How it works What We Check Pricing Articles About Free Scan →
Territorial scope · Part 1 of 5

Where your customers are is where your obligations are

Every major data protection law defines its reach by where the individual is — not by where you are incorporated, and not by whether you hold anything there. Here is what the six scope provisions actually say.

By the Sitetals research team· Published 27 August 2026· Updated 27 August 2026· 8 min read min read· All articles

The short version

There is a reasonable-sounding argument that a lot of founders outside Europe make, and it goes like this: my company is in Hong Kong, my bank is in Hong Kong, I have never set foot in the EU, and there is nothing there to take. Whatever Brussels writes has nothing to do with me.

The first four clauses are true. The conclusion does not follow from them, and the reason is narrow and specific.

Two questions that get collapsed into one

Can a regulator practically collect from me? That is the enforcement question, and the answer genuinely does depend on where your assets are. Does this law describe my business? That is the application question, and it is decided by the statute’s own scope provision — which, in every regime below, is written about where the individual is. The second question is the one that determines what your website is supposed to say and do.

So set enforcement aside for a moment. Start with application — because application is the half that determines what your site is supposed to contain, and it is knowable today, from public text, without a lawyer and without speculation.

This is compliance research, not legal advice. Sitetals is an independent website scanner, not a law firm, and is not affiliated with any data protection authority. Whether a particular law applies to a particular business is a question of fact and law that turns on that business’s own circumstances. Nothing here is a determination that any reader is subject to, or in breach of, anything. For a decision that carries risk, take advice from a practitioner qualified in the jurisdiction concerned.

What the scope provisions actually say

These are the territorial-scope provisions of six regimes, quoted or tightly paraphrased from the instruments themselves. Read what each one attaches to. The drafting styles have nothing in common; the structure does.

RegimeWhat triggers itWhat it does not ask
GDPR
EU / EEA
Art. 3(2): offering goods or services to data subjects who are in the Union, irrespective of whether payment is required — or monitoring their behaviour as far as it takes place in the Union.Where you are established. Whether you hold EU assets. Whether you have EU staff.
UK GDPR
United Kingdom
Art. 3: the same two limbs, applied to people in the United Kingdom.The same.
PDPA
Singapore
ss. 2 and 4: obligations attach to an organisation collecting, using or disclosing personal data in Singapore.Whether you are formed or recognised under Singapore law, resident there, or have an office there.
LGPD
Brazil
Art. 3(II): processing whose purpose is offering or supplying goods or services to, or processing the data of, individuals located in national territory.The country of your headquarters, or where the data is held.
CCPA / CPRA
California
§ 1798.140(d): doing business in California and meeting one of three thresholds: revenue, volume of consumers, or share of revenue from selling or sharing personal information.Physical presence in California.
PIPL
China
Art. 3: processing carried out outside China for the purpose of providing products or services to natural persons within China, or analysing their behaviour.Whether you have a Chinese entity.

Sources for every provision in this table are listed at the foot of the article, each pointing at the text published by the body that made the law.

Two details in the European wording that do most of the work

“Irrespective of whether a payment is required.” A free tool, a newsletter, a waitlist or a lead form counts. Revenue is not the trigger; the offering is.

Mere accessibility is not enough — but configuration is evidence. Recital 23 is explicit that a website simply being reachable from the Union does not by itself establish an intention to offer services there. It then names what does bear on it: using a language or a currency generally used in one or more Member States with the possibility of ordering in that language, and mentioning customers or users who are in the Union.

Why this cuts both ways

Recital 23 protects businesses that genuinely do not target the Union: being reachable is not enough, and a regulator cannot infer an offering from accessibility alone. It also means the indicators it does name — language, currency, ordering in that language, naming customers there — are worth knowing about, because they are the ones you put on the page yourself.

Why “no assets there” answers a different question

The “nothing to seize” argument treats a data protection obligation like a debt: if the creditor cannot reach your bank account, the debt is theoretical. That framing does not map onto how these regimes are built, for two reasons that have nothing to do with fines.

Obligations run to your users, not only to a regulator. Access, correction and deletion rights are exercised by individuals directly against you. The request arrives in your inbox from a customer, not from an authority, and whether you can answer it is a question about your own systems — one you answer at your own cost either way.

Your intermediaries are established where you are not. Payment processors, app stores, advertising platforms and marketplaces operate under these regimes and pass the requirements down through their own terms. In practice, the first consequence most small operators meet is a platform request, not a regulatory one.

None of that is a prediction about what will happen to you. It is a description of what the instruments say and how they reach the people who use them, which is the thing worth knowing before deciding it does not concern you.

How to find out which ones describe you

You do not need a lawyer for the first pass, because the first pass is factual. Your website already publishes the answer in its own source code, and all five of these are your own configuration rather than anyone’s opinion about you.

What to look atWhy it bears on scope
Which currencies you quoteRecital 23 names currency as an indicator that an offering is envisaged.
Which languages you declareAn hreflang tag naming a language is a published statement about who you expect to read the page.
Which countries a customer can chooseA shipping or billing dropdown is a list of the places you are willing to serve.
Which payment methods are mountedRails such as SEPA, IDeal, Bancontact or PayNow exist to take money from people in specific places.
What loads before anyone consentsAnalytics and advertising tags fire from your page source. “Monitoring of behaviour” is a description of what they do.

Read your own homepage source and you will have most of the answer in ten minutes. That is not a figure of speech — every item above is visible in the HTML your server sends to any visitor, which is the same thing a complainant, a platform reviewer or a supervisory authority would look at.

Check what your own site publishes

Sitetals reads the public pages of your website and reports the compliance basics it can see from the outside — privacy policy, legal notice, cookie and consent essentials — for Singapore, France and Germany. It is a reading of what your site publishes, not a finding of breach. The country-by-country mapping in this article is something to work through yourself with the table above.

Run a free compliance check

Free, no account required. We do not store personal data from scanned sites.

What this article is not

It is not a determination that any particular business is subject to any particular law, and it is not legal advice. Territorial scope turns on facts about a specific operation — who the customers actually are, what is actually processed, what the thresholds actually come to — and those facts are yours, not ours.

What we can do is set out what the tests are and point at where the evidence lives, which is on your own domain.

If the mapping in this article looks like it might describe your business, the useful next step is not to worry about it. It is to establish which of these regimes your configuration engages, and then decide, deliberately, what to do about each one. That decision is a reasonable one to take either way. Taking it without knowing the mapping is the part worth fixing.

Sources

Series, part 2Your checkout already told them which countries you serveSingaporePDPA for foreign businesses with no Singapore officeSingaporeThe PDPA website health check, 2026
Sitetals research team. Sitetals is an independent website compliance scanner operated by QuikForge Limited. We read what a website publishes about itself and report the obligations its own configuration engages. Every statutory provision quoted in this article was checked against the official text published by the legislature or regulator that made it, and the source of each is listed at the foot of the article. Corrections: hello@sitetals.com.