GDPR

Knowledge Base | GDPR | Who does GDPR apply to?

Who does GDPR apply to?

GDPR applies to data controllers and data processors whose personal data processing falls within its scope. This can include businesses, charities, public bodies, sole traders and other organisations; size or non-profit status does not create a general exemption.

Under Article 3 of the GDPR, its main territorial rules cover:

  • Processing connected with an establishment in the EU/EEA, even when the processing itself takes place elsewhere.

  • Processing by organisations outside the EU/EEA that relates to offering goods or services to people there, including free services.

  • Processing by organisations outside the EU/EEA that relates to monitoring people’s behaviour within that territory, such as tracking and profiling their online activity.

Coverage depends on the processing and its territorial connection, rather than a person’s citizenship. A foreign website being accessible in the EU/EEA does not, by itself, establish that it targets people there.

GDPR covers automated processing and manual records forming, or intended to form, part of a filing system. Purely personal or household activities fall outside its scope, alongside certain other statutory exclusions.