Before discussing the GDPR’s specific requirements in greater depth, this chapter will clarify exactly which organizations are within the scope of the Regulation, who the authorities are, and what the repercussions for non-compliance can be.


The GDPR applies to organizations within the EU, as well as to any external organizations doing business within the EU. Specifically, it applies to non-EU organizations that:

•Offer products and/or services to individuals based in the EU

•Monitor EU residents’ behavior

•Process EU residents’ personal data

This includes organizations potentially everywhere in the world. This extensive reach is likely, however, to keep European organizations ...

Get EU GDPR & EU-U.S. Privacy Shield: A pocket guide, second edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.