GDPR scope depends on the relationship among your organization, the people you target, and the processing behind the outreach. An organization outside the EEA can still fall within it if it offers goods or services in the EEA, monitors behavior there, or processes personal data in connection with an EEA establishment.1 Server location does not decide the question: cold emails to prospects in Europe and a company based there remain within GDPR scope regardless of server location.2 Check territorial scope before you debate the channel or infrastructure. Carry the result into the processing and contact review.
Run the scope check
Follow the campaign from the organization to the people and activity, then through the processing path. End by deciding whether it needs the full GDPR review.
| Stage | What you are trying to learn | Example question |
|---|---|---|
| Establishment | whether the organization has a relevant establishment | Which organization has an establishment connected to this campaign? |
| Audience | whether the people in the target list fall within a territorial trigger | Where do the people in this list live or work? |
| Offer or processing | whether the campaign offers goods or services or processes personal data connected to the target region | Are we offering something or processing data connected to that region? |
| Monitoring | whether the activity observes behavior | Does the campaign track, retarget, or analyze behavior? |
| Processing path | which organization is subject to the processing and whether data crosses a jurisdiction | Who handles the data, and where is it collected, accessed, or sent? |
| Decision | whether any test returns yes | Which answer moves this campaign into GDPR review? |
A yes answers the territorial question. Finish the later rows to document the basis and identify the separate contact checks that follow.
Start with the organization
Name the organization running the campaign and the other actors involved in processing before reviewing the audience or sending method.
An organization established in the EU or UK is within scope, whether that establishment is an office, subsidiary, or single employee.3 The scope test also asks whether a controller or processor is subject to GDPR for the relevant processing.4
Record which organization is responsible for the campaign and which other organization handles data for it. If the answer changes between list building, enrichment, sending, and reply handling, assess each processing activity instead of applying one broad label to the whole campaign.
Check the target and activity
A business audience can still involve personal data. Check who is involved and what activity creates the territorial connection.
An organization offering goods or services to individuals in the EU, or processing their data, must comply even when it is based elsewhere.5 Monitoring behavior in the EU includes tracking, retargeting, and behavioral analytics.6 For email, GDPR applies to individually identifiable business contacts in the EU or UK.7
Ask what puts each segment in the audience. It may be where people are located, the service being offered to them, or behavior observed about them. Keep that reason with the campaign record so the scope decision can be checked later.
Trace the processing path
Map where data is collected, accessed, stored, and sent. This keeps territorial scope separate from the question of whether a restricted transfer also exists.
A controller or processor subject to GDPR remains accountable for its processing even when no transfer occurs. This includes a non-EU business collecting personal data directly from people in the EU or traveling employees accessing company systems from third countries.8 For an EU GDPR restricted transfer, the controller or processor linked to the processing activity must be subject to the EU GDPR.9
Ask where the list came from, who can access it, and which organizations handle it during the campaign. A change in hosting or access location does not erase an existing scope decision. It may create a separate transfer question that needs its own review.
When the answer is yes
A positive result hands the campaign into the rest of the privacy review. Territorial scope identifies the regime. The contact decision still needs a separate review.
If any one of the applicability tests is true, GDPR applies.10 GDPR regulates the processing of personal data, including email addresses.11 It requires a legal basis for that processing.12
For B2B cold email, legitimate interest is typically the legal basis when there is a legitimate business reason to contact someone professionally about something relevant to their role.13 Keep that assessment separate from the territorial check, and record why the audience and message fit the stated purpose.
Review the data fields before approval. Personal data should be adequate and relevant to the purpose of its processing, which means checking how much data you need and whether it is the right data for the purpose.14 Send outreach only to people who can benefit from the product.15 Connect the offer to the specifics of the prospect's business.16
What not to do
These mistakes make a scope decision unreliable or leave the campaign with no clear next check.
- Salespeople using a mobile phone to call European prospects and leads need to consider their GDPR responsibilities.17
- Include broker-held records in the review. A data broker possessing data from people in the EU should comply with GDPR, which empowers data subjects to request removal.18
- Encryption does not settle the classification. Encrypted data can still qualify as personal data under GDPR.19
- Separate the channel choice from the permission decision. GDPR concerns whether the organization has permission to contact people.20
Before approving the next outbound campaign, apply the table to the organization, audience, activity, and processing path. Record the trigger that brought the campaign into review and document its processing route. Then hand the in-scope campaign to the separate legal basis and contact review. If a specific status or requirement remains unclear, consult a lawyer familiar with the regulation.21