A vendor claims the GDPR only applies to EU companies that keep servers inside the EU. Which response best corrects that myth at Domain I legislative-awareness level?
Select an answer to reveal the explanation.
Short Explanation
“We parked the servers in Frankfurt, so GDPR vanishes” is a myth. The GDPR is a real EU regulation with protective aims — scope turns on legal criteria like establishment and offering goods or services, not a hosting-location bumper sticker. Domain I is where you kill that slogan before deeper scope chapters.
Full Explanation
The GDPR is a regulation with direct applicability and twin aims of protection and free movement of personal data. Territorial and material scope involve establishment and certain non-establishment scenarios; they are not satisfied by a simplistic “EU servers only” rule of thumb. Later domains detail scope tests, but Domain I expects candidates to reject hosting-location myths about what the Regulation is.