← į akto dosjė

GDPR — 3 straipsnis

Straipsnio tekstas

3 straipsnis Teritorinė taikymo sritis 1. Šis reglamentas taikomas asmens duomenų tvarkymui, kai asmens duomenis Sąjungoje tvarko duomenų valdytojo arba duomenų tvarkytojo buveinė, vykdydama savo veiklą, neatsižvelgiant į tai, ar duomenys tvarkomi Sąjungoje, ar ne. 2. Šis reglamentas taikomas asmens duomenų tvarkymui, kai Sąjungoje esančių duomenų subjektų asmens duomenis tvarko Sąjungoje neįsisteigęs duomenų valdytojas arba duomenų tvarkytojas ir duomenų tvarkymo veikla yra susijusi su: a) prekių arba paslaugų siūlymu tokiems duomenų subjektams Sąjungoje, nepaisant to, ar už šias prekes arba paslaugas duomenų subjektui reikia mokėti; arba b) elgesio, kai jie veikia Sąjungoje, stebėsena. 3. Šis reglamentas taikomas asmens duomenų tvarkymui, kai asmens duomenis tvarko duomenų valdytojas, įsisteigęs ne Sąjungoje, o vietoje, kurioje pagal viešąją tarptautinę teisę taikoma valstybės narės teisė.

Kas dėl šio straipsnio rašė konsultacijose

Teikėjai, kurie savo tekste tiesiogiai nurodė būtent šį straipsnio numerį. Tai citata iš jų pačių teksto — ne mūsų vertinimas ir ne priežastinis ryšys.

11
verslo asociacija
8
įmonė
5
ACADEMIC_RESEARCH_INSTITTUTION
5
NVO
2
ES pilietis
KasŠalisKą parašė
Unipol GruppoIT(Motor Third Party Liability) Insurance MTPL insurance is an example of where the conflict above illustrated arises. According to Article 3 of the Directive 2009/103/CE1 (as further amended by Directive 2021/2118/UE), the conclusion of an insurance contract in
German Insurance AssociationDEdeal of effort for all group members, is hardly worthwhile anymore. • The EDPB guidelines on the interplay between Art. 3 and Chapter V GDPR have been useful as they clarity on the key criteria to qualify a processing as a transfer of personal data to a third
AMICE - Association of Mutual Insurers and Insurance Cooperatives in EuropeBE(Motor Third Party Liability) Insurance MTPL insurance is an example of where the conflict above illustrated arises. According to Article 3 of Directive 2009/103/CE1 (as further amended by Directive 2021/2118/UE), the conclusion of an insurance contract in res
DIGITALEUROPEBEupdates as parties transition roles. A new set of SCCs applicable to importers under Art. 3(2) GDPR remain necessary. Globally, numerous SCC sets, often for low-risk transfers, complicate integration, emphasising the importance of ongoing work towards mutual r
Selbstregulierung Informationswirtschaft e.V. (SRIW)DEadministrative fines – Joint Comments by SRIW and SCOPE Europe4 ■ Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR – Joint comments by SRIW, SCOPE Europe and th
Shoosmiths LLPGB2021 Standard Contractual Clauses are not suitable for importers whose processing operations are subject to the GDPR pursuant to Article 3, as they would duplicate and, in part, deviate from the obligations that already follow directly from the GDPR.
DoctrineFRce que de tels documents puissent être réutilisés conformément aux conditions définies aux chapitres III et IV de la directive, l’article 3 de celle-ci établit un droit à la réutilisation selon ces conditions » d’intérêt public, y compris le mode de fonction
MyData-TRUSTBEging to contact. One potential solution could involve implementing a central registry for organizations subject to the GDPR under Article 3.2 and active within the European Economic Area (EEA). Similar registries are in place in countries like Turkey, where fo
Van Bael & BellisBENo model clauses for international personal data transfers to controllers outside the EU who are subject to the GDPR pursuant to Article 3(2). In 2021, the Commission issued modernised Standard Contractual Clauses (SCCs) for international personal data transf
Technology Ireland, IbecIEreements adds complexity, requiring constant updates as parties transition roles. A new set of SCCs applicable to importers under Art. 3(2) GDPR remain necessary. Globally, numerous SCC sets, often for low-risk transfers, complicate integration, emphasising th
Centre for European PolicyDEtainties. For example, it should be expressly clarified whether or not the provision of data by the data owner in accordance with Art. 3-5 Data Act is covered by Art. 6 para. 1 lit c GDPR (processing necessary to comply with a legal obligation). 4 Röhl, K.-H.
Insurance EuropeBEes should be able to fulfil the controller’s obligation. • Other examples include: • The EDPB guidelines on the interplay between Art. 3 and Chapter V GDPR have been useful as they provide clarity on the key criteria to qualify a processing as a transfer of pe
La villa numerisFRion de réglementations semblables dans le monde. En réalité, c'est moins sa qualité intrinsèque que sa portée extra-territoriale (art. 3) qui a contraint les autres territoires à un alignement de fait. Il est d’ailleurs à craindre que dans d’autres zones géogr
Finnish EnergyFIf a "controller". In this specific example, it is unclear under the regulation whether the GDPR should be applicable according to Article 3(2b), as the service is not directly offered to the employees. General provisions and principles (Chapters I & II) Severa
Teodor TotevBGa Communication from the Commission to the Council and the European Parliament on European Contract Law /* COM/2001/0398 final */ Art. 3:102 Categories of Representation/ Clases de representación / Arten der Vertretung / English: (2) Where an intermediary acts
ITI - Information Technology Industry CouncilUSrly and avoid escalation to the EDPB. In particular, a case is admissible merely if the form in the Annex is completed correctly (Article 3(1)), a complaint is “non-contentious” if there are no objections from CSAs (Article 9(6)), and a complaint is deemed “ur
Centre for Information Policy Leadership (CIPL)BEobservation, CIPL welcomes the efforts to create standards of admissibility in Article 3 of the proposed Regulation. We note, however, that the Proposal is focused on form completeness and neglects a standard for substance. This carries the risk of incentivisi
Hans-Hermann SchildDEausgegangen werden. Immerhin soll die Aufsichtsbehörde zur Prüfung der Vollständigkeit des Formulars auch einen Monat Zeit haben, Art. 3 Abs. 3 VO-E. Zwar sollen durch die Klärung der Rollen aller Beteiligten und die Festlegung von Fristen für bestimmte Verfah
Border Violence Monitoring NetworkDEcontrols on how the data of people on the move is collected and processed. Not only within EU territory, but also at its borders. Article 3 of the EUDPR establishes that the regulation applies to the processing of personal data by controllers in the EU “regard
noybATobligations in Article 28 of this Regulation.4 3. This Regulation does not prevent Member States to further specify procedures.5 Article 3 - Definitions For the purpose of this Regulation, definitions in the GDPR equally apply to this Regulation and: 1. ‘Nat
Multi-Regional Clinical Trials Center of Harvard University and Brigham and Women’s HospitalUSGuidelines 3/2018 on the Territorial Scope of the GDPR (Article 3) – Version for Public Consultation (Nov. 16, 2018). 53 See European Commission, Standard contractual clauses for data transfers between EU and non-EU countries, https://ec.europa.eu/info/law/la
Fundamental Rights European Experts Group (FREE-Group)BEr the GDPR; among many other issues, they do not properly address transfers made to controllers who are subject to the GDPR under Article 3(2).5 (bd) there are no standard clauses for processor to processor transfers; (be) no codes of conduct have as yet been
Gesamtverband der Deutschen Versicherungswirtschaft e.V.DEare worthy of protection might be severely harmed. The applicability of Article 3(5) of Regulation (EEC, EURATOM) No. 1182/71 of the Council of 3 June 1971, which allows for at least two working days for the verification, should be explicitly clar- ified. e) C
International Society for Biological and Environmental Repositories (ISBER)USout outside of the EU by a non-EU entity, would fall under GDPR Article 3(2); and (3) guidance regarding when personal data may be transferred for research purposes on the basis of public interest.50 B.
Internet Corporation for Assigned Names and NumbersUSprocessors outside of the EEA which are directly subject to GDPR provisions pursuant to Art. 3 GDPR would be helpful. It 1 See https://edpb.europa.eu/news/news/2018/european-data-protection-board-endorsed-statement-wp29- icannwhois_en. 2 See http://data.consil
DIGITALEUROPEBEcontroller is also subject to the GDPR, but the obligations exist irrespective of this. Arguably, a processor could be caught by Art. 3(2) but not a controller.
of the personal data of an US customer by the headquarter in the EU using an EU-located server. 7 d) Suggestion: Art. 3 subsection 1 GDPR should be clarified as follows: “This Regulation ap- plies to the processing of personal data in the context of the activi
Global Alliance for Genomics and HealthCAtraterritorial effects. For example, in France, the relevant legislation applies where the data of French residents is processed (Art 3, ​Loi n° 78-17 du 6 janvier 1978 relative à l'informatique, aux fichiers et aux libertés​). This means that an EU controller
American ExpressUScifically regarding the “monitoring of data subjects’ behavior” to determine what specific activities constitute monitoring under Article 3(2)(b) of the GDPR. GDPR application in the online space American Express believes that the effective implementation of G
AFME - Association for Financial Markets in EuropeBEt concerns multinational organisations with cross-border activities which may pose challenges in determining the applicability of Article 3 GDPR.

Šaltinis: viešų konsultacijų atsiliepimai ir pozicijų dokumentai. n = 35 paminėjimų; skaičiuojama pažodinė nuoroda į straipsnio numerį.

Klausti apie šį straipsnį →