Material Scope (Article 2 GDPR)
When the GDPR applies as a matter of material scope: automated and filing-system-based processing, exclusions such as national security, criminal law enforcement and the household exemption, as well as sector-specific special rules.
Article 2 GDPR determines which forms of processing of personal data the Regulation covers at all and which activities it leaves out. The provision thus decides the first of the two threshold questions of data protection law; the second concerns the territorial scope. Only where the material scope applies do the legal basis and the principles relating to processing become relevant.
Key takeaways
- Covered is any processing wholly or partly by automated means as well as non-automated processing where the data are stored or are intended to be stored in a filing system (Article 2(1) GDPR).
- Purely analog, unstructured operations without any connection to a filing system are not covered; classic files are as a rule not a filing system.
- Excluded are, among other things, activities falling outside the scope of Union law (national security), the Common Foreign and Security Policy, criminal law enforcement, for which the Law Enforcement Directive (Directive (EU) 2016/680) applies, and the household exemption.
- The exclusions from the material scope must be interpreted narrowly; the household exemption ceases to apply as soon as there is a connection to a professional or commercial activity or to the public.
- For the media, employees and telecommunications, sector-specific special rules apply in addition.
1. Overview
1.1 Legal consequence and place within the assessment
Where the material scope applies, the GDPR governs the processing in question; where it does not, its obligations do not apply from the outset. The question arises at the beginning of the assessment, before the legal basis and the principles relating to processing. It is always a precondition that personal data are affected by way of a processing operation.
Purely non-personal data have been governed since 2019 by Regulation (EU) 2018/1807 on the free flow of non-personal data. Where personal data remain within a data set, however, the GDPR continues to apply; it covers the entire data set to the extent that a separation is not reasonably possible.
1.2 Two gateways and a catalog of exclusions
The material scope is opened through two gateways: automated processing and non-automated processing based on a filing system (Article 2(1) GDPR). If one of these gateways is open, the next step is to examine whether one of the exclusions under Article 2(2) and (3) GDPR applies.
2. Forms of processing covered (Article 2(1) GDPR)
2.1 Automated processing
At the center stands processing wholly or partly by automated means. What is meant is any use of data processing equipment; the Regulation deliberately refrains from giving a fixed definition or examples so that the concept also covers future technologies and remains technology-neutral (Recital 15 GDPR). It is therefore to be interpreted broadly. Word processing, email traffic and digital copiers are based on digital processing and are covered; the mere analog storage on image and sound carriers, the fax machine or the use of photomechanical copiers, by contrast, are not.
Video surveillance likewise constitutes automated processing, provided that the images are saved on a storage medium (CJEU, judgment of 11 December 2014, C-212/13, Ryneš). Dashcams, bodycams, action cameras and drone recordings are therefore covered. A camera that merely transmits a live image without any intermediate storage, by contrast, does not process anything and is not covered; whether the persons depicted are recognizable is a subsequent question concerning the personal nature of the data.
Because the Regulation expressly also includes partial automation, operations are covered in their entirety as soon as individual intermediate steps are digitized. This applies, for example, where the input is made by hand but the processing otherwise runs by machine, or where a set kept in analog form is made accessible through a digitally stored index, for instance examination records in paper form that are assigned by means of a digitally stored identification number. The direct use of automatically stored information outside the equipment also falls within this, for example the printout of a text and its subsequent disclosure. Even the oral disclosure of data that were previously stored by automated means may constitute processing within the scope of the Regulation.
2.2 Non-automated processing in a filing system
Through the second gateway, the Regulation extends to non-automated processing where the data are stored or are intended to be stored in a filing system (Article 2(1) GDPR). A filing system is any structured set of personal data which are accessible according to specific criteria, whether centralized, decentralized or dispersed on a functional or geographical basis (Article 4(6) GDPR).
Behind this extension lies a safeguard against circumvention: the legislature sought to prevent controllers from evading data protection obligations by setting up a manual card index instead of a database (Recital 15 GDPR). It follows that not every external ordering is sufficient. Covered are sets that can be evaluated according to at least two person-related criteria and thus facilitate the retrieval of information in a manner similar to automated processing. Card index cards with fixed fields (name, address, date of birth) are the typical example. Discussed in more depth under filing system.
The scope already applies where the data are intended to be included in a filing system, and not only once they have been filed. Anyone who takes handwritten notes during a job interview in order to place them afterwards in the file ordered by applicant is therefore already processing the data within the scope of the Regulation at the moment of recording.
The CJEU has likewise relied on this broad concept of the filing system, oriented toward retrievability: handwritten records kept in a decentralized manner may constitute a filing system where the data are easily retrievable according to specific criteria (CJEU, judgment of 10 July 2018, C-25/17, Jehovah's Witnesses).
Classic files are, as a starting point, not a filing system (Recital 15 GDPR). They fall within the Regulation only where they display a specific internal structure based on uniformly defined person-related criteria, as may be the case with systematically organized personnel files. A mere ordering by file reference number or by subject matter is not sufficient.
3. Exclusions from the material scope (Article 2(2) and (3) GDPR)
If one of the two gateways is open, it remains to be examined whether the processing falls within an excluded area. The following overview assigns the exclusions to their legal bases.
| Excluded area | Provision | Consequence |
|---|---|---|
| Activities falling outside the scope of Union law (including national security, intelligence services, the military) | Article 2(2)(a) GDPR | GDPR does not apply |
| Common Foreign and Security Policy | Article 2(2)(b) GDPR | GDPR does not apply |
| Exclusively personal or household activity (household exemption) | Article 2(2)(c) GDPR | GDPR does not apply |
| Prevention and prosecution of criminal offenses and the execution of criminal penalties | Article 2(2)(d) GDPR | Law Enforcement Directive and Part 3 of the German Federal Data Protection Act (BDSG) instead |
| Processing by Union institutions and bodies | Article 2(3) GDPR | Regulation (EU) 2018/1725 instead |
3.1 Activities falling outside the scope of Union law
Processing in the course of an activity which falls outside the scope of Union law is excluded (Article 2(2)(a) GDPR). The main area of application is national security, which, alongside the field of military defense, includes the activities of the intelligence services. This limitation already follows from the principle of conferral under primary law; to that extent the provision is merely declaratory.
The mere fact that a situation is purely domestic and involves no cross-border data traffic is not sufficient to trigger the exclusion; otherwise applicability would depend on the vagaries of the data flow. Irrespective of this, the German legislature subjects the public sector to the European data protection regime (§ 1(8) BDSG).
3.2 Common Foreign and Security Policy
Processing by the Member States in the course of the Common Foreign and Security Policy is also excluded (Article 2(2)(b) GDPR).
3.3 Criminal law enforcement and the distinction from the Law Enforcement Directive
Processing for the purposes of the prevention and prosecution of criminal offenses and the execution of criminal penalties, including the safeguarding against and prevention of threats to public security, is excluded from the scope of the GDPR (Article 2(2)(d) GDPR). This area is governed by the Law Enforcement Directive (Directive (EU) 2016/680), which was adopted at the same time and is transposed in Germany in Part 3 of the BDSG.
The scopes of the GDPR and of the Law Enforcement Directive are mutually exclusive. The same body of data may, however, fall under one regime or the other depending on the purpose of the processing. The exclusion covers only the core area of operational police activity, not general policing under special administrative law (for example building regulations, residence or disaster management law); in that respect the GDPR continues to apply.
Three distinctions matter in practice. The concept of a criminal offense includes regulatory (administrative) offenses. Official activities with no connection to a specific criminal offense, by contrast, remain subject to the GDPR; this applies, for example, to the handling of a missing person report by the police or to the determination of a tax liability by the tax authorities, the position being different only in the case of the prosecution of tax offenses. And the exclusion applies only to processing by the competent authority; where a non-public controller processes data, the GDPR continues to apply even if the processing serves the purposes of criminal law enforcement.
3.4 Household exemption
Processing by natural persons in the course of a purely personal or household activity is not covered (Article 2(2)(c) GDPR). This includes the keeping of private correspondence and of address books, diaries, photograph collections, hobbies, participation in private mail order trading as well as the use of social networks and online activities within that context (Recital 18 GDPR). Sets that do not concern the family circle, such as the address lists of a running group or of fellow collectors, may also fall within it.
The exclusion must be interpreted narrowly; the decisive element is that of exclusivity. It is a precondition that any connection to a professional or commercial activity is absent. Even the first use of private data for business purposes causes the exemption to lapse, as does a voluntary activity or an activity preparatory to business. A mixed address book containing private and business contacts is therefore not privileged; asset management of any appreciable extent, such as the letting of one's own real property, likewise no longer falls within it.
Three limits are particularly important in practice:
- Capture of public areas. Where private video surveillance extends, even if only partially, to public space, the exemption does not apply; the processing requires a legal basis (CJEU, judgment of 11 December 2014, C-212/13, Ryneš). The same applies to dashcam recordings in flowing traffic or to photographing illegally parked vehicles.
- Publication to the public. Anyone who discloses information via a freely accessible website or a social network without limiting the circle of recipients is no longer acting within the protected personal sphere (CJEU, judgment of 6 November 2003, C-101/01, Lindqvist). The decisive factor is the possibility of access: individual and group messages to a limited circle remain privileged, publication to an indeterminate group of persons does not.
- Processing of third-party data. The exemption concerns only the processing of data of other persons. The processing of one's own data, for instance for self-presentation on social networks, does not fall under the GDPR in any event.
In the case of photographs and video recordings, the purpose is decisive. Recordings of sights or the documentation of family events in public space remain privileged, even where third parties happen to appear in the picture. Where, by contrast, the recording is aimed precisely at collecting data of other persons, the personal sphere has been left behind.
Only the natural persons acting may rely on the exemption, not the platform operator who provides the means for the processing (Recital 18 GDPR). Anyone who operates a social network or a cloud service remains a controller or a processor, even where the individual user acts in a privileged capacity.
| Activity | Privileged? |
|---|---|
| Private address book, family and hobby contacts | Yes |
| Individual or group message to a limited circle | Yes |
| Vacation photographs, family events in public space | Yes |
| Address book mixing private and business contacts | No |
| Publication of third-party data on a freely accessible website | No |
| Private video surveillance that captures public space | No |
| Dashcam recordings, photographing illegally parked vehicles | No |
| Letting of one's own real property, other commercial activity | No |
3.5 Processing by Union institutions
Processing by the institutions, bodies, offices and agencies of the Union is excluded from the scope (Article 2(3) GDPR). It is governed by Regulation (EU) 2018/1725, which has been aligned with the principles of the GDPR.
4. Reach within the material scope
4.1 Public and non-public sector
German data protection law traditionally distinguishes between processing by public bodies and processing by non-public bodies. The decisive factor is the form of organization, not the form of action. Public bodies are the institutions of the executive, the judiciary and the legislature organized under public law; non-public bodies are natural persons and undertakings and associations organized under private law.
The GDPR does not adopt this formal dichotomy. It does, however, grant the Member States extended latitude for the public sector, in particular through Article 6(2) and (3) GDPR for processing carried out in the public interest and in the exercise of official authority (discussed in more depth under opening clauses and national law).
4.2 Courts
Courts are not excluded from the scope, even though a number of special rules apply to them (CJEU, judgment of 2 March 2023, C-268/21, Norra Stockholm Bygg). The criminal courts and the administrative courts in police law matters are governed by the law transposing the Law Enforcement Directive, and otherwise by the GDPR.
4.3 Areas reserved to the Member States and parliaments
Under the principle of conferral, some areas remain with the Member States, so that the European legislature has no power to regulate them at all. These include national security, the armed forces and the intelligence services.
The reach of the exclusion is disputed. The CJEU interprets Article 2(2)(a) GDPR narrowly: only the activities expressly named or activities of the same kind are excluded. Accordingly, an activity does not fall outside Union law merely because it is carried out by a parliamentary body; the GDPR applies in principle also to a parliamentary committee of inquiry, provided that the committee does not serve the protection of national security (CJEU, judgment of 16 January 2024, C-33/22, Committee of Inquiry).
5. Sector-specific special rules
Within the material scope, special provisions displace or supplement the general rules of the GDPR. Three fields are of practical significance:
- Media privilege. For processing carried out for journalistic purposes or for the purposes of academic, artistic or literary expression, the Member States provide for derogations and exemptions in order to reconcile data protection with the freedom of expression and information (Article 85 GDPR). On this basis, the media privileges of the German federal and state legislatures continue to apply.
- Employee data protection. Article 88 GDPR allows the Member States to shape data protection in the employment context. As a starting point, processing in the employment relationship is governed by the general provisions of the GDPR, in particular Article 6(1) GDPR.
- Telecommunications. Telecommunications data protection is governed by the German Telecommunications Digital Services Data Protection Act (TDDDG) and continues to exist alongside the GDPR as sector-specific law (Article 95 GDPR).
Before every data protection assessment, a short control question is worthwhile: is the processing automated or based on a filing system, and does no exclusion from the material scope apply? Only where both are answered in the affirmative is the GDPR applicable as a matter of material scope and the assessment of the legal basis and the principles opened.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
Scope of Application of the GDPR (Articles 2 and 3 GDPR)
Overview of the material and the territorial scope of the GDPR: when European data protection law applies at all, and which processing operations and which situations it covers.
Territorial Scope (Article 3 GDPR)
When the GDPR applies territorially: the establishment criterion, the targeting criterion and the monitoring of behavior, flag and diplomatic mission scenarios, and the international effect of European data protection law.