Law
Extraterritorial Application of National Data Protection Laws
Quick fact
The GDPR can fine companies up to €20 million or 4% of annual global turnover—whichever is higher—even if the company has no physical presence in the EU, as long as it targets or monitors EU residents.
Why this is interesting
You might think that the EU's data protection law (GDPR) only applies to companies inside Europe. But if you run a website from New York, you might still have to follow it. How can a law leap across borders and bind you?
Read the full explanation
Understanding Extraterritorial Application of National Data Protection Laws
Imagine you are in your house, and you make a rule that any noise that comes into your house must be quiet. That rule only works if you can control the source. Similarly, a country can make a law about what happens inside its borders, but how can it control what happens outside? Extraterritorial application means a country says 'If you want to interact with people in my country, you have to respect my rules, no matter where you are.' For data protection, this works by focusing on the people whose data is being processed, not the location of the company. If a company outside the EU offers goods or services to EU residents, or monitors their behavior (like tracking cookies), then the GDPR applies. This is like a club that says 'If you want to serve our members, you must follow our membership rules, even if your clubhouse is abroad.' The key is the 'targeting' or 'monitoring' test—it's about whether you deliberately reach out to people in the jurisdiction.
A deeper explanation
The mechanism behind extraterritoriality is rooted in the idea of 'effects'—if your actions have effects inside a country, that country claims the right to regulate them. This is supported by international law concepts like the 'effects doctrine,' which allows states to assert jurisdiction when conduct abroad has substantial effects within their territory. The GDPR's extraterritorial provisions (Article 3) are a prime example. They operate on two grounds: 1) an establishment in the EU (even a small branch), and 2) no establishment, but the processing is related to offering goods or services to individuals in the EU, regardless of payment, or monitoring of behavior as far as it takes place within the EU. This targeting is determined by factors like language, currency, or mentioning EU customers. Why does this matter? In a globalized digital economy, data flows across borders seamlessly. Allowing each country to apply its laws only within its physical territory would create legal loopholes. Extraterritoriality closes those loopholes, ensuring that companies cannot escape obligations by simply locating their servers elsewhere. However, it creates tensions between countries with differing legal standards, leading to jurisdictional conflicts and the risk of inconsistent or conflicting obligations. For example, a company might have to comply with both the GDPR and the US CLOUD Act, which requires data to be handed over even if it's stored abroad. This clash of laws is a major challenge in the modern political geography of the internet.