惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

大猫的无限游戏
大猫的无限游戏
J
Java Code Geeks
小众软件
小众软件
D
Docker
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
V
V2EX
博客园 - 叶小钗
GbyAI
GbyAI
Microsoft Azure Blog
Microsoft Azure Blog
Stack Overflow Blog
Stack Overflow Blog
B
Blog RSS Feed
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 【当耐特】
IT之家
IT之家
博客园 - 司徒正美
M
MIT News - Artificial intelligence
T
The Blog of Author Tim Ferriss
The GitHub Blog
The GitHub Blog
罗磊的独立博客
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
L
LangChain Blog
阮一峰的网络日志
阮一峰的网络日志
C
Check Point Blog

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations
Understanding GDPR Applicability: Does it Apply to You? |...
Alice Perseval · 2023-03-28 · via Compliance Solutions for Websites, Apps and Organizations | iubenda

GDPR applicability, i.e. whether an organization is subject to the GDPR or not, is a tricky topic. The Regulation’s definition of personal data is very broad and can include things like IP addresses.

This means that as a business, you’re likely to process personal data. Therefore, you must consider whether the GDPR applies to you from a territorial perspective.

👀 It’s not easy. That’s why we compiled this short guide with all that you need to know + examples. Of course, we always recommend consulting a legal professional for understanding your specific situation. Let’s dive in!

In this post, we explain:

  • What is the GDPR?
  • Who is subject to GDPR (aka GDPR Article 3)?
  • Who does the GDPR not apply to?
  • Examples

The GDPR is a European regulation that became fully enforceable on May 25th, 2018. It is the most robust and strictest privacy law to date, and applies to the processing of personal data.

At its most basic, it specifies how personal data should be lawfully processed, collected, used, protected or interacted with in general.

GDPR’s main provisions include:

  • having a valid legal basis for processing personal data;
  • in many cases, before processing any personal data, obtaining explicit user consent and keeping records;
  • honoring your users’ rights and requests;
  • implementing organizational privacy measures and keeping user data safe.

🔍 A bit confused with European Privacy Laws? Check out this quick recap here!

gpdr applicability

GDPR Article 3 sets out the conditions of territorial applicability, or in non-legalese, who is subject to the GDPR.

In short, the GDPR can apply where:

  • an entity’s base of operations is in the EU
    • this applies whether the processing takes place in the EU or not;

or

  • an entity not established in the EU offers goods or services to people in the EU
    • even if the offer is for free;
    • the entity can be government agencies, private / public companies, individuals and non-profits;

or where

  • an entity is not established in the EU, but it monitors the behavior of people who are in the EU
    • provided that such behavior takes place in the EU.

Read the relevant paragraphs from the official text here

This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.

This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: the offering of goods or services (…); or the monitoring of their behavior as far as their behavior takes place within the Union.

🔍 Key takeaways

👉 The GDPR can apply to you whether your organization is based in the EU or not;

👉 If you are an EU-based data controller, you must apply GDPR standards to all users (not only users in the EU)!

“Data controller” means any person or legal entity involved in determining the purpose and ways of processing the personal data.

Who does the GDPR not apply to?

There are 2 main instances in which GDPR may not apply to you. First, GDPR does not apply to you if you are not based in Europe AND if you are not targeting European users’ personal data. Secondly, GDPR does not apply to you if you are not processing any personal data at all. In both of those instances, the GDPR would not apply.

GDPR Applicability: Examples

📍 When GDPR Does Not Apply

  1. Is a Japanese-based company subject to the GDPR if it processes personal data related to the selling of goods and services to Japanese users only?

👉 No! Because…

  • the controller (or processor) is not based in Europe;
  • processing relates to the selling of goods/services, but does not target European users.

🇺🇸 GDPR Applicability For US Companies

The GDPR is meant to protect European users, and therefore it can extend to foreign businesses too.

You might be wondering if the GDPR applies to you as a US-based company. It depends on many different circumstances, but if you are targeting European users, then yes it may apply to you and you must comply. If you aren’t, the law should not apply to you.

Not sure if you are subject to the GDPR?

Find out which privacy laws most likely apply to you!

Take this free 1-min quiz