Common misconceptions: Thinking the GDPR stops at the European Union’s border

Written by

in

You are sitting somewhere outside the EU and thinking it’s not a you problem. Or you are sitting inside the EU, but thinking as you use a big US tech company everything is alright. Neither of these are automatically true and if you read below, you will see why.

In case you are a non-EU based company the GDPR might apply to you as it is purposely extraterritorial scoped. It means regardless that you sitting in the other end of the world it might apply to you, hence you might get even fined. You of course need to meet certain conditions for that, but the bar is not that high as you might think. It is well enough if you run a SaaS company and you advertise your services in the EU or even provide an EU language support line, like German or Swedish.

The reason for all this is quite straightforward. It would be just too easy to move EU data outside of the EU and then undermine the whole purpose of the regulation. So, the GDPR can only be relevant if it applies to all EU resident’s data, even outside its borders.

On the other hand, if you are established in the EU and think you automatically in the clear as you work with companies also present in the EU… you can’t automatically claim everything is alright as it’s your responsibility to make sure the services you use are up to the GDPR requirements. It’s just a sometimes-overlooked fact, but we will focus this time on the non-EU countries.

Non-EU based

If you are in a list of countries which have an adequacy decision you are mostly in the clear. It means your country’s personal data protection practices are accepted by the EU as adequate to GDPR. This post will not focus on these countries, especially as the list is not so long and missing important countries which have a significant ranking in the world’s service exporting countries, like Singapore, China or India. If there is an interest we can go deeper in these cases as well, but let’s talk about the rest.

USA, the Elephant in the room

If your US based company is participating in the EU-US Data Privacy Framework, meaning you self-certify with the DPF. You will need a compliant Privacy Policy Statement which is publicly available and some other steps including an appointed person to handle personal data related requests. The list of companies participating in the DPF can be verified here.

In case you are not participating you are risking that EU based business will not use your services as it would require extensive verification (and paperwork) from their side on your personal data protection practices.

Ok, but why the elephant mentioned, if it looks straightforward enough? My response is twofold. There is always debate and – and specially after the Schrems decisions – there is a looming risk of a new court decision which could make the DPF invalid, hence could hinder all data transfer to the US. On the other hand, the US technology and economic dominance makes politically nonviable to really stop all data transfer for long… this means that until there is a real alternative to the US tech for EU companies it is very unlikely there would be any long-term halt for data processing.

No shield and not on the list? Brace yourselves.

Rest of the world falls under the same category, regardless if they have their own robust privacy regulation, for example China and its Personal Information Protection Law (PIPL).

GDPR will apply to you in two cases:

You offer goods or services to EU residents. One off thing like an EU resident visiting your store in New York would not apply. But in case your company has a setup to target EU residents, then it will apply according to the regulators’ practices. For example, if your company have a German language website offering prices in Euro and placing German language ads on Facebook.

You are monitoring the behavior of EU residents. This is maybe a little bit less clear, so many US based website blocks visitors from EU countries for this reason. This might be an overkill, but to be safe it practice would be an option if your company uses tools track cookies or the IP addresses of people who visit your website from EU countries, as you would fall under the scope of the GDPR.

There are two main exceptions when GPDR would not apply: if it’s “purely personal or household activity” or if a “professional or commercial activity” done by a small organization, this case you have simplified requirements to meet.

Worth to note: There might be conflicting regulations out there, so you might get into a situation where there are competing or even conflicting things you have to comply with. In case its competing, like how many days you have to respond to a deletion request from a customer, the make sense solution would be to comply with the more restrictive regulation to avoid accidental mistakes. In case it is conflicting you might want to rethink your processes first before you try to find a specialist.

You assessed it applies? So what you have to comply with exactly?

First of all, remember, the scope of GDPR is the EU residents’ personal data. If you run a company and only a segment of your clients are from the EU, you might choose to only comply with the rules related to them. It means you do not have to overhaul everything; you just need a setup which accommodates the GDPR rules with them!

So let’s see what GDPR wants you to do in a nutshell:

  • GDPR representative:
  • Lawful basis of processing:
  • Privacy policy:
  • Handle data subject requests:
  • Data Processing Agreements:
  • Manage data transfers:
  • Prepare for data breaches:
  • Records of processing activities*: if you are a startup it’s might not apply…

All of the above are of course could be written a book about, but everything depends on the details. Even if GDPR applies you might only need a simple time-to-time revised documentation and processes in place to handle requests and report breaches. But it can go in the heights where you need to employ a dedicated team to deal with all this.

I hope after reading this simplified guide you have a proximate understanding if GDPR applies to your situation or not. I am sure you might have questions, shoot us an email and let’s discuss them!