6 ms·
This doesn't seem very GDPR compliant. Though I don't know -- it at least just doesn't seem that way, it could be. "By default privacy isn't baked in" something
by s_dev 8y ago
This doesn't seem very GDPR compliant. Though I don't know -- it at least just doesn't seem that way, it could be. "By default privacy isn't baked in" something that GDPR does require.
I understand GDPR only applies to EU citizens but I'd imagine theres a lot of EU citizens using this US only product in the US.
- toomuchtodo 8y agoGDPR applies to EU residents (“data subjects”). EU citizens in the US are not protected by GDPR. I don’t believe Venmo operates in the EU (as it’s a shim for US financial infrastructure).
- briandear 8y agoGDPR has nothing to do with this.
- s_dev 8y agoAny company that stores or processes identifiable info like photos, names or even ip address on EU citizens is within the scope of GDPR. If I withdraw my consent for example from Venmo to hold my name. Is that public record altered?
- freeone3000 8y agoThis does not service EU citizens.
- AndreasHae 8y agoWhat about EU citizens living in the United States? They also fall under the scope of GDPR AFAIK.
- briandear 8y agoYou might be confusing EU citizens with EU residents. An EU citizen in the US, dealing with a US health provider is covered by HIPAA, while an American citizen dealing with an EU health provider is not covered by HIPAA. EU consumer protection laws don’t apply to items purchased in the US, nor do US laws apply on EU purchases. There seems to be confusion over “jurisdiction.” An EU citizen resident in the US is subject to both EU and US tax law, but a US employer who hires a US resident who happens to be an EU citizen is not subject to EU tax law because that US company, in this context, is not within the jurisdiction of the EU, while an EU citizen still retains obligations to the EU by virtue of citizenship. (And vice versa for Americans.) Venmo isn’t doing any EU business even if EU citizens are using the system within the US. The citizenship of the customer is irrelevant.
- s_dev 8y agoCheck the official documentation -- the wording doesn't say residents or citizens. It says "Individuals in the EU". I guess we interpret this differently: https://ec.europa.eu/info/law/law-topic/data-protection/reform/rules-business-and-organisations/application-regulation/who-does-data-protection-law-apply_en https://ec.europa.eu/info/law/law-topic/data-protection/refo... Venmo is owned by PayPal who have an existing entity and operation in the EU -- they are absolutely covered by GDPR and they can't get out of it by having a subsidary based exclusively in the US.
- djsumdog 8y agoIf they're EU citizens living in the US, they're under US law and jurisdiction.
- deleted 8y ago[deleted]
- aidenn0 8y agoAnd they are also under EU law and jurisdiction.
- true_religion 8y agoFor sure, but the GDPR only applies to interactions with EU residents while they are in the EU. People on vacation away from the EU or emigrants are not covered.
- LocalH 8y agoWhy should someone be covered by the jurisdiction of their place of residence when they are elsewhere? That seems a bit authoritarian to me.
- djsumdog 8y agoSay you went to a place where child sex traffic was legal, or the laws not enforced. This is illegal in several EU countries and the US, and you can be prosecuted upon return: https://www.justice.gov/criminal-ceos/extraterritorial-sexual-exploitation-children https://www.justice.gov/criminal-ceos/extraterritorial-sexua...
- btown 8y agoI imagine if any of these people were an EU citizen and actually asked in paper writing to be removed, they would be. GDPR does not require that companies make this process electronically initiated, nor that deletion be the default.