Live Founding Cohort open, limited seats remaining Back to main site →

Article 3 territorial scope: does GDPR actually reach your entity?

Article 3 has two limbs. Establishment (Art 3(1)) and targeting or monitoring (Art 3(2)). This lesson walks both, with worked Indian-industry examples so you can decide correctly whether GDPR reaches your entity today.

Free preview 12 min read Verified
Legal basis
GDPR primary-source stack current to 10 August 2026. Core: Regulation (EU) 2016/679 (GDPR), in force 25 May 2018. EDPB Guidelines: 3/2018 (territorial scope, endorsed 12 November 2019), 05/2020 (consent, adopted 4 May 2020 v1.1), 07/2020 (controller/processor, adopted 7 July 2021 v2.1), 9/2022 (breach notification, v2.0 adopted 28 March 2023), 1/2024 (legitimate interests, adopted 8 October 2024), draft 02/2026 (Anonymisation, published for consultation 7 July 2026), 02/2025 v2.0 (Blockchain, adopted 7 July 2026). Cross-border: Commission Implementing Decision (EU) 2021/914 SCCs (4 June 2021); EU-US Data Privacy Framework Adequacy Decision C(2023) 4745 final (10 July 2023, Latombe C-703/25 P appeal pending at CJEU); adequacy list including Brazil mutual (Implementing Decision 2026/179, 26 January 2026), UK renewal (19 December 2025 with sunset 27 December 2031). Adjacent EU: Digital Services Act (Regulation 2022/2065), Digital Markets Act (Regulation 2022/1925), Data Governance Act (Regulation 2022/868), Data Act (Regulation 2023/2854), AI Act (Regulation 2024/1689) as amended by Regulation (EU) 2026/1744 Digital Omnibus on AI (OJ 24 July 2026, in force 27 July 2026, postponing high-risk AI to 2 December 2027 and 2 August 2028), NIS2 Directive (Directive 2022/2555). Landmark CJEU: Schrems II (C-311/18, 16 Jul 2020), Meta v Bundeskartellamt (C-252/21, 4 Jul 2023), IAB Europe (C-604/22, 7 Mar 2024), Lindenapotheke (C-21/23, 4 Oct 2024). India crosswalk: DPDP Act 2023 (No. 22 of 2023, assented 11 Aug 2023), DPDP Rules 2025 (notified 13 Nov 2025, operative Rules commencement expected 13 May 2027), RBI Payment Data Storage Direction (DPSS.CO.OD.No.2785 dated 6 Apr 2018), CERT-In Directions (No. 20(3)/2022-CERT-In dated 28 Apr 2022).

Every GDPR analysis starts with Article 3. If Article 3 does not reach your entity, GDPR does not apply. If it does, everything else follows. Getting Article 3 wrong is the most common failure mode of a first-time GDPR reader.

The two limbs

Article 3 has two limbs [L2-C1].

  1. Establishment (Article 3(1)). GDPR applies to the processing of personal data in the context of the activities of an establishment of a controller or processor in the Union, regardless of whether the processing takes place in the Union or not.
  2. Targeting or monitoring (Article 3(2)). GDPR applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to (a) the offering of goods or services, irrespective of whether payment is required, to such data subjects in the Union; or (b) the monitoring of their behaviour as far as their behaviour takes place within the Union.

EDPB Guidelines 3/2018 [L2-C2] is the operational reading. Both limbs are interpreted broadly.

Limb 1: establishment

Weltimmo (CJEU C-230/14) tells us "establishment" is a low bar. A single representative, a bank account, a domain in a Member-State language directed at Member-State users — any of these can qualify given a stable arrangement.

For an Indian company the practical question is: do you have any presence in the EU (branch, subsidiary, sales office, sales rep, even a single locally-employed person acting on your behalf) plus a stable arrangement? If yes, and the processing you do is "in the context of the activities" of that presence, Article 3(1) reaches you and every processing operation of yours can be caught by GDPR, wherever the servers sit.

Common Indian scenario: EU subsidiary of an Indian IT services firm

TCS, Infosys, Wipro, HCL and Tech Mahindra all operate EU subsidiaries. Those subsidiaries are establishments in the Union. Processing conducted by the Indian parent that is in the context of the activities of the EU subsidiary (say, HR processing of the subsidiary\'s employees, or delivery of a service the subsidiary sold to an EU customer) is caught by Article 3(1). This is why the Indian IT services biggies uniformly treat themselves as GDPR-in-scope for their EU-facing lines of business.

Limb 2: targeting or monitoring

Limb 2 catches non-EU controllers and processors that offer goods or services to EU data subjects, or that monitor their behaviour within the Union. Recital 23 sets the factors for offering: use of a Member-State language, a Member-State currency, provision of shipping to a Member-State address, marketing to Member-State users, a Member-State-specific top-level domain, or explicit mention of EU users on the website. Recital 24 sets the factors for monitoring: tracking on the internet with subsequent profiling, in particular for consumer-behaviour analysis, ad targeting, or fraud prevention involving EU users.

Common Indian scenario: SaaS with EU customers

Your Bengaluru SaaS company signs up an EU-based customer. That customer\'s employees log in and their personal data (names, emails, IPs, activity logs) is processed by you. Are you caught by Article 3(2)? Almost always yes, because you are offering a service to data subjects in the Union. Consequence: Article 27 EU Representative appointment obligation (unless the Art 27 exception applies), Chapter V transfer analysis for the data you move between your Indian servers and any subprocessors, and full Chapter III data-subject-rights obligations.

Common Indian scenario: BPO handling EU customer accounts on behalf of an EU controller

You are a processor for an EU controller who is offering goods to EU consumers. The EU controller is directly in scope of Article 3(1). You (the Indian BPO processor) are caught by Article 3(2) because you are processing personal data of EU data subjects on behalf of the controller. Article 28 processor obligations apply directly to you. Article 33(2) breach-notification-to-controller obligation applies. Chapter V transfer obligations for onward transfers you make from your Indian servers to any further sub-processor.

Common Indian scenario: adtech monitoring EU users

You run an Indian ad-network SDK that gets embedded in mobile apps used by EU users. Every impression and click is tracked to a profile you build for retargeting. Article 3(2)(b) is squarely on you: monitoring of behaviour of EU data subjects within the Union. IAB Europe (C-604/22) [L2-C3] tells us pseudonymous identifiers (like your TCF Consent String or your device advertising ID) are personal data when re-identification is reasonably likely. Consequence: full GDPR obligations plus adtech-specific consent architecture.

The two-question test for an Indian entity

Sit with the Chief Compliance Officer of your organisation and answer these two questions on the record:

  1. Do we have any presence in the EU (branch, subsidiary, sales office, sales rep, staff employed by us locally, or a stable enough contractor arrangement)? If yes, list each presence and the lines of business it supports.
  2. Do we offer goods or services to data subjects in the EU, or monitor their behaviour there, from any of our operations (whether EU-based or Indian-based)? If yes, list each line of business.

Any yes to either question means Article 3 reaches you for that scope. Document the decision, the reasoning, the presences identified, and the lines of business in scope. This memo is what a supervisor or a DPA official asks for first when they turn up.

The Article 27 EU Representative

If only Article 3(2) applies to you and you are not caught by an Art 27 exception (occasional processing, small-scale non-special-category processing, unlikely-to-result-in-risk processing, or a public authority), you must designate a representative in the Union in writing [L2-C4]. The representative is the DPA-and-data-subject-facing contact point in the EU. Named commercial providers with transparent 2026 pricing include Prighter, VeraSafe, and Engage Compliance. Annual fees for a mid-size Indian SaaS typically range from EUR 500 to EUR 3000 depending on volume and complexity tier.

Failure to appoint a Representative where required is a straight-out contravention that a DPA can act on independent of any breach. Get this done in the first ninety days of any EU-facing business launch.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 8 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 8 paid modules (30 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹14,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
GDPR (EU) 2016/679, Article 3 Territorial Scope (Article 3 territorial scope: establishment and targeting) L2-C1
Article 3 has two limbs. Art 3(1) applies GDPR to processing in the context of the activities of an establishment of a controller or processor in the Union, regardless of whether the processing takes place in the Union. Art 3(2) applies GDPR to non-EU controllers or processors that (a) offer goods or services to data subjects in the Union, whether or not payment is required, or (b) monitor the behaviour of data subjects taking place within the Union. Art 3(3) covers Member-State law application in a place where Member-State law applies by virtue of public international law. EDPB Guidelines 3/2018 is the operational reading.
EDPB Guidelines, Guidelines 3/2018 Territorial (EDPB Guidelines 3/2018 on territorial scope (Article 3)) L2-C2
Endorsed by the EDPB in November 2019. Explains the "establishment" limb (Art 3(1)) and the "targeting" limb (Art 3(2)) with worked examples. Establishment is interpreted broadly: even a minor presence with a stable arrangement in a Member State can qualify, per Weltimmo (C-230/14). Targeting: Recital 23 factors include use of a Member-State language or currency, provision of shipping to a Member-State address, marketing at Member-State users, and use of a top-level domain of a Member State. Monitoring: Recital 24 factors include tracking on the internet with subsequent profiling. Foundational for the Indian audience: this Guideline decides whether GDPR reaches your Indian entity at all.
CJEU Judgment, IAB Europe C-604/22 (IAB Europe (C-604/22, 7 March 2024)) L2-C3
CJEU judgment of 7 March 2024 in Case C-604/22 (IAB Europe v Belgian Data Protection Authority). Held that the Transparency and Consent Framework (TCF) Consent String, even in pseudonymous form, constitutes personal data where identifiability is reasonably likely. IAB Europe is a joint controller with adtech participants for the processing associated with the TCF signal, insofar as it influences purposes and means. Reshapes adtech: operators can no longer treat TCF strings as anonymous. Practical impact for Indian adtech vendors serving EU users: TCF integration alone does not launder legal-basis analysis.
GDPR (EU) 2016/679, Article 27 EU Representative (Article 27 obligation to designate an EU Representative) L2-C4
Article 27 requires controllers and processors that are not established in the Union but are subject to GDPR by virtue of Art 3(2) to designate in writing a representative in the Union. Exceptions: (a) processing which is occasional; (b) processing which does not include, on a large scale, processing of special categories or personal data relating to criminal convictions; and (c) processing which is unlikely to result in a risk to the rights and freedoms of natural persons. Public authorities are also exempt. The representative is the addressee for supervisory authorities and data subjects on all issues related to processing. Named commercial providers of Art 27 Representative services include Prighter, VeraSafe, EU-Rep.com, GDPR-Rep.eu, Datenschutzagentur, and DPO-Consulting; typical annual fees for a mid-size Indian SaaS range from EUR 500 to EUR 3000 depending on volume tier.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: Foundations: why GDPR reaches you as an Indian practitioner
Module 2: Lawful basis and consent
  • The six Article 6 lawful bases and why consent is overused
  • Legitimate interests: the three-part test (Guidelines 1/2024)
  • Article 7 consent standards and Guidelines 05/2020
  • Article 9 special categories and the ten Art 9(2) gateways
Module 3: Data subject rights end-to-end
  • The rights inventory and the one-month response clock
  • Article 15 access requests: the practitioner playbook
  • Article 17 erasure: six triggers, ten exceptions
  • Articles 20, 21, 22: portability, objection, automated decisions
Module 4: Controller vs processor, contracts, subprocessing
  • Determining the role: factually, not contractually
  • Article 28 processor contract: the eight mandatory clauses
  • Joint controllership under Article 26 and the transparency obligation
  • Article 30 records of processing: what an Indian processor's ROPA must show
Module 5: DPO office, DPIA, records of processing
  • Article 37 DPO trigger: when a DPO must be appointed
  • Articles 38-39: DPO independence, resources, tasks
  • Article 35 DPIA: when and how
  • One DPO office serving GDPR and DPDP in parallel
Module 6: Breach notification and the triple clock
  • Article 33: when the 72-hour clock actually starts
  • Article 34 data-subject notification: the high-risk test
  • The triple clock: CERT-In 6h, DPDP 72h, GDPR 72h
  • Worked scenario: ransomware at an Indian SaaS with EU customers
Module 7: Cross-border transfers: SCCs, adequacy, DPF, Transfer Impact Assessment
  • Chapter V architecture: adequacy, Article 46, Article 49 derogations
  • Commission SCCs 2021/914: four modules walkthrough
  • Schrems II TIA obligation: the practitioner working reference
  • EU-US Data Privacy Framework: read as fragile additional layer
  • DPDP Section 16 + Rule 15: the negative-list mirror
Module 8: Adjacent EU instruments + enforcement pattern + capstone
  • DSA, DMA, Data Act, AI Act, NIS2: what reaches an Indian entity
  • Top-15 GDPR fines 2018-2026: practitioner lessons
  • Reading the 2024-2026 enforcement pattern
  • AI Act plus GDPR for Indian AI providers: DPIA plus FRIA overlap
  • Capstone: dual-regime compliance programme for an Indian IT services firm
Module 9: Final Exam and Certificate