5 ms·
This guide does not clarify one important question: Does a company in the EU have to apply gdpr guidelines for none European users. If so, this would be a signi
by meinstream 8y ago
This guide does not clarify one important question:
Does a company in the EU have to apply gdpr guidelines for none European users. If so, this would be a significant disadvantage for all European companies since their none European competitors obviously only have to comply for European users.
One scenario in which this would be very relevant:
A website needs to show a very long consent form to users that want to use their service, under gdpr regulation. Under gdpr these consent forms are very alarming and they will have a drop-off rate. The drop-off rate of the form will be the competitive advantage of none European companies.
Hence, will we see an exodus of European startups from Europe to the US?
- the_mitsuhiko 8y ago> This guide does not clarify one important question: Does a company in the EU have to apply gdpr guidelines for none European users Does it really matter? Just give all users a fair treatment.
- meinstream 8y ago+1 for fair user treatment, but the way the laws are written, companies that serve users globally from within the EU will have a hard time competing with their international competitors under the new regulation. I just wonder if European law makers have thought this through.
- tscs37 8y agoI think in the current situation, having strong privacy for all users will be a feature you can bring to the market, especially for US users it can be a big plus since the US doesn't have any comparable privacy law.
- freeone3000 8y agoHow do you communicate this? Most people don't care.
- tscs37 8y agoThere are already companies like ProtonMail that sell the privacy laws of Switzerland as a pro and they seem to do alright.
- zerostar07 8y agoIf your company is located in the EU the regulation applies to all your users worldwide. Actually i don't think what you are suggesting is a big concern - people were predicting that about the cookie laws.
- meinstream 8y agoI think the guidelines for cookie laws are not comparable, since gdpr required explicit checking a box until the service can be provided as opposed to a not very intrusive box in the footer.
- viraptor 8y ago> gdpr required explicit checking a box until the service can be provided You don't need opt-in for things that are essential to providing the service. You need that for non-essential data storage and sharing. Unless you want to make providing your service conditional on extra collection, what you describe shouldn't be necessary.
- deleted 8y ago[deleted]
- jimktrains2 8y ago> This guide does not clarify one important question: Does a company in the EU have to apply gdpr guidelines for none European users. Yes, the GDRP applies to anyone "in the Union". Someone on vacation from the US would be covered _while they are in the EU_. If your company is based in the EU, then you must comply for all users, regardless of their current country or citizenship.
- frockington 8y agoSo the obvious solution is to base all companies in the US or Asia? I am hesitant to believe the EU is that short sighted
- gnud 8y agoMaybe I'm just stupid, but that seems very clear to me from article 3.1 [0]: This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not. [0]: https://gdpr-info.eu/art-3-gdpr/ https://gdpr-info.eu/art-3-gdpr/
- askmike 8y agoAFAIK that simply means that GDPR applies even if your servers are in the US (or anywhere else outside of the EU).
- Sylos 8y agoNo, that's what article 3.2 means: This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: - the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or - the monitoring of their behaviour as far as their behaviour takes place within the Union.
- meinstream 8y agoOk, let's assume this interpretation is correct. Targeted advertising will require explicit user consent under gdpr since pii is collected. It's fair to assume that there is no big incentive for a user of a website to consent to targeted ads. Targeted ads are usually way way more profitable that contextual ads. If you are a large publisher, would you really want to have your company in the EU in future?
- mattmanser 8y agoThey're only way more profitable right now because they exist. I guess if you want to sell something the EU has pretty much banned, basing your business inside the EU won't work.
- Sylos 8y agoThis is probably going to happen, yeah. It will however likely also establish European companies as particularly secure and trustworthy. For a long time already, it's been common practice to avoid Chinese services, because of the surveillance that the Chinese government does. And there's a growing number of people who avoid US-based services, too. The recent CLOUD Act certainly doesn't weakening their position either.
- bluGill 8y agoIt also gives some non-eu based companies the same secure and trustworthy benefits. They just need to have an obvious presence in the EU, and not check if someone is in the EU when they are asked to apply GDPR.