Material Scope of the GDPR

The GDPR's material scope determines which processing activities are regulated. It applies broadly to the automated processing of personal data and to structured manual filing systems, subject to limited exceptions. Understanding its scope is the first step in determining whether the GDPR applies.

Material Scope of the GDPR
ChatGPT modified from- Langley’s human computers at work (Photograph published in Winds of Change, 75th Anniversary NASA publication (page 48), by James Schultz) (1947) — NASA Commons DESCRIPTION: In the terminology of that period, ‘computers’ were employees typically female that performed mathematical computations
Key Points: The GDPR applies to the automated processing of personal data and to manual processing of personal data that forms part of, or is intended to form part of, a structured filing system. The Regulation applies broadly to organizations of all sizes, including private companies, public authorities, and nonprofit organizations.

What constitutes ‘computerized’ under EU data protection law?

The scope of EU data protection law expands beyond information in electronic form to cover processing of personal data in two ways:

  1. personal data processed wholly or partly by automated means (that is, information in electronic form); and
  2. personal data processed in a non-automated manner which forms part of, or is intended to form part of, a ‘filing system’ (that is, manual information in a filing system).

By expanding beyond data in electronic form, GDPR prevents situations where data protection law could be by-passed by keeping information in paper form during a particular stage of processing. For example, the rules that apply to cross-border data transfers cannot be by-passed by exporting information in paper form as part of a filing system which then can easily be transferred into electronic form once outside the borders of the European Union.

Un-structured paper records are outside of the scope of EU data protection law [1] but the line between structured and unstructured filing systems in practice can be blurry. You can read a detailed explanation, including examples and helpful guidelines.

What constitutes ‘processing’ under EU data protection law?

Article 4(2) of GDPR defines processing to mean:

“any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction”

‘Computerized’ processing under EU data protection law

The reference “any operation or set of operations” indicates the regulator’s intent to provide a broad definition for the concept of processing. “Processing”, in relation to information or data means obtaining, recording or holding the information or data or carrying out any operation or set of operations on the information or data, including:

  • organization, adaptation or alteration of the information or data,
  • retrieval, consultation or use of the information or data,
  • disclosure of the information or data by transmission,
  • dissemination or otherwise making available, or
  • alignment, combination, blocking, erasure or destruction of the information or data.

What is ‘personal data’ under EU data protection law?

See: What is Personal Data under EU Data Protection Law?

ChatGPT modified from - Early “computers” at work, summer 1949 — NASA on The Commons. The late 1940s saw increased flight activity, and more women computers were needed . A call went out to the NACA Langley, Lewis, and Ames laboratories for more women computers. Pictured in this photograph with the snowman are some of the women computers who responded to the call for help in 1948 along with those who were already there. Standing left to right: Mary (Tut) Hedgepeth, from Langley; Lilly Ann Bajus, Lewis; Roxanah Yancey, Emily Stephens, Jane Collons (Procurement), Leona Corbett (Personnel), Angel Dunn, Langley.

ACTIVITIES REGULATED BY EU DATA PROTECTION LAWS OTHER THAN GDPR

GDPR is not the only data protection law of the European Union. Also, there are limits to the ability of the European Union to legislate based on the international agreements that are the foundational documents of the EU. For those reasons, GDPR explicitly excludes from its material scope certain activities.

Article 2.2 of GDPR establishes that:

2. This Regulation does not apply to the processing of personal data:
(a) in the course of an activity which falls outside the scope of Union law;
(b) by the Member States when carrying out activities which fall within the scope of Chapter 2 of Title V of the TEU;
[…]
(d) by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security.

This means in practice that:

  1. The processing of personal data by competent authorities for law enforcementpurposes is outside the scope of GDPR (e.g. the Police investigating a crime), but subject to EU data protection law under Directive 2016/680, and may also be subject to Member State level data protection regulations
  2. Personal data processing for the purposes of safeguarding national security or defence is outside the scope of EU data protection law but may be subject to data protection regulations enacted by individual Member States

In addition, Article 2.3 of GDPR establishes that:

3. For the processing of personal data by the Union institutions, bodies, offices and agencies, Regulation (EC) No 45/2001 applies. Regulation (EC) No 45/2001 and other Union legal acts applicable to such processing of personal data shall be adapted to the principles and rules of this Regulation in accordance with Article 98.

This means that personal data processing by EU institutions is not subject to GDPR. Regulation No 45/2001 was derogated in 2018. The processing of personal data by the EU institutions is currentlysubject to Regulation EU 2018/1725.


EXCLUSIONS

The processing of personal data in the course of a purely personal or household activity, with no connection to a professional or commercial activity, is outside the scope of EU data protection law.

Article 2.2 of GDPR establishes that:

2. This Regulation does not apply to the processing of personal data:
[…]
(c) by a natural person in the course of a purely personal or household activity;

This means in practice that EU data protection law does not apply if you only use personal data for such things as writing to friends and family or taking pictures for personal enjoyment. This is a narrow exception.

Early “computers” at work — NASA on The Commons. NOTE: The late 1940s saw increased flight activity, and more women computers were needed . A call went out to the NACA Langley, Lewis, and Ames laboratories for more women computers. Pictured in this photograph with the snowman are some of the women computers who responded to the call for help in 1948 along with those who were already there. Kneeling left to right: Dorothy (Dottie) Crawford Roth, Lewis; Dorothy Clift Hughes, and Gertrude (Trudy) Wilken Valentine, Lewis.

End notes:

[1] Some countries have expanded the scope of their national data protection laws to include unstructured data in certain situations. For example, under the UK Data Protection Act 2018 (DPA 2018), unstructured manual information processed by public authorities only constitutes personal data, including paper records that are not held as part of a filing system. While this information is personal data under the DPA 2018, it is exempt from most of the principles and obligations in the GDPR to ensure that it is appropriately protected for requests under the Freedom of Information Act of 2000.

Resources:

Subscribe to The de la Torre Review

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe