controller or processor, instead of the geographical location of the personal data at
stake, is also to be found in some non-European jurisdictions. Such is the case of
Cape Verde,
149 and South Africa.
150
A more markedly territorial approach, based on the place of processing of the
personal data, is preferred by Brazil, which adopts it in its Civil Framework of the
Internet (“Marco Civil da Internet”),
151 and by Switzerland, where it has been
affirmed by the Federal Administrative Court.
152
4.2 The Applicability of Data Protection Rules to Foreign
Entities
A related issue is whether, and to what extent, electronic data processing by entities
seated outside a given jurisdiction is comprised in the scope of application of the
local rules concerning personal data protection.
Such is the purpose of article 3(2) of the GDPR, which states that:
This Regulation applies to the processing of personal data of data subjects who are in the
Union by a controller or processor not established in the Union, where the processing
activities are related to: (a) the offering of goods or services, irrespective of whether a
payment of the data subject is required, to such data subjects in the Union; or (b) the
monitoring of their behavior as far as their behavior takes place within the Union.
The GDPR hereby seeks to ensure that natural persons who are in the European
Union are not deprived of the protection to which they are entitled under the
Regulation, when the processing of their personal data is carried out by a controller
or processor not established in the Union, if the processing activities are related to
the offering goods or services to such persons
153 or to the monitoring of their
behavior.
154
The so-called market-place principle, which the previously applicable Directive
95/46/EC did not explicitly enshrine as a criterion for the determination of its spatial
scope of application,
155 was thus introduced in the Regulation.
156 By virtue of that
principle, European personal data protection rules have gained a certain degree of
extraterritorial applicability.
149 See the Cape-Verdean National Report, Sect. 4.1.
150 See the South-African National Report, Sect. 5.1.
151 Namely in article 11 thereof, according to which Brazilian law on rights to privacy shall apply to
any process of collection, storage, custody or treatment of personal data that occurs in national
territory: see the Brazilian National Report, Sect. 4.1.
152 See the Swiss National Report, Sect. 2.1.
153 See, on this, recital 23 of the Regulation.
154 See, on this, recital 24 of the Regulation.
155 On which see Carrascosa González (2015), pp. 448 ff.
156 See, in this sense, the German National Report, Sect. 2.7.1.
32
D. Moura Vicente and S. de Vasconcelos Casimiro
stake, is also to be found in some non-European jurisdictions. Such is the case of
Cape Verde,
149 and South Africa.
150
A more markedly territorial approach, based on the place of processing of the
personal data, is preferred by Brazil, which adopts it in its Civil Framework of the
Internet (“Marco Civil da Internet”),
151 and by Switzerland, where it has been
affirmed by the Federal Administrative Court.
152
4.2 The Applicability of Data Protection Rules to Foreign
Entities
A related issue is whether, and to what extent, electronic data processing by entities
seated outside a given jurisdiction is comprised in the scope of application of the
local rules concerning personal data protection.
Such is the purpose of article 3(2) of the GDPR, which states that:
This Regulation applies to the processing of personal data of data subjects who are in the
Union by a controller or processor not established in the Union, where the processing
activities are related to: (a) the offering of goods or services, irrespective of whether a
payment of the data subject is required, to such data subjects in the Union; or (b) the
monitoring of their behavior as far as their behavior takes place within the Union.
The GDPR hereby seeks to ensure that natural persons who are in the European
Union are not deprived of the protection to which they are entitled under the
Regulation, when the processing of their personal data is carried out by a controller
or processor not established in the Union, if the processing activities are related to
the offering goods or services to such persons
153 or to the monitoring of their
behavior.
154
The so-called market-place principle, which the previously applicable Directive
95/46/EC did not explicitly enshrine as a criterion for the determination of its spatial
scope of application,
155 was thus introduced in the Regulation.
156 By virtue of that
principle, European personal data protection rules have gained a certain degree of
extraterritorial applicability.
149 See the Cape-Verdean National Report, Sect. 4.1.
150 See the South-African National Report, Sect. 5.1.
151 Namely in article 11 thereof, according to which Brazilian law on rights to privacy shall apply to
any process of collection, storage, custody or treatment of personal data that occurs in national
territory: see the Brazilian National Report, Sect. 4.1.
152 See the Swiss National Report, Sect. 2.1.
153 See, on this, recital 23 of the Regulation.
154 See, on this, recital 24 of the Regulation.
155 On which see Carrascosa González (2015), pp. 448 ff.
156 See, in this sense, the German National Report, Sect. 2.7.1.
32
D. Moura Vicente and S. de Vasconcelos Casimiro
