Skip to main content
Andorra RGPD

When Does the GDPR Apply to an Andorran Company?

GDPR and Andorra may seem like two concepts that are not necessarily connected. Andorra is not a member of the European Union and has its own data protection legislation.

So, does an Andorran company have to comply with the General Data Protection Regulation (GDPR)?

The short answer is: it depends.

The fact that a company is established in Andorra does not automatically mean that the GDPR does not apply to it. Under certain circumstances, a company established outside the European Union may fall within the territorial scope of the Regulation.

And this can have important consequences, including the obligation to appoint a representative in the European Union.

Can the GDPR apply to an Andorran company?

Yes.

Article 3 of the GDPR establishes when the Regulation applies from a territorial perspective.

For a company established in Andorra — that is, outside the European Union — particular attention should be paid to Article 3(2).

Broadly speaking, the GDPR may apply when a company established outside the EU processes personal data relating to individuals who are in the European Union, where the processing activities are related to:

  • the offering of goods or services to those individuals; or
  • the monitoring of their behaviour, where their behaviour takes place within the European Union.

Therefore, the first question should not simply be where the company is established.

It is necessary to analyse what the company does, who it targets with its products or services and what personal data it processes.

The European Data Protection Board (EDPB) has developed these criteria in its Guidelines 3/2018 on the territorial scope of the GDPR.

Does an Andorran company selling to customers in Spain have to comply with the GDPR?

It may.

For example, imagine a company established in Andorra that sells products online.

If the company specifically targets consumers located in Spain, France or other EU Member States, it will be necessary to assess whether this activity constitutes an offering of goods or services to individuals in the EU for the purposes of Article 3(2) of the GDPR.

Simply having a website that can technically be accessed from Spain is not enough.

This is an important distinction.

The fact that someone located in Spain can access an Andorran company’s website does not automatically mean that the company is offering its services in Spain.

The relevant question is whether there are indications that the company’s activities are directed towards individuals in the European Union.

Factors such as the market targeted by the company, its advertising activities, the languages and currencies used, its contractual terms, whether it offers deliveries to particular countries and other elements of its commercial activity may therefore need to be considered.

What if the company monitors users in the EU?

The GDPR may also apply in this situation.

Article 3(2) covers processing activities related to the monitoring of the behaviour of individuals within the European Union.

This may be particularly relevant to certain digital business models.

For example, an Andorran company may need to assess the application of Article 3(2) if it systematically tracks users through certain technologies, identifiers, profiling tools or analytics systems.

Again, the relevant issue is not simply where the company is incorporated.

It is necessary to examine what processing takes place and where the individuals whose data are being processed are located.

What happens if the GDPR applies?

If an Andorran company falls within the territorial scope of the GDPR, it must comply with the obligations applicable to the processing activities it carries out.

Depending on the circumstances, these may include:

  • identifying the appropriate legal basis for processing;
  • providing the required privacy information;
  • facilitating the exercise of data subject rights;
  • entering into appropriate agreements with data processors;
  • implementing appropriate security measures;
  • maintaining records of processing activities;
  • complying with international data transfer requirements;
  • managing personal data breaches;
  • carrying out data protection impact assessments where required; and
  • appointing a Data Protection Officer (DPO), where applicable.

There is, however, another obligation that can easily be overlooked by companies established outside the European Union.

The obligation to appoint a representative in the European Union

Article 27 of the GDPR provides that, in certain circumstances, companies established outside the EU that are subject to the GDPR must appoint a representative in the European Union.

Therefore, an Andorran company that falls within Article 3(2) must assess whether it is required to appoint such a representative.

The representative must be established in one of the EU Member States where the individuals whose personal data are processed are located, in connection with the offering of goods or services or the monitoring of their behaviour.

What does the EU representative do?

The representative acts as a point of contact between the non-EU company, data protection authorities and individuals whose personal data are being processed.

Among other things, the representative may receive communications from supervisory authorities and data subjects and provide the information necessary to demonstrate compliance with the GDPR.

It is important, however, not to confuse the representative’s role with the company’s responsibility.

Appointing an EU representative does not transfer responsibility for GDPR compliance.

The controller or processor established outside the EU remains responsible for complying with the obligations applicable to it.

Does every Andorran company need an EU representative?

No.

Article 27 provides for certain exceptions.

For example, the obligation does not apply where the processing is occasional, does not involve certain categories of data on a large scale, and is unlikely to result in a risk to the rights and freedoms of individuals.

For this reason, the obligation to appoint a representative cannot be determined solely by the fact that an Andorran company has European customers.

The company’s specific activities and processing operations must be assessed.

An EU representative is not the same as a Data Protection Officer

These two roles are often confused, but they serve different purposes.

The EU representative is a specific requirement that may apply to certain controllers and processors established outside the EU that fall within the GDPR.

The Data Protection Officer (DPO) is a different role that certain organisations must appoint when the circumstances set out in Article 37 of the GDPR apply.

Therefore:

EU representative ≠ Data Protection Officer.

An Andorran company may need to assess whether it must appoint one, the other or, in certain circumstances, both.

What about Andorra’s own data protection legislation?

The fact that an Andorran company may be subject to the GDPR does not mean that Andorran data protection legislation ceases to apply.

Andorra has its own data protection framework, principally based on Qualified Law 29/2021 on the Protection of Personal Data, and it has its own supervisory authority, the Andorran Data Protection Agency (APDA).

An Andorran company operating internationally should therefore carefully assess which legal requirements apply to each processing activity.

In some cases, the company may need to comply with both Andorran data protection requirements and GDPR requirements.

What about transfers of personal data between the EU and Andorra?

This issue should be distinguished from the territorial scope of the GDPR.

Andorra benefits from a European Commission adequacy decision, meaning that transfers of personal data from the European Union to Andorra can generally rely on this adequacy mechanism.

The fact that an Andorran company receives personal data from the EU therefore does not, by itself, mean that additional safeguards for international transfers are required.

However, two separate questions should be distinguished:

First, whether a transfer of personal data to Andorra is lawful.

Second, whether the Andorran company itself falls within the territorial scope of the GDPR.

These are related but legally distinct questions.

So, when does the GDPR apply to an Andorran company?

The key points can be summarised as follows:

Company established in Andorra + activity exclusively targeting the Andorran market → generally, Andorran data protection law will apply.

Company established in Andorra + goods or services specifically offered to individuals in the EU → the GDPR may apply.

Company established in Andorra + monitoring the behaviour of individuals in the EU → the GDPR may apply.

Andorran company subject to the GDPR under Article 3(2) → it should assess, among other obligations, whether it must appoint an EU representative.

Establishing a company in Andorra therefore does not automatically exclude the application of the GDPR when the company’s activities target the European market or involve certain processing activities relating to individuals in the EU.

The right question is not simply:

“Where is my company established?”

It is:

“Who do I target, what personal data do I process, and where are the individuals whose data I process located?”

That is the starting point for determining whether an Andorran company must also comply with the GDPR.

Further information

For more information on this topic, see our article GDPR and Andorra, where we examine the relationship between Andorran data protection legislation and the European GDPR.

Author: Victor Roselló, Lawyer and Data Protection Consultant.

If you need help writing Data Protection regulations, contact us!

Information on data protection

Company name
LEGAL IT GLOBAL 2017, SLP
Purpose
Providing the service.
Sending the newsletter.
Legal basis
Compliance with the service provision.
Consent.
Recipients
Your data will not be shared with any third party, except service providers with which we have signed a valid service agreement.

Rights
You may access, rectify or delete your data and exercise the rights indicated in our Privacy Policy.

Further information
See the Privacy Policy.

Do you want to stay up to date on all legal news?

Subscribe to our newsletter for news, articles, and events.


Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.