3 ms·
GDPR applies to all EU citizens. It doesn't matter if the citizen is accessing the web site from the eu or another country. Blocking people in the EU doesn't bl
by nrdgrl 8y ago
GDPR applies to all EU citizens. It doesn't matter if the citizen is accessing the web site from the eu or another country. Blocking people in the EU doesn't block all eu citizens from accessing your product/service.
- itake 8y agoDo you have a source? It is my understanding that the world operates on the idea that the laws of where you are located only apply to you. An expat living in the EU is protected because they reside in the EU. If you are living in the USA, you must follow American laws.
- outside1234 8y agoPeople keep saying this but its not true. The EU has no jurisdiction outside of the EU. If both the user and site are outside of the EU at the time of the transaction, they can not make claims, regardless of citizenship.
- JBReefer 8y agoNo, it is true, If you don't the EU Army will come and get you. /s It's a basic idea, and HN prides itself on being smart, but there aren't global laws. No one gets to enforce civil penalties outside of their jurisdictions, without exceptional circumstances. If they fine you and you don't have offices there just ... don't pay? The EU might not exist in 10 years anyway.
- exegete 8y agoThe EU has jurisdiction over EU citizens, even those outside of the EU (see US citizens and taxes). But I question how the EU would have jurisdiction on anyone who is outside of the EU and does all their business outside of the EU, even with EU citizens. The EU can prohibit EU citizens from visiting websites that violate the law if they want. They can also block EU residents from visiting those sites.
- outside1234 8y agoMaybe they can get the firewall technology to do all of that from China too.
- jsnell 8y agoThat's just not how it works. Recital 23 (referring to Article 3, Territorial Scope) > In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union. An attempt to prevent EU users from accessing the site at all is about as strong a signal as it gets regarding this. When you're blocking all of Europe by IP, it's pretty fucking obvious you're not envisaging offering services there.