Art. 3 GDPR – Territorial scope
- This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.
- This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:
- the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or
- the monitoring of their behaviour as far as their behaviour takes place within the Union.
- This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.
Related Recitals
(22) Processing by an Establishment
(23) Applicable to Controllers/Processors Not Established in the Union if Data Subjects Within the Union are Targeted
(24) Applicable to Controllers/Processors Not Established in the Union if Data Subjects Within the Union are Profiled
(25) Applicable to Controllers Due to International Law
Frequently Asked Questions about Article 3
+ Who does the GDPR apply to?
The GDPR applies to organisations established in the EU that process personal data, and to organisations outside the EU that offer goods or services to people in the EU or monitor their behaviour.
+ Does the GDPR apply to companies outside the EU?
Yes. Under Article 3, a non-EU company is covered if it targets individuals in the EU with goods or services, or monitors the behaviour of people located in the EU, regardless of where the company is based.
+ What is the extraterritorial scope of the GDPR?
Extraterritorial scope means the GDPR can apply beyond EU borders. If a business outside the EU processes the personal data of people in the EU in connection with offering goods, services, or behaviour monitoring, it must comply.