01 · The decisive tests
Headquarters do not settle the question.
EEA establishment
The organisation is based outside the EEA. Check whether it has a stable EEA arrangement connected to this processing before moving to the targeting tests.
Offering goods or services
Look for intentional direction toward people in Norway: market-specific language, currency, delivery, campaigns, customers or other evidence. Payment is not required.
Monitoring behaviour
Ask whether behaviour in Norway is tracked or profiled—for example through persistent online tracking, behavioural analysis or location monitoring.
Mere accessibility
A website that can simply be opened from Norway does not, by itself, prove intentional offering under the EDPB’s guidance.
02 · Sector context
What a legal services operation should map.
A legal services nonprofit commonly handles client identity, matter, correspondence and sensitive case information. Inventory the individual processing activities rather than giving the entire business one territorial answer.
Nonprofit status does not by itself remove GDPR territorial scope, and free services can still satisfy Article 3(2).
03 · If a trigger applies
Turn scope into an operating plan.
- 1Map the processing
Record the people, purposes, data, systems and locations connected to Norway.
- 2Assign controller and processor roles
Article 3 applies to specific processing activities, not just a brand or group label.
- 3Check representative requirements
An organisation caught by Article 3(2) may need a written representative in the Union, subject to Article 27’s limited exceptions.
- 4Operationalise the duties
Choose the records, request handling, breach response and review workflows required for the processing.