All tools › GDPR Applicability Checker

GDPR Applicability Checker

Seven yes/no questions based on Article 3 of the GDPR — for companies anywhere in the world.

Personal data
Do you process any personal data?

Any information about an identifiable person: names, emails, IP addresses, cookie IDs, customer records.

European Union
Do you have an office, branch, staff or other stable establishment in the EU?
Do you offer goods or services (paid or free) to people in the EU?

Signs: EU languages or currencies, shipping to the EU, EU-targeted ads, EU customers mentioned.

Do you track the behaviour of people in the EU?

For example analytics profiles, behavioural advertising, location tracking.

United Kingdom
Do you have an establishment in the UK?
Do you offer goods or services to people in the UK?
Do you track the behaviour of people in the UK?

When does GDPR apply to a company outside Europe?

Article 3 of the GDPR applies the law in two ways. First, to any organisation established in the EU, for processing in the context of that establishment. Second, to organisations outside the EU that offer goods or services to people in the EU or monitor their behaviour there. The UK GDPR copies this test for the UK.

Simply having a website that Europeans can visit is not enough. Regulators look for signs that you intend to serve people in Europe. Non-EU organisations caught by Article 3(2) usually need an EU representative under Article 27.

Frequently asked questions

Does GDPR apply to US companies?

Yes, if they offer goods or services to people in the EU or monitor their behaviour there, even with no EU office.

Do B2B companies need to comply?

Yes. Business contacts' names and emails are personal data.

What is an EU representative?

A person or company in the EU that acts as your contact point for regulators and individuals (Article 27).

Last reviewed 2026-10-09. Sources: official legal texts on EUR-Lex, legislation.gov.uk and the California Privacy Protection Agency.