The classic trap
Recital 22 extends the GDPR to any processing carried out in the context of the activities of an establishment in the Union, even if the technical processing takes place elsewhere. The CNPD and CNIL regularly sanction groups that believed they escaped the GDPR because their servers or parent company were in the United States: as soon as a Luxembourg subsidiary, branch or representative office carries out real activity linked to the processing (sales, support, recruitment), the GDPR applies in full. The Google Spain ruling (CJEU C-131/12) and the Weltimmo ruling (C-230/14) sealed this broad reading.
The establishment test: 3 cumulative criteria to document
- Stable arrangement: lasting physical or organisational presence, even minimal (a single sales representative with a LU bank account is enough under Weltimmo).
- Effective and real exercise: genuine activity, not a shell. A mailbox address is not enough, but a team of 2 people generating revenue is.
- Link with the processing: the processing must be carried out in the context of the activities of that establishment (functional and economic link, not necessarily technical).
- The legal form is irrelevant: branch, subsidiary, representative office, joint venture, it does not matter.
- Direct consequence: a US group with a mere commercial branch in Luxembourg becomes accountable to the CNPD for all processing linked to European activity, including those operated from Californian servers.
The blind spot of international groups
The most common pitfall: a group appoints a global DPO at headquarters (London, New York, Singapore) and forgets to map the EU establishments that trigger territorial applicability. Result: the Article 30 record ignores dozens of processing activities that are nonetheless subject to the GDPR, and the CNPD demands the missing documentation during an audit.
How Luxgap automates this risk
Our Luxgap Territorial Scope Mapper eliminates the blind spot of territorial applicability by automatically mapping all your group's EU establishments and qualifying each processing activity against Recital 22. The tool cross-references your European trade register data (RCSL, RCS, KBO, Handelsregister), your consolidated accounting flows (Sage, SAP, Workday), your Bamboo HR / Personio employment contracts and your public DNS signatures to identify the stable arrangements your legal department is unaware of, without asking the DPO to fill in a single Excel spreadsheet.
- Automatically detects each EU establishment of your group via official registers (RCSL in Luxembourg, RCS in France, KBO in Belgium, Handelsregister in Germany) and consolidated payroll flows.
- Qualifies each entity according to the Weltimmo and Google Spain criteria: stable arrangement, real activity, functional link with the processing.
- Generates a processing x establishment matrix that demonstrates why each processing falls (or does not fall) under the GDPR, with the legal reasoning ready for the CNPD.
- Alerts in real time as soon as a new EU entity is created in the group or a sales representative is hired in a new country, triggering automatic perimeter updates.
- Produces a time-stamped PDF report, cryptographically sealed, enforceable before the CNPD, documenting the territorial perimeter of the GDPR applicable to your group.
- Identifies cases where an EU representative (Article 27) is mandatory for non-EU entities targeting the European market.
Available as a complement to a Luxgap DPO mandate or as a dedicated SaaS module depending on your perimeter. Request a personalised quote and our teams will prepare a demonstration on your group's actual structure, with a free white audit within 48 hours to measure your territorial exposure before any commitment.