GDPR · ART 3IT / RO

Does GDPR apply to an insurance enterprise in Italy serving Romania?

Based inItaly
ServesRomania
Sectorinsurance
Typeenterprise
LIKELY

Short answer

GDPR is likely in scope through the EEA establishment test.

Article 3(1) covers processing carried out in the context of an EEA establishment, even when the processing itself happens elsewhere. Confirm which establishment is connected to the processing rather than relying only on where servers or staff sit.

01 · The decisive tests

Headquarters do not settle the question.

01

EEA establishment

Italy is an EEA state. Determine whether this processing takes place in the context of the organisation’s establishment there.

Primary route
02

Offering goods or services

Look for intentional direction toward people in Romania: market-specific language, currency, delivery, campaigns, customers or other evidence. Payment is not required.

Still relevant
03

Monitoring behaviour

Ask whether behaviour in Romania is tracked or profiled—for example through persistent online tracking, behavioural analysis or location monitoring.

Check activity
04

Mere accessibility

A website that can simply be opened from Romania does not, by itself, prove intentional offering under the EDPB’s guidance.

Not enough alone

02 · Sector context

What a insurance operation should map.

A insurance enterprise commonly handles policyholder, claimant, health, financial and risk information. Inventory the individual processing activities rather than giving the entire business one territorial answer.

Separate the group’s EEA establishments, controllers and processors instead of treating the whole group as one processing operation.

03 · If a trigger applies

Turn scope into an operating plan.

  1. 1
    Map the processing

    Record the people, purposes, data, systems and locations connected to Romania.

  2. 2
    Assign controller and processor roles

    Article 3 applies to specific processing activities, not just a brand or group label.

  3. 3
    Check representative requirements

    An organisation caught by Article 3(2) may need a written representative in the Union, subject to Article 27’s limited exceptions.

  4. 4
    Operationalise the duties

    Choose the records, request handling, breach response and review workflows required for the processing.

04 · Common questions

Questions for this scenario.

Does being based in Italy keep this organisation outside GDPR?+

No. Italy is in the EEA, so processing connected to an establishment there can fall under the establishment test in Article 3(1).

Does a service need to be paid for before GDPR can apply in Romania?+

No. Article 3(2)(a) expressly covers an offering of goods or services whether or not payment by the person is required.

Does operating in insurance decide territorial scope?+

No. Sector alone is not an Article 3 trigger. It changes the kinds and risks of data involved—such as policyholder, claimant, health, financial and risk information—but establishment, offering and monitoring facts decide territorial scope.

Primary material

Read the source,
not only the summary.

Knowing the rule is the start.

Make the interpretation
repeatable.