Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: EN

Article 3 Territorial scope


Summary What does Article 3 of the GDPR regulation say?

This article defines the territorial scope of the GDPR, establishing exactly when and where the regulation applies.

It takes a broad, extraterritorial approach: the regulation does not simply apply to organisations based in the EU, but extends to any controller or processor outside the Union that targets or monitors individuals located within it.

This makes Article 3 a critical gateway article, as it determines which entities fall under the obligations set out throughout the rest of the regulation.

Important points:

  • Controllers and processors established in the Union are subject to this regulation regardless of where the actual processing takes place.
  • Controllers and processors outside the Union are also subject to this regulation if they offer goods or services to, or monitor the behaviour of, individuals located in the Union.
  • The regulation also applies to controllers operating in locations where Member State law applies by virtue of public international law, even without a Union establishment.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.

    1. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:

      1. the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or

      2. the monitoring of their behaviour as far as their behaviour takes place within the Union.

    1. This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod