---
title: GDPR - New Guidelines on Territorial Scope
date: '2018-11-26'
year: 2018
lang: en
type: post
wp_slug: english-gdpr-new-guidelines-on-territorial-scope
wp_url: >-
  http://armingaud-avocat.fr/en/english-gdpr-new-guidelines-on-territorial-scope/
categories:
  - Europe
  - Privacy
tags:
  - site
visibility: private
Language:
  - English
Publication Date: null
Publication Type: null
Ext. Link: null
Source: null
Author(s): null
NoteType: Publications
icon: "\U0001F4DA"
created: '2018-11-26'
modified: '2018-11-26'
published: '2018-11-26'
---

On 23 November 2018, the European Data Protection Board (“**[EDPB](<https://edpb.europa.eu/news/news/2018/european-data-protection-board-fourth-plenary-session-eu-japan-draft-adequacy_en>)** ”) - the gathering of all European Union (EU) data protection authorities - adopted new draft guidelines on territorial scope of the General Data Protection Regulation ("[[Official Texts/GDPR|GDPR]]" - [external source](<https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN>)). The EDPB was previously known as the Article 29 Working Party.

The long awaited guidelines (“**Guidelines** ”, available [here](<https://edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-32018-territorial-scope-gdpr-article-3-version_en>)) provide a common interpretation on the scope of application of the GDPR. Its territorial scope, laid down in [[Official Texts/GDPR#^article3|Article 3 GDPR]], states that GDPR applies to:

  * any EU-based [[controller]] or [[processor]] [[processing]] [[personal data]] in the context of its activities ([[Official Texts/GDPR#^article3-1|Art. 3.1 GDPR]]); or
  * any non-EU-based controller or processor processing personal data of EU residents in connection with either: 
    1. the offer of goods or services ([[Official Texts/GDPR#^article3|Art. 3.2.a GDPR]]); or
    2. the monitoring of their behavior taking place in the EU ([[Official Texts/GDPR#^article3|Art. 3.2.b GDPR]]). 

The Guidelines provide clarification for both EU and non-EU based companies to assess whether all or parts of their activities would fall under the scope of the GDPR and to what extent they would be subject to the application of the GDPR.

Notably, the Guidelines clarified aspects which had been subject to controversy or misinterpretation in the six months since GDPR’s entry into force, such as:

  * A non-EU controller using an EU processor for activities outside of the EU not targeting EU residents does not have to comply with GDPR. An EU processor will be subject to the relevant GDPR provisions directly applicable to data processors;
  * The irrelevancy of the “_targeting_” criterion when considering applicability of the GDPR to monitoring activities; and
  * Citizenship, established residency or other type of legal status of the [[data subject]] is irrelevant to determine the application of the targeting criterion.

Moreover, the Guidelines also clarified the criteria of the appointment of an EU [[representative]] defined in [[Official Texts/GDPR#^article27|Art. 27 GDPR]] for non-EU controllers and processors.

The Guidelines will still be subject to a public consultation before being revised and ultimately adopted in a final version.
