欧盟-GDPR适用地域指南(英文)-2019.11.12-28页_517kb
报告摘要
GDPR Territorial Scope Guidelines (3/2018)
Introduction
The General Data Protection Regulation (GDPR) defines its territorial scope under Article 3, marking a significant evolution from the previous Directive 95/46/EC. The GDPR aims to ensure comprehensive protection of data subjects' rights within the EU and to create a level playing field for companies operating in the EU, even in the context of global data flows.
The guidelines clarify the application of the GDPR based on two main territorial criteria:
- Establishment criterion (Article 3(1))
- Targeting criterion (Article 3(2))
Additionally, Article 3(3) confirms the application of the GDPR to processing activities where Member State law applies due to public international law.
These guidelines were initially adopted on 16 November 2018 and updated after a public consultation from 23 November 2018 to 18 January 2019. They provide a common interpretation for data protection authorities and help controllers and processors, both inside and outside the EU, to determine their obligations under the GDPR.
1. Application of the Establishment Criterion - Article 3(1)
Core Content
Article 3(1) of the GDPR states that the Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or processor located in the EU, regardless of where the processing takes place.
Key Points
- The definition of an establishment is not explicitly provided in the GDPR, but it is interpreted as effective and real exercise of activities through stable arrangements.
- An establishment can be a branch, subsidiary, or office, and does not require a formal legal structure.
- The presence of a single employee or agent in the EU may be sufficient to constitute a stable arrangement if they act with a sufficient degree of stability.
- Revenue raising in the EU by a local establishment can be indicative of processing being carried out in the context of that establishment.
- Geographical location of the data subject or the processing activity itself is not relevant for Article 3(1); only the location of the establishment matters.
Examples
- Example 1: A US-based car company with a Brussels branch overseeing EU operations is considered to have an establishment in the Union, and thus the GDPR applies.
- Example 4: A French company collects data in non-EU countries but processes it in the context of its EU establishment, so the GDPR applies.
- Example 5: A Swedish pharmaceutical company processes clinical trial data in Singapore but under the activities of its EU-based headquarters, so the GDPR applies.
2. Application of the Targeting Criterion - Article 3(2)
Core Content
Article 3(2) of the GDPR applies when personal data is processed in relation to offering goods or services to data subjects in the Union, or when monitoring their behaviour within the Union.
Key Points
- The targeting criterion applies to any processing activity that targets individuals in the EU, even if the data is processed outside the Union.
- This criterion is broader than the establishment criterion and applies to international companies offering services or monitoring behavior in the EU.
- It is important to analyze the specific facts of the case to determine if the processing is targeted at individuals in the EU.
Examples
- Example 2: A Chinese e-commerce company with a Berlin office that supports marketing campaigns to the EU is subject to the GDPR under Article 3(1).
- Example 3: A South African hotel chain without any EU presence is not subject to the GDPR under Article 3(1), but may be under Article 3(2) if it targets EU individuals.
3. Processing in a Place Where Member State Law Applies by Virtue of Public International Law
Core Content
Article 3(3) of the GDPR states that the GDPR applies to processing activities where Member State law applies by virtue of public international law.
Key Points
- This includes processing related to the exercise of diplomatic or consular functions, or judicial proceedings.
- The EDPB emphasizes that this provision is limited and should be applied carefully to avoid overreach.
4. Representative of Controllers or Processors Not Established in the Union
Core Content
Controllers or processors not established in the EU but engaging in processing activities under Article 3(2) are required to designate a representative in the Union.
Key Points
- The guidelines provide clarification on the designation process and the responsibilities of such representatives.
- The representative must be designated under Article 27 of the GDPR and act on behalf of the controller or processor in the Union.
Main Objectives and Recommendations
- Ensure consistent application of the GDPR across the EU.
- Help controllers and processors to assess compliance based on the nature of their activities.
- Emphasize the importance of a case-by-case analysis in determining the applicability of the GDPR.
- Clarify that only the establishment of a controller or processor in the EU triggers the GDPR, not the location of data subjects or processing.
Conclusion
The territorial scope of the GDPR is determined by the establishment and targeting criteria, with the establishment criterion being more relevant for companies with physical or operational presence in the EU. The targeting criterion is broader and applies to any processing activity that targets individuals in the EU, regardless of the company's location. The EDPB recommends that international organizations conduct a detailed and concrete assessment of their processing activities to determine if they fall under the GDPR's scope.
试读结束,高清完整版pdf/doc/ppt,请点下载