Plus a minimum of 20M€ fine in case they don't think your "common sense" is good enough.
For a one man shop that is not working under the legal protection an LLC or equivalent provides, this can be deadly!
Plus a minimum of 20M€ fine in case they don't think your "common sense" is good enough.
For a one man shop that is not working under the legal protection an LLC or equivalent provides, this can be deadly!
That is a figure used to bring non-European companies who wish to trade in the EEA but not comply to the negotiating table.
We rarely see the largest tier of fines here in the UK, I'd expect little to change there too.
Reputational damage should be a focus of anyone concerned with risk here.
This time EU did it right, I doubt some small local shop will ever get max punishment but the % of global revenue is on the other side still something that can bite global corporations.
Why? It's selective prosecution, plain and simple.
These things have a history of being selectively used to punish institutions for other reasons that are not easy to do using the law
To the people downvoting, imagine the following scenario:
Website promotes ideas the EU finds problematic. The EU wants to silence it but can't because of free-speech laws or any other constraint.
All they have to do is find something trivial under this law and punish them for it, bankrupting the company.
All of these "I hope the law will be applied reasonably" are dangerous because they give the state too much power.
As for IPs. Any website could claim they need IP addresses for analyzing malicious use. So either it'll be a new cookie law in which they all use the vagueness of the new rules to loophole themselves out, or the EU will decide that this is only "reasonable" sometimes. The law effectively says nothing so whether or not HN would be entitled to store this data is essentially undefined.
Here's what will really happen to HN - nothing. But Google will get huge fines for doing exactly the same thing, and everyone will be left wondering if they're next.
Which they explicitly choose to do
> some use their real names as their username
Which is not required to use the site
> the site asks for email addresses
But you don't have to give one. If you do give one it is only used for password resets. Write that in your privacy policy and keep the email safe.
> Any website could claim they need IP addresses for analyzing malicious use
Yes they can, and the law allows it. Don't sell them to data aggregators and put it in your privacy policy why you are keeping it. If you don't want to then send the logs to /dev/null
> or the EU will decide
The courts will decide.
> The law effectively says nothing so whether or not HN would be entitled to store this data is essentially undefined.
What do you want from the EU? A law that references the internet protocol explicitly, and every possible use of it? What happens when the protocol changes, or someone invents a new protocol, or a new way of exploiting it? Pass another law that says the same thing? Laws in the EU are generally principle based for exactly this reason, they age much better.
> Here's what will really happen to HN - nothing
Because they are doing nothing wrong!
I'm genuinely curious.
However, it is a lot more likely that the LLC is owned by those with no nexus to Europe it is extremely unlikely that EU can do anything to punish this company. Hell 99% of web forums have European users.
Maybe it will have teeth against Google/Facebook/Tinder/Match/etc because those companies actually have assets in Europe but it won't be effective against companies with no nexus.
[0] https://en.wikipedia.org/wiki/List_of_United_States_extradit...
These laws have to be implemented in each of the member countries, so you'd be violating the law of one of those countries.
If there is a tax agreement between a specific member state (EU) and the US, IRS can show interest in Joe. If there are like a thousand sales in a specific member state (the taxation is not EU wide global), no one will show interested, so if Joe is small - it's very likely Joe is safe.
Operating w/o the VAT could also spring money laundering interests -- the institutions concerned with anti-money-laundering cases tend to have rather long reach.
Overall VAT is taxation on the consumption, the consumption is within the EU member state, the state receives the tax.
Summary:
When US companies encounter European VAT: When doing business in the territory of the EU a company will deal with VAT: when selling something, the company will have to charge the customer with VAT... [0]
Also: The EU’s VAT law considers everything that is not a good (generally a tangible property) as a service. Services can include everything from the licensing for intellectual property to downloadable software to consulting – to name but a few examples. The VAT requirements for services depend on the final customer
U.S. Foreign Commercial Services for U.S. Companies [1], [2]
[0]: https://www.rsm.global/insights/tax-news/europe-how-european... [1]: https://2016.export.gov/europeanunion/eg_eu_030910.asp [2]: https://www.export.gov/article?id=European-Union-How-the-EU-...
You are confused. Selling services to EU residents without VAT is perfectly fine if the company has no nexus to EU. Just like it is perfectly fine for a company that has no nexus to the United States to sell services to residents of New York City without collecting NYC sales tax. Not only is this done all the time, it is a standard tax minimization strategy peddled by the likes of DT and BDO.
The VAT structure in the EU is the responsibility of the EU. An EU customer buying something or some service in USD from a US company with no presence in the EU is responsible for handling their own tax liability with the EU.
Conversely, I have bought many items and services online from EU companies who don’t have presence in the USA. Not one has charged me VAT nor the local “use tax” the People’s Republic of Chicago charges for internet-based services.
In short, my experience is you’re just plain wrong. A bunch of expensive and competent accountants hired by my various employers agree that you’re wrong.
If you import goods (receive them via mail), there is a customs clearance required + VAT for prices over N euro (where N varies on the country but usually less than 25e). Indeed that's a direct responsibility of the receiver.
>Not one has charged me VAT nor the local “use tax” the People’s Republic of Chicago charges for internet-based services.
Please don't mix the laws in different jurisdictions. VAT is quite different than sale/use tax. Try and buy goods from USA (even ebay suffices) and receive it within the EU w/o paying VAT (unless explicitly exempt from the tax)
Electronic services have no customs clearance or physical presence and what I explained above (VAT number, etc.) applies.
>A bunch of expensive and competent accountants hired by my various employers agree that you’re wrong.
Proof by authority ain't cool. VAT does apply to the end user (companies can receive it back, etc.), so I am unaware if your employers used to sell to end users directly. If selling services was that easy, registering outside EU would so temping as pricing ~20% less would be great. As proof goes: I consulted an accountant about US offered services to a local EU member state. (didn't have to pay anything)
Examples of not being able to sell services to US residents are forex and gambling. Non-US companies practically can not take US customers. Selling services online ain't that easy even to US.
Appeal to authority isn’t a logical fallacy when the authority is an expert in the domain.