4 ms·
This isn't actually correct. If you collect or process process the data of European citizens, no matter where in the world you are, then you're affected by GDPR
by delogos 3y ago
This isn't actually correct. If you collect or process process the data of European citizens, no matter where in the world you are, then you're affected by GDPR.
- akerl_ 3y agoIf I'm a US citizen in the US, hosting a website on US infrastructure, why would a rule that the EU put in place impact me?
- BOOSTERHIDROGEN 3y agoSimply you block everyone from EU visiting your web or put a disclaimer you don't provide services for EU citizen
- akerl_ 3y agoWhy though? If Norway passed a law saying that all US websites have to include a disclaimer saying Norway is the best country, it would be pretty clear that it doesn't affect me, because Norwegian law doesn't apply to people who aren't in Norway and aren't Norwegian citizens. I put up a website. If people from the EU visit my website, why does EU law apply to me? Opening a brick and mortar bakery in the US doesn't make me subject to EU food regulations just because somebody from Europe flies over and buys a cake.
- BOOSTERHIDROGEN 3y agoWhat distinguishes online interaction from physical interaction in terms of jurisdiction and law enforcement?
- db48x 3y agoExactly. Plenty of people from the EU will claim that an EU law must be followed by US citizens, usually for magical reasons (or because they have been told that it is so). It just isn’t true.
- Ekaros 3y agoIf you sell services to EU residents then it would apply. Or otherwise generate significant revenue. If not, I would not worry too much.
- solomatov 3y agoIt's much more complicated than that. The article 3 (https://gdpr-info.eu/art-3-gdpr/ https://gdpr-info.eu/art-3-gdpr/) says two possible ways to get into a territorial scope of GDPR: - the offering of goods or services - the monitoring of behavior of data subjects Offering doesn't mean that it's just available and/or sellable in EU. It's more complicated than that. EDPB has a guidance on this topic: https://edpb.europa.eu/our-work-tools/general-guidance/guidelines-recommendations-best-practices_en https://edpb.europa.eu/our-work-tools/general-guidance/guide... In short, document shows examples where some services are available in EU, and sellable there but personal data isn't covered by GDPR. On the other hand, my understanding is that monitoring of behavior is always covered by GDPR. (I am not a lawyer and this is not a legal advice)
- akerl_ 3y agoI don’t think I dispute that the GDPR and related laws claim to apply to me if I have a website that EU residents access. I dispute that they have jurisdiction to actually apply their laws to me, any more than the US can charge somebody with violating FCC regulations for a radio signal sent from Norway. There are specific things like extradition treaties, trade agreements, and parallel legislation that cover existing areas where this happens. Is there one that covers application of the GDPR in the US?
- db48x 3y ago> There are specific things like extradition treaties, trade agreements, and parallel legislation that cover existing areas where this happens. Is there one that covers application of the GDPR in the US? Nope. Extradition only covers the case where you go to some other country and commit a crime there, then return to the US. If the crime you committed there is serious, and is also a crime here, then extradition can apply. There are other conditions as well, but the key is that it has to be a crime in both places. Europeans can claim that you must follow their laws until they are blue in the face but it won’t magically become true. You can safely ignore it. Enjoy competing against European businesses without having to pay any of the same costs.