Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: EN

Article 2 Material scope


Summary What does Article 2 of the GDPR regulation say?

This article defines the material scope of the regulation — in other words, what types of processing activity it actually covers.

It establishes that the regulation applies to automated processing of personal data, as well as to manual processing where the data forms part of a structured filing system.

Critically, the article carves out several important exclusions, making clear that not all personal data processing falls under the GDPR.

It also clarifies the relationship between this regulation and other legal instruments, including a separate EU regulation governing data processing by EU institutions themselves, and the e-Commerce Directive.

Important points:

  • The regulation applies to you if you process personal data by automated means or within a structured filing system.
  • Four categories of processing are explicitly excluded: activities outside Union law, certain Member State activities under the TEU, purely personal or household activity, and processing by competent authorities for law enforcement purposes.
  • Processing by EU institutions and bodies falls under a separate regulation (EC) No 45/2001, not the GDPR directly.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. This Regulation applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system.

    1. This Regulation does not apply to the processing of personal data:

      1. in the course of an activity which falls outside the scope of Union law;

      2. by the Member States when carrying out activities which fall within the scope of Chapter 2 of Title V of the TEU;

      3. by a natural person in the course of a purely personal or household activity;

      4. by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security.

    1. For the processing of personal data by the Union institutions, bodies, offices and agencies, Regulation (EC) No 45/2001 applies. Regulation (EC) No 45/2001 and other Union legal acts applicable to such processing of personal data shall be adapted to the principles and rules of this Regulation in accordance with Article 98.

    1. This Regulation shall be without prejudice to the application of Directive 2000/31/EC, in particular of the liability rules of intermediary service providers in Articles 12 to 15 of that Directive.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod