3 ms·
If you, a GDPR-bound business, are silently serving, embedding, or otherwise using resources served by US businesses without explicit opt-in approval, then you
by floatingatoll 5y ago
If you, a GDPR-bound business, are silently serving, embedding, or otherwise using resources served by US businesses without explicit opt-in approval, then you absolutely could be violating GDPR, specifically for example if the user’s IP becomes known to the US-operated resources.
This would theoretically apply whether using AWS hosting (even in EU availability zones), Stripe or PayPal cart checkouts, or any other platform owned and/or operated by a US business or its subsidiaries. It isn’t relevant where those US-owned data or servers are hosted.
This unfortunate situation could be corrected by the US signing a new treaty or other law that ensures that the US governments, law enforcement, and courts cannot compel US business to violate GDPR.
(I am not your lawyer, this is not legal advice.)
- shafyy 5y agoThanks for explaining - that's how I also understood it, just wanted to make sure I didn't miss anything.