欧盟-GDPR适用地域指南(英文)28页_587kb
报告摘要
GDPR Guidelines on Territorial Scope (Article 3) - Summary
Core Content
These guidelines, adopted by the European Data Protection Board (EDPB), clarify the territorial scope of the General Data Protection Regulation (GDPR) under Article 3, which determines when the GDPR applies to data processing activities. The document outlines the application of two main criteria – the "establishment" criterion (Article 3(1)) and the "targeting" criterion (Article 3(2)) – and discusses how they affect the obligations of data controllers and processors.
Main Objectives
- Ensure comprehensive protection of data subjects' rights within the EU.
- Establish a level playing field for companies operating in the EU.
- Provide a common interpretation of the GDPR's territorial scope to ensure consistent application across the EU.
- Clarify the process for designating a representative for non-EU controllers or processors under Article 27.
Key Information
1. Application of the Establishment Criterion – Article 3(1)
- Scope: The GDPR applies to the processing of personal data in the context of the activities of an establishment of a controller or processor located in the EU.
- Definition of Establishment: An establishment is defined as the effective and real exercise of activities through stable arrangements, regardless of the legal form (branch, subsidiary, office, etc.).
- Processing Location: The location of the processing is not relevant, only whether it is carried out in the context of the activities of the establishment.
- Case-by-case Analysis: Each scenario must be assessed based on specific facts and the relationship between the processing and the establishment.
- Examples:
- A Belgian branch of a US-based car manufacturer is considered an establishment.
- A Chinese e-commerce company with a European office in Berlin may be subject to the GDPR if its data processing is inextricably linked to the activities of that office.
- A South African hotel chain without any EU presence is not subject to the GDPR under Article 3(1).
2. Application of the Targeting Criterion – Article 3(2)
- Scope: The GDPR applies to processing activities that target individuals in the EU, regardless of where the processing is carried out.
- Targeting: This includes offering goods or services to individuals in the EU or monitoring their behavior.
- Importance: This criterion ensures that non-EU entities that target EU residents are subject to the GDPR.
- Relevance: The location of the data subject is key in determining applicability under this criterion.
3. Processing in a Place Where Member State Law Applies by Virtue of Public International Law
- Scope: The GDPR applies if Member State law applies to the processing by virtue of public international law.
- Context: This is relevant in situations where international treaties or agreements require the application of EU data protection rules.
4. Representatives of Non-EU Controllers or Processors
- Requirement: Non-EU controllers or processors that fall under Article 3(2) must designate a representative in the EU.
- Responsibilities: The representative must ensure compliance with the GDPR and act as a point of contact for data protection authorities.
Structure and Interpretation
- The EDPB emphasizes that the focus is on the processing activity, not the person or legal entity.
- Stable Arrangements: A single employee or agent in the EU may be sufficient to constitute a stable arrangement if they act with sufficient stability.
- Revenue in the EU: Revenue-raising in the EU can be a key indicator of whether processing is carried out in the context of an EU establishment.
- Separate Obligations: Controllers and processors subject to the GDPR have separate obligations, even if they are linked by a contractual relationship.
Conclusion
These guidelines are essential for controllers and processors, both inside and outside the EU, to understand when they are subject to the GDPR. They provide clear criteria for determining the territorial scope, and emphasize the importance of a case-by-case analysis. The EDPB also highlights that non-EU entities must consider the designation of a representative in the EU if their activities fall under Article 3(2).
The guidelines were initially adopted in November 2018 and updated in November 2019 following public consultation. They reflect the evolution of EU data protection law from Directive 95/46/EC to the GDPR, and aim to ensure consistency and clarity in the application of the GDPR across the EU.
试读结束,高清完整版pdf/doc/ppt,请点下载