4 ms·
The law applies to websites, not businesses. If your website has European visitors, then it is making the relevant interaction even without business happening.
by tobylane 5y ago
The law applies to websites, not businesses. If your website has European visitors, then it is making the relevant interaction even without business happening. I’ve come across websites that simply deny me access, guaranteeing they don’t have any European visitors. US law spreads in a few ways, eg licence to use the dollar, though that may be broader than the exact wording.
- MR4D 5y agoI would love to see this fought in court for my local neighborhood restaurant. No way would a US court hold that GDPR has any standing.
- tobylane 5y agoI'm sure they wouldn't, as it's not a US law. But a local company may be small enough not to have to bother, just as they don't have to provide certain US law based employer benefits. > The second exception is for organizations with fewer than 250 employees. Small- and medium-sized enterprises (SMEs) are not totally exempt from the GDPR, but the regulation does free them from record-keeping obligations in most cases (see Article 30.5).
- MR4D 5y agoI’d add to that Lawyers, Engineers, Financial Advisors, and many other roles that are licensed by territory. Regardless of what the GDPR says.
- bryanrasmussen 5y agoI don't actually see any way that your local neighborhood restaurant, assuming your local neighborhood is not in the EU, will in any way be covered by the GDPR. It will for the first be too small to require much record keeping. Second, it is unlikely to be keeping any personally identifying information from someone using the site while in the EU because nobody is ordering food from a pizza place in NYC while sitting in Napoli. IP address is sometimes PII but more often not. Thirdly, as your local restaurant does not have any business operations in the EU any potential fines levied against them would probably be unenforceable. Those are just the top three things that spring to my mind though, pretty sure that there are other reasons the worry is nonsensical.
- itake 5y agoOP's site seems to focus on where servers are hosted, not about how or what data is stored or whether or not violations are enforceable. A European could order delivery in the USA for a friend. The business (website) would happily accept money for this.
- bryanrasmussen 5y agotheoretically this situation could arise, in practice c'mon. I have friends in the U.S but I'm not ordering any delivery for them unless I'm there.
- MR4D 5y agoA friend did that with flowers for my wife's birthday during 1st year of Covid (although the person was from the UK, not the EU proper).
- bryanrasmussen 5y agoEvery time I have ever bought flowers internationally it has been through some big international floral delivery company that handles the actual contact to the local florist, hence I do not believe that any of the florists that actually delivered the flowers to their recipient was in possession of any personal information. Thus a small florist does not operate the same way as a small local restaurant, the big international company with my personal information however will be on the hook for it and should have processes in place to handle that.
- itake 5y agoManagers in the EU could order food for their team in SF for a "lunch and learn." I don't think this is that crazy of an example in this world.
- bryanrasmussen 5y agoOk, well in that case if they did that and the restaurant decided to save the personal data longer than was necessary to fulfill their legitimate business purposes then I guess they would be under GDPR. Legitimate business purposes might be (just guessing as I am not a restaurateur)- IP addresses kept for a week until profile of website visitors report for that week made, credit card and name kept until payment received.
- hash872 5y agoNot to be repetitive, but- let's say your website has visitors from Thailand, and you do something to defame their monarch. Are you in compliance with Thai law? What if you have Chinese visitors, are you subject to Chinese law? What if the Central African Republic passes some completely out-there law and you have CAE visitors- do you feel like you need to comply with the laws of the Central African Republic? If not, why not? Let's just think this out- seeing as your visitors can come from any of the 300+ countries on Earth, you are saying that by hosting a website, you must simultaneously comply with the Internet laws of every country on the planet. Please just consider how ridiculous that is for a moment
- tobylane 5y agoIf you speak in your country and someone hears it where it's illegal then that's of no interest to you. But if you visit someone's home and they add your name to their guestbook you may care that you're in the records. Yes, it's reaching beyond borders, but I like this one more than any of the other examples of that. I could repetitively make up new analogies to explain my opinion (and subsequent actions in democracy), but after a moment's consideration that would be ridiculous.