Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: DE

Artikel 3 Räumlicher Anwendungsbereich


Summary What does Article 3 of the GDPR regulation say?

This article defines the territorial scope of the GDPR, establishing exactly when and where the regulation applies.

It takes a broad, extraterritorial approach: the regulation does not simply apply to organisations based in the EU, but extends to any controller or processor outside the Union that targets or monitors individuals located within it.

This makes Article 3 a critical gateway article, as it determines which entities fall under the obligations set out throughout the rest of the regulation.

Important points:

  • Controllers and processors established in the Union are subject to this regulation regardless of where the actual processing takes place.
  • Controllers and processors outside the Union are also subject to this regulation if they offer goods or services to, or monitor the behaviour of, individuals located in the Union.
  • The regulation also applies to controllers operating in locations where Member State law applies by virtue of public international law, even without a Union establishment.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Diese Verordnung findet Anwendung auf die Verarbeitung personenbezogener Daten, soweit diese im Rahmen der Tätigkeiten einer Niederlassung eines Verantwortlichen oder eines Auftragsverarbeiters in der Union erfolgt, unabhängig davon, ob die Verarbeitung in der Union stattfindet.

    1. Diese Verordnung findet Anwendung auf die Verarbeitung personenbezogener Daten von betroffenen Personen, die sich in der Union befinden, durch einen nicht in der Union niedergelassenen Verantwortlichen oder Auftragsverarbeiter, wenn die Datenverarbeitung im Zusammenhang damit steht

      1. betroffenen Personen in der Union Waren oder Dienstleistungen anzubieten, unabhängig davon, ob von diesen betroffenen Personen eine Zahlung zu leisten ist;

      2. das Verhalten betroffener Personen zu beobachten, soweit ihr Verhalten in der Union erfolgt.

    1. Diese Verordnung findet Anwendung auf die Verarbeitung personenbezogener Daten durch einen nicht in der Union niedergelassenen Verantwortlichen an einem Ort, der aufgrund Völkerrechts dem Recht eines Mitgliedstaats unterliegt.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod