<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GDPR Scope in Privacy</title>
    <link>https://community.isc2.org/t5/Privacy/GDPR-Scope/m-p/20516#M748</link>
    <description>&lt;P&gt;I think the point here is that if you do business in a specific country, you will follow the rules of that country.&lt;/P&gt;</description>
    <pubDate>Wed, 27 Mar 2019 13:40:05 GMT</pubDate>
    <dc:creator>Balby84</dc:creator>
    <dc:date>2019-03-27T13:40:05Z</dc:date>
    <item>
      <title>GDPR Scope</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Scope/m-p/20504#M743</link>
      <description>&lt;P&gt;Does GDPR apply to Non-EU data subjects (living outside the EU member countries) if the controller(Data Owner company) or processor (Cloud Service Provider )company based in the EU?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2019 08:20:59 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Scope/m-p/20504#M743</guid>
      <dc:creator>iluom</dc:creator>
      <dc:date>2019-03-27T08:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR Scope</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Scope/m-p/20507#M744</link>
      <description>&lt;P&gt;This is actually a quite interesting question, following this thread&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2019 11:40:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Scope/m-p/20507#M744</guid>
      <dc:creator>Balby84</dc:creator>
      <dc:date>2019-03-27T11:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR Scope</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Scope/m-p/20508#M745</link>
      <description>&lt;P&gt;Personally I would never want someone that I didn't elect making laws "on my behalf".&amp;nbsp; Most likely they wouldn't have my best interests at heart because they didn't consult me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2019 11:40:43 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Scope/m-p/20508#M745</guid>
      <dc:creator>Flyslinger2</dc:creator>
      <dc:date>2019-03-27T11:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR Scope</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Scope/m-p/20513#M746</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/637665353"&gt;@iluom&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Does GDPR apply to Non-EU data subjects (living outside the EU member countries) if the controller(Data Owner company) or processor (Cloud Service Provider )company based in the EU?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Yes, the GDPR would apply in your example.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is covered under the first point in Article 3 of the General Provisions section of the GDPR:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://gdpr-info.eu/art-3-gdpr/" target="_blank"&gt;https://gdpr-info.eu/art-3-gdpr/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"Article 3&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Territorial scope&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;1. This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Effectively it is saying that all EU based companies have to process ALL personal data in accordance with the GDPR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2019 13:28:30 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Scope/m-p/20513#M746</guid>
      <dc:creator>AlecTrevelyan</dc:creator>
      <dc:date>2019-03-27T13:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR Scope</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Scope/m-p/20514#M747</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/297159657"&gt;@Flyslinger2&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Personally I would never want someone that I didn't elect making laws "on my behalf".&amp;nbsp; Most likely they wouldn't have my best interests at heart because they didn't consult me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;This is one of the core arguments used by people who voted for Brexit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2019 13:29:27 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Scope/m-p/20514#M747</guid>
      <dc:creator>AlecTrevelyan</dc:creator>
      <dc:date>2019-03-27T13:29:27Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR Scope</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Scope/m-p/20516#M748</link>
      <description>&lt;P&gt;I think the point here is that if you do business in a specific country, you will follow the rules of that country.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2019 13:40:05 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Scope/m-p/20516#M748</guid>
      <dc:creator>Balby84</dc:creator>
      <dc:date>2019-03-27T13:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR Scope</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Scope/m-p/20520#M749</link>
      <description>&lt;P&gt;If you happen to be an American, and with no intention to say something against America, but the data laws in place there, as well as the gvm'ts ability to access any data it wants at any time with the flip of a finger, should make you wish your data was stored in the EU or subject to EU regulations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I, when considering where to store my corporate data, will never store it in the US, for that reason.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so you should be happy with what the EU does in privacy regards, even if it is a bit of a mishmash.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2019 14:19:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Scope/m-p/20520#M749</guid>
      <dc:creator>MikeGlassman</dc:creator>
      <dc:date>2019-03-27T14:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR Scope</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Scope/m-p/20521#M750</link>
      <description>I would change the words "you will" to "you are required".&lt;BR /&gt;&lt;BR /&gt;This is even more true if you are discussing privacy issues.</description>
      <pubDate>Wed, 27 Mar 2019 14:21:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Scope/m-p/20521#M750</guid>
      <dc:creator>MikeGlassman</dc:creator>
      <dc:date>2019-03-27T14:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR Scope</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Scope/m-p/20530#M751</link>
      <description>&lt;P&gt;If ever you have any sort of doubt around whether GDPR is in scope or not, follow a simple rule:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If at any point a reference is made to the EU, an EU citizen or anything European, it is more or less certain that GDPR is applicable.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Therefore, while looking at your task, if any single piece of it lands on EU soil, or citizen - Bingo - GDPR.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2019 16:01:58 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Scope/m-p/20530#M751</guid>
      <dc:creator>HTCPCP-TEA</dc:creator>
      <dc:date>2019-03-27T16:01:58Z</dc:date>
    </item>
    <item>
      <title>Re: GDPR Scope</title>
      <link>https://community.isc2.org/t5/Privacy/GDPR-Scope/m-p/20531#M752</link>
      <description>&lt;P&gt;&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.isc2.org/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; awesome!!!&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2019 16:13:28 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GDPR-Scope/m-p/20531#M752</guid>
      <dc:creator>iluom</dc:creator>
      <dc:date>2019-03-27T16:13:28Z</dc:date>
    </item>
  </channel>
</rss>

