Recital 24

Recital 24

General Data Protection Regulation · UE 2016/679

(24)

The processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union should also be subject to this Regulation when it is related to the monitoring of the behaviour of such data subjects in so far as their behaviour takes place within the Union. In order to determine whether a processing activity can be considered to monitor the behaviour of data subjects, it should be ascertained whether natural persons are tracked on the internet including potential subsequent use of personal data processing techniques which consist of profiling a natural person, particularly in order to take decisions concerning her or him or for analysing or predicting her or his personal preferences, behaviours and attitudes.

Luxembourg specificity
loi luxembourgeoise du 1er aout 2018 portant organisation de la Commission nationale pour la protection des donnees et du regime general sur la protection des donnees

In Luxembourg, the CNPD (not APDL, which does not exist) is the competent supervisory authority for non-EU controllers and processors targeting individuals located in Luxembourg, save for the one-stop-shop mechanism. The law of 1 August 2018 organising the CNPD and implementing the GDPR confirms CNPD competence for complaints filed by Luxembourg residents against foreign actors, and Luxembourg's position as a fintech and e-commerce hub significantly increases extraterritorial exposure.

Luxgap practice: we recommend that Luxembourg fintechs and e-commerce platforms hosting third-party SDKs or pixels formally document, in their Article 30 record, the GDPR status of every detected non-EU actor, with proof of Article 27 representative designation on the vendor side.