7 ms·
So what is your beef then? Businesses that operate in the EU have to comply, businesses that don't interact with EU residents don't. As the US has a special r
by shadowtree 9y ago
So what is your beef then?
Businesses that operate in the EU have to comply, businesses that don't interact with EU residents don't.
As the US has a special relationship with EU (Privacy Shield, ..), it recognizes GDPR as valid.
Don't like it? Focus on China, where WeChat is now your national ID card and is also linked to your personal credit score. Violate any government rules - your credit score goes down. Medical reps now have to register with the Chinese government before they're allowed to enter hospitals and their personal credit score is linked to their behavior. There you go, full data transparency nirvana.
The world is a big and complicated space and big regions define their culture differently. Europe is not business-focused, but puts the citizen first. The US considers businesses as citizens, data privacy a hindrance for profitability - and China wonders what this citizen thing is.
- ryanwaggoner 9y agoSome random EU resident visiting your website != operating in the EU, by any reasonable definition.
- IntronExon 9y agoWhy not? It would certainly be ludicrous for a brick and mortar establishment to be subjected to that, but if you’re offering a global product, welcome to the rest of the world.
- mrtksn 9y agoWhat's the reasonable definition of operating in the EU?
- GlitchMr 9y ago- Being located in EU. - Or in case where you aren't located in EU, providing services specifically to EU residents, which can be hinted by having a language choice mostly spoken in EU countries, allowing EU currencies (Euro, British pound and so on) or specifically mentioning supporting EU, for instance by saying that your website can deliver packages to European Union. Facebook for instance has offices in EU, which makes it clear that they are under GDPR, but even if they didn't, they do provide Facebook in EU languages.
- mrtksn 9y agoSo, for instance, you can pretend that you're not operating in France if your website is in English and you only accept payments in USD? I would argue that this is a bad definition because what you described is just operating in a jurisdiction but without localization. I prefer the definition where you're making money(directly or indirectly) by providing services in a jurisdiction. An example would be collecting French users data and then selling it to ad agencies(or being acquired by Google?).
- GlitchMr 9y agoYes. That's how the current GDPR law works. And it seems reasonable to me. Accepting payments in USD is a pretty clear signal that a website mostly cares about US users, and if someone else uses the website, oh well, it happened, doesn't really change anything under GDPR. (although you probably could have French support anyway, just expand the website to Canada as well ;), of course it isn't the same French as in France, but it's still French somewhat, EU currencies are trickier however)
- xxs 9y agoFrench is widely spoken in Africa as well.
- icebraining 9y agoEnglish is an EU language; the UK is still in the EU, and Ireland is not expected to leave.
- xxs 9y agoMalta has English as official language, just so people remember.
- shadowtree 9y agoSo, again, there is no big problem. Easiest step: stop logging every single hit on your site (IP, browser, etc). You want a bit more analytics? Log general attributes, but not the IP. Just that a hit occurred, browser, general geo (country). that's it. Perfectly compliant. Want them to fill out a form? Welcome to GDPR, as you should. As Maciej Cieglowski (idlewords, pinboard) so eloquently states, over and over again, you don't have to store and hoard all this data. It's BS to begin with, and dangerous in the long run.
- elorant 9y agoAnd how will the legislator know what I'm logging and what not?
- shadowtree 9y agoThey don't. GDPR kicks in once a EU resident files a complaint. GDPR also enforces a data report card - so if a EU resident (not just a citizen!) asks you about their data, you have to comply and give a complete answer. If you then reveal you store PII without their consent or fail to reveal everything and get caught, the fines will kick in. Don't screw over EU residents and you're fine. And if you think this laughable, remember that it was a single Austrian law student, Max Schrems, who went after Facebook and killed the EU-US Safe Harbor agreement. EU pensioneers and students are what will kill you, endless time on their hands. :)
- ryanwaggoner 9y agoActually, easiest step: completely ignore this, just like I would any random law from some international bureaucracy that has no jurisdiction over me.
- IntronExon 9y agoaka “The Burning Bridges” plan. It could work, assuming you don’t like to travel, and never do business in those countries, and the global geopolitical situation does not radically change. A bit short-sighted...