Outbound Wiki

GDPR territorial scope

When GDPR applies to outbound prospecting based on the people targeted, the organization involved and where processing occurs.

GDPR scope depends on the relationship among your organization, the people you target, and the processing behind the outreach. An organization outside the EEA can still fall within it if it offers goods or services in the EEA, monitors behavior there, or processes personal data in connection with an EEA establishment.1 Server location does not decide the question: cold emails to prospects in Europe and a company based there remain within GDPR scope regardless of server location.2 Check territorial scope before you debate the channel or infrastructure. Carry the result into the processing and contact review.

Run the scope check

Follow the campaign from the organization to the people and activity, then through the processing path. End by deciding whether it needs the full GDPR review.

Stage What you are trying to learn Example question
Establishment whether the organization has a relevant establishment Which organization has an establishment connected to this campaign?
Audience whether the people in the target list fall within a territorial trigger Where do the people in this list live or work?
Offer or processing whether the campaign offers goods or services or processes personal data connected to the target region Are we offering something or processing data connected to that region?
Monitoring whether the activity observes behavior Does the campaign track, retarget, or analyze behavior?
Processing path which organization is subject to the processing and whether data crosses a jurisdiction Who handles the data, and where is it collected, accessed, or sent?
Decision whether any test returns yes Which answer moves this campaign into GDPR review?

A yes answers the territorial question. Finish the later rows to document the basis and identify the separate contact checks that follow.

Start with the organization

Name the organization running the campaign and the other actors involved in processing before reviewing the audience or sending method.

An organization established in the EU or UK is within scope, whether that establishment is an office, subsidiary, or single employee.3 The scope test also asks whether a controller or processor is subject to GDPR for the relevant processing.4

Record which organization is responsible for the campaign and which other organization handles data for it. If the answer changes between list building, enrichment, sending, and reply handling, assess each processing activity instead of applying one broad label to the whole campaign.

Check the target and activity

A business audience can still involve personal data. Check who is involved and what activity creates the territorial connection.

An organization offering goods or services to individuals in the EU, or processing their data, must comply even when it is based elsewhere.5 Monitoring behavior in the EU includes tracking, retargeting, and behavioral analytics.6 For email, GDPR applies to individually identifiable business contacts in the EU or UK.7

Ask what puts each segment in the audience. It may be where people are located, the service being offered to them, or behavior observed about them. Keep that reason with the campaign record so the scope decision can be checked later.

Trace the processing path

Map where data is collected, accessed, stored, and sent. This keeps territorial scope separate from the question of whether a restricted transfer also exists.

A controller or processor subject to GDPR remains accountable for its processing even when no transfer occurs. This includes a non-EU business collecting personal data directly from people in the EU or traveling employees accessing company systems from third countries.8 For an EU GDPR restricted transfer, the controller or processor linked to the processing activity must be subject to the EU GDPR.9

Ask where the list came from, who can access it, and which organizations handle it during the campaign. A change in hosting or access location does not erase an existing scope decision. It may create a separate transfer question that needs its own review.

When the answer is yes

A positive result hands the campaign into the rest of the privacy review. Territorial scope identifies the regime. The contact decision still needs a separate review.

If any one of the applicability tests is true, GDPR applies.10 GDPR regulates the processing of personal data, including email addresses.11 It requires a legal basis for that processing.12

For B2B cold email, legitimate interest is typically the legal basis when there is a legitimate business reason to contact someone professionally about something relevant to their role.13 Keep that assessment separate from the territorial check, and record why the audience and message fit the stated purpose.

Review the data fields before approval. Personal data should be adequate and relevant to the purpose of its processing, which means checking how much data you need and whether it is the right data for the purpose.14 Send outreach only to people who can benefit from the product.15 Connect the offer to the specifics of the prospect's business.16

What not to do

These mistakes make a scope decision unreliable or leave the campaign with no clear next check.

  • Salespeople using a mobile phone to call European prospects and leads need to consider their GDPR responsibilities.17
  • Include broker-held records in the review. A data broker possessing data from people in the EU should comply with GDPR, which empowers data subjects to request removal.18
  • Encryption does not settle the classification. Encrypted data can still qualify as personal data under GDPR.19
  • Separate the channel choice from the permission decision. GDPR concerns whether the organization has permission to contact people.20

Before approving the next outbound campaign, apply the table to the organization, audience, activity, and processing path. Record the trigger that brought the campaign into review and document its processing route. Then hand the in-scope campaign to the separate legal basis and contact review. If a specific status or requirement remains unclear, consult a lawyer familiar with the regulation.21

Sources

  1. 1
    “However, the GDPR also significantly extended the territorial scope of EEA data protection laws by applying directly to organizations outside the EEA that offer goods or services in the EEA, monitor behavior in the EEA, or process personal data in connection with an EEA establishment.”
  2. 2
    “If you send cold emails to prospects in Europe — or if your company is based there — GDPR applies to you, regardless of where your servers are located.”
  3. 3
    “You’re established in the EU or UK. Office, subsidiary, single employee, doesn’t matter the size.”
  4. 4
    “a controller or a processor is subject to the GDPR for the given processing;”
  5. 5
    “Organizations that offer goods or services to, or process data from, individuals in the EU must comply with GDPR requirements, even if they are not based in the EU themselves.”
  6. 6
    “You monitor the behavior of people in the EU or UK. Tracking, retargeting, behavioral analytics on EU visitors. All of it.”
  7. 7
    “For B2B email marketing to individually identifiable business contacts in the EU or UK, GDPR applies.”
  8. 8
    “The Guidelines emphasise that even if there is no data transfer (e.g., non-EU businesses collecting personal data directly from EU consumers or travelling employees accessing Company systems from third countries), a controller or processor that is subject to GDPR remains accountable for its processing activities generally.”
  9. 9
    “The “exporting” controller or processor must be subject to the GDPR for the given processing.”
  10. 10
    “If any one of them is true, GDPR applies to you:”
  11. 11
    “GDPR regulates how you process personal data — including email addresses.”
  12. 12
    “It requires a legal basis for processing.”
  13. 13
    “For B2B cold email, that basis is typically 'legitimate interest' (Article 6(1)(f)): you have a legitimate business reason to contact someone in a professional capacity about something relevant to their role.”
  14. 14
    ““Under the GDPR, the personal data you collect should be adequate and relevant to the purpose of its processing (Principle c: Data Minimisation). That means you have to consider two key things: the adequacy of your data collection (how much data do you really need for what you are going to achieve) and the relevancy of your data collection (is the data you are collecting the right data for your purposes).””
  15. 15
    “1. Only reach out out to people who can benefit from your product”
  16. 16
    “Breaking that down, any offer you send via cold email should be clearly connected to the specifics of your prospects’ business.”
  17. 17
    “That mobile phone of yours needs electricity - so you need to be aware of your GDPR responsibilities when making sales calls to European prospects and leads.”
  18. 18
    “Furthermore, if the data broker possesses data from people in the European Union, the data broker should comply with the General Data Protection Regulation (GDPR), which empowers data subjects to request the removal of their personal data.”
  19. 19
    “Even encrypted data can fall under this category.”
  20. 20
    “GDPR isn’t just about how you contact people. It’s about whether you have permission to do it.”
  21. 21
    “If you have any specific concerns about your GDPR status or its requirements, consult with a lawyer who’s familiar with the regulation.”