GDPR's extraterritorial reach is one of its most misunderstood features. A fund headquartered outside the EU that processes personal data belonging to someone in the EU — including for something like founder diligence ahead of an investment — can still fall within GDPR's scope for that specific activity, under Article 3.
This surprises a lot of non-EU investors who assume the regulation is a purely European-market concern. It isn't. If the founder being checked is an EU data subject, the processing of their personal data is potentially covered regardless of where the fund itself is based.
In practice, this means a US or UK fund building an informal dossier on a founder in Amsterdam or Warsaw carries the same underlying exposure as a fund physically in the EU would. The founder's location is what matters, not the investor's.
This is general information about GDPR's territorial scope, not a jurisdiction-specific legal opinion.
See how a consent-based check actually works.