processor in the Union, regardless of whether the processing takes place in the Union
or not, (Art. 3 para. 1 GDPR)
85 but also to processing of personal data of data
subjects who are in the Union by a controller or processor not established in the
Union, where the processing activities are related to either the offering of goods or
services to such data subjects in the Union, or the monitoring of their behaviour as
far as this behaviour takes place within the Union (Art. 3 para. 2 GDPR). The latter
so-called “market place principle” did not form part of the former data protection
Framework of the European Union and so significantly extends the territorial scope
of application compared to the Directive 95/46.Moreover, the notion of establishment of the controller under Art. 3 para. 1 GDPR has to be understood in a rather
broad sense.
86 Following the Google Case of the ECJit would be sufficient for an
establishment in a Member State to have an office or subsidiary (as a separate legal
person) for the purpose of promoting and selling advertising space, which orientates
its activity towards the inhabitants of that Member State.
87
Art. 3 para. 1 ePR mainly extends the principle enshrined in Art. 3 para. 2 GDPR
to the provision of electronic communications services to “end-users in the Union”
(Art. 3 para. 1 lit. a)ePR). Art. 3 para. 1 lit. b) and c) ePR clarify that this includes the
pure use of such services and the protection of information related to the terminal
equipment of end-users located in the Union. Moreover Art. 3 paras. 2–5 ePR oblige
the provider to designate a representative in the Union.
Whereas the exact meaning of the rules on the territorial scope under the 1995
Directive had been open to discussion, Art. 3 GDPR brought some clarifications:
The article not only has to be understood as a rule for the international application of
administrative law but in the sense of private international law, also. In the latter
sense the Article also serves as basis for a general lex protectionis datorum within the
Internal Market,
88 which concurs with other legal instruments on private international law. As did Art. 4 of the Directive 95/46
89 Art. 3 GDPR beyond regulating the
pure scope of application of the regulation also establishes general principles for the
application of data protection rules within the Internal Market. Therefore, Art.
3 GDPR also provides for rules of private international law organizing the application of the remaining national data protection rules of the Member States.
In its scope of application, Art. 3 GDPR (and the lex protectionis datorum)
overrules the general regimes of the Rome I and Rome II Regulations as far as
applicable, cf. Art. 1 para. 2 lit. g) Rome II Regulation,
90 and the respective national
rules on private international law. However, this particular regime does not exclude
the application of Art. 9 Rome I Regulation but—as with articles 6 and 8 Rome I
85 This includes controllers not established in the Union, but in a place where Member State law
applies by virtue of public international law, Art. 3 para. 3 GDPR.
86 Oberverwaltungsgericht Schleswig, NJW 2013, p. 1977, para. 13.
87 ECJ, judgmentof13 May 2014, C-131/12 ¼ EuZW 2014, 541.
88 Cf. Schmidt-Kessel in Ferrari (2014), Art. 9 Rome I-Regulation, no. 51–57.
89 Schmidt-Kessel in Ferrari (2014), Art. 9 Rome I-Regulation, no. 54.
90 Cf. Voigt (2014), pp. 15 et seq.; cf. Bach in Huber (2009), Art. 1 no. 53–59.
Data Protection in the Internet: National Report Germany
207
Précédent

- 215/540

Suivant