Short Reads

Countdown 10 weeks until GDPR : Does the GDPR apply to any organization controlling or processing data of an EU resident?

Stibbe - Does the GDPR apply to any organization controlling or

Countdown 10 weeks until GDPR : Does the GDPR apply to any organization controlling or processing data of an EU resident?

15.03.2018 EU law

Only 10 more weeks to go before the GDPR becomes fully effective. Preparing your company for the application of this new regulation requires a correct understanding of its principles. Each week, we highlight one particular misconception regarding the interpretation of the GDPR.

Does the GDPR apply to any organization controlling or processing data of an EU resident?

Although the territorial scope of application of the GDPR is defined rather broadly, it does not apply to any organization controlling or processing data of an EU resident. In fact, Article 3 of the GDPR lays down several criteria or connecting factors for its application.

Firstly, if a controller or a processor has an establishment in the EU whose activities include the processing of personal data, then the GDPR applies to that controller or processor. This is irrespective of whether the actual data processing takes place in the EU or not.

Secondly, if the controller or processor is not established in the EU but processes personal data of data subjects who are in the EU (i.e., also data subjects who are non-EU residents but find themselves in the EU), then the GDPR applies to that controller or processor if it offers goods or services to those data subjects in the EU, whether in return for payment or not, or if it monitors data subjects’ behaviour taking place within the EU.

Thirdly, the GDPR also applies to personal data processing by a controller who is not established in the EU but in a place where Member State law applies by virtue of public international law, such as in a Member State's diplomatic mission or consular post outside the EU.

 

Stibbe, together with Chiomenti, Cuatrecasas, GIDE and Gleiss Lutz, have gathered this useful information, reflecting some common misconceptions about the implementation of the GDPR.

Team

Related news

06.06.2019 BE law
TMT Roundtable: Getting a handle on software quality

Roundtable - Erik Valgaeren, TMT Partner at Stibbe Brussels, and his team organize a roundtable on software quality in our Brussels office on June 6th, 2019. Software quality is a recurring theme in many matters handled by our TMT team. Whether our assistance relates to preparing tender documents, contracting effectively, assessing proper performance or allocating ownership and accountability in challenging IT projects, questions concerning software quality always arise.

Read more

24.05.2019 EU law
One year of GDPR - The regulatory warm-up

Short Reads - The first year of the General Data Protection Regulation ("GDPR") is over. Although early noises predicted an entirely new data protection regime, the European legal framework did not change substantially, the major changes being an expansion of the territorial scope to non-EU countries and stronger powers of enforcement. In spite of fears and rumours of immediate enforcement and huge fines, most regulators focused on helping companies achieve compliance, or they enforced without directly imposing fines.

Read more

21.05.2019 EU law
Part one - GDPR and Public Law - Applicability of GDPR to public bodies

Articles - Since the GDPR became applicable almost one year ago, multiple questions have arisen about its interaction with other fields of law. In this three-part blog series of “GDPR and Public Law”, we discuss three relevant issues of the interaction of GDPR with public law and government. In this blog we discuss the applicability of GDPR to public bodies.

Read more

Our website uses functional cookies for the functioning of the website and analytic cookies that enable us to generate aggregated visitor data. We also use other cookies, such as third party tracking cookies - please indicate whether you agree to the use of these other cookies:

Privacy – en cookieverklaring