Having EU visitors is not the test
What it is
The General Data Protection Regulation governs the processing of personal data about people in the EU. It applies to organizations established in the EU, and to organizations outside it that offer goods or services to people in the EU or monitor their behavior.
Does it apply to you
- You are established in the EU, in which case it applies to your processing generally.
- You offer goods or services to people in the EU. Merely being reachable from Europe does not meet this test. What does is evidence of intent to serve that market, such as pricing in euros, translated pages, or EU shipping.
- You monitor the behavior of people in the EU, which includes tracking visitors across a site to build a profile, whether or not you sell anything.
What being wrong costs
Supervisory authorities in each member state can investigate and fine, with the regulation setting maximum penalties as a percentage of worldwide annual turnover or a fixed ceiling, whichever is higher. Individuals can also bring claims. In practice the more common outcome for a small business is an order to change what it does, which is cheap to comply with and expensive to have discovered.
What it demands
- A lawful basis for each processing purpose, identified before processing starts.
- Transparent information about what is collected, why, for how long, and who else receives it.
- Consent that is freely given, specific, informed and unambiguous where consent is the basis, with withdrawal as easy as giving it.
- Honoring access, rectification, erasure, restriction, portability and objection rights, generally within one month.
- Appropriate security, and notification of certain breaches to a supervisory authority within 72 hours.
What WebSpark does
- Nothing third-party loads before consent in regions where prior consent is required, verified by a test that loads the site from an EU geography and watches for outbound requests.
- Retention is enforced by the storage rather than by a promise, and deletions are logged.
- Requests arrive through a form, are dated, and are tracked against the one-month deadline.
What you can show
- A consent log recording what was presented and what was chosen, by region.
- A record of the pre-consent request test, dated, showing zero third-party requests.
- A data processing agreement naming sub-processors and the retention schedule.
What stays yours
- Deciding whether you target the EU market, and appointing a representative if that obligation applies to you.
- Your lawful basis for processing that happens away from the website, and any records of processing activities the regulation requires you to keep.
Sources
- Regulation (EU) 2016/679 (General Data Protection Regulation)EUR-Lex, Publications Office of the European Union
- Guidelines 3/2018 on the territorial scope of the GDPREuropean Data Protection Board
WebSpark describes obligations and evidences what a site does. It does not provide legal advice, and this page is not a substitute for a lawyer who knows your business.