Assessment: Does GDPR Apply?

Answer these questions to help you determine whether the General Data Protection Regulation (GDPR) applies to the data you collect and use.

  1. Is the data about individuals physically in the European Union (EU) at the time of collection? (yes or no)
  2. Does the data include personal information (for example, national identification number, date of birth, address, photos, cookie IDs, exam info, and so on) or sensitive personal information (for example, racial or ethnic origin, religion, medical info, sexual orientation)? (yes or no)

If you answered no to either Question 1 or 2, GDPR likely does not apply. No further action is required at this time.

If you answered yes to both Questions 1 and 2, GDPR likely applies. Please take action:

  • For data collected for research purposes, contact the IRB Health Sciences and Behavioral Sciences (HSBS) at [email protected]. Michigan Medicine researchers, contact [email protected].
  • For data collected for any other purpose, complete the GDPR Data Survey (U-M Google Form; U-M login required).