Short Reads

Countdown 10 weeks until GDPR : Does the GDPR apply to any organization controlling or processing data of an EU resident?

Stibbe - Does the GDPR apply to any organization controlling or

Countdown 10 weeks until GDPR : Does the GDPR apply to any organization controlling or processing data of an EU resident?

15.03.2018 EU law

Only 10 more weeks to go before the GDPR becomes fully effective. Preparing your company for the application of this new regulation requires a correct understanding of its principles. Each week, we highlight one particular misconception regarding the interpretation of the GDPR.

Does the GDPR apply to any organization controlling or processing data of an EU resident?

Although the territorial scope of application of the GDPR is defined rather broadly, it does not apply to any organization controlling or processing data of an EU resident. In fact, Article 3 of the GDPR lays down several criteria or connecting factors for its application.

Firstly, if a controller or a processor has an establishment in the EU whose activities include the processing of personal data, then the GDPR applies to that controller or processor. This is irrespective of whether the actual data processing takes place in the EU or not.

Secondly, if the controller or processor is not established in the EU but processes personal data of data subjects who are in the EU (i.e., also data subjects who are non-EU residents but find themselves in the EU), then the GDPR applies to that controller or processor if it offers goods or services to those data subjects in the EU, whether in return for payment or not, or if it monitors data subjects’ behaviour taking place within the EU.

Thirdly, the GDPR also applies to personal data processing by a controller who is not established in the EU but in a place where Member State law applies by virtue of public international law, such as in a Member State's diplomatic mission or consular post outside the EU.

 

Stibbe, together with Chiomenti, Cuatrecasas, GIDE and Gleiss Lutz, have gathered this useful information, reflecting some common misconceptions about the implementation of the GDPR.

Team

Related news

02.10.2019 EU law
Seminar: Data protection implications of (a no-deal) Brexit

Seminar - On October 2nd at 4 pm, we organize a seminar where we will discus the implications of a (no-deal) Brexit on data protection.  These issues affect all businesses interacting between UK and EEA (including EU) and which send or receive data to and from UK. We will highlight the main challenges both in the case of a hard Brexit on 31 October 2019 and in other scenarios. We will also offer guidelines to help your organisation mitigate the respective risks.

Read more

19.08.2019 EU law
Enable “likes” and bear joint-controllership

Articles - The Court of Justice of the European Union recently ruled, in Case C-40/14 Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV,  that a website operator that features “Like” social-media plugin from Facebook likely qualifies as joint-controller with Facebook for its website visitors’ personal data collection and transmission to Facebook.

Read more

28.08.2019 NL law
Masterclass: e-signature and electronic identifiers

Masterclass - Stibbe is organising a Masterclass on 26 September 2019 in Amsterdam on the subject of e-signature and electronic identifiers. This Masterclass will cover the legal framework and focus especially on the numerous possibilities for applying the various electronic signatures in different situations. In addition, we explain the regulations governing electronic identifiers, and the mandatory European recognition they receive.

Read more

Our website uses functional cookies for the functioning of the website and analytic cookies that enable us to generate aggregated visitor data. We also use other cookies, such as third party tracking cookies - please indicate whether you agree to the use of these other cookies:

Privacy – en cookieverklaring