4 ms·
There seems to be common misconception that GDPR only applies to the geographical region that is the EU, this is false. GDPR applies to all Europeans, independe
by Entalpi 8y ago
There seems to be common misconception that GDPR only applies to the geographical region that is the EU, this is false. GDPR applies to all Europeans, independent of location.
- TheForumTroll 8y agoNo it does not. It covers data in the EU. Being from the EU but using for example a US service while you are in the US means you are not covered. EU law doesn't cover people not inside the EUs borders.
- kokx 8y agoWith one exception, when your business targets EU markets, EU citizens abroad are still covered. For example, when you are a EU citizen using a US social network that operates world wide (and thus also targets EU markets), you are still covered when in the US.
- icebraining 8y agoWhere is that defined? The word "citizen" doesn't even appear in the law.
- hk__2 8y agoI thought this, too. But it does depend on location: * If your company is EU-based, you must comply with GDPR, whatever the location of your users/clients * If your users/clients are EU-based, idem * If your users/clients are EU citizens located abroad, it applies *only* if you target EU as a market. If you operate a website dedicated to sell t-shirts to Californian people, and an EU citizen living in California buys from your website, you aren’t expected to comply with GDPR.
- azernik 8y agoThis is false. See Article 3 (Territorial Scope): """ 1. This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not. [i.e. EU companies, or EU subsidiaries of foreign companies, have to obey GDPR with all data they deal with] 2. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: [foreign companies dealing with the data of people physically inside the territory of the EU have to follow the GDPR if...] (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union [they're offering services to those people]; or (b) the monitoring of their behaviour as far as their behaviour takes place within the Union. [they're tracking what those people do in the EU - but tracking what they do abroad doesn't trigger GDPR!] 3. This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law. [it applies to businesses in places with weird legal status, like some overseas possessions, or maybe the Channel Islands] """