Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

Does the GDPR apply to a company established outside the EU?

Yes, where the company offers goods or services to people in the EU or monitors their behaviour there. Establishment is not the test: Article 3 attaches to the location of the individual, and a company caught this way must appoint a representative inside the Union.

This answer differs by jurisdiction — see EU, US, SE, NO and DE below.

The answer per jurisdiction

Sources

  • Article 3(1): processing in the context of an establishment in the Union, wherever the processing happens.
  • Article 3(2): offering goods or services to, or monitoring the behaviour of, people in the Union.
  • Article 27: a written representative in the Union unless the processing is occasional and low risk.

What it means for the company

Decide the question per audience, not per office. A language, a currency and a delivery country in the checkout are the facts a supervisory authority reads as offering goods to the Union.

Comparison across jurisdictions
JurisdictionRequirementSource
EUArticle 3(2) test, representative under Article 27Regulation (EU) 2016/679
United StatesGDPR and state privacy law apply in parallelCal. Civ. Code § 1798.100
SwedenRepresentative in Sweden where the public is SwedishSFS 2018:218
NorwaySame test through the EEA agreementLOV-2018-06-15-38
GermanyState authority follows the representative's addressBDSG 2018

What it means for the individual

You keep your rights against a company with no EU office, and the representative named in the privacy notice is a valid address for your request.

Sources

  • General Data Protection Regulation
    Regulation (EU) 2016/679 · Europeiska unionens publikationsbyrå · read 2026-08-24 · proof 8f89a1711e57be3e
    Official source
  • California Consumer Privacy Act, as amended by CPRA
    Cal. Civ. Code § 1798.100 · California Legislative Counsel · read 2026-08-24 · proof 8f89a1711e57be3e
    Official source
  • Swedish Act supplementing the GDPR
    SFS 2018:218 · Sveriges riksdag · read 2026-08-24 · proof 8f89a1711e57be3e
    Official source
  • Norwegian Personal Data Act
    LOV-2018-06-15-38 · Lovdata · read 2026-08-24 · proof 8f89a1711e57be3e
    Official source
  • German Federal Data Protection Act
    BDSG 2018 · Bundesministerium der Justiz · read 2026-08-24 · proof 8f89a1711e57be3e
    Official source

Next step

Read the representative rule together with the transfer rules, because a company caught by Article 3 usually needs a transfer basis as well.

All global questions

The page reports what the sources say, with identifier and address to the publisher. It is not legal advice and does not assess an individual matter.

Next step

Three ways to put the register to work in your own practice.

Start with your task