15 ms·
Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you a
by donogh 8y ago
Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR.
The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater. Again, this applies to US companies even if it's a single record of EU personal data.
Furthermore, individuals are fully entitled to sue in the event of a data breach, and there is legal precedent in the EU for compensation of between 10-15k euro per person.
As to the question of EU law applying in the US, just look to financial regulation like Sarbanes–Oxley to see it going the other way.
- dogma1138 8y agoThat’s not exactly correct GDPR is a mess. If you are a non-EU company and you don’t have any legal entities in the EU even if you deal with EU customers (retail) the application of GDPR isn’t going to be relevant at least initially. (The fear for example is that PayPal etc. will force you to comply in the usually blind and deaf PayPal manner for fear of EU retaliation) If you are a non-EU company with no legal entities in the EU but you are dealing with EU companies and process data for them those companies would have to ensure you are compliant this is a purely B2B route. If you are a non-EU company with EU legal entities this is the vector the DPAs will use to go after you. The GDPR is currently in a retarded state with near zero official guidance and definition for things that matter. And as far as non-EU companies go GDPR is well in a though spot. GDPR does not trump lawful data retention and data access requirements in the EU those fall under then final jurisdiction of the high court but there is no way for them to influence non-EU law. And SOX is a terrible example SOX affects a tiny portion of companies and those who need to comply are huge and there are clear definitions, requirements and arbitration channels which the GDPR lacks. P.S. we’re talking so far about the periphery of the EU, Canada, Australia The US etc... when you’ll find a way to make Alibaba and China at al comply let me know please.
- morgante 8y ago> Again, this applies to US companies even if it's a single record of EU personal data. This is part of why I think GDPR is a disaster for startups. It's a massive regulatory burden which big companies will be able to comply with but small startups don't have the legal horsepower to handle. Typical EU regulatory overreach.
- dogma1138 8y agoI don't know why people were downvoting this. GDPR outside of the EU (for purely non-EU entities) is a non sequitur there are zero internal processes to make it work. Lets take the most basic example the GDPR does not apply in a vacuum it's enforced and supported by Data Protection Agencies (DPA) in each member state which are responsible to ensure that companies in those member states comply with EU regulation like the GDPR within the context of local laws and regulations. The DPA is responsible for the application of the GDPR within it's member state (and it's power is limited to that member state only but the GDPR does have a few venues for applying a local DPA directive across member state lines) it's also responsible for handling complaints in that state and it provides directives and advice to both law makers and the industry. If I'm a UK company and need to deal with the GDPR (till Brexit do us part) I work with the ICO which is the UK Data Protection Agency. While other DPA might affect me the ICO is my primary source of both advice and enforcement and any issues that might originate in another DPA would still pass through the ICO. Now I am a company in don't know where lets take Argentina I want to sell to EU customers which DPA do I answer too? which DPA to I ask for advice? How do I arbitrate complaints filed against me and to which DPA do I prove I handled data disclosure requests in a manner compliant with the GDPR? which DPA would know my local laws to ensure if my application with the GDPR was complaint with local data retention and lawful access laws? In fact other than going through my own state/trade department and organizations what venue do I have as a non-EU resident and a non-EU entity to any EU services and resources. The question to all of this is none as a non-EU company there is fuck all you can do even if you want to comply with the GDPR.
- briandear 8y agoNot exactly correct. GDPR is closer to FATCA meaning — non US banks that deal with US citizens are subject to FATCA reporting IF they also have US assets. The penalty for a foreign bank not complying with FATCA is a penalty against US assets. A bank with zero US financial system exposure can’t be penalized under FATCA because they have nothing to penalize. FATCA only works because banks have exposure to US assets. The unintended consequence of FATCA is that it is dramatically harder for a US person to do any business with European banks — banks have closed accounts in order to reduce operational risk. So this “good law” (occurring to Democrats that passed it) actually made it much more difficult for Americans overseas and American companies who need overseas banking. GDPR could be considered similar — it won’t have any jurisdiction if the company involved has no EU presence, but it could result in companies denying services to EU persons based on operational risk. People should have thought this through much better.
- dogma1138 8y agoFATCA was designed to apply to non-US entities it provides clear definitions and channels on what to do and who do you work with, the GDPR has no functional models for non-EU entities.
- nocha 8y agoActually it kinda does... Article 27: "the controller or the processor shall designate in writing a representative in the Union"
- dogma1138 8y agoNo it's a joke article 27 says that you need to establish a presence in the union which isn't going to happen article 3 is also vague as hell. Compare this to FATCA: https://www.irs.gov/businesses/corporations/foreign-account-tax-compliance-act-fatca https://www.irs.gov/businesses/corporations/foreign-account-... And again FATCA and SOX applies to huge financial institutions that can afford all the lawyers in the world. Say I make guitar picks and tuning forks in Zimbabwe I sell it online and I have costumers in the EU. I either need to comply with the GDPR which will be prohibitively expensive or will have to stop selling to EU customers. The problem with the GDPR is that people don't understand both the inconsistency and the scope of it. Come 25th of May I'm sending a data access request letter to my dry cleaner which they will have to comply with within 30 days or face fines.
- pc86 8y agoIf you run a small US company with a few hundred paying customers and low single digit EU customers, how is the EU going to penalize you? Especially if those EU customers' funds go directly to a US bank account?
- pbhjpbhj 8y agoMaybe put you on a naughty list and inhibit internet access - as the UK does for TPB, et al.?
- dhimes 8y agoIt might be worth specifying your co. is for US users only in your TOS until you are more attractive to European customers.
- rmc 8y agoI don't know if they can. But if you're a VC funded business aiming to "change the world" and grow big, then it might be a problem for you later.
- YeGoblynQueenne 8y ago>> If you run a small US company with a few hundred paying customers and low single digit EU customers, how is the EU going to penalize you? By forcing EU ISPs to block your ip.
- xxs 8y agoIt's an unlikely scenario - but block your domain, block bank transfers (not for small offenses, though). "Ask" any EU based payment providers (pretty much all have offices in the EU) to stop servicing you. You can use crypto currencies and the like but the inconvenience is there. Then probably (or your employees) would not like to visit the countries there, etc. Technically you should not be selling electronic services in the EU w/o EU VAT, so that already is sort of a breach... but no one chases so small fish.
- sydd 8y ago> Furthermore, individuals are fully entitled to sue in the event of a data breach, and there is legal precedent in the EU for compensation of between 10-15k euro per person. This means that I can bankrupt small, careless companies that hold a few hundred users data?
- deleted 8y ago[deleted]
- solarkraft 8y agoYes, because they hold user data and are careless.
- jkaplowitz 8y agoThe EU will retain its current ability to impose lower fines than the maximum, which I imagine they'll do in most cases where the fine would bankrupt a company unless the behavior is amazingly egregious (e.g. "We refuse to do the barest attempts to comply even after several warnings despite dealing very heavily with Europe and collecting lots of data"). That said, the existing legal precedents won't prevent the imposition of much larger fines when warranted after May 25, given the new law's higher maximums.
- rmc 8y agoSo companies that are careless with personal data and get hacked get out of business? That sounds like a benefit! Within small companies, it's now easier to push for proper data security, for not being careless. "Boss, I know it'll slow down our release, but if we don't do it, we could go bankrupt!"
- unethical_ban 8y agoIf I don't have a server in your country, I shouldn't be in your jurisdiction. And as for ANY regulation, progressive enforcement should be the norm. We shouldn't expect the same level of data security from John Buckley's local tool supply that we expect out of Amazon.
- outside2344 8y agoMy counter example to this is that nobody in the US does the super annoying cookie popup thing that's required in the EU already - why would they do GDPR which is orders of magnitude more complicated.
- the_watcher 8y agoI live in the US and am constantly annoyed by the stupid cookie popup.
- chopin 8y agoYou are annoyed by stupid people who think they need a bunch of third party trackers on their site. Nobody, even not the EU, has problems with first party cookies. This will change anyways with the GDPR.
- the_watcher 8y agoAgreed that many, if not most, of the trackers on most websites are at the very least overkill, if not actively negative. I disagree that I need to be reminded that websites use cookies with a modal or popover every single time I visit a website that I visit daily.
- civilitty 8y agoMy counter example is that I live in the US and I see that cookie popup seemingly almost everywhere I go.