GDPR
Which European countries are not covered by the GDPR?
The EU GDPR applies throughout the European Economic Area: all 27 EU Member States, plus Iceland, Liechtenstein and Norway. Other European countries are outside this shared legal framework, although organisations based there can still fall within GDPR’s scope.
Examples include:
The United Kingdom, which has its own UK GDPR and Data Protection Act 2018.
Switzerland, which has its own Federal Act on Data Protection.
Albania, Bosnia and Herzegovina, Serbia, Montenegro, North Macedonia, Moldova, Ukraine, Russia and Türkiye.
However, location alone does not determine who GDPR applies to. Under its territorial scope rules, a business outside the EU/EEA can still be covered when its processing relates to offering goods or services to people there, monitoring their behaviour there, or the activities of an EU/EEA establishment.
An EU adequacy decision is a separate matter: it facilitates data transfers to a recognised destination. It does not make that country part of the EU/EEA or replace its domestic privacy laws.
Türkçe
English