The classic trap
Recital 23 clarifies Article 3(2)(a) on the targeting criterion. The CNPD and CNIL regularly sanction non-EU companies (US, UK post-Brexit, Switzerland, Asia) that thought they escaped the GDPR because they had no EU office. The trap: an e-commerce site accepting euros, delivering to Luxembourg or displaying a Brussels client testimonial is enough to trigger territorial application, hence the obligation to appoint an Article 27 representative, maintain a record of processing, and potentially notify a breach to the CNPD.
Targeting indicators that trigger the GDPR under recital 23
The EDPB (Guidelines 3/2018 on territorial scope) consolidated the criteria. The following do not establish targeting:
- Mere accessibility of the site from the EU
- An email address or contact form being reachable
- Use of English when the company is based in the US or UK
The following, however, establish targeting (bundle of indicators):
- Prices displayed in euros or option to pay in EUR
- French, German or Luxembourgish version of the site while the company sits outside the EU
- Delivery offered to Member States, mention of intra-EU VAT
- Google Ads or Meta campaigns geographically targeted at EU countries
- European customer testimonials, local references, attendance at EU trade shows
- .lu, .fr, .de, .eu domain or localized SEO
- Phone number with European international prefix
Why this also concerns Luxembourg groups
Symmetrically, many Luxembourg holdings own non-EU subsidiaries (Delaware, Singapore, Jersey, Cayman) that process European customer data. Recital 23 requires qualifying each group entity against the targeting criterion, regardless of its registered office. A Delaware entity invoicing Luxembourg clients in euros is subject to the GDPR, must appoint an Article 27 representative in the EU and appear in the group record of processing.
How Luxgap automates this risk
Our Luxgap Targeting Radar answers the question "am I subject to the GDPR?" for your non-EU subsidiaries within 48h, without interviewing legal. A specialized AI agent automatically scans your websites, Stripe and Adyen payment flows, Google Ads and Meta Business campaigns, Salesforce and Hubspot CRM exports, then applies the EDPB 3/2018 grid indicator by indicator to produce a defensible EU targeting score.
- Scans your public websites and detects EU targeting indicators: displayed currency, languages, shipping options, legal notices, phone prefixes, domains and hreflang tags.
- Analyzes your Google Ads, Meta Business and LinkedIn campaigns to identify geographic audiences actually targeted in the EEA, even when marketing claims "we don't target Europe".
- Cross-references your Stripe, Adyen, PayPal and SAP transactions to detect the real share of EU customers per subsidiary and per month, and alerts as soon as a trigger threshold is crossed.
- Classifies each group entity as "out of scope", "marginal targeting to monitor" or "clear targeting - Article 3(2) triggered", with a written justification usable before the CNPD.
- Automatically generates the prefilled Article 27 representative mandate for triggered entities, with Luxgap contact details if you appoint us.
- Produces a timestamped, cryptographically sealed PDF report, defensible in a CNPD audit, demonstrating that the territorial scope analysis was conducted seriously.
Available as a complement to a Luxgap DPO mandate or as a standalone SaaS module depending on your group perimeter. Request a tailored quote and our teams will prepare a demonstration on your actual subsidiaries, with a free 48h scan to map your territorial exposure before any engagement.