Decide whether a product, vendor, workflow, or data flow is inside GDPR scope before assigning notices, records, contracts, security controls, transfer safeguards, or data-subject rights work.
Use the test to record personal-data facts, controller and processor roles, EU establishment, EU targeting or monitoring, special-category and child-data flags, transfer branches, vendor dependencies, and evidence.
This GDPR applicability test applies when a team launches a product, changes telemetry, adds a vendor, opens an EU market, imports customer lists, processes employee or applicant data, or moves data outside the EEA. The result should be a short evidence record that says whether GDPR applies to the specific processing activity and which follow-up branches are triggered.
1
Section 1
Step 1: confirm personal data and processing
Start with Article 2 and Article 4. GDPR scope begins with processing of by automated means, or non-automated personal data that forms or is intended to form part of a filing system. If the data cannot relate to an identified or identifiable natural person, record why the GDPR test stops at this step.
Do not treat the system name as the unit of analysis. Test each processing activity separately: collection, storage, enrichment, support access, analytics, disclosure to a vendor, model evaluation, deletion, and transfer can have different facts.
List the data subjects: customers, prospects, users, employees, applicants, contractors, children, trial participants, support contacts, or website visitors.
List identifiers and linkability: name, email, account ID, customer ID, device ID, IP address, location data, online identifiers, profile attributes, or linked event history.
Describe the processing operations: collection, recording, organisation, storage, retrieval, consultation, use, disclosure, alignment, restriction, erasure, or destruction.
Do not treat pseudonymised data as automatically anonymous: if a person remains identifiable using additional information reasonably available, continue the GDPR analysis.
Flag exclusions only when supported by facts. Record the exact Article 2 branch, including a purely personal or household activity or competent-authority criminal-law processing governed by Directive (EU) 2016/680, and check whether another EU or Member State rule governs it. Recital 27 also excludes deceased persons while allowing Member States to provide their own rules.
Step 2: assign controller, processor, or joint-controller roles
After confirming , decide who determines the purposes and essential means of each processing activity. The EDPB describes controller, joint controller, and processor as functional roles, so contract labels are evidence but not the whole answer.
A product team can be a controller for its own analytics, a processor for customer-hosted data, and a separate controller for billing or security logs. Keep those role decisions separate, because each branch drives different Article 28 contracts, Article 30 records, notices, security obligations, and rights handling.
Controller branch: the organisation decides why the data is processed and the essential means of that processing.
Processor branch: the organisation processes on another controller's documented instructions and does not reuse it for its own purposes.
Joint-controller branch: two or more parties jointly determine purposes and means for the same processing stage and need a clear allocation of GDPR responsibilities.
Vendor branch: classify each vendor by activity, not procurement category; hosting, support, analytics, fraud screening, payroll, CRM, and AI tooling may sit in different role branches.
Step 3: test EU establishment, targeting, and monitoring
Use Article 3 as a separate territorial-scope test. GDPR can apply where processing is in the context of an EU establishment, even if processing occurs outside the Union. It can also apply to non-EU controllers or processors when processing relates to offering goods or services to data subjects in the Union or monitoring their behaviour there. Article 3(2) turns on where the person is during the relevant activity, not EU citizenship.
Record facts that show the link to the Union. For establishment, capture stable EU arrangements and how the processing is connected to those activities. For targeting, capture EU-facing offers such as language, currency, delivery, sales, signup, or service availability. For monitoring, capture tracking, profiling, behavioural analytics, location monitoring, health or lifestyle app telemetry, or similar observation of people in the Union. Article 3(3) separately covers a controller outside the Union in a place where Member State law applies by public international law, such as certain processing by a Member State embassy or consulate.
EU establishment branch: name the EU entity, branch, office, sales operation, employee presence, or processor establishment and explain the connection to the processing activity.
Targeting branch: record the goods or services offered to people in the Union and the evidence that the offer is directed at them.
Monitoring branch: describe the behavioural observation, tracking, profiling, analytics, or location pattern and why it concerns people in the Union.
Public-international-law branch: identify the place outside the Union, the Member State law that applies there, and the processing carried out by the controller under Article 3(3).
Article 27 branch: if a non-EU controller or processor is in scope through Article 3(2), check whether an EU representative must be designated. The exception is narrow: public authorities and bodies are excluded, and other processing must be occasional, must not include large-scale Article 9 or Article 10 processing, and must be unlikely to create risk.
Step 4: flag special categories, children, security, and records
If GDPR applies, add risk and governance flags before routing the work. Special-category data, criminal-offence data, child consent in information-society services, large-scale processing, systematic monitoring, and high-risk processing can change the controls, review depth, and evidence needed.
The applicability record should not decide every downstream obligation. It should make the branching visible so privacy, product, security, procurement, support, HR, and data-governance owners know which workstream starts next.
Special-category flag: identify health, biometric, genetic, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, sex life, or sexual-orientation data when Article 9 may be relevant.
Children flag: identify whether an information-society service is offered directly to children and whether consent is the proposed Article 6 basis.
Records flag: create or update Article 30 records with purposes, categories of data subjects and , recipients, transfers, retention periods where possible, and security measures where possible. For an organisation with fewer than 250 staff, document whether Article 30(5)'s exception applies; it does not apply to non-occasional processing, processing likely to create risk, or processing that includes Article 9 or Article 10 data.
Security and DPIA routing flag: route high-risk, large-scale, sensitive, or systematic-monitoring processing to the security, DPIA, and data-protection-by-design workflows instead of closing the test as a simple yes or no.
Apply the EDPB's three cumulative transfer criteria before choosing a Chapter V mechanism: a controller or processor is subject to the GDPR for the processing; that exporter sends or otherwise makes available to a different controller, joint controller, or processor; and that importer is in a third country or is an international organisation. The importer's own Article 3 status does not remove the transfer. Article 44 also covers onward transfers, so follow hosted data, vendor support access, subprocessors, analytics pipelines, backups, and group-company access.
Remote access from a third country is not automatically a Chapter V transfer when the person accessing the data is an employee acting within the same controller rather than a different importer. The overseas access still requires GDPR security, purpose, access-control, and accountability review. If the employee makes the data available to a different controller or processor in the third country, the transfer test is met.
Use a transfer branch that starts with adequacy, then appropriate safeguards such as Commission standard contractual clauses, and then any Article 49 derogation only when the GDPR conditions are actually met. Do not treat a vendor's certificate, security questionnaire, or generic DPA as a substitute for the transfer mechanism and evidence.
Adequacy branch: record whether the destination country, territory, sector, or international organisation is covered by a Commission adequacy decision.
SCC branch: select the module that matches the exporter and importer roles, such as controller-to-controller, controller-to-processor, processor-to-processor, or processor-to-controller.
Transfer-risk branch: record the destination, importer, data categories, processing purpose, onward transfers, government-access risk analysis, supplementary measures, and review trigger.
Vendor-chain branch: require subprocessors and support-access locations to appear in the same transfer evidence, not only in procurement notes.
The output of the test should be compact enough to review but specific enough to prove the decision later. Save the facts, not just the conclusion. If the answer is outside GDPR scope, the record should still show the personal-data, role, and territorial-scope facts that made the team stop.
Reopen the test when the product changes data categories, adds profiling or monitoring, enters an EU market, changes vendors, adds support access from a new country, changes controller or processor roles, launches a child-facing service, or begins a new transfer path.
Can a non-EU company be subject to GDPR without having an EU office?
Yes. A non-EU controller or processor can be in scope for a processing activity that relates to offering goods or services to people in the Union or monitoring their behaviour in the Union. Record the targeting or monitoring facts and check the Article 27 representative branch.
Does a vendor contract decide whether a party is a processor?
No. The contract is evidence, but the role test is factual. Decide who determines the purposes and essential means of the specific processing activity, then align the Article 28 contract, records, transfer evidence, and vendor controls with that role.
What evidence should teams keep for a GDPR applicability test?
Keep the personal-data inventory, processing activity, role analysis, Article 3 territorial-scope facts, special-category and child-data flags, vendor and transfer branches, cited source URLs, owner approval, and reassessment trigger.
Processing activity name, product or workflow owner, legal reviewer, operational owner, approval date, and reassessment trigger.
Personal-data inventory with data subjects, identifiers, data categories, processing operations, and any Article 9, Article 10, or child-data flags.
Role analysis for each party, including controller, processor, joint-controller, subprocessor, representative, exporter, and importer where relevant.
Territorial-scope evidence for EU establishment, EU targeting, EU behavioural monitoring, or the reason Article 3 is not triggered.
Transfer and vendor evidence, including destination countries, adequacy or SCC basis, module selection, supplementary measures, subprocessors, onward transfers, and review trigger.
Route GDPR scope decisions before product, vendor, and transfer approvals
Sorena can convert this GDPR applicability test into cited intake questions, owner assignments, vendor and transfer branches, evidence requests, and reassessment triggers for privacy, security, product, procurement, support, HR, and legal teams.
Defines the EDPB's three cumulative transfer criteria and explains why access by an employee within the same controller is not a transfer to a different importer.
EDPB guidance supports recording territorial-scope facts per processing activity, rather than treating a whole company as uniformly in or out of scope.