Companies outside the European Union now have some much-needed guidance on the territorial scope of the EU’s General Data Protection Regulation to determine whether they are directly subject to the GDPR’s stringent data-privacy protection requirements.

On Nov. 23, 2018, the European Data Protection Board (EDPB)—the European Commission body tasked with ensuring that the GDPR is applied consistently across the EU—released the first official guidance on how the GDPR will be applied in practice. Although still in draft form, the guidelines provide important insight on how the regulation applies to companies and activities outside the European Union.

Jaclyn Jaeger is a freelance contributor to Compliance Week after working for the company for 15 years. She writes on a wide variety of topics, including ethics and compliance, risk management, legal,...