Material scope (GDPR)
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.What processing the GDPR applies to — and the exclusions: purely personal or household activity, law enforcement, EU institutions (Article 2 GDPR).
Overview
27 sources · Aug 27, 2026Legal Framework
Article 2 GDPR sets out the material scope of the regulation. It applies to two categories of processing: any processing of personal data wholly or partly by automated means, and non-automated processing of personal data that forms part of a filing system or is intended to do so.
"the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system"
— GDPR Art. 2(1)
Article 2(2) carves out four exclusions. Processing falls outside the GDPR where it occurs: (a) in the course of an activity outside the scope of Union law; (b) by Member States under the Common Foreign and Security Policy; (c) by a natural person in a purely personal or household activity; or (d) by competent authorities for law enforcement and criminal justice purposes. Article 2(3) routes processing by EU institutions to Regulation 45/2001, while Article 2(4) preserves the e-Commerce Directive's liability regime for intermediary service providers. The household exemption at Article 2(2)(c) is the most litigated boundary:
"by a natural person in the course of a purely personal or household activity"
— GDPR Art. 2(2)(c)
Key Developments
The CJEU's ruling in RYNES (C-212/13) established the leading benchmark for the household exemption. The case involved a home-owner whose surveillance camera, installed for property protection, also recorded a public street. The Court framed the core question as follows:
"installed by an individual on his family home for the purposes of protecting the property, health and life of the home owners, but which also monitors a public space"
— RYNES, C-212/13, ¶3
The CJEU held that processing extending beyond the personal sphere into public space falls outside the household exemption, meaning the data protection legislation applied. The ruling confirmed that the exemption is narrowly construed and turns on whether the processing remains confined to the domestic sphere.
The EDPB has reinforced this boundary in the connected-vehicle context. Even where an individual's own use qualifies as household activity, the controller providing the means of processing remains subject to the GDPR:
"it does apply to controllers or processors, which provide the means for processing personal data for such personal or household activities"
— EDPB Guidelines 1/2020, ¶73
This means car manufacturers, app developers, and service providers cannot shelter behind the end-user's household exemption.
Status of the Debate
This topic is contested. While the automated-processing threshold in Article 2(1) is settled, the household exemption at Article 2(2)(c) remains actively litigated. RYNES drew the line at public-space monitoring, but the precise boundary for borderline scenarios—home-office CCTV, social media posts, neighbourhood WhatsApp groups—has not been definitively resolved at the CJEU level. National courts and DPAs continue to diverge on where "personal" ends and "professional or public" begins. A further CJEU reference clarifying the outer limits of the household exemption, particularly in the context of online activities and remote work, would resolve the open question.
Practical Guidance
- Automated processing: If personal data is processed wholly or partly by automated means, the GDPR applies regardless of data volume or purpose—assess compliance from this baseline.
- Non-automated records: Manual processing of personal data is covered only if the data forms part of a structured filing system. Verify whether your paper records meet this threshold before claiming an exclusion.
- Household exemption: Apply RYNES narrowly—any processing that extends to public spaces or involves professional activity likely falls outside the exemption. Document the rationale if you claim it.
- Provider liability: Even if your end-users benefit from the household exemption, as a controller or processor providing the processing infrastructure you remain subject to the GDPR in full.
- EU institutions: If your entity is an EU institution, body, or agency, confirm compliance with Regulation 45/2001 rather than the GDPR directly.
why this is here
This Regulation applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system.
The provision directly defines the material scope by specifying which processing activities fall under the GDPR.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
the Regulation does not apply to processing of data that has no reference to a person
The document explicitly discusses household exemption and law enforcement directive exclusions, key for material scope.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
het door de belastingautoriteit van een lidstaat verzamelen van persoonsgegevens betreffende de op de website van een marktdeelnemer geplaatste advertenties voor de verkoop van voertuigen binnen het materiële toepassingsgebied van de AVG valt
The central issue is whether the GDPR applies to a tax authority's data request, with detailed analysis of Articles 2(1) and 2(2), making it a primary source on material scope.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026