Scope of Application of the GDPR (Articles 2 and 3 GDPR)
Overview of the material and the territorial scope of the GDPR: when European data protection law applies at all, and which processing operations and which situations it covers.
Before an individual processing operation is measured against the standard of the GDPR, the preliminary question has to be answered whether the Regulation applies at all. This is decided on two levels: the material scope (Article 2 GDPR) determines which forms of processing are covered and which activities are excluded. The territorial scope (Article 3 GDPR) determines which cross-border situations fall under European data protection law. Both must be established for the obligations of the GDPR to take effect.
Key takeaways
- The GDPR applies only where both the material scope (Article 2 GDPR) and the territorial scope (Article 3 GDPR) are established.
- As a matter of material scope, processing wholly or partly by automated means as well as non-automated processing based on a filing system are covered; excluded are, among other things, national security, criminal law enforcement under the Law Enforcement Directive (Directive (EU) 2016/680), and the household exemption.
- In territorial terms, the Regulation connects to an establishment in the Union (Article 3(1) GDPR) and to the targeting criterion (Article 3(2) GDPR), not to the nationality of the data subject.
- The examination of the scope of application precedes the question of the legal basis (Article 6 GDPR) and of the principles (Article 5 GDPR).
1 The two levels of the scope of application
The material scope and the territorial scope answer different questions. The material scope asks what kind of handling of data the GDPR governs and which areas of life it deliberately leaves out. The territorial scope asks which bodies and which cross-border scenarios are bound by the European requirements. Only once both are established do the legal basis and the principles relating to processing become relevant.
Material Scope
Article 2 GDPR: automated and filing-system-based processing, exclusions from the material scope, the household exemption, the public and the non-public sector.
Territorial Scope
Article 3 GDPR: the establishment criterion, the targeting criterion, monitoring of behavior, flag and diplomatic mission scenarios.
2 Place within the assessment
The scope of application is the first fork in any data protection assessment. As long as it is not established, the question of a legal basis or of the principles relating to processing does not arise. Whether personal data are involved at all is determined by the concept of personal data; whether there is processing is determined by the concept of processing. These statutory criteria are logically prior to the scope of application and are dealt with in more depth there.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
Individual Topics
Individual topics of the GDPR, organized by regulatory area.
Material Scope (Article 2 GDPR)
When the GDPR applies as a matter of material scope: automated and filing-system-based processing, exclusions such as national security, criminal law enforcement and the household exemption, as well as sector-specific special rules.