4 ms·
1. Many indie developers will not actually be subject to the GDPR. The GDPR effectively only applies to non-EU controllers if they are actively targeting and ex
by latk 7y ago
1. Many indie developers will not actually be subject to the GDPR. The GDPR effectively only applies to non-EU controllers if they are actively targeting and expecting EU users, or if they are monitoring/tracking users in the EU.
The canonical reference to when that's the case is the EDPB Guideline 3/2018 on the territorial scope of the GDPR [1]. These guidelines are more narrow than widely perceived, e.g. that regional US news websites started blocking EU visitors is totally silly and unnecessary. Mere accessibility of a service, without offering the service to persons in the EU, does not trigger the GDPR.
2. If the developer does expect to be subject to the GDPR, they can hire a representative. There are many lawyers offering this service. It's not a terribly involved job, but it affects which member state's data protection agency is responsible. E.g. if you think Austrian GDPR interpretations are nuts, go look for someone in Ireland instead.
[1]: https://edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-32018-territorial-scope-gdpr-article-3-version_en https://edpb.europa.eu/our-work-tools/our-documents/guidelin...