I believe the company in question would also need a legal entity in the EU in order for the EU to prosecute them, as I don't think you can take (e.g.) an American company to an EU court. IANAL though.
Without a US court case they'd be dependent on assets or an income stream in the EU to be able to force payment of any fines, though.
If the company wants to do business with a EU customers, they have _some_ surface area in the EU, which is enough.
> an income stream in the EU
If the company cares for EU customers, there's probably also _some_ way to make money on them. Unless EU customers will exclusively get Netflix USA ads in the future (which are 100% useless to them) on an otherwise 100% free service, there is a money stream to hook into.
That said, that's usually only a problem with small companies. Very few large companies manage to avoid all financial exposure to the EU and still do business with EU residents, so it has relatively little practical impact.
e.g. if Facebook pulled out (unlikely), then someone can just make a new Facebook site (we already know what functionality to copy), and then suddenly Facebook has a competitor.
But I can't find anything about how they'd make it enforceable in other jurisdictions (as opposed to enforcing the judgements by e.g. fining EU subsidiaries and the like).
Article 50 does say the Commission should take "appropriate steps" to ensure international "cooperation mechanisms", and its clear under e.g article 44 onwards that carrying out a transfer to a jurisdiction where the data would be subject to inadequate controls would be a violation of the directive, so you may very well be right.
Sure you can. EU Courts did it to Microsoft over (IIRC) internet explorer resulting in a brand new SKU. Microsoft tried the logic you used at which point the EU courts started levying 1.5m euro / day fines for noncompliance.
Turns out that if you want to do business in a jurisdiction badly enough, it creates their leverage to enforce their laws on you.
I don't quite get what logic you think I used that doesn't agree fully with what you said above would be.
No, but they can go after the original company who transfered the data. Remember, under EU law, companies don't own that personal data. It's not theirs to give away.
At first I thought "how would they know that" but it's simple: establish "home" for each of a match pair and identify that both parties' devices are at one or the other "home" during certain hours after matching.
In that sense, it's more than just data, it's inference, and that's almost worse as a private company's data could end up libeling you if it leaks!