4 ms·
According to art. 27 GDPR, affected data processors outside the EU have to establish a data privacy representative in the EU. In addition, authorities could fo
by chmars 9y ago
According to art. 27 GDPR, affected data processors outside the EU have to establish a data privacy representative in the EU.
In addition, authorities could for example seize local servers in the case of non-compliance. In many EU countries including Germany, data privacy violations can also be prosecuted as criminal offenses.
- madeofpalk 9y agoBut this doesn't answer my question: I'm running a little side project here in Australia but with customers who happen to be in the EU. I have nothing in the EU - no sales office or support in Ireland, no hosting anywhere in the EU. How is the EU supposed to mandate that I do anything?
- Xylakant 9y agoThe EU can (and in fact does) mandate that you comply with the GDPR. It cannot, however, enforce compliance since there is limited legal leverage. The Australian government is unlikely to help the EU to bring a case unless there'd be a treaty or an agreement (Safe Haven laws in the US for example). They could theoretically go via your revenue stream and seize your European customers payments or hold you or any officer of your company liable if you ever set foot on European soil or hold any assets that your company has in or moves via Europe. That's all very unlikely to happen over minor infractions, but some business folks already had their private jets impounded for outstanding payments as for example the Thai Prince learned the hard way: http://www.airliners.de/kronprinzen-boeing-in-muenchen-beschlagnahmt/24651 http://www.airliners.de/kronprinzen-boeing-in-muenchen-besch... (sorry, german only, but google translate should correctly translate the gist of the story) All of this is nothing new, it's been working like that for centuries, back when business correspondence was still on old-fashioned paper.
- isostatic 9y agoAs long as you don't go on holiday to Rome, you'll be fine.