Skip to main content
Category: Scope & Exemptions

Household Exemption

Also known as: Domestic Purposes Exemption, Personal or Household Activity Exemption
Simply put

The household exemption is a rule that means data protection law generally does not apply when an individual handles personal data purely for their own private, family, or household life, for example keeping a personal address book or private correspondence. The exemption is meant to protect ordinary personal activities from regulatory obligations. It typically does not apply once processing has a professional or commercial dimension, or extends beyond the purely private sphere.

Formal definition

Under the GDPR, the household exemption excludes from the Regulation's scope the processing of personal data by a natural person 'in the course of a purely personal or household activity' with no connection to a professional or commercial activity. This provision is generally understood to derive from the GDPR text on the material scope of the Regulation, with accompanying interpretive guidance in the recitals concerning matters such as personal correspondence, address books, and personal social networking, subject to the qualification that such activity has no professional or commercial link. The exact article and recital numbering, and the precise wording, should be verified against the current official text, as the evidence packet supplied does not contain the controlling GDPR provisions or supervisory-authority guidance. The boundaries of the exemption are context-dependent and have been examined in case law and regulator guidance, particularly where private activity (for example online publication or use of monitoring technology) affects individuals beyond the private sphere, so its application typically requires a fact-specific assessment. Note: none of the sources provided in the evidence packet relate to the GDPR household exemption; they concern U.S. property-tax homestead exemptions and are therefore not relied upon for this definition, and no verified GDPR or supervisory-authority sources were available to cite.

Why it matters

The household exemption marks one of the outer boundaries of data protection law: it is the mechanism that keeps ordinary private life, personal address books, private letters and emails, family photographs, outside the reach of obligations designed for controllers and processors. Without such a boundary, every individual keeping a contacts list or writing to a friend could in principle be treated as a regulated data controller, which is not the purpose of the framework. The exemption therefore matters because it determines whether the full apparatus of accountability, lawful basis, transparency and data subject rights applies at all, or whether the activity falls entirely outside scope.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs assessing whether particular processing falls within an organisation's regulated activity, or whether an individual's actions sit outside scope, need to understand where the household exemption begins and ends. This is particularly relevant when advising on employee personal use of systems or on user-generated content, where a purely private characterisation may not hold.
Privacy Lawyers and Advisers
Legal advisers rely on the exemption when analysing scope questions and disputes involving individuals who process personal data, such as online publication, personal social media use, or home monitoring devices affecting others. Because the boundaries are context-dependent and shaped by case law and regulator guidance, advisers should base conclusions on a fact-specific assessment and verify the controlling provisions.
Engineers and Product Teams
Teams building consumer-facing products, particularly those involving cameras, social sharing, or contact management, should recognise that a user's activity may or may not attract the exemption depending on whether it stays within the private sphere. Design choices that push activity toward public dissemination can move users, and potentially the provider, into regulated territory.
Individuals Using Personal Technology
Ordinary users keeping private correspondence, personal address books, or engaging in genuinely private personal networking are generally the intended beneficiaries of the exemption. However, individuals should be aware that activities extending beyond the purely private sphere, such as capturing public spaces or publishing to an indefinite audience, may fall outside it.

Inside Household Exemption

Personal or Household Activity
The household exemption applies where an individual processes personal data in the course of a purely personal or household activity. It is set out in Article 2(2)(c) GDPR, which excludes such processing from the material scope of the Regulation, and is elaborated by Recital 18. It typically covers activities with no connection to a professional or commercial purpose, such as private correspondence, holding personal address books, or social networking used purely privately.
Purely Personal Character
The exemption is generally understood to require that the activity be genuinely private in nature. Recital 18 gives examples such as correspondence and the holding of addresses. Where processing serves a professional, commercial, or organizational aim, the exemption typically does not apply. The boundary is assessed on the facts of each case.
Exclusion from Material Scope
Where the exemption applies, the GDPR as a whole is generally treated as not applying to that processing, meaning obligations on controllers and processors do not attach to the individual acting in the personal or household capacity. This differs from a mere lawful basis; the processing falls outside the Regulation's material scope rather than being permitted within it.
Application to Individuals, Not Organizations
The exemption is directed at natural persons acting privately. Recital 18 notes that the Regulation nonetheless applies to controllers or processors who provide the means for processing personal data for personal or household activities. Platforms and service providers enabling such activity are therefore generally not covered by the exemption.
Boundary and Interpretive Uncertainty
The precise limits of the exemption, particularly for online publication, social media, and video surveillance capturing public spaces, have been shaped by CJEU case law and supervisory guidance rather than the Regulation text alone. Practitioners should verify the current interpretation against controlling provisions and up-to-date guidance, as the line between private and non-private activity is fact-specific and can be contested.

Common questions

Answers to the questions practitioners most commonly ask about Household Exemption.

Does the household exemption mean any personal activity involving other people's data falls outside the GDPR?
No. The exemption in Article 2(2)(c) GDPR applies only to processing carried out by a natural person in the course of a purely personal or household activity. As clarified in Recital 18, this covers activities such as personal correspondence, keeping address books, or social networking undertaken in that personal context. Where processing has a connection to a professional or commercial activity, or extends beyond the private sphere, the exemption generally does not apply. The presence of other people's data alone does not trigger the exemption; the nature and context of the activity is what matters, and this typically requires a case-by-case assessment.
If my activity qualifies for the household exemption, does that mean nobody has GDPR obligations for that data?
Not necessarily. Recital 18 notes that even where a natural person's processing is exempt, the Regulation can still apply to controllers or processors that provide the means for such personal or household activities. In other words, a platform or service provider facilitating the activity may remain subject to GDPR even if the individual user's own processing falls within the exemption. The exemption addresses the position of the individual acting in a personal capacity, not the wider ecosystem of parties who may process the same data.
How do I assess whether a particular activity is 'purely personal or household' in scope?
Assessment is generally fact-specific and considers the context and purpose of the processing rather than a single fixed test. Relevant factors typically include whether the activity has any professional or commercial dimension, how far the data is disclosed beyond the private sphere, and the number and nature of people affected. Because this is a scope boundary interpreted through supervisory guidance and case law, organisations and individuals should document their reasoning and verify their conclusion against current official sources and the specific circumstances, as regulators may take differing views.
What happens if an activity starts as personal but later develops a professional or commercial element?
In most cases, where an activity acquires a professional or commercial character, the household exemption is likely to cease to apply from that point, and the processing would generally fall within the scope of the GDPR. This means the person may become a controller with corresponding obligations. Because the boundary can shift as circumstances change, it is prudent to reassess the position when the nature or purpose of the activity changes, and to treat the transition as a point requiring fresh analysis.
Can an organisation rely on the household exemption to avoid its own obligations?
Generally no. The exemption is framed around processing by a natural person in a personal or household context, not processing by organisations acting as controllers or processors. As Recital 18 indicates, entities providing the means for personal or household activities may still be within scope. Organisations should not treat the exemption as a route to disapply their own GDPR responsibilities and should assess their role and legal basis independently.
Where should I look to confirm the current interpretation of the household exemption?
The controlling provisions are Article 2(2)(c) GDPR and Recital 18, which should be read together and against the current official text. Because interpretation is shaped by supervisory authority guidance and Court of Justice of the European Union case law, and because positions can evolve, readers should verify against up-to-date regulator guidance. Note also that the UK GDPR and national implementing laws may address the household context, and member state derogations can affect related matters, so the applicable framework should be confirmed for the relevant jurisdiction.

Common misconceptions

Anything an individual does with personal data at home is automatically outside the GDPR.
The exemption is not blanket. It generally requires the activity to be purely personal or household in nature. Processing connected to a professional or commercial purpose typically falls back within the GDPR's scope, and the assessment is fact-specific.
The household exemption also protects the online platforms and services people use for private purposes.
Recital 18 indicates that the Regulation still applies to controllers and processors that provide the means for such personal or household processing. The exemption generally shields the individual acting privately, not the service providers enabling the activity.
Relying on the household exemption is the same as having a lawful basis under Article 6.
These are distinct concepts. Where the exemption applies, the processing falls outside the material scope of the GDPR (Article 2(2)(c)), so the Article 6 lawful basis analysis is not reached. A lawful basis, by contrast, operates within the scope of the Regulation.

Best practices

Assess each activity on its facts against Article 2(2)(c) GDPR and Recital 18, asking whether the processing is genuinely personal or household in character or whether it has a professional or commercial dimension.
Do not treat the exemption as blanket coverage; document the reasoning where an individual's processing is relied upon as falling outside GDPR scope, and reassess if the purpose changes.
Remember that where your organization provides the means for individuals' personal or household processing, you may still be a controller or processor and should evaluate your own obligations accordingly.
Consult current CJEU case law and supervisory authority guidance for edge cases such as social media publication or surveillance capturing public areas, as these are shaped by interpretation beyond the text.
Verify the precise wording and numbering of the controlling provisions against the current official GDPR text, and check whether UK GDPR or national implementing law diverges for your context.
Where the boundary is uncertain, adopt a cautious approach and consider whether GDPR obligations should be met rather than assuming the exemption applies.