GDPR does not reach you because you are in Cyprus. It reaches you because of who you sell to.
EU law is suspended in the north, so geography does none of the work. What can reach a North Cyprus business is Article 3(2), and the European Data Protection Board published nine factors that decide it. You can check your own site against them in about five minutes.
QUICK ANSWER
Being in North Cyprus does not put you inside GDPR. The treaty that took Cyprus into the European Union suspends EU law in the north, so geography does none of the work here. What can reach you is Article 3(2), which applies to businesses with no EU presence at all when they offer goods or services to people in the EU. The European Data Protection Board published nine factors that decide it, and you can check your own site against them in about five minutes.
Open your own website on a phone and look at three things. Which languages it offers. Which currencies it prices in. Whether the booking form has ever taken a booking from someone sitting in Germany.
Those are not marketing questions. Two of them appear almost word for word in the European Data Protection Board's list of factors that decide whether EU data protection law applies to a business outside the EU.
Most advice on this starts from the wrong end. It asks where you are, and then either frightens you because Cyprus is in the EU or reassures you because the north is not. Both are wrong for the same reason: the law does not ask where you are.
Being on Cyprus does not put you inside GDPR
Start with the part that is genuinely settled, because a lot of people here carry this fear for no reason. When Cyprus joined the European Union in 2004, the accession treaty carried a protocol dealing with the divided island. Protocol No 10 on Cyprus, Article 1(1), says it in one sentence:
"The application of the acquis shall be suspended in those areas of the Republic of Cyprus in which the Government of the Republic of Cyprus does not exercise effective control."
The acquis is the entire body of EU law, GDPR included. It is suspended in the north, and nothing since has changed that for data: the Green Line Regulation has exactly one article on services and it is a VAT rule.
So the border does no work here at all. A customer standing in Girne is not in the Union. One sitting in Limassol is in the Union whether the business they are buying from is in Girne or in Kansas.
GDPR reaches businesses with no EU presence at all
Here is the part that surprises people, and it is in the regulation's own text.
Article 3(2) opens by describing exactly the kind of business it is aimed at:
"This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union."
Read that clause again. It applies because you are not established in the Union. No branch, no server, no EU bank account. A business with none of those things is precisely who it was written for.
And "in the Union" is about location, not nationality. A German living in Lapta is not a data subject in the Union while they are in Lapta. A Cypriot in Limassol filling in your booking form is.
A website Europeans can open is explicitly not enough
This is where consultants overreach, so it is worth quoting the law against them. Recital 23 states that "the mere accessibility" of your website in the Union, "of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient" to bring you into scope.
The European Data Protection Board's guidelines on territorial scope, adopted 12 November 2019, go further on page 18. Your email address, your geographical address and your "telephone number without an international code" do not, on their own, provide sufficient evidence of intention. Then the sentence that matters most:
"when goods or services are inadvertently or incidentally provided to a person on the territory of the Union, the related processing of personal data would not fall within the territorial scope of the GDPR."
A German tourist walks in off the street and you take their name for a booking. That is incidental, and it does not put you in scope.
Nine factors decide it, and you can check your own site in five minutes
What does bring you into scope is evidence that you intended to sell to people in the EU. The EDPB lists nine factors on pages 17 and 18, weighed together rather than one at a time.
[ 01 / The test, in nine parts ]
Nine factors decide whether Brussels is talking to you
Weighed together, not one at a time. Matching one is usually not enough on its own.
Counts towards being in scope
- 1 The EU or a member state is named next to what you sell
- 2 You pay for search referencing, or run ads aimed at an EU audience
- 3 The activity is international by nature, such as tourism
- 4 You give an address or phone number to be reached from an EU country
- 5 You use a top level domain other than your own country's
- 6 You describe travel directions from an EU member state
- 7 You mention an international clientele from EU member states
- 8 You use a language or currency other than your country's own
- 9 You offer delivery into EU member states
Explicitly does not count
- Your website simply being reachable from the EU
- An email address or a geographical address on the page
- A telephone number without an international code
- Serving someone from the EU inadvertently or incidentally
European Data Protection Board, Guidelines 3/2018 on the territorial scope of the GDPR, version 2.1 adopted 12 November 2019, pages 17 and 18.
Go through them honestly. Most businesses here match none and can stop reading. Some match one, which the EDPB says is usually not enough on its own.
But a hotel with a German language page, prices in euro, driving directions from Larnaca airport and reviews from Dutch guests has matched four. That is not an accident. That is a business that decided to sell to Europe, which is the right decision for most of the coast.
One factor lands strangely here. Factor five is a top level domain other than your own country's, and North Cyprus has no country domain anyone can actually register. Almost every business here runs on .com, which is neutral. It will not catch you, and it will not clear you either.
If several describe you, Article 27 is the obligation nobody mentions
If you are in scope, the regulation asks for something concrete, and it is not a cookie banner. Article 27(1): "Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union." Article 27(3) adds that the representative must sit in a member state where your customers actually are.
This is not aimed only at large technology companies. The EDPB's own worked example, on page 18, is a website "based and managed in Turkey", offering photo albums in English, French, Dutch and German with payment in euro. The Board concludes it is in scope, and that "in accordance with Article 27, the data controller will have to designate a representative in the Union."
Page 25 adds a quieter consequence: the representative's identity has to appear in your privacy notice, and a controller who has one and does not name it is separately in breach of Articles 13 and 14.
Occasional does not mean what you would like it to mean
Article 27(2) exempts processing that is "occasional", not large scale, and unlikely to result in a risk. Everyone reaching this point wants to land here, so read what the Board says it means.
Page 25: a processing activity is occasional only "if it is not carried out regularly, and occurs outside the regular course of business or activity of the controller."
Taking bookings is the regular course of business of a hotel. It is the opposite of occasional, however few of those bookings come from the EU. And page 26 closes the other escape route: the exemption covers processing unlikely to result in a risk, "thus not limiting the exemption to processing unlikely to result in a high risk."
There is a local law too, and nobody has ever been fined under it
Almost nobody reading this has been told that North Cyprus has had its own data protection law for nineteen years.
It is Law 89/2007, Kişisel Verilerin Korunması Yasası, published in Resmî Gazete Sayı 210 on 26 November 2007. If you find a date of 7 April 2007 online, it is wrong, and comes from confusing this law with Turkey's separate Law 6698.
On its face it asks more of you than GDPR does: Article 10 requires every organisation processing personal data to designate at least one person to protect it, with no size threshold at all.
Then look at what enforcing it is worth. The fines in Article 35 run from 1,000 to 3,000 YTL. Yeni Türk Lirası was retired at the start of 2010 and the figures have never been uprated. The maximum administrative fine in this law is worth less than a hundred euro.
[ 02 / Two laws, one website ]
Both can reach you. They are not the same size.
One asks more of you on paper. The other is the one with consequences.
Local · Law 89/2007
In force since 26 November 2007
Notify the Board in writing before you start processing
At least one designated person, with no size threshold
Maximum administrative fine 3,000 YTL, a currency retired in 2010 and never uprated
Publicly recorded enforcement actions in nineteen years: none
EU · GDPR Article 3(2)
Reaches you only if you target customers in the EU
Designate a representative in the Union, in writing (Article 27)
Name that representative in your privacy notice
Fines up to 20 million euro or 4% of worldwide turnover
Published cases against a small business outside the EU: none
TRNC Resmî Gazete Sayı 210, 26 November 2007, Articles 8, 10 and 35. Regulation (EU) 2016/679, Articles 3(2), 27 and 83.
Every entry under this law in the Resmî Gazete from 2007 to 2026 is an appointment, a budget, an office lease, a regulation or one procedural decision. There is no fine and no named respondent, and the Board's own legislation and decisions section adds nothing. In nineteen years there is no publicly recorded enforcement action against anyone.
One detail says more than the rest together. The authority every controller must notify in writing publishes no postal address. Its contact page offers a web form.
What the risk actually is, and what to do this week
Nobody should act on a fine that has never been issued, so here is the honest exposure. It is not a penalty.
There is no published decision anywhere against a small business outside the EU with no EU establishment. Enforcement outside the Union is real, but the examples are one company: Clearview AI, an American facial recognition firm that ignored European regulators entirely, fined 30.5 million euro by the Dutch authority in September 2024. Not a precedent about your booking form.
[ 03 / What the exposure actually is ]
The fine is not the risk. It has never once been the risk.
Published decisions against a small business outside the EU, with no EU establishment.
What actually arrives instead
- A compliance questionnaire from a booking platform, and no way to answer it
- A request for everything you hold on one guest, with one month to answer it
- A European client who asks who your EU representative is, then goes elsewhere
Clearview AI, fined 30.5 million euro by the Dutch authority in September 2024, is the outer bound of enforcement outside the Union, not a comparison. It is a facial recognition company that declined to engage with regulators at all.
Autoriteit Persoonsgegevens, 3 September 2024. GDPR Article 12(3) sets the one month response deadline. Null result checked 6 September 2026.
The realistic cost arrives commercially. A booking platform sends a compliance questionnaire and you cannot answer it. A German guest asks for a copy of everything you hold on them, you have a month to answer, and their data is in a spreadsheet, two WhatsApp threads and an inbox. A European client asks who your EU representative is before signing, and moves on.
So, the free version, which takes an afternoon and costs nothing. Run the nine factors against your own site and write the answer down with the date. If none describe you, you are done, and you now have a record saying why. If several do, name a representative in a member state where your customers are, put them in your privacy notice, and write down every place a customer's name currently lives.
That last one is the part nobody finishes, and it is the part the free version cannot cross. Naming a representative is a form. Being able to answer, within a month, what you hold on one named person, when bookings arrive through four channels never designed to be searched together, is not a form. It is how the business is put together.
Find out which of the nine describe you
Elevates is a design and engineering studio.
Send us your website. We will tell you which of the nine factors it currently matches, and whether that puts you in scope or leaves you comfortably out.
If the answer is that none of them do, we will say so and there is nothing to buy.