3 ms·
If you make money from EU users and are US based you need to be GDPR compliant or they will target you through payment processors and ad networks. If you don't
by infinitismal8 8y ago
If you make money from EU users and are US based you need to be GDPR compliant or they will target you through payment processors and ad networks.
If you don't make money from EU users and don't want to be GDPR compliant you should probably just shut them off if you ever want to operate in the EU in the future
- skinnymuch 8y agoThe OP initially says if you’re small time they likely won’t target you. Are you really saying if you’re super small time, the EU is going to go after your payment processing? Of course anything is possible. It seems highly unlikely though. Then his/her last point is that they’ll give you a chance to correct things. Your post doesn’t seem to cover that either.
- infinitismal8 8y agoThey will go after you the moment you become bigger and if you are person running a business one of your hopes is that you won't remain small time forever
- bigbugbag 8y agoThe way it's been done in the past, it usually starts by notifying you and giving you reasonable time (a month) to fix things then move up to sanctions. But this is not a given every time and not everyone goes the nice route, some go directly to court. So when you are a small fish, you are better off doing your best to follow the GDPR in the first place than scrambling to avoid sanction in a limited time later. it is not that complicated to not collect data you don't need, ask before collecting it and informing about what you do with it.
- dpark 8y ago> it is not that complicated to not collect data you don't need, ask before collecting it and informing about what you do with it. This is not all the GDPR requires. You’re just describing traditional Privacy Policy.
- parenthephobia 8y ago> they will target you through payment processors and ad networks How will they do that, and on what legal basis?
- zAy0LfpBZLC8mAC 8y agoGarnishment. If the regulatory agency decides to fine you, and you don't successfully defend yourself against that in court, then you'll have to pay that fine. If you fail to pay the fine on time, any entities within the juristiction that owe you can be ordered to pay the fine instead (i.e., your payment processor will be ordered to redirect funds arriving for you to the state, which also, as far as their juristiction is concerned, fulfills their debt towards you--as far as their legal system is concerned, the payment processor has paid you and you have paid the fine).
- whataretensors 8y agoSounds like a good reason to start only accepting crypto
- zAy0LfpBZLC8mAC 8y agoExcept that won't help you? Usually, payment processors are ordered to redirect funds as that is usually the easiest way, but if that is not an option, your customers will be ordered directly to redirect payments. As long as you have customers within the jurisdiction, they will find a way to make you not earn any money from them until your fine is paid.
- briandear 8y agoSo you admit that GDPR is really just a trade barrier.
- adventured 8y agoGDPR - the core of it - is about privacy, it's an increment on prior laws in EU countries. It's also in part a response to the data hungry US tech companies, without question. The 4% of worldwide revenue fine potential is exclusively targeted at the US tech giants. By my last count, the US has roughly 100 tech companies worth over $10 billion each (with trillions of dollars in worldwide revenue). Nobody taxes revenue, that's about the most moronic thing you can possibly do - unless you're doing it to try to harm / punish companies. Very few EU tech companies have meaningful worldwide revenue to tax.
- deleted 8y ago[deleted]
- icebraining 8y agoOf course they're trying to harm companies when they fine them. That's implicit in the term "fine". They target revenue because otherwise companies will just use Hollywood accounting to declare they make 0% profit, they just pay huge licensing fees to some cayman island company.
- icebraining 8y agoHow can it be a trade barrier when EU companies are more affected by it? (They have to provide these protections for everyone, whereas non-EU companies only have to provide them for people in the EU).
- qeternity 8y agoYou just answered your own question. The cost of compliance is largely a fixed cost. So if only 50% of my users come from the EU, then my per-user costs are 2x what an EU-centric company's would be. So it skews the economics in favor of blocking the EU if your business is not EU-centric. This in turn means users are pushed to EU companies that have no choice but to comply.