which contains a similar territorial-scope provision following the UK's post-Brexit framework. These organisations should treat the two regimes as potentially distinct and verify obligations under each.
Data protection officers and compliance leads
Those responsible for compliance programs typically treat territorial scope as the threshold question when mapping an organisation's obligations. They benefit from documenting a fact-specific analysis under Article 3, informed by the EDPB guidance, and revisiting it as activities, guidance, and interpretations evolve.
Privacy counsel and legal advisers
Lawyers advising on GDPR applicability must distinguish the establishment and targeting limbs and apply them to specific facts. Because the meaning of establishment, offering, and monitoring is subject to interpretation, counsel should ground advice in current official text and EDPB guidance rather than presenting any single interpretation as settled.

Inside Territorial Scope

Establishment criterion
The GDPR generally applies to the processing of personal data carried out in the context of the activities of an establishment of a controller or processor in the EU, regardless of whether the processing itself takes place within the EU. Case law and guidance indicate that 'establishment' is interpreted broadly and does not depend on legal form, but this is subject to assessment of the specific arrangements.
Targeting criterion (offering goods or services)
The Regulation can apply to controllers or processors not established in the EU where processing relates to the offering of goods or services to data subjects in the EU, whether or not payment is required. Whether an organisation is 'targeting' EU individuals typically depends on factors indicating an intention to offer services to them, rather than mere accessibility of a website.
Monitoring criterion
The Regulation can also apply to non-EU controllers or processors where processing relates to monitoring the behaviour of data subjects insofar as their behaviour takes place within the EU. This is subject to assessment of the nature of the monitoring activity.
Location of the data subject
For the targeting and monitoring criteria, the relevant factor is generally the location of the individuals in the EU rather than their nationality or residence. The precise application depends on the circumstances at the time of the relevant processing.
Representative requirement for non-EU organisations
Where an organisation falls within scope through the targeting or monitoring criteria without an EU establishment, it may be required to designate a representative in the EU, subject to available exemptions. Practitioners should verify the specific conditions against the current official text.
Relationship to UK GDPR and national law
Following divergence, the UK GDPR applies its own territorial scope provisions, which broadly mirror the EU position but operate by reference to the UK. Member state implementing laws and derogations may also affect how scope operates in practice, so the EU and UK positions should be assessed separately.

Common questions

Answers to the questions practitioners most commonly ask about Territorial Scope.

Does an organisation have to be established in the EU for the GDPR to apply to it?
No. Establishment in the EU is one trigger for territorial scope, but it is not the only one. Under the targeting criterion, an organisation without any EU establishment can still fall within scope where it offers goods or services to individuals in the EU or monitors their behaviour as it takes place within the EU. The location of the organisation is therefore not by itself decisive; the focus is on where the establishment is and on whether the processing activities relate to individuals in the EU in the ways described. You should assess your specific processing against both the establishment and targeting limbs, and note that regulatory guidance in this area has developed over time and should be verified against the current official text and guidance.
Does the mere fact that a website is accessible from the EU mean the GDPR automatically applies?
Not on its own. Accessibility of a website from the EU is generally not treated as sufficient by itself to establish that goods or services are being offered to individuals in the EU. Guidance has indicated that additional factors pointing to an intention to target individuals in the EU are typically relevant to the assessment. This is a fact-sensitive question that depends on the surrounding circumstances rather than accessibility alone, so it should be evaluated case by case and checked against current regulatory guidance, which continues to evolve.
How should an organisation determine whether it falls within the establishment criterion?
The assessment generally focuses on whether there is an establishment in the EU and whether the processing is carried out in the context of the activities of that establishment, rather than on where the processing itself physically occurs. This typically involves examining the nature and stability of the organisation's arrangements in the EU and the connection between those arrangements and the relevant processing. Because this can be nuanced, particularly for group structures and remote arrangements, it should be documented as part of a scope analysis and assessed against the specific facts.
What practical steps can an organisation take to evaluate the targeting criterion for its services?
In most cases this involves reviewing whether the offering of goods or services is directed at individuals in the EU and whether any behaviour of individuals in the EU is being monitored as it takes place within the EU. Organisations typically examine indicators relevant to these questions, document the reasoning, and revisit the analysis when the nature of their offering or their user base changes. Given that this is a fact-sensitive determination, the analysis should be kept under review rather than treated as a one-off exercise, and it should be checked against current guidance.
If the GDPR applies under the targeting criterion but the organisation has no EU establishment, what obligations may follow?
Where the GDPR applies on the basis of targeting and the organisation is not established in the EU, the Regulation contemplates the designation of a representative in the EU in certain circumstances, subject to the exceptions provided in the relevant provision. The applicable obligations, and any exceptions, should be assessed against the specific facts and verified against the current official text, as the precise conditions and exemptions are set out in the Regulation and associated guidance.
How does an organisation address the interaction between the EU GDPR and the UK GDPR when its activities span both?
Activities may fall within the scope of the EU GDPR, the UK GDPR, or both, depending on where establishments are located and where individuals being targeted or monitored are situated. Because these regimes have separate territorial scope provisions, an organisation operating across both should assess each regime separately rather than assuming a single analysis covers both. National implementing law and divergence between the regimes can affect the position, so the analysis should be documented and kept under review against the current applicable texts and guidance.

Common misconceptions

The GDPR only applies to organisations physically located in the EU.
The Regulation can apply to organisations with no EU establishment where they offer goods or services to, or monitor the behaviour of, individuals in the EU. Scope is not determined solely by physical presence and depends on assessment of the relevant criteria.
Simply having a website that EU users can access brings an organisation within scope.
Mere accessibility of a website is generally not sufficient. The targeting criterion typically requires factors indicating an intention to offer goods or services to individuals in the EU, which is a fact-specific assessment.
The territorial scope of the EU GDPR and the UK GDPR are identical.
The two regimes are closely aligned but operate separately, with the UK GDPR applying by reference to the UK. Organisations may fall within one, both, or neither, and each position should be assessed independently.

Best practices

Map processing activities against the establishment, targeting, and monitoring criteria separately, documenting the assessment and its reasoning to support accountability.
Assess targeting on a fact-specific basis using indicators of an intention to offer goods or services to individuals in the EU, rather than relying on website accessibility alone.
Where an organisation falls within scope without an EU establishment, evaluate whether an EU representative must be designated and verify the applicable conditions and exemptions against the current official text.
Conduct the EU GDPR and UK GDPR scope analyses independently, and consider whether member state implementing laws or derogations affect the position.
Re-review territorial scope conclusions when business activities, target markets, or monitoring practices change, since scope is assessed by reference to actual processing.
Confirm article references, representative obligations, and any exemptions against the current authoritative text and regulator guidance before relying on them in a compliance program.