- Official guidance for role mapping once scope is established.
References and citations
- Official guidance on establishment, targeting, and monitoring under Article 3.
- Primary legal text for Articles 2, 3, and 27.
Decide whether GDPR applies, which role you have, and what to document.
Focus: Article 2 (material scope), Article 3 (territorial scope), Article 27 (representative), and practical outcomes.
Structured answer sets in this page tree.
Cited legal and guidance references.
A GDPR applicability decision must be defensible: it should be tied to facts (where processing happens, who is established, and what data subjects you target) and it should produce a concrete output (what controls and evidence you need). This page provides an execution-ready applicability test and the deliverables that make the decision auditable.
Start with the core question: is there processing of personal data (automated or part of a filing system) in your activity?
Then validate whether any Article 2 exclusions are relevant (these often appear in public sector or law enforcement contexts).
Article 3 has three key paths: (1) processing in the context of an EU establishment, (2) targeting EU data subjects (goods/services or monitoring behavior), and (3) Member State law applying by public international law.
Your goal is not to win a debate-it's to map facts to the Article 3 path and keep evidence of that mapping.
Role mapping is a control design step: it determines who owns transparency, DSAR handling, DPIAs, and vendor oversight.
Most failures happen when teams label themselves a processor but behave like a controller, or the reverse.
Use these as red flag prompts in scoping workshops. If any apply, you likely need deeper analysis and stronger documentation.
A good applicability test ends with artifacts, not a sentence. These outputs are what make the decision explainable and actionable.
Assessment Autopilot can take EU GDPR Applicability Test from deciding whether these obligations apply in practice to a reusable workflow inside Sorena. Teams working on EU GDPR can keep owners, evidence, and next steps aligned without copying this guide into separate documents.
Start from EU GDPR Applicability Test and turn the guidance into owned tasks, evidence requests, and review checkpoints.
Review your current process, evidence gaps, and next steps for EU GDPR Applicability Test.