# Territorial Scope (Article 3 GDPR)

When the GDPR applies territorially: the establishment criterion, the targeting criterion and the monitoring of behavior, flag and diplomatic mission scenarios, and the international effect of European data protection law.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/einzelthemen/anwendungsbereich-der-dsgvo/1.3.1.2-raeumlicher-anwendungsbereich
> Sprache: en



Article 3 GDPR determines which cross-border situations fall under European data protection law. While data processing is technically hardly bound by borders, law remains a territorial concept. The provision resolves this tension through two main connecting factors, the establishment criterion and the targeting criterion, and thus answers the second threshold question of data protection law alongside the [material scope](/docs/dsgvo-hub/einzelthemen/anwendungsbereich-der-dsgvo/1.3.1.1-sachlicher-anwendungsbereich).

<Callout type="info">
  **Key takeaways**

  * The GDPR applies where the processing is carried out in the context of the activities of an **establishment in the Union** (Article 3(1) GDPR), irrespective of where the processing itself takes place.
  * It also applies where a controller without an EU establishment directs its offering to persons in the Union or monitors their behavior (**targeting criterion**, Article 3(2) GDPR).
  * The nationality or Union citizenship of the data subject is **not** a connecting factor.
  * The concept of an establishment is broad: a stable arrangement with minimal but real activity is sufficient; the legal form and the state of incorporation are irrelevant.
  * What is decisive for the targeting criterion are the circumstances of the individual case (language, currency, delivery area), not the mere accessibility of a website.
</Callout>

## 1. Overview [#1-overview]

### 1.1 Function and connecting factors [#11-function-and-connecting-factors]

The function of Article 3 GDPR is to reconcile ubiquitous data processing with territorially bound law. The Regulation provides several connecting factors for this purpose. Two of them are central: the place of establishment (Article 3(1) GDPR) and the place of the market, that is, the targeting of the internal market or the monitoring of persons in the Union (Article 3(2) GDPR). In addition, there are special constellations for bodies outside the territory of the Union (Article 3(3) GDPR).

| Connecting factor                     | Provision            | Underlying idea                                                                                                  |
| ------------------------------------- | -------------------- | ---------------------------------------------------------------------------------------------------------------- |
| Establishment                         | Article 3(1) GDPR    | Country-of-establishment principle: processing in the context of the activities of an establishment in the Union |
| Offering of goods or services         | Article 3(2)(a) GDPR | The offering is directed at persons in the Union                                                                 |
| Monitoring of behavior                | Article 3(2)(b) GDPR | Monitoring of persons who are in the Union                                                                       |
| Flag and diplomatic mission scenarios | Article 3(3) GDPR    | Bodies outside the territory of the Union that are bound to Union law by virtue of public international law      |

### 1.2 No connection to Union citizenship [#12-no-connection-to-union-citizenship]

The nationality or Union citizenship of the data subject is not a connecting factor. What is protected is not the Union citizen as such, but the person who comes into contact with a body established in the Union or who is in the Union at the time goods and services are offered or their behavior is monitored.

## 2. Establishment criterion (Article 3(1) GDPR) [#2-establishment-criterion-article-31-gdpr]

### 2.1 The concept of an establishment [#21-the-concept-of-an-establishment]

The first connecting factor is the place of establishment of a controller or processor; this reflects the country-of-establishment principle that is widespread in Union law. What matters is not where the processing takes place technically, but whether it is carried out in the context of the activities of an establishment in the Union.

The concept of an establishment is not defined in law. What is required is a stable arrangement (Recital 22 GDPR). The concept is to be understood broadly: it covers any real and effective activity exercised through stable arrangements, even a minimal one; the legal form and whether the entity is a legal person are irrelevant ([CJEU, judgment of 1 October 2015, C-230/14, Weltimmo](/docs/dsgvo-hub/rechtsprechung/1.4.42-eugh-weltimmo)). What is decisive is the interplay of human and technical resources with a certain degree of stability, not registration in a public register.

It follows at the same time what does **not yet** in itself constitute an establishment: a server operated in the Union, a data center without human activity, a letterbox company, or the mere accessibility of a website within the territory of the Union. Conversely, depending on the nature of the activity, a single representative or employee may suffice if that person acts in the Member State with sufficient stability and with the resources necessary to provide the service. In those cases in which stable arrangements are lacking, applicability may nevertheless follow from the targeting criterion (Article 3(2) GDPR).

### 2.2 Effective and real exercise of activity [#22-effective-and-real-exercise-of-activity]

An establishment is a connecting factor only if effective and real exercise of activity takes place there (Recital 22 GDPR). The requirements are not high; even a small office is sufficient, and the extent or intensity of the activity is generally irrelevant. Nor does the activity have to be of an economic nature; establishments of associations, churches, and other non-profit bodies are equally covered.

The data processed in the context of the establishment do not have to be processed by the establishment itself, and the establishment does not have to be the controller under data protection law. It is sufficient that the data processing is connected with its activity. Thus, a marketing or sales company that is only indirectly involved in the processing is sufficient to trigger applicability if its activity and the actual data processing are inextricably linked in economic terms ([CJEU, judgment of 13 May 2014, C-131/12, Google Spain](/docs/dsgvo-hub/rechtsprechung/1.4.6-eugh-google-spain)). Under the GDPR, however, constellations of this kind can frequently already be resolved through the targeting criterion, which is the more closely fitting provision here.

### 2.3 Processors in third countries [#23-processors-in-third-countries]

Processors in third countries frequently do not fall within the scope of application via the establishment criterion if they have no establishment in the Union and typically do not offer their services to the data subjects. The protection gap that arises in this way is compensated by the fact that the primarily responsible controller remains within reach and has to answer for the rights of data subjects.

## 3. Targeting criterion (Article 3(2) GDPR) [#3-targeting-criterion-article-32-gdpr]

The targeting criterion extends the scope of application to controllers and processors without an establishment in the Union, provided that their activity is aimed at the internal market. It covers both classic distance selling situations and internet scenarios and is, for undertakings outside the Union, the practically most significant requirement of the Regulation. Whoever falls within the scope of application is in principle subject to the same set of obligations as a controller established in the Union.

### 3.1 Persons who are in the Union [#31-persons-who-are-in-the-union]

Both grounds under Article 3(2) presuppose that the data subject **is in the Union**. What matters is actual presence at the time of the first processing operation in question, not a permanent residence and not nationality. Even a merely temporary stay is sufficient; travelers entering from third countries or workers temporarily employed in the Union are therefore covered. Conversely, anyone who is outside the Union at the time of the offering or the monitoring does not fall within the scope of application, even if that person is a Union citizen.

### 3.2 Offering of goods or services [#32-offering-of-goods-or-services]

Covered is anyone who offers goods or services to persons in the Union, irrespective of whether payment is required (Article 3(2)(a) GDPR, Recital 23 GDPR). The terms are to be understood broadly and autonomously: they range from paid mail-order business through advertising-financed online services to the mere invitation to submit an offer; the actual conclusion of a contract is irrelevant.

What is decisive is whether the provider **manifestly envisages** offering goods or services to persons in the Union (Recital 23 GDPR). What is required, therefore, is a recognizable direction of the offering toward the internal market; the mere accessibility of a website, a language customary in the third country, or a mere contact address are not sufficient. Because the intention must be manifest, ambiguities do not operate to the detriment of the provider.

Factors that indicate targeting of the Union include in particular:

* the **currency** used (the euro or another currency of a Member State) together with the possibility of placing an order in a language customary there,
* in the case of physical goods, the **delivery area** (shipping to the Union as well) or a separate shipping cost arrangement for Member States,
* the **language** used, to the extent that it is not spoken to any significant degree outside the Union,
* the **express mention** of Member States or references to customers from the Union,
* a Member-State-specific **top-level domain** (such as `.de`, `.fr`, `.es`), an international dialing code, itineraries from Member States, or customer reviews from the Union,
* expenditure on a **search engine referencing service** intended to facilitate access by users from Member States.

Language calls for differentiation: English, Spanish, or French are not in themselves a compelling indication, because they are also widespread outside the Union. As regards German, it must be borne in mind that Switzerland and Liechtenstein, German-speaking states outside the internal market, may also be addressed, so that further factors have to be present. By contrast, a language that is customary exclusively in Member States (such as Swedish) generally does indicate targeting.

<Callout type="info">
  **Practical tip: disclaimers.** There is no obligation to declare that no offering is being made in the Union; a provider does not have to state expressly that it has no intention of serving that market. A clear notice (such as "no shipping to the EU" or "no overseas shipping") can nevertheless safeguard the inapplicability of the GDPR, provided that there are no other indications of targeting of the Union.
</Callout>

### 3.3 Monitoring of behavior [#33-monitoring-of-behavior]

The second ground is the monitoring of the behavior of persons who are in the Union, in so far as their behavior takes place within the Union (Article 3(2)(b) GDPR). This connecting factor takes account of the internet economy, in which users frequently pay for services not with money but with the disclosure of their data. It covers above all operations on the internet: the tracing of internet activities and their subsequent evaluation into a profile, that is, measures of **tracking** and **profiling** (Recital 24 GDPR). The monitoring must be designed to last for a certain period of time; a recognizably one-off, isolated act is not sufficient.

Typical areas of application are behavioral advertising, online tracking via cookies or fingerprinting, geolocation for marketing purposes, and profiling through social plugins ([EDPB, Guidelines 3/2018 on the territorial scope of the GDPR](https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-32018-territorial-scope-gdpr-article-3-version_en)). Not every collection of data relating to a person in the Union already amounts to monitoring; in the view of the European Data Protection Board, the processing must specifically be aimed at persons in the Union. A further and constant precondition is that the data processed relate to a person at all, that is, that they qualify as [personal data](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.1-personenbezogene-daten).

### 3.4 Practical example: cloud services [#34-practical-example-cloud-services]

In the case of cloud offerings by a provider established outside the Union, applicability depends on to whom the service is rendered.

* **Two-party relationship.** The provider renders its service directly to a natural person in the Union (for example a storage service for private users). Here the processing is related to the offering of a service; the provider is itself subject to the GDPR as a controller (Article 3(2)(a) GDPR).
* **Three-party relationship.** The provider processes the customer or employee data of an undertaking in the Union on that undertaking's behalf. Here it renders its service to the undertaking, not to the data subjects; the targeting criterion does not apply to the provider. The transfer of data to the provider does, however, fall under the GDPR at the level of the instructing undertaking (Article 3(1) GDPR), which has to bind the provider contractually and to comply with the requirements for [transfers to third countries](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.8-auftragsverarbeiter) (Articles 28 and 44 et seq. GDPR).

## 4. Flag and diplomatic mission scenarios (Article 3(3) GDPR) [#4-flag-and-diplomatic-mission-scenarios-article-33-gdpr]

While the establishment and targeting criteria attach to a link with the territory of the Union, Article 3(3) GDPR addresses the reverse situation, namely bodies outside the territory of the Union. The German language version is misleading in this respect: what matters is not that the processing takes place at the location concerned, but that the controller maintains an establishment at a place where Member State law applies by virtue of public international law. In the case of diplomatic and consular missions, which are regarded as extraterritorial under public international law, European data protection law applies in so far as those bodies are in any event subject to European law owing to the special status of external relations under public international law. The same applies, under the flag principle, to ships and aircraft flying the flag of a Member State that are outside the territory of the Union.

## 5. Geographical scope and international effect [#5-geographical-scope-and-international-effect]

### 5.1 EEA States [#51-eea-states]

As an internal market provision, the GDPR also applies in the EEA States of Norway, Iceland, and Liechtenstein. In data protection terms, they form part of the area in which the Regulation applies.

### 5.2 Conflicts between data protection regimes [#52-conflicts-between-data-protection-regimes]

Because the GDPR reaches beyond the territorial boundaries of the Union through the targeting criterion, it may come into contact with the data protection law of other states. At the substantive level, the Regulation leaves no room for unwritten conflict-of-laws rules or a choice of law, with the result that a conflict of norms may remain unresolved. In practice, this is mitigated by the fact that the enforcement of decisions is, as a starting point, limited to the respective national territory. A pragmatic solution is provided by the obligation of controllers established outside the Union to designate a representative in the Union (Article 27 GDPR), who serves as a point of contact.

### 5.3 International effect (Brussels effect) [#53-international-effect-brussels-effect]

Many legal systems and foreign providers follow European data protection law. This rests not only on the persuasive force of the concept, but also on the economic importance of the internal market: those seeking access to the European market frequently orient themselves toward the standards of the GDPR.

<Callout type="info">
  For practical purposes, the following control question is usually sufficient: is there an establishment in the Union in the context of whose activities the processing is carried out? If not, is the offering directed at persons in the Union, or is their behavior being monitored? If one of these questions is answered in the affirmative, the territorial scope of application is triggered.
</Callout>

<Cards>
  <Card title="Article 3 GDPR" href="https://dsgvo-gesetz.de/art-3-dsgvo/" description="Territorial scope in the wording of the Regulation." />

  <Card title="EDPB Guidelines 3/2018" href="https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-32018-territorial-scope-gdpr-article-3-version_en" description="Benchmarks for the establishment and targeting criteria as well as for monitoring (targeting)." />

  <Card title="CJEU, Weltimmo (C-230/14)" href="/docs/dsgvo-hub/rechtsprechung/1.4.42-eugh-weltimmo" description="Broad concept of establishment; minimal but real activity is sufficient." />

  <Card title="Material scope" href="/docs/dsgvo-hub/einzelthemen/anwendungsbereich-der-dsgvo/1.3.1.1-sachlicher-anwendungsbereich" description="The first threshold question: Article 2 GDPR." />
</Cards>


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.