Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Fiches
  4. Legal Qualification Decision Tree
Courses Guides Blog Resources News
Français English Nederlands
Fiche 11/54 Part I — General Introduction Intermediate Reviewed 2026-08-23

Legal Qualification Decision Tree

This tool operationalises the mechanics of GDPR applicability. By stepping through four successive tests (Personal Data, Processing, Territorial Nexus, and Actor Role), it enables practitioners to fir

Open in interactive reader
⚖️ Operational Decision Tool 📋 4-Step Analytical Framework

Legal Qualification Decision Tree

⚡ In 30 seconds

Determining GDPR applicability requires answering four sequential questions in strict order: 1. Is personal data present? (Art. 4.1) → 2. Is an operation performed? (Art. 4.2) → 3. Is there an EU nexus? (Art. 3) → 4. What is the actor's role: Controller or Processor? (Art. 4.7/4.8).

Step Assessment Question If YES If NO
Step 1 Does the information relate to an identifiable human? Proceed to Step 2. Out of scope: GDPR does not apply.
Step 2 Is there any operation (collection, storage, query)? Proceed to Step 3. Out of scope: No processing activity.
Step 3 Is there an EU establishment or targeting of EU users? GDPR applies! Proceed to Step 4. Out of scope: No territorial nexus.
Step 4 Who decides why (purposes) and how (essential means)? Controller: Full accountability. Processor: Acts on instructions.
⚡ Key Takeaways
  • A methodical decision flow avoids false assumptions and wasted resources.
  • Controller status is an objective factual determination, not a contract negotiation label.
  • Territorial nexus applies even if the technical servers are hosted overseas.
⚠️ Common Pitfall

Rushing into consent banner design without verifying whether the underlying data is actually personal.

🛠️ In Practice

Run through this tree whenever onboarding a third-party software service into your company ecosystem.

⚖️ Official Sources: Art. 2, 3, 4(1), 4(2), 4(7), 4(8) GDPR · EDPB Guidelines 07/2020 ✓ Legal review: 23 August 2026

✓ Key takeaways

  • Formal sequential validation: Personal Data presence, then Processing operation.
  • Verification of EU territorial nexus (establishment or targeting under Art. 3).
  • Binary structural distinction between Controller status and Processor status.

⚠ Common pitfall: Initiating complex compliance drafting without first establishing whether personal data is actually involved.

→ Actionable practice: Use this structured 4-step tree in project reviews to clarify contractual roles before finalizing architecture diagrams.

← The Risk-Based Approach Practical Case Study: Ecosystem Qualification →