Just because you don't have a business presence (in the form of an office and employees) doesn't mean you don't have a presence: collecting data from, and making a profit on, users and customers in the EU is a presence. The alternative would be to surrender the obligation to regulate business practice and the protection of citizens to other countries, with no political accountability.
The EU is trying to imposing a huge regulatory burden on companies over which it has no authority. Why do I or any other non-EU company have to put up with this? What happens when the laws in my country conflict with the laws the EU imposes on me from afar?
You don't have to. Just don't do business in the EU / with EU citizens.
> What happens when the laws in my country conflict with the laws the EU imposes on me from afar?
You have a choice - either break the laws or your country, or... just don't do business in the EU.
(I do hope GDPR doesn't affect your company much; it seems to be doing God's good work, unlike most of the companies GDPR is targeted at.)
As for not doing any business with EU citizens this is impossible to comply with even if it was an option as there is no way of knowing if a person is an EU citizen or not.
Besides, this situation only came about because companies did nothing, especially US companies w.r.t. EU data protection laws. It's a bit like the loot box thing, they thought they could get away with it, pushed it too far, and now they're dealing with the backlash of being huge, amoral scumbags.
Anyway this is the sort of argument children use - “john did it too”.
This does not make sense on web.
EU resident streaming a movie from netflix. Is netflix doing business in EU ? Or Is it the customer doing business in USA ? For example, it can be argued that its as if the customer went to USA, bought the dvd.
> For example, it can be argued that its as if the customer went to USA, bought the dvd.
A DVD does not collect your personal information and send them to the producer for processing.
Are you saying if I sell to EU tourists visiting USA, I have to follow EU laws ?
> A DVD does not collect your personal information and send them to the producer for processing.
Thats come after when we determine whos doing business where. Or replace dvd with a survilliance device disguised as a toy.
Yes. Furthermore they have licensed content for this purpose.
If you have zero establishment in EU whatsoever, fines could be taken from all your EU sales revenue (i.e. any funds en route from EU customers to you), and it could be expected that (after they smooth out the process) they also might get a local (e.g. USA) court ruling to enforce that debt on you, there's a lot of international cooperation between the authorities in regards to enforcing trade law. That will take time, though, so until that you're safe unless you want to take money from EU customers or sell the user/advertisement information to EU (or compliant) businesses - in which case, you'll rather want to be compliant.
Do you think it is fine for countries to apply their laws as they want on people outside of their country? What would happen if Fiji (just picking a random country here) applied a 10% income tax on all citizens of the EU. Would you think this was reasonable?
Anyway it is not the data collection, or even removing data that I don’t even collect that I am concerned about, but the the EU applying its laws on me even though I am not in the EU and have no connection with the EU beyond visiting the place a few times.
It's a joke that the same government will go ahead and collect info for "protect the public from terrorists" purposes, yet try to constrain a company outside of their jurisdiction from collecting simmilar information with no real mechanism of enforcement.
People really think these technologies are just going to crawl in a ditch somewhere because some eurocrats (and those who've accepted the bread and circus they provide to the public) want to put pen to paper and act as if these are laws of phyisics... next we'll hear madates that all companies around the world must offer affordable privacy in a can™ for the EU chattel.
The more deep packet inspection/filtering of non complient sites, the more resilient the web will become, so I look forward to the continued escalation.
I suspect that without global jurisdiction we would end up with data laundering jurisdictions, just as we have tax laundering ones today.
And GDPR is not about the laws. It is about crooked people breaking basic human rights for their profit, every normal person should be glad that he has a straight (well almost :) ) directions how to respect and show respect for his customers. The attitude of "you cant force me" is fundamentally wrong.
One more thing, as a non european cityzen, I would be carefully monitor what the sites are doing with basic human rights (as now it will become evident) and protect myself from those who show their disrespect by not using their sites, services etc. Whole world will profit from this legislation and you can bet a lot of other countries will adopt it.
I suspect that has happened before. The tool to resolve these disputes is called diplomacy.
If we think of this as import/export it suddenly becomes more obvious - when importing or exporting physical goods from the EU, you have to follow EU law even if you're a non-national with no say in it.
(The example of US extraterritorialism I have is the other way round: https://en.wikipedia.org/wiki/United_States_v._Elcom_Ltd. ; as it says there, "it involved an individual being prosecuted for activities that were fully legal in the country where they occurred")
And why would I block EU ? Connection is intiated by user. So its user importing/exporting data from/to server jurisdiction. Why does not EU force their own citizens to not do business with those companies ?
This line of reasoning didn't work for the poker companies: https://en.wikipedia.org/wiki/United_States_v._Scheinberg
The US very definitely started the idea that it has global jurisdiction over the internet; why should it be the only such country?