7 Private International Law Rules
The territorial scope of application of data protection rules is laid down in Art. 3 of
the GDPR that reads as follows:
Article 3 Territorial scope
1. This Regulation applies to the processing of personal data in the context of the activities
of an establishment of a controller or a processor in the Union, regardless of whether the
processing takes place in the Union or not.
2. This Regulation applies to the processing of personal data of data subjects who are in the
Union by a controller or processor not established in the Union, where the processing
activities are related to:
(a) the offering of goods or services, irrespective of whether a payment of the data
subject is required, to such data subjects in the Union; or
(b) the monitoring of their behaviour as far as their behaviour takes place within the
Union.
3. This Regulation applies to the processing of personal data by a controller not established
in the Union, but in a place where Member State law applies by virtue of public
international law.
The above relatively broad reach of the GDPR raises a number of questions
namely as to enforcement. To put it short, the GDPR also theoretically applies to
cases when data are processed by offshore entities and processing takes place on
foreign soil and so it is questionable to which extent can the EU or its member-states
provide for truly efficient investigation and sanctions of data compliance or data
breaches.
Due to overall lack of case-law and past lack of investigative activity of the Czech
DPA in cases with cross-border outreach, there is no substantial Czech case-law on
data transfers. Most relevant case-law of the CJEU on cross-border processing of
personal data includes:
– C-131/12 Google Spain SL and Google Inc. v Agencia Española de Protección de
Datos (AEPD) and Mario Costeja González.
– C-230/14 Weltimmo s. r. o. v Nemzeti Adatvédelmiés Információszabadság
Hatóság.
– C-498/16 Maximilian Schrems v Facebook Ireland Limited.
For the sake of efficiency, the GDPR contains limitations to data transfers. Data
are allowed to be transferred for processing in a third country or an international
organisation (incl. making them available for access from a third country) only under
conditions specified in Art. 45 and 46 of the GDPR. The general rule for data
transfers to third countries is laid down in Art. 44 that reads as follows:
Article 44 General principle for transfers
Any transfer of personal data which are undergoing processing or are intended for
processing after transfer to a third country or to an international organisation shall take
place only if, subject to the other provisions of this Regulation, the conditions laid down in
this Chapter are complied with by the controller and processor, including for onward
154
R. Polčák et al.
The territorial scope of application of data protection rules is laid down in Art. 3 of
the GDPR that reads as follows:
Article 3 Territorial scope
1. This Regulation applies to the processing of personal data in the context of the activities
of an establishment of a controller or a processor in the Union, regardless of whether the
processing takes place in the Union or not.
2. This Regulation applies to the processing of personal data of data subjects who are in the
Union by a controller or processor not established in the Union, where the processing
activities are related to:
(a) the offering of goods or services, irrespective of whether a payment of the data
subject is required, to such data subjects in the Union; or
(b) the monitoring of their behaviour as far as their behaviour takes place within the
Union.
3. This Regulation applies to the processing of personal data by a controller not established
in the Union, but in a place where Member State law applies by virtue of public
international law.
The above relatively broad reach of the GDPR raises a number of questions
namely as to enforcement. To put it short, the GDPR also theoretically applies to
cases when data are processed by offshore entities and processing takes place on
foreign soil and so it is questionable to which extent can the EU or its member-states
provide for truly efficient investigation and sanctions of data compliance or data
breaches.
Due to overall lack of case-law and past lack of investigative activity of the Czech
DPA in cases with cross-border outreach, there is no substantial Czech case-law on
data transfers. Most relevant case-law of the CJEU on cross-border processing of
personal data includes:
– C-131/12 Google Spain SL and Google Inc. v Agencia Española de Protección de
Datos (AEPD) and Mario Costeja González.
– C-230/14 Weltimmo s. r. o. v Nemzeti Adatvédelmiés Információszabadság
Hatóság.
– C-498/16 Maximilian Schrems v Facebook Ireland Limited.
For the sake of efficiency, the GDPR contains limitations to data transfers. Data
are allowed to be transferred for processing in a third country or an international
organisation (incl. making them available for access from a third country) only under
conditions specified in Art. 45 and 46 of the GDPR. The general rule for data
transfers to third countries is laid down in Art. 44 that reads as follows:
Article 44 General principle for transfers
Any transfer of personal data which are undergoing processing or are intended for
processing after transfer to a third country or to an international organisation shall take
place only if, subject to the other provisions of this Regulation, the conditions laid down in
this Chapter are complied with by the controller and processor, including for onward
154
R. Polčák et al.
