Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: SV

Artikel 3 Territoriellt tillämpningsområde


Summary What does Article 3 of the GDPR regulation say?

This article defines the territorial scope of the GDPR, establishing exactly when and where the regulation applies.

It takes a broad, extraterritorial approach: the regulation does not simply apply to organisations based in the EU, but extends to any controller or processor outside the Union that targets or monitors individuals located within it.

This makes Article 3 a critical gateway article, as it determines which entities fall under the obligations set out throughout the rest of the regulation.

Important points:

  • Controllers and processors established in the Union are subject to this regulation regardless of where the actual processing takes place.
  • Controllers and processors outside the Union are also subject to this regulation if they offer goods or services to, or monitor the behaviour of, individuals located in the Union.
  • The regulation also applies to controllers operating in locations where Member State law applies by virtue of public international law, even without a Union establishment.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

  1. ▼C1
    1. Denna förordning ska tillämpas på behandlingen av personuppgifter inom ramen för den verksamhet som bedrivs på personuppgiftsansvarigas eller personuppgiftsbiträdens verksamhetsställen inom unionen, oavsett om behandlingen utförs i unionen eller inte.

    1. Denna förordning ska tillämpas på behandling av personuppgifter som avser registrerade som befinner sig i unionen och som utförs av en personuppgiftsansvarig eller ett personuppgiftsbiträde som inte är etablerad i unionen, om behandlingen har anknytning till

      1. utbjudande av varor eller tjänster till sådana registrerade i unionen, oavsett om dessa varor eller tjänster erbjuds kostnadsfritt eller inte, eller

      2. övervakning av deras beteende så länge beteendet sker inom unionen.

    1. Denna förordning ska tillämpas på behandling av personuppgifter som utförs av en personuppgiftsansvarig som inte är etablerad i unionen, men på en plats där en medlemsstats nationella rätt gäller enligt folkrätten.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod