Short Reads

Countdown 10 weeks until GDPR : Does the GDPR apply to any organization controlling or processing data of an EU resident?

Stibbe - Does the GDPR apply to any organization controlling or

Countdown 10 weeks until GDPR : Does the GDPR apply to any organization controlling or processing data of an EU resident?

15.03.2018 EU law

Only 10 more weeks to go before the GDPR becomes fully effective. Preparing your company for the application of this new regulation requires a correct understanding of its principles. Each week, we highlight one particular misconception regarding the interpretation of the GDPR.

Does the GDPR apply to any organization controlling or processing data of an EU resident?

Although the territorial scope of application of the GDPR is defined rather broadly, it does not apply to any organization controlling or processing data of an EU resident. In fact, Article 3 of the GDPR lays down several criteria or connecting factors for its application.

Firstly, if a controller or a processor has an establishment in the EU whose activities include the processing of personal data, then the GDPR applies to that controller or processor. This is irrespective of whether the actual data processing takes place in the EU or not.

Secondly, if the controller or processor is not established in the EU but processes personal data of data subjects who are in the EU (i.e., also data subjects who are non-EU residents but find themselves in the EU), then the GDPR applies to that controller or processor if it offers goods or services to those data subjects in the EU, whether in return for payment or not, or if it monitors data subjects’ behaviour taking place within the EU.

Thirdly, the GDPR also applies to personal data processing by a controller who is not established in the EU but in a place where Member State law applies by virtue of public international law, such as in a Member State's diplomatic mission or consular post outside the EU.

 

Stibbe, together with Chiomenti, Cuatrecasas, GIDE and Gleiss Lutz, have gathered this useful information, reflecting some common misconceptions about the implementation of the GDPR.

Team

Related news

02.07.2019 NL law
Debate night: HR Analytics: opportunity or threat?

Seminar - On 2 July 2019, Stibbe's Digital Economy Group will host a debate night in Amsterdam on the hot topic of HR analytics. During Stibbe's debate night, speakers from the world of business, politics, science and law will exchange views on HR analytics, how they can be used in practice, and their development in the context of employment and privacy law.

Read more

15.07.2019 EU law
ICO to impose record-breaking fines for inadequate security measures and data breaches

Short Reads - Though the European data protection authorities have taken their time in enforcing the GDPR, two announcements by the ICO in the UK regarding proposed fines for British Airways and Marriott demonstrate that large fines are about to start landing regularly. Both of the substantial fines are to be handed out as a result of shortcomings in handling data breaches caused by cyber-attacks.

Read more

27.06.2019 NL law
Stibbe launches website about Digital Economy

Inside Stibbe - Stibbe's Digital Economy group published a new website this week: Stibbedigital.com With this new website we aim to view technological developments including artificial intelligence (AI), blockchain, the Internet of Things, smart mobility and the rise of digital platforms from a legal perspective.

Read more

05.07.2019 EU law
The two sides of the ECS coin

Articles - The concept of ‘electronic communications service’ (“ECS”) defined in Article 2(c) of Directive 2002/21/EC (“Framework Directive”) has been interpreted in two decisions of the ECJ in June 2019: C‑142/18 Skype communications and C-193/18 Google LLC.

Read more

21.06.2019 NL law
Nieuw boetebeleid van de Autoriteit Persoonsgegevens

Short Reads - Op 14 maart 2019 zijn de nieuwe Boetebeleidsregels Autoriteit Persoonsgegevens 2019 ("Boetebeleidsregels") van de Autoriteit Persoonsgegevens ("AP") gepubliceerd. Dit boetebeleid heeft de AP opgesteld vanwege de inwerkingtreding van de Algemene verordening gegevensverwerking ("AVG") en omdat er op Europees niveau nog geen boeterichtsnoeren zijn opgesteld.

Read more

Our website uses functional cookies for the functioning of the website and analytic cookies that enable us to generate aggregated visitor data. We also use other cookies, such as third party tracking cookies - please indicate whether you agree to the use of these other cookies:

Privacy – en cookieverklaring