The GDPR's reach is extra-territorial. It applies to organisations established in the EU, and to those outside the EU that offer goods or services to, or monitor, people in the EU.
Key points
- Covers processing by an EU establishment, wherever the processing happens.
- Covers non-EU organisations targeting or monitoring people in the EU.
- Non-EU controllers may need to appoint an EU representative (Article 27).
Official text & source
Article 3 of the General Data Protection Regulation (Regulation (EU) 2016/679). Read the full, authoritative text on EUR-Lex.
Official text
Verbatim text of Article 3 of the General Data Protection Regulation — Regulation (EU) 2016/679.
This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.
This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:
the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or
the monitoring of their behaviour as far as their behaviour takes place within the Union.
This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.
Source: Regulation (EU) 2016/679 (OJ L 119, 4.5.2016, p. 1). Official text reproduced from EUR-Lex — © European Union. Only European Union legislation published in the Official Journal is deemed authentic.
Related articles
These summaries are a plain-English orientation only and are not a substitute for the official text of the Regulation or for legal advice.
Need to apply Article 3?
Our data-protection lawyers turn the text into a plan.