Does GDPR Apply Outside the EU? The Article 3 Test
Does GDPR apply outside the EU? Test EU establishment, targeted offers and monitoring, then decide whether an Article 27 representative is required.

Does GDPR apply outside the EU? Yes, it can. The answer does not follow from a company's mailing address, the location of its servers or the fact that someone in Europe can open its website. Article 3 instead connects scope to defined processing and three factual routes: an EU establishment, a targeted offer, or monitoring in the EU 1,2.
Quick Answer: The answer to “does GDPR apply outside the EU?” is yes for defined processing, not because a firm is foreign. Test an EU establishment link, an intended offer to people in the EU, and monitoring there. Accessibility alone is not targeting, so many US-only businesses are outside Article 3 on those facts 1,2.
Last updated: 26 August 2026
Start with the processing, not headquarters
Treat scope as a conclusion about processing, not a badge placed on the whole company. First name the personal data, the people concerned, the purpose and the operational activity. Then identify which business unit controls or performs it. Article 3 can cover customer profiling without automatically settling a separate payroll or supplier process.
A non-EU headquarters can therefore conduct processing that falls within GDPR. The reverse is equally important. One EU customer, one traveller or one page view from Europe does not pull every system into scope. The conclusion needs an Article 3 connection supported by evidence, not a guess based on the internet's reach 1,2.
For Article 3(2), location concerns the person when the relevant offer or monitored behaviour occurs. Nationality and residence do not replace that question. A US citizen in France may be in the Union for the relevant event, while an EU citizen in California may not be. Incidental presence, however, still does not prove that a US-only service intended to target the EU 2,3.
Begin the record with one sentence: “We are assessing the processing of [data] about [people] for [purpose] through [activity].” That boundary prevents a strong fact in one business line from silently becoming a company-wide answer.
The three Article 3 routes
For most commercial organisations, three routes resolve the question. Establishment comes first because Article 3(1) has its own contextual test. If that route does not apply, an organisation not established in the Union tests the offering and monitoring routes in Article 3(2).
| Route | Question | Yes branch | No branch |
|---|---|---|---|
| Establishment | Is processing in the context of an EU establishment's activities? | Article 3(1) applies, even if processing occurs elsewhere | Continue to the Article 3(2) routes |
| Offering | Does processing relate to an intended offer to people in the EU? | Article 3(2)(a) applies; payment is irrelevant | Test monitoring |
| Monitoring | Does processing relate to monitoring behaviour occurring in the EU? | Article 3(2)(b) applies | Outside Article 3 on these routes |
Each branch belongs to the processing under review. A yes answer needs the factual link shown in its row; a no answer should record the evidence that rules the route out, including facts that might later change 1,2. Article 3(3) separately covers the narrow case where public international law makes Member-State law applicable to a controller not established in the Union.
The flow begins with defined processing and asks whether an EU establishment has the required contextual link; a yes means GDPR applies under Article 3(1) 1,2. Without that link, an intended offer to people in the EU can engage Article 3(2)(a), but accessibility alone passes to the monitoring question. Monitoring asks whether the processing observes behaviour taking place in the EU, and a yes then leads to the Article 27 test 3. If neither the offer nor monitoring route applies, the defined processing is outside Article 3 on those facts.
An EU establishment can reach overseas processing
Article 3(1) asks whether processing occurs in the context of the activities of a controller's or processor's establishment in the Union. It expressly does not require the processing itself to happen there. A US headquarters therefore cannot end the analysis merely by locating its databases, staff or vendors in the United States 1.
“Establishment” is not limited to a subsidiary or formally registered branch. The question is whether there is a real and effective activity exercised through stable arrangements. After identifying such an EU presence, examine the relationship between its activities and the processing. Group ownership alone is too broad, and physical server location is too narrow 2,3.
Consider a US software group with a small EU sales and support operation. Its EU staff promote subscriptions, help customers adopt the service and pass account information to the US platform team. Processing those account and support data may occur in the context of the establishment's activities, although the platform and database operate in the United States. The operational relationship supports the answer; the group chart alone does not 1,2.
Now change one fact pattern. A separate EU affiliate sells an unrelated product, shares no customers and performs no work supporting the assessed US service. Its existence does not by itself establish the required context for that service's processing. Record the functions, revenue relationship, customer journey and data flows that support either answer.
Offering uses a targeting test
For a controller or processor not established in the Union, Article 3(2)(a) can apply when processing relates to offering goods or services to data subjects in the Union. Charging money is not required. A free trial, free platform or unpaid service can still be an offer if the objective evidence shows an intention to address people there 1.
Intention to target is the centre of the offering analysis, and objective facts reveal that intention. Signals may include naming the Union or a Member State, advertising directed there, EU delivery, EU contact routes, references to EU customers, and a language or currency beyond what is ordinary in the trader's country. Travel directions from the EU or an EU-focused domain may contribute too 2,3.
One signal cannot mechanically decide the result. English is used in many countries. Euros can appear for administrative reasons, and a testimonial may remain online after the underlying strategy changes. By contrast, euro pricing combined with EU shipping, EU campaigns and European customer references can make the intended audience plain. The decision should weigh the signals together and explain how the processing relates to the offer.
| Evidence | What it may indicate | What to verify |
|---|---|---|
| EU delivery and euro pricing | An offer designed for people in the EU | Eligible destinations, checkout rules and campaign dates |
| EU-directed advertising | Deliberate market activity | Audience settings, creative, spend and landing pages |
| EU customer references | An intention to attract similar customers | Context, date and whether the references remain purposeful |
| General English website | Ordinary global accessibility | Whether stronger targeting signals exist elsewhere |
A US exporter provides a clear yes branch when it launches euro pricing, ships to EU addresses, buys EU-directed campaigns and publishes EU customer references. Processing orders and customer accounts related to that offer can fall within Article 3(2)(a) 1,2. The same company may still need a separate assessment for processing unrelated US supplier contacts.
Accessibility is not targeting
A website that people in Europe can open is not, for that reason alone, an offer directed to people in the EU. An email address, ordinary contact details or a broadly available English page are also insufficient by themselves. The guidelines distinguish global technical reach from an apparent intention to serve an EU market 2,3.
That distinction gives many small US businesses a genuine no branch. Imagine a SaaS provider with US-dollar pricing, US campaigns, US onboarding and support, no EU delivery promise, no EU customer references and no relevant EU establishment. A traveller in Spain opens the site and sends an unsolicited enquiry. The visit and message do not establish EU targeting. If the provider also does not monitor behaviour in the EU, the assessed processing ordinarily falls outside Article 3 2,3.
The answer should not be hardened into “we block Europe” or “we have never had an EU visitor”. Neither statement is the legal test. Preserve evidence of the intended market: product terms, available destinations, campaign settings, pricing, sales instructions and support scope. Reassess when those facts change.
An incidental EU presence by an existing US customer is similar. If the service remains designed and promoted only for the US, the customer's short trip does not automatically transform it into an EU-directed offer. The person's location can matter under Article 3(2), but location alone does not supply the missing intention to target 2,3.
Monitoring behaviour is a separate route
Article 3(2)(b) covers processing related to monitoring the behaviour of data subjects as far as that behaviour takes place within the Union 1. It does not use the intention-to-offer test. A business may avoid EU sales entirely yet still enter scope through an observation or profiling activity focused on behaviour in the EU.
Monitoring implies a purpose to collect and later reuse relevant behavioural data. Not every technical event, cookie or analytics report qualifies automatically. The assessment should identify what the organisation intends to observe, whether it tracks people over time, which inferences or profiles it produces, and what happens to the resulting information 2,3.
Behavioural advertising, geolocation, cookies or fingerprinting and personalised analytics can be relevant examples. CCTV and market surveys can also matter. These labels are starting points, not conclusions: a tool called “analytics” does not prove monitoring, while a system described as “security telemetry” should not be accepted without examining its purpose and reuse.
Suppose a non-EU analytics operator deliberately profiles browsing sequences of people while they are in the EU, groups them by inferred interests and uses the profiles to personalise advertising. The monitored behaviour occurs in the Union and the processing is built around its later reuse. Article 3(2)(b) can apply even if the operator sells no service to those people 1,2.
For the no branch, consider a service receiving a single operational event solely to complete a requested transaction, without a purpose to observe behaviour or reuse it for a behavioural profile. The absence of monitoring cannot be assumed from a short retention period or a product label, but the actual purpose and activity may support a conclusion that this route is not engaged 2,3.
Work the borderline cases
Borderline decisions improve when the team separates facts that answer different branches. Use a small matrix rather than a general impression.
| Scenario | Establishment | Offer | Monitoring | Working result |
|---|---|---|---|---|
| US-only accessible SaaS site | No relevant EU link | No objective EU targeting | No monitoring in the EU | Outside Article 3 on those facts |
| US exporter enters Europe | No EU establishment | Euro pricing, delivery and campaigns | Not needed for the offer result | Article 3(2)(a) applies to related processing |
| Non-EU behavioural profiler | No EU establishment | No offer to the observed people | Purposeful profiling in the EU | Article 3(2)(b) applies to related processing |
| US group with EU support unit | Relevant EU operational link | Separate question | Separate question | Article 3(1) can apply to linked processing |
The matrix sorts evidence; it does not turn indicators into rules. A page view from Paris belongs in the location record but does not prove an offer. Euro pricing informs targeting but says nothing by itself about monitoring. An EU subsidiary belongs in the establishment analysis, yet it cannot settle whether every headquarters system operates in the context of that establishment.
When evidence points both ways, state the open fact rather than averaging it away. For example, a US business may say it targets only US customers while its checkout accepts EU delivery and its campaigns name European markets. Resolve the actual destinations, campaign audiences and dates before reaching a conclusion.
Test the Article 27 representative duty
Article 27 follows a positive Article 3(2) result; it is not a fourth territorial-scope route. Test it when the controller or processor is not established in the Union and the relevant processing falls under Article 3(2). Processing covered through Article 3(1) does not enter this sequence, and appointing a representative does not create an EU establishment 2,3.
The exception is cumulative and fact-specific. Processing must be occasional, must not include large-scale processing of Article 9 special-category data or Article 10 criminal-conviction and offence data, and must be unlikely to result in a risk to people's rights and freedoms. A business must satisfy every part; this is not a general small-business exemption. Public authorities and bodies are separately exempt 2,3.
Where a representative is required, the controller or processor designates one in writing in a Member State where relevant people are located. The representative serves as a contact point, but the organisation retains its own duties and responsibility. Keep the territorial-scope conclusion and representative analysis as separate records 2,3.
A non-EU advertiser whose continuing behavioural profiling in the EU engages Article 3(2)(b) should therefore test Article 27. A non-EU trader making only rare, low-risk offers may examine the cumulative exception, but “small” or “occasional” alone cannot decide it. Document frequency, data categories, scale and risk rather than choosing the exception by instinct.
Record the decision and its triggers
A useful conclusion says more than “GDPR applies” or “GDPR does not apply”. It identifies the processing, the people and relevant location, the evidence, every Article 3 route tested, unresolved facts and the review date. That record lets a later reviewer reproduce the answer instead of inheriting an unexplained label.
For an establishment conclusion, record the stable EU arrangement and why the processing occurs in the context of its activities. For an offer conclusion, retain the targeting signals and explain how the processing relates to the offer. For monitoring, describe the observation or profiling purpose, the behaviour in the EU and the later reuse. A no conclusion should be equally concrete.
Useful review triggers include opening an EU office, changing delivery destinations, adding euro pricing, launching EU campaigns, publishing EU customer references, or introducing profiling of behaviour in the EU. Also revisit Article 27 when the frequency, scale, data categories or risk of Article 3(2) processing changes.
The final record should avoid labelling the organisation forever. It should say, for example, that order processing for the defined EU-facing offer falls within Article 3(2)(a), while a separately defined US supplier process has no identified Article 3 route on the evidence reviewed. That precision makes later review possible.
Frequently asked questions
Does GDPR apply to US companies?
Yes, for particular processing activities. A US company may be within Article 3 because processing is connected to an EU establishment, relates to an intended offer to people in the EU, or monitors their behaviour there. A genuinely US-only operation without those links is ordinarily outside Article 3 on those facts 1,2.
Does an EU-accessible website trigger GDPR?
No, not by accessibility alone. An ordinary website, email address or contact details do not by themselves show an intention to offer goods or services to people in the EU. Objective signals such as EU-directed campaigns, delivery, currency or customer references may establish targeting when considered together 2,3.
Does GDPR apply if we only target US customers?
Usually not under Article 3 if the business has no relevant EU establishment, genuinely directs its offer only to US customers, and does not monitor behaviour in the EU. An unsolicited visit or enquiry from someone temporarily in the EU does not automatically change that conclusion, although the evidence should be checked 2,3.
What shows an intention to target people in the EU?
Look for objective signals in combination, including EU-directed advertising, euro pricing, EU delivery, EU customer references, local contact routes, or a language not ordinarily used in the trader's country. No single signal is automatically decisive, and ordinary worldwide website accessibility is not enough on its own 2,3.
Does analytics count as monitoring under Article 3?
Sometimes. Monitoring implies a purpose for collecting and later reusing behavioural data about people while they are in the EU. Personalised analytics, behavioural advertising, geolocation, cookies or fingerprinting can be relevant examples, but the tool's name alone does not decide the issue and not every online analysis qualifies 1,2,3.
When does a non-EU firm need an EU representative?
Test Article 27 when a controller or processor without an EU establishment is in scope under Article 3(2). The exception is cumulative: processing must be occasional, exclude large-scale Article 9 or Article 10 processing, and be unlikely to risk people's rights and freedoms. Public authorities and bodies are separately exempt 1,2,3.
Frequently Asked Questions
Does GDPR apply to US companies?
Does an EU-accessible website trigger GDPR?
Does GDPR apply if we only target US customers?
What shows an intention to target people in the EU?
Does analytics count as monitoring under Article 3?
When does a non-EU firm need an EU representative?
Sources
Want this run on your business?
AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.
You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.