28.2 GDPR scope, lawful processing and incident response

Key Takeaways

  • GDPR territorial scope depends on establishment, offering services or monitoring behavior.

  • Processing needs an applicable lawful basis; consent is not the only possible basis.

  • The seventy-two-hour supervisory breach rule has a risk exception and differs from the individual-notice test.

Last updated: October 2026

Establish territorial and activity scope

The European Union’s General Data Protection Regulation (GDPR) is not automatically applicable to every United States bank record about a European citizen. Article 3 establishes territorial scope, including processing in the context of an establishment in the Union and specified activities involving people in the Union by an entity outside it. Those activities include offering goods or services and monitoring behavior occurring there. Citizenship alone is not the test.

A United States bank with a European establishment or an intentional service offering to people in the Union needs a supported scope analysis. A website merely being accessible from Europe does not by itself settle whether the bank offers services there. Examine language, marketing, service availability, targeting and actual operations. Do not confuse GDPR with GLBA: they can govern overlapping data but use different definitions, duties and jurisdiction tests.

Define the actors and information

Personal data means information relating to an identified or identifiable natural person. An identifier combined with other information can remain personal data even after a name is removed. Pseudonymization changes identification risk but does not necessarily make the information anonymous and outside the regulation. Determine whether reidentification is reasonably possible in the relevant context.

A controller determines purposes and means of processing; a processor processes personal data on the controller’s behalf. Contract labels are not conclusive when the actual roles differ. A vendor can be a processor for one service and a controller for another. Document the relationship, purposes, instructions, security and required contractual terms. Subprocessor and cross-border arrangements require their own assessment.

Principles and lawful bases

Article 5 includes principles of lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability. A bank should be able to explain why it collects information, how long it retains it, who receives it and how it protects it. Collecting everything that may be useful someday conflicts with a purpose-based approach.

Article 6 identifies lawful bases, including consent, contractual necessity, legal obligation and legitimate interests subject to its conditions. Consent is not the universal answer for bank processing. A genuinely necessary account service may have another basis, while optional marketing or unrelated reuse requires its own analysis. A notice is not consent simply because it describes a practice. Special-category data and criminal-offense information have additional restrictions.

Processing questionEvidence to examine
Purpose and lawful basisData inventory and documented analysis
Consumer understandingAppropriate privacy information
RetentionApplicable legal duties and retention schedule
Vendor roleActual service and processor terms
Cross-border transferAuthorized transfer mechanism and assessment

GDPR does not demand erasing every record immediately on request when legal retention duties or other exceptions apply. Nor does a United States legal requirement automatically resolve every conflict under European law. Escalate overlapping duties and document the legal basis rather than promising unconditional deletion or unlimited retention.

Rights and governance

Data subjects have rights that can include access, rectification, erasure, restriction, portability and objection, subject to the applicable conditions and exceptions. Requests require identity verification and timely handling. An erasure request differs from closing an account; a portability request differs from giving access to every internal document. Automated decision-making has additional provisions when the statutory conditions are met.

A data protection impact assessment can be required for processing likely to result in high risk to individuals’ rights and freedoms. A data protection officer is required in the circumstances specified by Article 37, not simply because every bank has customer information. Identify whether the conditions apply to the particular organization and processing. Document decisions, responsibilities and escalation paths.

Personal data breaches

Article 33 generally requires notification to the competent supervisory authority without undue delay and, where feasible, within seventy-two hours after awareness of a personal data breach, unless it is unlikely to result in risk to individuals’ rights and freedoms. If notification is later, explain the delay. A processor notifies the controller without undue delay. Do not start a bank’s timer from a convenient later executive meeting if the relevant awareness has already occurred.

Article 34’s communication to affected individuals applies where the breach is likely to result in high risk, with specified exceptions. The regulator and individual-notice standards are different. A breach can require documented investigation even where notification is not required. Encryption, recoverability and mitigation facts matter; simply asserting that the system was encrypted does not decide every condition.

Consider a scoped European account service suffering unauthorized access to identifying records. The bank should establish controller and processor roles, awareness, likely risk, mitigation and the competent authority, then handle the actual deadlines. United States thirty-six-hour bank regulator notice and GLBA customer notice require parallel assessment rather than being replaced by GDPR’s clock.

The official GDPR text supplies Articles 3, 5, 6, 28, 33, 34 and the individual rights provisions. The CRCM lesson is to recognize when an international data regime may apply and coordinate its distinct requirements with the bank’s domestic program.

Test Your Knowledge

A United States bank has a customer who is an EU citizen but no EU establishment or relevant EU-directed activity. Does citizenship alone establish GDPR scope?

A

Yes, for every bank record.

B

No, because GDPR never applies outside the EU.

C

No; apply Article 3’s actual territorial tests.

D

Yes, but only for deposit accounts.

Sections you finish are checked off in the contents.