GDPR Applicability Checker
Check whether the GDPR applies to your organisation based on establishment in the EU and offering goods or services to or monitoring EU residents.
Last reviewed by the Radiatus Cloud team
Check whether the GDPR is likely to apply to your organisation.
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
Check if the GDPR applies to you
The General Data Protection Regulation has a broad reach, and many organisations outside the EU are surprised to find it applies to them. This checker helps you assess applicability based on the two routes set out in Article 3: having an establishment in the EU or EEA, which triggers the regulation for your processing regardless of where it happens; and, even without an EU establishment, offering goods or services to people in the EU or monitoring their behaviour, which triggers it extraterritorially.
The regulation only applies where personal data is processed, so that is the starting condition.
Understanding territorial scope
The extraterritorial reach of the GDPR means a business anywhere in the world can fall within its scope if it targets EU residents, for example by shipping to the EU, pricing in euros, or tracking EU visitors with cookies. Merely having a website accessible from the EU is not enough; there must be an intention to offer to or monitor people there. Getting this assessment right determines whether you must appoint a representative, meet GDPR obligations and face its penalties.
This tool gives general guidance to prompt a proper assessment; the precise application of the law to your situation should be confirmed with qualified advice. All processing happens locally in your browser.
Related tools
- SOC 2 Evidence Readiness — Interactive checklist to gauge your SOC 2 evidence readiness.
- Privacy Policy Checker — Check if your policy covers standard requirements (GDPR/CCPA basics).
- Compliance Req Finder — Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
- Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Frequently Asked Questions
When does the GDPR apply to a non-EU business?
When it offers goods or services to people in the EU or monitors their behaviour, even without an EU establishment, under Article 3(2).
Does having an EU office trigger the GDPR?
Yes. An establishment in the EU or EEA brings your processing within the GDPR under Article 3(1), regardless of where the processing happens.
Is an EU-accessible website enough?
No. Mere accessibility is not enough; there must be evidence of intending to offer to or monitor people in the EU, such as EU shipping or tracking.
Is this legal advice?
No. It is general guidance to help you assess applicability. Confirm the precise position for your organisation with qualified legal advice.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Answer the questions about your EU presence and activities.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.