Will this also apply for citizens of a EU country living outside the EU?
Will this also apply for citizens of a EU country living outside the EU?
My understanding is the GDPR applies to residents of the EU, not just citizens, and it also applies when they are outside the EU. In practice this means it is impossible to determine if it applies unless you gather far more information than you really need from your users - “sorry we have to invade your privacy to protect your privacy”.
That makes no sense.
This sounds unenforceable.
The next fun job is working out how to remove the data from all your backups when you get a removal request.
I have taken the approach that I will comply with the general intent of the GDPR (which I did long before it existed), but not try to apply the ridiculous parts.
You're going to have to provide proof to back up that statement.
"The principles of, and rules on the protection of natural persons with regard to the processing of their personal data should, whatever their nationality or residence, respect their fundamental rights and freedoms, in particular their right to the protection of personal data.”
0. http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX...
Yes the regulations make no sense and they really aren’t enforceable outside of the EU.
I think it's both.
If someone in the EU (say a visitor) asks to have their data removed that was collected while they were outside the EU, then the controller or processor is supposed to comply.
How is any business supposed to know if a user while they were in the USA of a service located in the USA will not later travel to the EU and make a data removal request while there? If the request comes from someone located in the EU then the regulations apply.
The practical result is you can’t just geo ban people from the EU and this is before we get to the problem of proxies.
> where the processing activities are related to: the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or the monitoring of their behaviour as far as their behaviour takes place within the Union.
It is interesting that the monitoring clause only applied if the subject is inside the EU when the monitoring is done, while the service or goods clause applies if the person is inside the EU with no requirement that the service or good was acquire or used within the EU. I can’t really think of any logical reason for this distinction. The “takes place within the Union” for one and not the other is strange.
> the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union
> the monitoring of their behaviour as far as their behaviour takes place within the Union.
If you get a request from someone in the EU to remove their data you have to comply no matter where or when the data about them was acquired. The clause is quite clear on this point and it why it is written differently to the clause about monitoring.