Every GDPR analysis starts with Article 3. If Article 3 does not reach your entity, GDPR does not apply. If it does, everything else follows. Getting Article 3 wrong is the most common failure mode of a first-time GDPR reader.
The two limbs
Article 3 has two limbs [L2-C1].
- Establishment (Article 3(1)). GDPR applies to the processing of personal data in the context of the activities of an establishment of a controller or processor in the Union, regardless of whether the processing takes place in the Union or not.
- Targeting or monitoring (Article 3(2)). GDPR applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to (a) the offering of goods or services, irrespective of whether payment is required, to such data subjects in the Union; or (b) the monitoring of their behaviour as far as their behaviour takes place within the Union.
EDPB Guidelines 3/2018 [L2-C2] is the operational reading. Both limbs are interpreted broadly.
Limb 1: establishment
Weltimmo (CJEU C-230/14) tells us "establishment" is a low bar. A single representative, a bank account, a domain in a Member-State language directed at Member-State users — any of these can qualify given a stable arrangement.
For an Indian company the practical question is: do you have any presence in the EU (branch, subsidiary, sales office, sales rep, even a single locally-employed person acting on your behalf) plus a stable arrangement? If yes, and the processing you do is "in the context of the activities" of that presence, Article 3(1) reaches you and every processing operation of yours can be caught by GDPR, wherever the servers sit.
Common Indian scenario: EU subsidiary of an Indian IT services firm
TCS, Infosys, Wipro, HCL and Tech Mahindra all operate EU subsidiaries. Those subsidiaries are establishments in the Union. Processing conducted by the Indian parent that is in the context of the activities of the EU subsidiary (say, HR processing of the subsidiary\'s employees, or delivery of a service the subsidiary sold to an EU customer) is caught by Article 3(1). This is why the Indian IT services biggies uniformly treat themselves as GDPR-in-scope for their EU-facing lines of business.
Limb 2: targeting or monitoring
Limb 2 catches non-EU controllers and processors that offer goods or services to EU data subjects, or that monitor their behaviour within the Union. Recital 23 sets the factors for offering: use of a Member-State language, a Member-State currency, provision of shipping to a Member-State address, marketing to Member-State users, a Member-State-specific top-level domain, or explicit mention of EU users on the website. Recital 24 sets the factors for monitoring: tracking on the internet with subsequent profiling, in particular for consumer-behaviour analysis, ad targeting, or fraud prevention involving EU users.
Common Indian scenario: SaaS with EU customers
Your Bengaluru SaaS company signs up an EU-based customer. That customer\'s employees log in and their personal data (names, emails, IPs, activity logs) is processed by you. Are you caught by Article 3(2)? Almost always yes, because you are offering a service to data subjects in the Union. Consequence: Article 27 EU Representative appointment obligation (unless the Art 27 exception applies), Chapter V transfer analysis for the data you move between your Indian servers and any subprocessors, and full Chapter III data-subject-rights obligations.
Common Indian scenario: BPO handling EU customer accounts on behalf of an EU controller
You are a processor for an EU controller who is offering goods to EU consumers. The EU controller is directly in scope of Article 3(1). You (the Indian BPO processor) are caught by Article 3(2) because you are processing personal data of EU data subjects on behalf of the controller. Article 28 processor obligations apply directly to you. Article 33(2) breach-notification-to-controller obligation applies. Chapter V transfer obligations for onward transfers you make from your Indian servers to any further sub-processor.
Common Indian scenario: adtech monitoring EU users
You run an Indian ad-network SDK that gets embedded in mobile apps used by EU users. Every impression and click is tracked to a profile you build for retargeting. Article 3(2)(b) is squarely on you: monitoring of behaviour of EU data subjects within the Union. IAB Europe (C-604/22) [L2-C3] tells us pseudonymous identifiers (like your TCF Consent String or your device advertising ID) are personal data when re-identification is reasonably likely. Consequence: full GDPR obligations plus adtech-specific consent architecture.
The two-question test for an Indian entity
Sit with the Chief Compliance Officer of your organisation and answer these two questions on the record:
- Do we have any presence in the EU (branch, subsidiary, sales office, sales rep, staff employed by us locally, or a stable enough contractor arrangement)? If yes, list each presence and the lines of business it supports.
- Do we offer goods or services to data subjects in the EU, or monitor their behaviour there, from any of our operations (whether EU-based or Indian-based)? If yes, list each line of business.
Any yes to either question means Article 3 reaches you for that scope. Document the decision, the reasoning, the presences identified, and the lines of business in scope. This memo is what a supervisor or a DPA official asks for first when they turn up.
The Article 27 EU Representative
If only Article 3(2) applies to you and you are not caught by an Art 27 exception (occasional processing, small-scale non-special-category processing, unlikely-to-result-in-risk processing, or a public authority), you must designate a representative in the Union in writing [L2-C4]. The representative is the DPA-and-data-subject-facing contact point in the EU. Named commercial providers with transparent 2026 pricing include Prighter, VeraSafe, and Engage Compliance. Annual fees for a mid-size Indian SaaS typically range from EUR 500 to EUR 3000 depending on volume and complexity tier.
Failure to appoint a Representative where required is a straight-out contravention that a DPA can act on independent of any breach. Get this done in the first ninety days of any EU-facing business launch.