
In order to specify precisely what is meant to be covered and, conversely, what is not, the scope of a legal norm is usually supplemented by provisions governing both its positive scope (what the GDPR applies to) and its negative scope (what the GDPR does not apply to). In keeping with the traditional division of the scope of a legal norm into the factors mentioned above — something legal theory teaches us in the very first year of law school — we will structure the following explanation of the scope of the GDPR accordingly. In a given case, the GDPR will apply where the conditions of positive material scope, personal scope and temporal scope are met and where, at the same time, no grounds for applying the negative scope are present.
Negative scope
This is a very important part of the GDPR, because the related provision of Article 2(2)(a) to (d) GDPR sets out cases that constitute an absolute exclusion of the scope of the GDPR as a whole.
1 Activities which fall outside the scope of Union law
This ground is explained in more detail by recital 16 GDPR, which states that the GDPR “does not apply to issues of protection of fundamental rights and freedoms or the free flow of personal data related to activities which fall outside the scope of Union law, such as activities concerning national security.”
The scope of EU law includes a number of exclusive competences reaching into areas such as the customs union, the common commercial policy, the monetary policy of the eurozone, or competition rules within the EU internal market, but also competences shared between the EU and the Member States (e.g. social policy, the environment, consumer protection, etc.) and likewise the so-called supporting, coordinating and supplementary competences of the EU (e.g. industry, culture, education, tourism, etc.). The scope of EU law does not include the residual competences of the Member States, i.e. the competences of the Member States that were not conferred on the EU by the founding treaties (the Treaty on European Union and the Treaty on the Functioning of the EU). Under Article 5(2) of the consolidated version of the Treaty on European Union: “Under the principle of conferral, the Union shall act only within the limits of the competences conferred upon it by the Member States in the Treaties to attain the objectives set out therein. Competences not conferred upon the Union in the Treaties remain with the Member States.”
Under Article 4(2) of the consolidated version of the Treaty on European Union: “The Union shall respect the equality of Member States before the Treaties as well as their national identities, inherent in their fundamental structures, political and constitutional, inclusive of regional and local self-government. It shall respect their essential State functions, including ensuring the territorial integrity of the State, maintaining law and order and safeguarding national security. In particular, national security remains the sole responsibility of each Member State.”
On the basis of the above, it can be concluded that Article 2(2)(a) GDPR renders the GDPR inapplicable to the processing of personal data that must be carried out at Member State level in pursuit of national security, or in connection with other activities entailing the necessary processing of personal data in the exercise of other exclusive residual competences of an EU Member State that, under EU primary law or the founding treaties, are entrusted to the exclusive competence of the Member States (e.g. tax policy, national security), or of a Member State that has negotiated exemptions with the EU.
2 Processing of personal data by Member States when carrying out activities related to the EU’s common foreign and security policy
Under Article 2(2)(b) GDPR, the GDPR does not apply to the processing of personal data by Member States when carrying out activities in connection with the common foreign and security policy of the Union (i.e. within the scope of the specific provisions on the common foreign and security policy under Chapter 2 of Title V of the Treaty on European Union).
3 Processing of personal data by EU institutions, bodies, offices and agencies
Because the institutional apparatus of the European Union created its own legislation on the protection of personal data in the past, as well as its own supervisory authority overseeing these institutions — the so-called EDPS, the European Data Protection Supervisor — and because representatives of the European Commission sat at the head of the table during the GDPR negotiations in the Council of the EU, it was possible to secure that the GDPR does not apply to the processing of personal data carried out by the EU bureaucratic apparatus based mainly in Brussels, Strasbourg and Luxembourg.
Recital 17 GDPR nevertheless clarifies that: “Regulation (EC) No 45/2001 of the European Parliament and of the Council applies to the processing of personal data by the Union institutions, bodies, offices and agencies. Regulation (EC) No 45/2001 and other Union legal acts applicable to such processing of personal data should be adapted to the principles and rules established in this Regulation and applied in the light of this Regulation. In order to provide a strong and coherent data protection framework in the Union, the necessary adaptations of Regulation (EC) No 45/2001 should follow after the adoption of this Regulation, in order to allow application at the same time as this Regulation.”
4 The exemption for household or personal activities
Under recital 18, the GDPR “does not apply to the processing of personal data by a natural person in the course of a purely personal or household activity and thus with no connection to a professional or commercial activity. Personal or household activities could include correspondence and the holding of addresses, or social networking and online activity undertaken within the context of such activities. However, this Regulation applies to controllers or processors which provide the means for processing personal data for such personal or household activities.”
The household or personal activities exemption may seem clear at first glance. In the enforcement practice of supervisory authorities, however, there have already been a number of cases in the past that were difficult to assess in terms of whether this exemption from the generally binding rules on personal data protection — an exemption preserved in the GDPR — could be applied. Today, with the development of the digital economy, the exemption for personal and household activities cannot be narrowed down to contact lists on a mobile phone, private databases on a home PC, or household folders belonging to private individuals containing various insurance policies, medical records, certificates, diplomas and the like. Today it is also necessary to take into account that a private individual may have their own blog, website or social-media profile that may serve purely personal (private) purposes, or may also use various smart applications (e.g. tracking the geolocation of members of their family or community).
It is precisely these new forms of processing of personal data within the scope of the exemption for household or personal activities that pose an increased risk of overstepping (going beyond) its framework.
Determining the objective criteria needed to identify the presence of a personal-activity component in the conduct of an informal group, or of a person acting formally as an individual but in fact acting as a publicly, politically or commercially active person, as distinct from an entity that, purposefully and in the context of a predefined purpose, carries out activities that include the processing of personal data, may be difficult. In such unclear cases it is advisable to use the methodology of prevailing factors to determine, or conversely to exclude, the possibility of applying the exemption for household or personal activities by means of the guiding questions formulated by the Working Party set up under Article 29 of Directive 95/46/EC (hereinafter “WP 29”), as follows:
- Are the personal data disseminated to an indefinite number of people rather than to a limited community of friends, family members or acquaintances?
- Do the personal data concern an individual with whom the person who used the data (e.g. posted them on a social network) has no personal or household relationship?
- Do the scale and frequency of the processing of personal data indicate the character of a professional activity and/or an activity carried out on a full-time basis?
- Is there evidence that the processing of personal data is carried out by several people acting collectively and in an organised manner?
- Is there a possible adverse impact on individuals, including interference with their privacy?
Where, in a given case, most of the above questions can be answered “yes”, there is a strong likelihood that the case will constitute an overstepping (going beyond) of the exemption for household or personal activities, and the related processing of personal data should be assessed against the GDPR.
5 Processing of personal data by authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including safeguarding against threats to public security
This exemption from the scope of the GDPR for so-called law-enforcement purposes maintains continuity with Directive 95/46/EC, which likewise excluded several of its provisions from its scope in such cases. Since the processing of personal data for the purposes of the prevention, investigation, detection or prosecution of criminal offences is fully covered by the so-called Police Directive on the protection of personal data, which will begin to apply on the same day as the GDPR, it is no longer necessary to exempt specifically selected provisions in part; instead, the entire scope of all GDPR provisions can be excluded for these cases.
6 The option to limit the legal effects of the GDPR on courts and other judicial bodies at national level
In EU Member States the independence of the judiciary is a carefully protected component of the democratic organisation of society, and it must therefore be pointed out that in a number of places the GDPR excludes, or creates room for a Member State’s national legislation to exclude, the application of several GDPR provisions to the processing of personal data carried out by courts in the exercise of their judicial functions.
On the basis of this approach it is possible to restrict the exercise of certain rights of the data subject granted by the GDPR (e.g. Articles 12 to 22 GDPR), or to restrict the application of the basic principles of processing personal data (Article 5 GDPR) or the obligation to communicate a personal data breach to the data subject (Article 34 GDPR), by means of a legislative measure meeting the substantive requirements set out in Article 23(2) GDPR at national or EU level, provided that such a restriction respects the essence of fundamental rights and freedoms and is a necessary and proportionate measure in a democratic society to safeguard the independence of the judiciary and judicial proceedings.
On the basis of the above, it can be assumed that legislative measures under Article 23(2) GDPR will also be adopted in Slovakia in order to strengthen the independence of the judiciary (e.g. through an amendment to the Act on Courts).
Positive scope
The positive scope of the GDPR is largely identical to the basic positive material scope of the GDPR, which is expressed in Article 2(1) GDPR, providing that the rules apply “to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system.” The term “filing system” is legally defined as “any structured set of personal data which are accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis.”
This can be interpreted to mean that the GDPR applies to any processing of personal data carried out as a result of a purpose of processing autonomously defined by the controller (e.g. a decision to set up an e-shop) or of a purpose of processing prescriptively imposed on the controller as a result of the application of a statutory obligation (e.g. the obligation to register an employee with the relevant register of the Social Insurance Agency), regardless of whether the processing uses only technology (e.g. a smart application), a combination of technology and the human factor (e.g. filling in an Excel spreadsheet), or only the human factor (e.g. a class teacher collecting completed paper enrolment forms for children going to an outdoor school).
The GDPR likewise applies to any processing of personal data that takes place between substantively defined and distinct entities with which the controller may carry out individual processing operations on personal data. Primarily and to the greatest possible extent, this positive scope of the GDPR affects the controller and the processor as the controller’s business partner, but it also covers the processing of personal data carried out from the processor to subcontractors, or from the controller and/or processor to third parties or recipients of personal data.
Material scope
As we have already noted, the material scope of the GDPR largely overlaps with both its positive scope and its negative scope. Put simply, the material scope of the GDPR concerns any manner of processing personal data in a filing system (primarily) carried out by a controller and/or processor, and does not concern the categories of personal data processing defined in Article 2(2) GDPR.
The essence of the material scope of the GDPR is that it applies to the processing of personal data. The term “personal data” is legally defined in Article 4(1) GDPR and the term “processing” is legally defined in Article 4(2) GDPR. In this connection it is worth noting that the GDPR refines the concept of personal data so that various online identifiers of persons (for example an IP address or cookies) and other electronic identifiers (for example RFID technologies, or so-called operational and location data) are now also regarded as personal data, as are so-called pseudonymised data legally defined in Article 4(5) GDPR and explained in more detail in recital 26 GDPR. Of course, as in the past, it will still be necessary for the data or set of processed data to be capable, in the given case, of directly or indirectly identifying the data subject. Where the data are legally qualified as personal data and an entity carries out any processing operations on them (e.g. collection, recording, consultation, structuring, organising, use, dissemination, provision, disclosure, and others), the material scope of the GDPR is established.
In addition, it must be borne in mind that the processing of personal data by EU bodies and institutions is governed by its own legal regime distinct from the GDPR (Regulation (EC) No 45/2001 of the European Parliament and of the Council of 18 December 2000 on the protection of individuals with regard to the processing of personal data by the Community institutions and bodies and on the free movement of such data), as is the processing of personal data by law-enforcement authorities and courts in criminal proceedings (the Police Directive on data protection).
Likewise, the processing of personal data carried out by information-society service providers (e.g. various providers of online services, from operators of social networks, through classified-ad portals, so-called dating sites, online loan intermediation and data storage, to e-shops) may, regardless of the GDPR, be affected by rules transposed into the national legal orders of the Member States — in our case specifically by Section 6 of Act No. 22/2004 Coll. on electronic commerce and amending Act No. 128/2002 Coll. on state control of the internal market in matters of consumer protection and amending certain acts, as amended by Act No. 284/2002 Coll. (hereinafter the “Electronic Commerce Act”), as a result of Articles 12 to 15 of Directive 2000/31/EC of the European Parliament and of the Council of 8 June 2000 on certain legal aspects of information society services, in particular electronic commerce, in the internal market (the Directive on electronic commerce).
Personal scope
The GDPR applies primarily to entities that process personal data as controllers (including so-called joint controllers within the meaning of Article 26 GDPR) and processors (including their processors, i.e. so-called subcontractors involved in the personal data processing on the processor’s side with the controller’s consent).
The rules also reach representatives of controllers or processors not established in the European Union (Article 27 GDPR), i.e. indirectly they also reach entities that process the personal data of EU citizens without being established in any Member State. The personal scope of the GDPR also reaches other persons who process personal data under the authority of a controller or processor pursuant to Article 29 GDPR (e.g. the current authorised persons within the meaning of the national act on the protection of personal data).
Of course, the personal scope of the GDPR also applies to data subjects whose personal data are processed by the entities mentioned above and who always have primarily the status of a natural person — an individual — and not, for example, of a natural person acting as an entrepreneur. That, however, applies only in respect of the identification data of a natural person — an entrepreneur — used in ordinary business dealings, which are commonly published in accordance with the law in the relevant registers (e.g. the trade register), and not to other identifiers which might already be private in nature and would have to be regarded as personal data in relation to the natural person — the entrepreneur; such an entity would then, as a data subject, also become subject to the personal scope of the GDPR. Paradoxically, the term “data subject” is not legally defined in the GDPR, although in our national act on the protection of personal data the data subject is legally defined as “every natural person to whom the personal data relate.”
A more detailed explanation of how to define the data subject for the purposes of the GDPR is provided by recital 26 GDPR.
In connection with the personal scope of the GDPR, it is also necessary to note that, in accordance with recital 27, the rules contained in the GDPR should not apply to the personal data of deceased persons, although Member States may lay down rules on the processing of the personal data of deceased persons.
Our current national rules in the Act on the Protection of Personal Data contain only a brief mention that, where the data subject is no longer alive, consent to the processing of personal data may be given by a close person, whereby such consent is not valid if even a single close person has expressed disagreement. This handling of the consent of a deceased data subject de facto builds on the so-called post-mortem protection of personality provided for in Section 15 of Act No. 40/1964 Coll., the Civil Code, as amended (hereinafter the “Civil Code”), which grants the right to assert the right to protection of the personality of a deceased data subject to their spouse and children, and, if there are none, to their parents.
Temporal scope
The GDPR will begin to apply fully in practice and to be enforced by supervisory authorities only from 25 May 2018, regardless of whether a national act on the protection of personal data — one that would incorporate the GDPR and supplement it with its own rules, which must nevertheless be consistent with the GDPR — is adopted at national level, or no such national act is adopted at Member State level at all.
The GDPR has been in force since 25 May 2016, following the expiry of the twentieth day after its publication in the Official Journal of the EU. The temporal scope is therefore regulated very simply — there are not several transitional provisions for fulfilling the individual obligations laid down by the GDPR. Responsible entities currently have a two-year transitional period intended for the overall conversion of their personal data processing conditions to the new rules. After 25 May 2016, only compliance with the GDPR will be enforced throughout the EU, with the understanding that, naturally, legal proceedings initiated before 25 May 2016 will be completed under the legal regime of the original national acts on the protection of personal data.
Territorial scope
The territorial scope of the GDPR is the subject of the rules in Article 3(1) to (3) GDPR and is also explained in more detail in recitals 23 to 25 GDPR.
Compared with Directive 95/46/EC, which it replaces, the GDPR seeks to extend the scope of EU data protection law, among other things by making the location of the means of processing personal data — which was decisive until now — irrelevant, and by introducing certain extraterritorial elements aimed at bringing within the reach of the GDPR even those undertakings acting as controllers and processors which, although they have no establishment in any EU Member State, nevertheless process the personal data of Union citizens.
First of all, the GDPR of course applies to controllers and processors established in the territory of all Member States of the European Union (EU) and having their seat in the European Economic Area (EEA) — i.e. including Iceland, Norway and Liechtenstein. In this respect it is interesting to consider BREXIT, which will in fact affect the current position of the United Kingdom. According to the available information, it can be assumed that, despite BREXIT, the United Kingdom will comply with the GDPR, since many of the positions of the British delegation were taken into account during its adoption and technological and social developments urgently require new rules in this area. The position of the United Kingdom, including from the point of view of personal data protection, is currently the subject of political discussions. The most likely alternative appears to us to be that the United Kingdom will implement the GDPR and the European Commission will, for the period after BREXIT, determine by a decision issued in accordance with Article 45 GDPR that it is a country ensuring an adequate level of personal data protection, which will ensure continuity in the free flow of personal data between the United Kingdom and the other EU Member States.
The GDPR applies to controllers and processors established in the EU / EEA regardless of whether the processing is actually carried out in the territory of the EU / EEA, which makes the location of the means of processing personal data irrelevant (e.g. cloud infrastructure spread across data centres on different continents of the world); what will be decisive, rather, is the organisation’s legal domicile in connection with the legal determination of whether the processing of personal data by that organisation constitutes the activities of a controller or a processor.
Given that on the EU internal market it is common, within the corporate structures of various business companies, for business activities to be accompanied by the processing of personal data with a cross-border element in several Member States, it is worth considering how to address such cases. For these cases the GDPR has established the principle of the so-called one-stop-shop, which is normatively expressed in Article 60 GDPR (Cooperation between the lead supervisory authority and the other supervisory authorities concerned), which we will explain in more detail in the following parts of our series. In brief, the principle of the one-stop-shop mechanism is to determine the lead supervisory authority according to the place of the main establishment of the controller or processor with processing activities in several Member States, which is essentially the country in which the corporation has its headquarters (so-called HQ — Headquarters). This lead supervisory authority is then competent for all matters connected with the GDPR and the protection of personal data in relation to the processing of personal data carried out through the corporation’s affiliated establishments in several Member States.
The GDPR will therefore apply to companies that have “establishments” in the EU where personal data are processed “in the context of the activities” of such an establishment. Where the relevant conditions are met, the GDPR applies regardless of whether the actual data processing takes place within the geographical territory of the EU Member States or not.
A decisive new element present in the GDPR is the explicit extension of the territorial scope of this legal act, which reflects both the political ambitions of the European Commission to protect the internal market extraterritorially and the trend of the growing influence of the Court of Justice of the EU and of supervisory authorities in the field of personal data protection, which will have to apply the EU rules on personal data protection (the GDPR) even to companies that in the past did not fall within their scope.
Under Article 3(2), companies established outside the EU will be subject to the GDPR where they process the personal data of data subjects in the EU in connection with:
- the offering of goods or services (payment is not required); or
- the monitoring of their behaviour within the EU.
As regards the offering of goods and services (but not monitoring), the mere accessibility of a website within the European Union is not sufficient. It must be apparent that the company is directing its activities at data subjects living in the EU. Contact addresses accessible from the EU and the use of a language used in the controller’s country are likewise not sufficient. However, the ability to place an order in the official language of the Member State concerned and the possibility of payment in the relevant currency will already be relevant factors for determining the extraterritorial scope of the GDPR. Recital 23 GDPR develops these considerations in more detail.
In connection with the monitoring of the behaviour of data subjects living, or physically present, in the EU, it is necessary, in accordance with recital 24 GDPR, to ascertain “whether natural persons are tracked on the internet including potential subsequent use of personal data processing techniques which consist of profiling a natural person, particularly in order to take decisions concerning her or him or for analysing or predicting her or his personal preferences, behaviours and attitudes.”
Monitoring the behaviour of a data subject thus refers mainly to online tracking and behavioural advertising generated by operators of internet search engines or operators of social networks. Through this provision the GDPR pursues its ambition to reach, and to compel respect for its rules from, even the largest giants of the digital economy, which profit most from the processing of personal data and which are predominantly established in the USA.
The law of an EU Member State, or the GDPR, will in some cases also be applicable extraterritorially on the basis of public international law.