Marketplace principle
The marketplace principle extends the territorial scope of the GDPR to controllers and processors with no establishment in the EU whenever they offer goods or services to data subjects in the Union or monitor their behaviour (Art. 3(2) GDPR).
The territorial scope of the GDPR rests on two ideas. Under the establishment principle in Art. 3(1) GDPR, the Regulation applies to any processing carried out in the context of the activities of an establishment in the Union, regardless of where the processing physically takes place. The marketplace principle in Art. 3(2) GDPR complements this by looking at the market rather than the corporate seat: a controller or processor without an EU establishment falls under the full GDPR as soon as it reaches people who are located in the Union. The legislator wanted to prevent providers from escaping European data protection standards simply by choosing where to incorporate, and to create a level playing field between European and non-European providers. What matters is that the data subject is located in the Union at the time of the processing, not their nationality or permanent residence.
Art. 3(2) GDPR sets out two connecting factors. Point (a) covers the offering of goods or services to data subjects in the Union, irrespective of whether payment is required. This calls for deliberate targeting of the Union market; under Recital 23, the mere accessibility of a website from the EU or the presence of a contact address is expressly not enough. Relevant indicators include the use of an official language or currency of a Member State, delivery options into the EU, EU-specific domains, targeted advertising, customer references from the Union, or prices quoted in euro. Point (b) covers the monitoring of the behaviour of data subjects as far as that behaviour takes place in the Union, for example through tracking, cookies, device fingerprinting, profiling for advertising or scoring purposes, or behavioural analytics. The European Data Protection Board has fleshed out both limbs in its Guidelines 3/2018 on the territorial scope of the GDPR, using numerous worked examples and always insisting on an overall assessment of the individual case.
Where the marketplace principle applies, the GDPR applies in full rather than selectively: legal bases under Art. 6 GDPR, transparency duties, data subject rights, the record of processing activities, technical and organisational measures, breach notification duties and the accountability principle. In addition, Art. 27 GDPR generally requires the organisation to designate a representative in the Union in writing, who serves as the point of contact for supervisory authorities and data subjects; exemptions apply only to occasional processing that involves no large-scale processing of special categories of data and is unlikely to result in a risk to individuals, and to public authorities. Supervisory authorities may exercise their powers, including fines under Art. 83 GDPR, against third-country organisations as well; the one-stop-shop mechanism with a lead supervisory authority is not available to companies without an EU establishment, so any concerned authority may act. For European companies the principle also matters along the supply chain: it does not replace the requirements for transfers to third countries under Chapter V GDPR but applies alongside them.
Legal Basis
Art. 3(2) GDPR (read with Art. 3(1) and Art. 3(3) GDPR), Recitals 22 to 24, Art. 27 GDPR; EDPB Guidelines 3/2018 on the territorial scope of the GDPR
Practical Example
A Swiss manufacturer of outdoor equipment runs an online shop that is available in German as well as French, quotes prices in euro, advertises shipping to Germany and Austria, and analyses visitors with an analytics and retargeting pixel. The privacy coordinator assesses the territorial scope and concludes that both limbs are met: targeted offering to people in the Union under Art. 3(2)(a) GDPR and behavioural monitoring under point (b). As a result, the company appoints a representative under Art. 27 GDPR in Germany and names them in the privacy notice, builds a record of processing activities under Art. 30 GDPR, adds GDPR-compliant consent management for the tracking technologies, and defines a process for handling data subject requests and for notifying personal data breaches within 72 hours. In parallel, the coordinator documents that Swiss data protection law continues to apply and that the GDPR merely applies in addition to it.