Skip to main content
ExplainerGDPR JurisdictionExplainer· 5 min read· in Technology

The Two Conditions in Article 3 That Give the GDPR Extraterritorial Reach

Article 3 of the GDPR extends European data privacy laws to foreign companies through two specific legal mechanisms: the establishment criterion and the targeting criterion.

By Diego Navarro

European Regulators 40%Foreign Digital Services 35%Legal & Compliance Industry 25%
European Regulators
Focus on comprehensive data protection and closing offshore loopholes.
Foreign Digital Services
Focus on the administrative burden and legal ambiguity of the targeting criterion.
Legal & Compliance Industry
Focus on strict interpretation and the necessity of formal compliance mechanisms.

Perspectives this story doesn't cover

  • Small non-EU businesses unaware of their compliance obligations

The General Data Protection Regulation (GDPR) extends its jurisdiction outside the European Union through two specific mechanisms in Article 3: the "establishment" criterion, which covers foreign companies with any stable operational presence in the EU, and the "targeting" criterion, which captures entities that intentionally offer goods or monitor the behavior of people located within the bloc. If a non-EU organization meets either of these conditions, it is legally bound by the 2018 regulation regardless of where its servers are physically located or where the actual data processing takes place.[1][4]

Many foreign companies assume that because they have no European offices, they are immune to the GDPR. Conversely, privacy compliance vendors often market the regulation as a universal net that catches any website accessible from Europe. The actual legal capability, as defined by the European Data Protection Board (EDPB) in its Guidelines 3/2018, sits between these extremes. The regulation does not apply simply because an EU resident accesses a foreign website; it applies when a company deliberately targets that resident or maintains a local footprint.[3][4]

The first condition, outlined in Article 3(1), is the establishment criterion. This rule dictates that the GDPR applies to the processing of personal data "in the context of the activities of an establishment" of a controller or processor in the Union. Crucially, the processing itself does not need to happen in the EU. A company headquartered in the United States that routes all its data through servers in California is still subject to the GDPR if the data is collected in connection with a European branch office.[1]

The definition of an "establishment" is intentionally broad and flexible. It does not require a formally registered subsidiary or a corporate headquarters. According to legal precedents carried over from the 1995 Data Protection Directive (Directive 95/46/EC), an establishment implies the "effective and real exercise of activity through stable arrangements." In the landmark case Weltimmo v. NAIH (C-230/14), the Court of Justice of the European Union (CJEU) ruled that even a single representative or a local bank account could trigger this threshold.[2][4]

The two mechanisms that trigger GDPR compliance for non-EU organizations.

The second condition, detailed in Article 3(2), is the targeting criterion. This is the mechanism that fundamentally shifted European data law from a physical jurisdiction to a digital one. It applies to controllers and processors with no physical presence in the EU whatsoever, provided they are processing the personal data of individuals who are currently in the Union.[1]

The targeting criterion is divided into two distinct triggers. The first is the offering of goods or services to individuals in the EU, irrespective of whether a payment is required. The EDPB guidelines specify that mere accessibility of a website is insufficient to prove intent. Instead, regulators look for evidence that the company "envisages" offering services to European users.[3][4]

The targeting criterion is divided into two distinct triggers.

Evidence of this intent includes using a language or currency generally used in an EU member state, offering shipping to European addresses, or mentioning European customers in marketing materials. If a Canadian e-commerce site prices its items in Euros and offers delivery to France, it has triggered Article 3(2) and must comply with the GDPR, even if it has exactly zero European employees.[4]

The second trigger under the targeting criterion is the monitoring of behavior, provided that the behavior takes place within the Union. This clause was designed directly for the modern internet economy, capturing ad-tech networks, analytics providers, and behavioral profiling systems that operate entirely offshore.[2]

Monitoring involves tracking natural persons on the internet to analyze or predict their personal preferences, behaviors, and attitudes. This includes the use of cookies, device fingerprinting, and personalized advertising. If a foreign analytics firm tracks the browsing habits of 10,000 users located in Germany to serve them targeted ads, that firm is subject to the GDPR's extraterritorial reach.[4]

A critical distinction in Article 3(2) is its focus on location rather than citizenship. The regulation protects data subjects "who are in the Union." It does not matter if the individual is an EU citizen, a foreign tourist, an expatriate, or a stateless person. If an American tourist is browsing the internet from a hotel in Rome, their data is protected by the GDPR. Conversely, the data of an EU citizen living permanently in the United States is not covered by the targeting criterion.[2]

When a non-EU company falls under the targeting criterion of Article 3(2), the regulation imposes an additional administrative burden: the appointment of an EU-based representative. Mandated by Article 27, this representative acts as the primary point of contact for European supervisory authorities and data subjects.[2]

Maximum penalties for violating the GDPR's extraterritorial provisions.

The representative must be established in one of the member states where the targeted data subjects are located. This requirement ensures that European regulators have a local entity to interact with—and potentially penalize—when enforcing the law against a foreign company. Failure to appoint a representative is itself a violation of the GDPR and can trigger enforcement action.[2]

The shift from the 1995 Directive to the 2018 GDPR represents a fundamental change in how the EU projects its regulatory power. Under the old Directive, extraterritoriality often hinged on the "use of equipment" within the EU, such as physical servers. The GDPR discarded this hardware-dependent test in favor of an intent-based standard, closing the loophole that allowed digital services to operate in Europe without legal accountability.[4]

Under the targeting criterion, the physical location of the servers processing the data is legally irrelevant.

Despite the clear language of Article 3, enforcement remains the primary limitation of the GDPR's extraterritorial reach. While European authorities can issue substantial fines—up to €20 million or 4% of global annual turnover—collecting those fines from a company with no European assets is legally and logistically complex. The regulation relies heavily on international cooperation and the threat of market exclusion to compel compliance from foreign actors.[2]

Unsettled ground

  • How effectively European authorities can actually collect fines from foreign companies with zero EU assets.
  • The exact threshold of website localization (e.g., accepting a specific international credit card) that definitively proves an 'intent' to target EU users in borderline cases.
2
Extraterritorial criteria in Article 3
€20M
Maximum fixed penalty
4%
Maximum global turnover penalty

Sources

Source coverage

5 outlets

3 viewpoints surfaced

European Regulators 40%Foreign Digital Services 35%Legal & Compliance Industry 25%
  1. [1]GDPRhubEuropean Regulators

    Article 3 GDPR

    Read on GDPRhub
  2. [2]IAPPForeign Digital Services

    Territorial scope of the GDPR from a US perspective

    Read on IAPP
  3. [3]Covington & BurlingForeign Digital Services

    EDPB Guidelines – What is the Territorial Reach of the GDPR?

    Read on Covington & Burling
  4. [4]European Data Protection BoardEuropean Regulators

    Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) - version adopted after public consultation

    Read on European Data Protection Board
  5. [5]Factlen Editorial Team

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team

Comments

Stay informed

Every angle. Every day.

Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.