4 ms·
While GDPR is supposed to apply to any controller processing personal data where the processing activities are related to the offering of goods or service to da
by ghwst 8y ago
While GDPR is supposed to apply to any controller processing personal data where the processing activities are related to the offering of goods or service to data subjects in the Union, I believe it is fair to say that we have no idea yet how this will exactly be enforced outside of the EU (when it is enforced) until the first attempts appear.
It's true that this extra-territorial scope is a bold move when it comes to international law. I see a trend in the latest EU regulations that would suggest they are not close to abandoning this idea.
- dragonwriter 8y ago> It's true that this extra-territorial scope is a bold move when it comes to international law Not really. Foreign opponents (especially American opponents) of the law make a big deal out of it, but extraterritorial application of laws, especially to acts occurring outside of but having effect within the territorial boundaries of the State whose law is concerned, is in no way novel.
- ghwst 8y agoYou are right. It is something that has been known in criminal law for a long time. However, the possibilities to enforce have always been submitted to the rules of legal assistance that most of the time provides the limits of another national law. We might end up in a situation where US authorities could accept to apply GDPR, but with fees limited to what US law allows, for example.
- guitarbill 8y agoIronically, the US is one of the worst countries for extraterritorial application of laws, but I guess it's convenient to ignore for the sake of argument. See e.g. Foreign Account Tax Compliance Act (FATCA).
- M2Ys4U 8y agoThe UK's ICO has already taken action against a Canadian company (Aggregate IQ Data Services Ltd)