CHAPTER IGENERAL PROVISIONS

Article 2Material scope

Official text

(1)This Regulation applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system.

(2)This Regulation does not apply to the processing of personal data:

(a)in the course of an activity which falls outside the scope of Union law;

(b)by the Member States when carrying out activities which fall within the scope of Chapter 2 of Title V of the TEU;

(c)by a natural person in the course of a purely personal or household activity;

(d)by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security.

(3)For the processing of personal data by the Union institutions, bodies, offices and agencies, Regulation (EC) No 45/2001 applies. Regulation (EC) No 45/2001 and other Union legal acts applicable to such processing of personal data shall be adapted to the principles and rules of this Regulation in accordance with Article 98.

(4)This Regulation shall be without prejudice to the application of Directive 2000/31/EC, in particular of the liability rules of intermediary service providers in Articles 12 to 15 of that Directive.

Commentary

Article 2 GDPR, Material Scope Commentary Article 2 explains what types of processing activities are covered by the GDPR. While Article 3 answers the geographical question -“where does the GDPR apply?” - Article 2 answers the subject-matter question -“what kinds of data processing does the GDPR regulate?”

Article 2 must be read with Recitals 13 to 21 and Recital 27. These Recitals explain the GDPR's technology-neutral approach, its non-application to legal persons and deceased persons, the household exemption, exclusions for national security and criminal law enforcement, and the relationship with electronic commerce rules.

Article 2(1): Automated processing and filing systems

Article 2(1) has two main limbs. The GDPR applies to:

  • processing of personal data wholly or partly by automated means; and
  • non-automated processing of personal data where the data forms part of, or is intended to form part of, a filing system.

This provision is deliberately broad. The first requirement is that there must be personal data. This links to Article 4(1), which defines personal data as information relating to an identified or identifiable natural person. The second requirement is processing, defined under Article 4(2), which includes collection, recording, storage, use, disclosure, alteration, restriction and deletion. In practical terms, almost every meaningful use of personal data in a digital environment will fall under Article 2(1).

Illustration

Illustration

A “filing system” is defined in Article 4(6) as a structured set of personal data accessible according to specific criteria. The structure does not need to be sophisticated. If records are arranged by name, employee number, room number, membership ID, date of visit or file reference, they may be part of a filing system.

Illustration

Article 2(2): Exclusions from GDPR

Article 2(2) lists situations where the GDPR does not apply, even if personal data is involved.

2.1 Article 2(2)(a): Activities outside Union law The GDPR does not apply to processing carried out in the course of activities outside the scope of EU law. This exclusion is linked to Recital 16, which mentions national security. The EU can legislate only within its legal competence. Matters outside EU competence, especially national security, remain primarily with Member States. Therefore, processing by state intelligence agencies for national security purposes would usually fall outside the GDPR.

Illustration

2 Article 2(2)(b): Common Foreign and Security Policy

Article 2(2)(b) excludes processing by Member States when carrying out activities under the EU's Common Foreign and Security Policy. This also connects with Recital 16. This provision is relatively specialised. It covers Member State activities in areas such as foreign policy, defence cooperation and security policy within the framework of the Treaty on European Union.

Illustration

3 Article 2(2)(c): Purely personal or household activity

This is one of the most practically important exclusions. The GDPR does not apply when a natural person processes personal data in the course of a purely personal or household activity. This is linked to Recital 18, which gives examples such as personal correspondence, maintaining address books, and social networking where the activity remains purely personal. There are three important limits. First, the exemption applies only to natural persons, not companies, societies, trusts, NGOs or associations.

Illustration

Illustration

Illustration

4 Article 2(2)(d): Criminal law enforcement by competent authorities

The GDPR does not apply to processing by competent authorities for prevention, investigation, detection or prosecution of criminal offences, execution of criminal penalties, or safeguarding against threats to public security. This connects with Recital 19. Such processing is mainly governed by the Law Enforcement Directive, Directive (EU) 2016/680, as implemented by Member States. The exclusion applies only where processing is carried out by competent authorities for law enforcement purposes.

Illustration

Article 2(3): EU institutions

Article 2(3) deals with data processing by EU institutions, bodies, offices and agencies. The GDPR itself does not directly govern them in the same way it governs private controllers or Member State bodies. Instead, EU institutions are governed by a separate but aligned framework, now Regulation (EU) 2018/1725. This connects with Recital 17, which required EU institutional data protection rules to be adapted to GDPR principles. The European Data Protection Supervisor supervises EU institutions.

Illustration

Article 2(4): E-Commerce Directive

Article 2(4) states that the GDPR does not prejudice the application of Directive 2000/31/EC, especially intermediary liability rules. This connects with Recital 21. This means GDPR obligations and intermediary liability rules operate side by side. Online intermediaries may benefit from liability protections for third-party content under e-commerce rules, but they must still comply with GDPR for their own processing of personal data.

Illustration