{"id":192,"date":"2018-12-10T15:18:19","date_gmt":"2018-12-10T20:18:19","guid":{"rendered":"https:\/\/pbacyber.com\/?p=192"},"modified":"2018-12-11T09:22:30","modified_gmt":"2018-12-11T14:22:30","slug":"the-eu-issues-provisional-guidelines-on-the-territorial-scope-of-the-gdpr","status":"publish","type":"post","link":"https:\/\/pbacyber.com\/index.php\/2018\/12\/10\/the-eu-issues-provisional-guidelines-on-the-territorial-scope-of-the-gdpr\/","title":{"rendered":"The EU Issues Provisional Guidelines on the Territorial Scope of the GDPR"},"content":{"rendered":"<p>By <a href=\"https:\/\/xpanlawgroup.com\/our-tean\/\">Jordan L. Fischer<\/a> of XPAN Law Group LLC<\/p>\n<p>&nbsp;<\/p>\n<p>On Nov. 16, 2018, the <a href=\"https:\/\/edpb.europa.eu\/\">European Data Protection Board<\/a> (EDPB) adopted <a href=\"https:\/\/edpb.europa.eu\/sites\/edpb\/files\/consultation\/edpb_guidelines_3_2018_territorial_scope_en.pdf\">Guidelines 3\/2018 on the territorial scope of the GDPR<\/a> (Guidelines), soliciting public consultation through Jan. 18, 2019. While these are not final, they provide some of the first indicators on how the EU will interpret the jurisdictional reach of the GDPR \u2013 a critical analysis for many U.S.-based companies.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:32016R0679&amp;from=EN\">Article 3 of the GDPR<\/a> outlines the criteria to be used to determine <em>who<\/em> is impacted by &#8212; and therefore required to comply with &#8212; the GDPR.\u00a0 Article 3 has garnered a lot of consideration, especially for entities not established within the European Union. The Guidelines outline two main criteria for determining whether the GDPR applies: \u201cthe &#8216;establishment&#8217; criterion, as per Article 3(1), and the &#8216;targeting&#8217; criterion as per Article 3(2).\u201d <em>See<\/em> Guidelines, at 3.<\/p>\n<p>&nbsp;<\/p>\n<p>Article 3(1) states:<\/p>\n<p><em>This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>The EDPB makes clear that Article 3(1) can apply to both controllers or processors. As such, a processor impacted by the GDPR would still need to comply with the GDPR in the processing of the personal data, even if the controller would not need to comply. <em>See<\/em> Guidelines, at 9. As such, the GDPR can apply even if the personal data was not originally GDPR-impacted by virtue of a processor \u201cestablished\u201d within the EU. And, the EDPB makes it abundantly clear that the nationality of the data subject is irrelevant to whether the GDPR applies. <em>See<\/em> Guidelines, at 9.<\/p>\n<p>&nbsp;<\/p>\n<p>Under the Article 3(1) criterion, the EDPB provides a three-consideration approach. First, an entity needs to determine if it is \u201cestablished\u201d within the Union. Drawing guidance from prior Court of Justice of the European Union (\u201cCJEU\u201d) case law, the EDPB states that \u201cboth the degree of stability of the arrangements and the effective exercise of activities in that Member State must be considered in the light of the specific nature of the economic activities and the provision of services concerned.\u201d <em>See<\/em> Guidelines, at 5. Physical presence in the EU is not the sole determinant of \u201cestablishment.\u201d<\/p>\n<p>&nbsp;<\/p>\n<p>Second, the processing activities at issue must be carried out in the context of the activities of the establishment. This requires an entity to identify \u201cany potential links between the activity for which the data is being processed and the activities of any presence of the organisation in the Union\u201d (i.e., the establishment). <em>See<\/em> Guidelines, at 7.<\/p>\n<p>&nbsp;<\/p>\n<p>Third, the EDPB makes clear that whether the processing occurs in the EU or outside of it is irrelevant for the application of Article 3(1). The trigger is processing that \u201ctakes place in the context of the activities of\u201d an establishment within the Union. <em>See<\/em> Guidelines, at 8.<\/p>\n<p>&nbsp;<\/p>\n<p>For the \u201ctargeting\u201d criterion, Article 3(2) states:<\/p>\n<p><em>This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:<\/em><\/p>\n<p><em>(a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or<br \/>\n(b) the monitoring of their behaviour as far as their behaviour takes place within the Union.<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>For this criterion, the EDPB states that the focus is on \u201cwhat the \u2018processing activities\u2019 are \u2018related to\u2019\u201d and breaks the analysis into two parts. <em>See<\/em> Guidelines, at 11.<\/p>\n<p>&nbsp;<\/p>\n<p>First, the triggers for Article 3(2) are (a) a data subject\u2019s location within the EU at the time the activity takes place and (b) some element of \u201ctargeting\u201d data subjects within the EU.\u00a0 The EDPB makes it clear that the processing of EU citizen or resident personal data alone is not sufficient to trigger GDPR requirements. <em>See<\/em> Guidelines, at 14.<\/p>\n<p>&nbsp;<\/p>\n<p>Second, an entity must determine \u201cwhether the conduct on the part of the controller or processor demonstrates its intention to offer goods or a services to a data subject located in the Union.\u201d <em>See<\/em> Guidelines, at 15. Some connection, either directly or indirectly, needs to exist between the processing activity and the offering of a good or service, in order to trigger Article 3(2). The EDPB goes on to list a number of factors to be taken into consideration when making this determination.<\/p>\n<p>&nbsp;<\/p>\n<p>Alternatively, Article 3(2) is triggered when monitoring the behavior of a data subject within the EU. <em>See<\/em> Guidelines, at 17. The Guidelines clarify that online collection of personal data and any subsequent analysis does not, by itself, necessarily trigger the \u201cmonitoring\u201d jurisdictional requirement. Instead, it is a fact-based analysis, with the EDPB listing a number of activities that could be considered \u201cmonitoring behavior.\u201d<\/p>\n<p>&nbsp;<\/p>\n<p>Finally, the EDPB provides guidance on the designation of a representative for controllers or processors not established in the Union under Article 27, making it clear that a DPO (Data Protection Officer) should not be designated as a representative because of the \u201cpossible conflict of obligation and interests\u201d inherent in the two separate and distinct roles.\u00a0 <em>See<\/em> Guidelines, at 21.<\/p>\n<p>&nbsp;<\/p>\n<p>These Guidelines are <em>not<\/em> in final form, but they do provide great insight into the approach the EDPB is taking as it relates to the jurisdictional impact of the GDPR. The Guidelines also reiterate that the GDPR is meant to be all encompassing and not limited by citizenship, residence or any other legal status of the data subject. Companies need to assess the impact of the GDPR on their organisations with this new guidance on the jurisdictional reach of this Regulation, and determine whether these Guidelines foreshadow risk of non-compliance under the GDPR.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/xpanlawgroup.com\/our-team\/\">Jordan L. Fischer<\/a> is co-founder and managing partner of <a href=\"https:\/\/xpanlawgroup.com\/\">XPAN Law Group LLC<\/a>, a women-owned boutique international cybersecurity and data privacy law firm, and she serves as an editor of this blog.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Jordan L. Fischer of XPAN Law Group LLC &nbsp; On Nov. 16, 2018, the European Data Protection Board (EDPB) adopted Guidelines 3\/2018 on the territorial scope of the GDPR (Guidelines), soliciting public consultation through Jan. 18, 2019. While these are not final, they provide some of the first indicators on how the EU will <br \/><a class=\"read-more-button\" href=\"https:\/\/pbacyber.com\/index.php\/2018\/12\/10\/the-eu-issues-provisional-guidelines-on-the-territorial-scope-of-the-gdpr\/\">Read More &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3],"tags":[],"_links":{"self":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/192"}],"collection":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/comments?post=192"}],"version-history":[{"count":6,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/192\/revisions"}],"predecessor-version":[{"id":199,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/192\/revisions\/199"}],"wp:attachment":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/media?parent=192"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/categories?post=192"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/tags?post=192"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}