GDPR · ART 3DE / BG

Does GDPR apply to a cybersecurity nonprofit in Germany serving Bulgaria?

Based inGermany
ServesBulgaria
Sectorcybersecurity
Typenonprofit
LIKELY

Short answer

GDPR is likely in scope through the EEA establishment test.

Article 3(1) covers processing carried out in the context of an EEA establishment, even when the processing itself happens elsewhere. Confirm which establishment is connected to the processing rather than relying only on where servers or staff sit.

01 · The decisive tests

Headquarters do not settle the question.

01

EEA establishment

Germany is an EEA state. Determine whether this processing takes place in the context of the organisation’s establishment there.

Primary route
02

Offering goods or services

Look for intentional direction toward people in Bulgaria: market-specific language, currency, delivery, campaigns, customers or other evidence. Payment is not required.

Still relevant
03

Monitoring behaviour

Ask whether behaviour in Bulgaria is tracked or profiled—for example through persistent online tracking, behavioural analysis or location monitoring.

Check activity
04

Mere accessibility

A website that can simply be opened from Bulgaria does not, by itself, prove intentional offering under the EDPB’s guidance.

Not enough alone

02 · Sector context

What a cybersecurity operation should map.

A cybersecurity nonprofit commonly handles user, device, network, threat and incident information. Inventory the individual processing activities rather than giving the entire business one territorial answer.

Nonprofit status does not by itself remove GDPR territorial scope, and free services can still satisfy Article 3(2).

03 · If a trigger applies

Turn scope into an operating plan.

  1. 1
    Map the processing

    Record the people, purposes, data, systems and locations connected to Bulgaria.

  2. 2
    Assign controller and processor roles

    Article 3 applies to specific processing activities, not just a brand or group label.

  3. 3
    Check representative requirements

    An organisation caught by Article 3(2) may need a written representative in the Union, subject to Article 27’s limited exceptions.

  4. 4
    Operationalise the duties

    Choose the records, request handling, breach response and review workflows required for the processing.

04 · Common questions

Questions for this scenario.

Does being based in Germany keep this organisation outside GDPR?+

No. Germany is in the EEA, so processing connected to an establishment there can fall under the establishment test in Article 3(1).

Does a service need to be paid for before GDPR can apply in Bulgaria?+

No. Article 3(2)(a) expressly covers an offering of goods or services whether or not payment by the person is required.

Does operating in cybersecurity decide territorial scope?+

No. Sector alone is not an Article 3 trigger. It changes the kinds and risks of data involved—such as user, device, network, threat and incident information—but establishment, offering and monitoring facts decide territorial scope.

Primary material

Read the source,
not only the summary.

Knowing the rule is the start.

Make the interpretation
repeatable.