03 Jun Commonly-asked questions no.3 – “What does ‘established’ in the EU or UK mean under GDPR?”
In this series of articles we are unpacking some of the questions that we frequently get asked about the role of data protection representatives.
Here, our director Kym Fletcher answers the question: “What does ‘established’ in the EU/UK mean under GDPR?”
Understanding whether your organisation has an “establishment” in the EU or the UK is crucial when determining its obligations under both the EU GDPR and the UK GDPR. This question is especially important for businesses operating internationally, because the answer will determine whether your organisation is subject to GDPR by virtue of having a local presence, or whether you instead need to appoint an EU Representative, a UK Representative, or both — services that Willans Data Protection Services specialises in providing.
In practice, we often see organisations misjudge this point. For example, a number of non-UK businesses we have advised initially assumed that having a small number of UK-based sales or support staff did not amount to an establishment — only to find that their activities did, in fact, create a sufficient local presence for GDPR purposes.
The GDPR’s definition of an establishment
The GDPR does not offer a simple, one sentence definition of “establishment”. Instead, its meaning comes from several legal sources, including Recital 22 to the GDPR, case law from the Court of Justice of the EU (CJEU), and guidance from the European Data Protection Board (EDPB).
Under Recital 22, an establishment exists where there is “the effective and real exercise of activity through stable arrangements”. The legal form of the arrangement — whether a branch, office, or subsidiary — is not the determining factor.
This means a company can be established in the EU or UK even if it is not legally incorporated there — something that frequently surprises businesses we speak to.
What counts as “stable arrangements”?
The concept is deliberately broad. The GDPR emphasises that establishment “implies the effective and real exercise of activity”, not merely a physical office.
In practice, stable arrangements can include:
- a registered office
- a branch or subsidiary
- a physical office or team
- staff or agents who carry out regular activities
- any ongoing operations showing that the organisation conducts business from within the region.
The key question is whether your organisation is genuinely carrying out business activities in the EU or UK through some form of ongoing presence.
In our work with clients, we often see grey areas here. For instance, one overseas technology company we supported had no formal UK entity, but had posted a member of staff to the UK, who was working from his apartment whilst ‘kick starting’ the client’s UK operations. In that case, the regulator would be unlikely to view those arrangements as sufficiently “stable” to constitute an establishment, at least for the time being.
The role of “central administration” and decision making
The GDPR and later EDPB guidance clarify that central administration (where an organisation’s management decisions are made) is a major factor in identifying an establishment. The CJEU and EDPB highlight that the place where decisions about the purposes and means of processing personal data are made is highly relevant.
Similarly, the EDPB (via Opinion 04/2024) states that a location can only be viewed as a main establishment if it both:
- makes decisions about how and why personal data is processed, and
- has the power to implement these decisions
Although this opinion focuses on the “main establishment” concept used for one-stop-shop purposes (i.e. which country’s regulator has jurisdiction for enforcement), it reinforces the same principle: decision-making authority matters.
We regularly advise clients who initially focus on where their company is registered, rather than where decisions are actually being made in practice. In some cases, organisations have senior leadership or operational decision-makers based in the UK or EU, which can significantly affect the analysis.
Does having infrastructure or staff in the EU/UK automatically make you established?
Not necessarily.
GDPR Recital 36 notes that having technical infrastructure (e.g., servers) in a region is not determinative of a ‘main establishment’ (and regulators would likely take the same view in relation to ‘establishment’ more generally), though it may form part of the overall picture.
Likewise, having occasional activities, isolated staff, or merely serving customers in the EU/UK does not automatically create an establishment.
That said, we often encounter prospective clients who assume that any in-region presence automatically triggers establishment — and others who assume the exact opposite. The reality is more nuanced: regulators look at substance over form, assessing whether there is meaningful, ongoing activity in the region.
Examples of when an organisation is likely to have an establishment
You are likely to be considered established in the EU/UK if you:
- maintain an office, branch, or subsidiary that carries out business operations
- employ personnel who regularly carry out work for the company from within the region
- base your senior management or decision-making functions in an EU/UK location
- coordinate European or UK commercial activities from a local base.
We have seen a number of cases where organisations initially approached us for Representative services, only for it to become clear during discussions that they already had an establishment — meaning their compliance obligations were different from what they expected.
When you are not considered established
If your organisation:
- has no physical base, branch, or stable presence in the EU/UK
- makes all data-processing decisions outside the region
- operates internationally without staff or meaningful operations in Europe or the UK
…then you are not considered established under GDPR.
This is often the position for many of the international clients we support, particularly those headquartered in the US or Asia with purely cross-border services.
In this case, if you process or monitor the data of individuals located in the EU or UK, you will generally need to appoint an EU Representative, UK Representative, or both — which is precisely the role that Willans Data Protection Services provides.
As a data controller, engaging a data processor in the EU or UK does not, by itself, mean that you are “established” in that jurisdiction for GDPR purposes. The concept of establishment focuses on the controller’s own activities — specifically whether it exercises “effective and real activity through stable arrangements” in the EU or UK. Simply appointing a processor (for example, a payroll provider, outsourced service partner, or clinical research organisation (if you are an overseas trial sponsor)) does not create a local presence for you, because your processor is acting on your behalf, rather than forming part of your organisational structure or business operations.
That said, in practice, the relationship should still be assessed carefully. If the arrangements go beyond a typical processor engagement — for example, if the processor effectively acts as a long-term operational base, with dedicated staff or resources closely integrated into your business, or if elements of decision-making begin to be exercised in-region — regulators may look more closely at the substance of the arrangement. However, in the vast majority of cases we see in practice, engaging an EU or UK processor (in isolation) does not amount to an establishment, and the controller will instead need to consider its obligations under Article 3(2), including whether it must appoint an EU or UK GDPR Representative.
Why does the definition of establishment matter so much?
Because it determines:
- whether the GDPR applies due to local presence, or due to the targeting rules under Article 3(2)
- which supervisory authority will oversee your activities
- whether your organisation can rely on the one-stop-shop mechanism (available only where you have an EU main establishment)
- whether you need to appoint an EU/UK GDPR Representative
Even small signs of local activity can change your obligations. From our experience, this is one of the most common areas where businesses either over-comply or under-comply, simply because the concept of “establishment” is misunderstood.
Conclusion
In GDPR terms, an “establishment” does not simply mean having a registered company or office. It means a real and stable presence from which your organisation carries out activities — particularly those related to decision-making and ongoing operations. In practice, regulators will assess the existence of an establishment pragmatically rather than formalistically.
For any organisation based outside the EU or UK, determining whether an establishment exists is a crucial first step. In our experience working with clients and prospects across a range of sectors, this assessment often requires a careful, fact-specific review rather than a simple yes/no answer.
If no such establishment exists, you will very likely require an EU Representative, a UK Representative, or both, to comply with GDPR — and this is exactly what Willans Data Protection Services helps organisations around the world to achieve.
If you think you may need to appoint a Representative in the EU and/or UK, please contact us.