GDPR · ART 3US / DE

Does GDPR apply to a SaaS company in United States serving Germany?

Based inUnited States
ServesGermany
SectorSaaS
Typecompany
CHECK

Short answer

GDPR may apply if the activity intentionally targets or monitors people in Germany.

Article 3(2) can reach an organisation outside the EEA when its processing relates to offering goods or services to people in the EEA, whether paid or free, or monitoring their behaviour there. A website merely being reachable from Germany is not enough on its own; targeting and the processing activity matter.

01 · The decisive tests

Headquarters do not settle the question.

01

EEA establishment

The organisation is based outside the EEA. Check whether it has a stable EEA arrangement connected to this processing before moving to the targeting tests.

Check facts
02

Offering goods or services

Look for intentional direction toward people in Germany: market-specific language, currency, delivery, campaigns, customers or other evidence. Payment is not required.

Primary route
03

Monitoring behaviour

Ask whether behaviour in Germany is tracked or profiled—for example through persistent online tracking, behavioural analysis or location monitoring.

Check activity
04

Mere accessibility

A website that can simply be opened from Germany does not, by itself, prove intentional offering under the EDPB’s guidance.

Not enough alone

02 · Sector context

What a SaaS operation should map.

A SaaS company commonly handles account profiles, product usage, support conversations and billing contacts. Inventory the individual processing activities rather than giving the entire business one territorial answer.

Company size does not decide territorial scope. The establishment, offering and monitoring tests still control.

03 · If a trigger applies

Turn scope into an operating plan.

  1. 1
    Map the processing

    Record the people, purposes, data, systems and locations connected to Germany.

  2. 2
    Assign controller and processor roles

    Article 3 applies to specific processing activities, not just a brand or group label.

  3. 3
    Check representative requirements

    An organisation caught by Article 3(2) may need a written representative in the Union, subject to Article 27’s limited exceptions.

  4. 4
    Operationalise the duties

    Choose the records, request handling, breach response and review workflows required for the processing.

04 · Common questions

Questions for this scenario.

Does being based in United States keep this organisation outside GDPR?+

Not necessarily. Article 3(2) can apply to an organisation outside the EEA when relevant processing concerns intentionally offering goods or services to people in the EEA or monitoring their behaviour there.

Does a service need to be paid for before GDPR can apply in Germany?+

No. Article 3(2)(a) expressly covers an offering of goods or services whether or not payment by the person is required.

Does operating in SaaS decide territorial scope?+

No. Sector alone is not an Article 3 trigger. It changes the kinds and risks of data involved—such as account profiles, product usage, support conversations and billing contacts—but establishment, offering and monitoring facts decide territorial scope.

Primary material

Read the source,
not only the summary.

Knowing the rule is the start.

Make the interpretation
repeatable.