7 ms·
Genuine question as it pertains to US-based companies. How can a foreign law have such seemingly deep impact on US-based companies, let alone, situations where
by dwrowe 8y ago
Genuine question as it pertains to US-based companies. How can a foreign law have such seemingly deep impact on US-based companies, let alone, situations where the visitor is not paying for services? Maybe this gets into International Law, but even if I'm not _targeting_ European visitors, say they cross some threshold by percentage compared to US visitors - why must I abide by a foreign law?
- kazen44 8y agobecause the EU has enough global influence in terms of it economic power that it is able to hurt economic interests of US companies who want to operate in the EU. For most of the world, this has been true in regards to following US laws for a long time. (DMCA, copyright law) In the end, international law is mostly a game of (economic) influence, and the EU is economically significant enough for these companies for EU law to matter.
- chimeracoder 8y ago> For most of the world, this has been true in regards to following US laws for a long time. (DMCA, copyright law) Let's not pretend that the US is unilaterally shoving copyright law onto the rest of the world. When the US made its last major overhaul of the copyright system, it was to harmonize copyright law with what already existed in Europe. In addition, the EU already signed onto the TTIP, which is a massive concession to the media industry on copyright. That wasn't due to US influence; in fact, the US backed out of the TPP.
- kazen44 8y ago> the EU already signed the TTIP, which is a massive concession to the media industry on copyright. That wasn't due to US influence; in fact, the US backed out of the TPP. TTIP was NOT signed into law already. It is also a completely different treaty from TTP. (TTP has nothing to do with the EU btw).
- chimeracoder 8y ago> TTIP was NOT signed into law already. It is also a completely different treaty from TTP. (TTP has nothing to do with the EU btw). TTIP hasn't been signed into law, but it's been written by EU member states to serve EU members' interests, so it's pretty reasonable to use it as a measure of what the EU wants. TPP is a different treaty from the TTIP, though not very - the TPP and TTIP were written in tandem to be companion agreements, and the TPP contains many provisions that were explicitly included as concessions to the interests of EU states, even though they're not parties to the TPP itself.
- crest 8y agoHow can a US embargo on certain countries disrupt their trade with the rest of the world?
- Waterluvian 8y agoIt's really funny to read this because my perception, possibly wrong, is that the U.S. acts this way all the time to the rest of the world.
- dwrowe 8y agoThat perception is likely more true than many Americans would prefer to admit.
- the_watcher 8y agoAs an American, I agree with this. It comes down to the value of the market. GDPR has a major impact on American companies because the EU is a valuable market - as I understand it, every company has the option to opt out of GDPR by ceasing operations in the EU, which would mean blocking EU traffic (I may be oversimplifying a bit, but the crux is the same). The US treats the rest of the world complying with its laws the same way, and any company could opt out of US laws by not servicing US customers.
- deleted 8y ago[deleted]
- ovao 8y agoCan you provide a few examples?
- lawn 8y agoIn Sweden we have a mandatory tax on all storage units, harddrives, dvds usb drives, you name it. This is to combat piracy and the loss of profit for companies. Of course this was pushed through by US lobbyists and, you guessed it, that's where the money goes as well.
- ekianjo 8y ago> Of course this was pushed through by US lobbyists and, you guessed it, that's where the money goes as well. You can be certain that some (local) politicians got some kick-backs out of it.
- deleted 8y ago[deleted]
- Vinnl 8y agoIf a US-based company is not making any money from EU-based users or companies, I don't think there's anything they have to do. When they do, however, that money supply can be targeted.
- the_watcher 8y agoGDPR is far more aggressive than this. If you collect data on EU residents (this data collection is defined extremely broadly - basically any kind of logging or tracking on a session level), GDPR applies, and the fines are based on global revenue, not revenue derived from EU users.
- lovich 8y agoThe EU can't reach over into another country and start applying their laws unless they are willing to invade. The only way the EU has to enforce this law is if you interact with them, so they can physically block or take your assets, or if your government thinks that the EU laws should be applied at home, in which case why are you complaining to the EU? There is no world police enforcing laws in every country. It all boils down to a monopoly on violence and if a country can't physically get to you or your stuff you can tell them to fuck off all day
- 0x4f3759df 8y agoIf they can enforce their data protection laws on the global net, why can't they enforce their 'hate speech' laws on the global net?
- Pulcinella 8y agoThey do. For example, Twitter filters out Nazi related hate speech in Germany and France.
- rovek 8y agoI think the spirit of GDPR is to target the multinationals who also have tax dodging subsidiaries the world over. E.g. The EU could calculate global revenue for Facebook and then fine Facebook Ireland (or wherever) the resulting sum; which Facebook Ireland would be legally obliged to pay. But I am speculating Edit for clarity
- downandout 8y agoIt’s questionable as to whether or not judgements under the GDPR can be enforced in the US. There are existing treaties that generally enable this, but those also allow for a large number of exceptions. One of those exceptions is usually where something is illegal in one country and not illegal in the other, but we’ve been told there may be exceptions to that as well. It’s a big mess, but generally it would be up to a US judge in each individual case to decide whether the judgment can be domesticated. However, recital 23 makes it clear that you do not need to comply with GDPR unless ”it is apparent that [you] envisage offering services to data subjects in one or more Member States in the Union”. In other words, it’s not your fault if you are a US-based site and it goes viral in the EU unless it was targeted to them. Don’t translate to EU only languages, mention EU users or customers, or use an EU-based domain extension. You can also announce your intention to not serve EU customers by blocking EU visitors. Even though some EU traffic may get to your site through VPNs etc, merely trying to block them is more than enough to show that you do not “envisage” serving EU customers, which makes you not subject to GDPR. Those EU users that evade your block through technical means are not subject to the protections of the GDPR. Finally, one law firm suggested that we put a checkbox similar to this on our registration forms: ”This website was designed to comply with US privacy laws. By checking this box, you attest that you are NOT subject to any law or regulation that conflicts with or is more restrictive than US privacy laws, including but not limited to the GDPR.”
- _o_ 8y agoHm, that seems like a good advice, I was thinking about that too, and came to quite tricky problem, hypothetical situation: EU user uses technical measures (or just click the checkbox) to circumvent your blocking and then sues your ads provider which is US based and does operate in EU, due to personal data collection without consent. And they figure out they are having legal/operational costs due to you, as operator, serving them poisoned data. Can they (ads provider) sue you? And if they do, even if you are not guilty, how much money would it cost to win at the court?
- downandout 8y agoTalk to any proponent of the GDPR, and they’ll tell you that it’s all about principles and intentions. But that’s a double-edged sword. Sites can’t lure EU users in and ignore GDPR, but at the same time, users cannot lie to you, and then go file a complaint with a regulator or demand rights that they told you they don’t have (either by using a VPN, which means they are lying about their location, or checking the box attesting to something they know to be false). When looking at whether an action can proceed under the GDPR (either against you or an ad network whose code you have on your site), their regulators will review your site and see that the checkbox was required to register. That, combined with not having content or services targeted to EU users, should stop any GDPR action in its tracks before it is filed. This of course all depends on the GDPR being enforced in good faith. They have every incentive to be abusive with it, and no incentive not to be. But we just have to hope that newly self-declared privacy overlords in the EU are kind and benevolent.
- s73v3r_ 8y agoWell, for one, many of these companies, like Facebook, are not US companies. They're headquartered in Dublin, an EU country. And, you don't have to abide by foreign laws as long as you never intend to go into that country or do business with people in that country. But, as many EU companies are about to find out, they're subject to US laws, most notably those pertaining to sanctions on Iran. So why shouldn't US companies be subject to EU laws?
- tw1010 8y agoIf none of your customers are outside the US, go ahead, feel free to ignore GDPR. When companies are unable or unwilling to discriminate their service by geographical boundaries, the country with the strictest law rules.