GDPR
Who is not covered by GDPR?
GDPR coverage depends on the processing activity and its territorial connection, rather than nationality or business size.
Under Article 3 of the GDPR, an organisation outside the EU/EEA generally falls outside its territorial scope where it has no relevant establishment there and its processing does not relate to offering goods or services to people there or monitoring their behaviour there. A website being accessible from the EU is not, by itself, enough.
Individuals processing information solely for personal or household activities are generally outside scope. As rights holders, companies and deceased people are not protected by GDPR in the same way as living individuals.
Small businesses, sole traders and non-profits are not automatically exempt. Non-EU citizens can also receive GDPR protection when the processing falls within its scope.
Türkçe
English