Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: FR

Article 3 Champ d'application territorial


Summary What does Article 3 of the GDPR regulation say?

This article defines the territorial scope of the GDPR, establishing exactly when and where the regulation applies.

It takes a broad, extraterritorial approach: the regulation does not simply apply to organisations based in the EU, but extends to any controller or processor outside the Union that targets or monitors individuals located within it.

This makes Article 3 a critical gateway article, as it determines which entities fall under the obligations set out throughout the rest of the regulation.

Important points:

  • Controllers and processors established in the Union are subject to this regulation regardless of where the actual processing takes place.
  • Controllers and processors outside the Union are also subject to this regulation if they offer goods or services to, or monitor the behaviour of, individuals located in the Union.
  • The regulation also applies to controllers operating in locations where Member State law applies by virtue of public international law, even without a Union establishment.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Le présent règlement s'applique au traitement des données à caractère personnel effectué dans le cadre des activités d'un établissement d'un responsable du traitement ou d'un sous-traitant sur le territoire de l'Union, que le traitement ait lieu ou non dans l'Union.

    1. Le présent règlement s'applique au traitement des données à caractère personnel relatives à des personnes concernées qui se trouvent sur le territoire de l'Union par un responsable du traitement ou un sous-traitant qui n'est pas établi dans l'Union, lorsque les activités de traitement sont liées:

      1. à l'offre de biens ou de services à ces personnes concernées dans l'Union, qu'un paiement soit exigé ou non desdites personnes; ou

      2. au suivi du comportement de ces personnes, dans la mesure où il s'agit d'un comportement qui a lieu au sein de l'Union.

    1. Le présent règlement s'applique au traitement de données à caractère personnel par un responsable du traitement qui n'est pas établi dans l'Union mais dans un lieu où le droit d'un État membre s'applique en vertu du droit international public.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod