4 ms·
No any authority over sites not hosted/run in the EU. I'm a US citizen running a business in the US; the EU has no legal authority whatsoever over me. If an EU
by zorga 8y ago
No any authority over sites not hosted/run in the EU. I'm a US citizen running a business in the US; the EU has no legal authority whatsoever over me. If an EU citizens buys something from my site, as far as I'm concerned they came to the US virtually to do it, and US laws apply here, not EU laws. They can shove their GDPR where the sun doesn't shine.
- wglb 8y agoUnfortunately unless you are explicitly not soliciting business from EU residents, you fall under that regulation. One possible consequence is reputational damage.
- zorga 8y agoNo I don't, I'm not an EU citizen and have no EU physical presence; they can claim whatever they want, they have no jurisdiction over me, I am not subject to EU laws no matter what the GDPR tries to assert. It's toothless, they have no enforcement mechanism on a US citizen in the US. I'm am not subject to the laws of every country that asserts it so; I'm subject to the laws of the US only.
- ghwst 8y agoWhile GDPR is supposed to apply to any controller processing personal data where the processing activities are related to the offering of goods or service to data subjects in the Union, I believe it is fair to say that we have no idea yet how this will exactly be enforced outside of the EU (when it is enforced) until the first attempts appear. It's true that this extra-territorial scope is a bold move when it comes to international law. I see a trend in the latest EU regulations that would suggest they are not close to abandoning this idea.
- dragonwriter 8y ago> It's true that this extra-territorial scope is a bold move when it comes to international law Not really. Foreign opponents (especially American opponents) of the law make a big deal out of it, but extraterritorial application of laws, especially to acts occurring outside of but having effect within the territorial boundaries of the State whose law is concerned, is in no way novel.
- ghwst 8y agoYou are right. It is something that has been known in criminal law for a long time. However, the possibilities to enforce have always been submitted to the rules of legal assistance that most of the time provides the limits of another national law. We might end up in a situation where US authorities could accept to apply GDPR, but with fees limited to what US law allows, for example.
- guitarbill 8y agoIronically, the US is one of the worst countries for extraterritorial application of laws, but I guess it's convenient to ignore for the sake of argument. See e.g. Foreign Account Tax Compliance Act (FATCA).
- M2Ys4U 8y agoThe UK's ICO has already taken action against a Canadian company (Aggregate IQ Data Services Ltd)