skip to content

Under GDPR Art. 3, does the Regulation apply to a US product-analytics SaaS vendor with EU users but no EU establishment?

level: middleimportance: must knowfreq 62%

answer

  1. establishment first, then targeting
  2. offering or monitoring
  3. people in the Union, not citizens
  4. Art. 3(2) and Art. 27

basics

~20 s

Very likely yes. GDPR Art. 3(2) reaches a non-EU company whose processing relates to offering services to, or monitoring the behaviour of, people in the Union, and product analytics monitors behaviour. Art. 27 then generally requires an EU representative.

solid answer

~50 s

Under GDPR `Art. 3(1)`, the first question is whether processing happens *in the context of the activities of an establishment* in the Union; with no EU establishment, that route is closed. `Art. 3(2)` then catches a controller or processor **not established in the Union** when its processing of data of people *who are in the Union* relates to **(a) offering goods or services** to them, paid or free, or **(b) monitoring their behaviour** as far as it takes place in the Union. Recital 24 describes monitoring as tracking people on the internet, including profiling, which is what product analytics does, so `Art. 3(2)(b)` is the likely hook. Server location is irrelevant. Once `Art. 3(2)` applies, the vendor must designate **in writing** a representative in the Union (`Art. 27(1)`), unless the processing is occasional, low-risk and involves no large-scale special-category or criminal data, and the representative does not shield it from liability (`Art. 27(5)`).

go deeper

for a junior

Recall that the GDPR reaches non-EU companies that offer services to, or monitor, people in the Union, and that server location does not decide it.

for a middle

Walk through Art. 3(1) establishment first, then both Art. 3(2) limbs with the Recital 23 and 24 indicators, and state the Art. 27 representative duty and its narrow exemption.

for a senior

Separate the vendor's controller processing from its processor processing for customers, and show why continuous behavioural analytics defeats the Art. 27(2) occasional-processing exemption.

for a principal

Treat market entry decisions as scope decisions: launching an EU-language funnel or tracking EU sessions brings Art. 3(2) and Art. 27 obligations with it.

## Two routes into the GDPR's territorial scope `Art. 3` gives the GDPR (Regulation (EU) 2016/679) two main ways to reach a company, plus a narrow third: | Route | Trigger | Where the processing happens | |---|---|---| | **Establishment** | Processing in the context of the activities of an establishment of a controller or processor in the Union | Irrelevant: "regardless of whether the processing takes place in the Union or not" (`Art. 3(1)`) | | **Targeting** | A controller or processor *not* established in the Union processes data of people *in the Union*, related to offering goods or services to them or monitoring their behaviour there | Irrelevant (`Art. 3(2)`) | | **Public international law** | Member State law applies by virtue of public international law, such as a diplomatic mission | `Art. 3(3)`, Recital 25 | Recital 22 explains **establishment**: *the effective and real exercise of activity through stable arrangements*, whatever the legal form, branch or subsidiary. A US vendor with no office, staff or other stable arrangement in the Union has no establishment, so the analysis moves to `Art. 3(2)`. ## Art. 3(2)(a): offering goods or services The first targeting limb covers offering goods or services to data subjects in the Union, *irrespective of whether a payment of the data subject is required*, so a free tier counts. Recital 23 sets the test: whether it is **apparent that the company envisages** offering services to people in one or more Member States. - **Not enough on its own:** the mere accessibility of a website, an email address or other contact details from the Union, or using a language generally used in the company's own country. - **Indicators that it is:** a language or currency used in a Member State with the possibility of ordering in it, or mentioning customers or users who are in the Union. ## Art. 3(2)(b): monitoring behaviour The second limb covers monitoring the behaviour of people in the Union, as far as that behaviour takes place in the Union. Recital 24 describes it as people being **tracked on the internet**, including later use of profiling techniques, particularly to take decisions about them or to analyse or predict their preferences, behaviours and attitudes. A product-analytics product exists to record what users do, session by session and event by event, and to build profiles and funnels from it. When those users are in the Union, the behaviour being tracked takes place in the Union. This is the limb most likely to bring the vendor within scope. Two precision points: - The trigger is people **who are in the Union**, not EU citizens or residents. An EU citizen using the product from outside the Union is not caught by this limb on that account; a non-EU visitor while in the Union can be. - `Art. 3(2)` names **controllers and processors**. Where the vendor tracks end users on its customers' behalf, it is also a processor in that role, bound by its `Art. 28` contract with each customer; for its own sign-ups and account data it is typically a controller. ## Art. 27: the EU representative Once `Art. 3(2)` applies, `Art. 27` follows: 1. The controller or processor must **designate in writing** a representative in the Union (`Art. 27(1)`). 2. The representative must be **established in a Member State where the data subjects** being offered services or monitored are (`Art. 27(3)`). 3. It is mandated to be addressed, **in addition to or instead of** the company, by supervisory authorities and data subjects on all processing issues (`Art. 27(4)`). 4. Designation is **without prejudice to legal actions** against the controller or processor itself (`Art. 27(5)`); Recital 80 adds that the representative should be subject to enforcement proceedings if the company does not comply. The exemption in `Art. 27(2)` is narrow: processing that is **occasional**, does not include large-scale processing of special categories or criminal-offence data, and is **unlikely to result in a risk**, or a public authority or body. Continuous behavioural analytics is not occasional, so the exemption will rarely fit. ## What applying the GDPR means for the vendor Being in scope under `Art. 3(2)` is not a lighter version of the GDPR. The vendor's processing of those people's data is subject to the Regulation's rules for its role: principles, records (`Art. 30`, which also names the representative), security, breach duties and, as a controller, data-subject rights. Moving data between the vendor's US systems and EU customers raises separate questions under Chapter V. ## Common mistakes - "We have no EU office, so the GDPR does not apply." `Art. 3(2)` exists for exactly this case. - "Our servers are in the US." Location of processing is irrelevant under both `Art. 3(1)` and `Art. 3(2)`. - "The GDPR protects EU citizens worldwide." The targeting limb turns on where the person is. - "Our service is free, so we offer nothing." Payment is expressly irrelevant.

  • Under GDPR Recital 23, is an English-language website reachable from the EU enough to show a US company targets EU users?
    No. Recital 23 says mere accessibility of the website, an email address or contact details, or use of a language generally used in the company's own country, is insufficient. Indicators such as a Member State's language or currency with ordering in it, or mentioning users in the Union, can make the intention apparent. Monitoring under `Art. 3(2)(b)` is a separate limb that needs no such intention.
  • Under GDPR Art. 27, does appointing an EU representative move the non-EU company's liability onto the representative?
    No. `Art. 27(5)` says designation is without prejudice to legal actions against the controller or processor themselves. The representative is a point of contact that authorities and data subjects may address in addition to or instead of the company (`Art. 27(4)`), and Recital 80 says it should be subject to enforcement proceedings if the company fails to comply.
  • Under the GDPR, if the vendor opened a small EU sales office, which provision would then be relevant?
    `Art. 3(1)`: processing in the context of the activities of an EU establishment is covered wherever it takes place. Recital 22 defines establishment as effective and real activity through stable arrangements, whatever their legal form. Whether a given processing is in the context of that office's activities is the question to analyse; `Art. 3(2)` covers only companies not established in the Union.

saying these in an interview costs you the question

  • We have no office in the EU, so the GDPR cannot apply to us.
  • The GDPR protects EU citizens wherever in the world they are.
  • Hosting all data on US servers keeps the processing outside the GDPR.
  • A free service offers nothing, so Art. 3(2)(a) cannot apply.
  • Appointing an EU representative transfers our GDPR liability to it.