---- begin quote ----
(1) This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.
(2) This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:
a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or
b) the monitoring of their behaviour as far as their behaviour takes place within the Union.
(3) This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.
---- end quote ----
Based on this, it looks like for GDPR to apply to an establishment in regard to a particular person, at least one of those two parties must be in the Union. An EU citizen traveling outside the Union dealing with an establishment that is not in the Union appears to not be covered.
See https://cybercounsel.co.uk/data-subjects/
> 1. A Data Subject under GDPR is anyone within the borders of the EU at the time of processing of their personal data. However, they can also be anyone and anywhere in the context of EU established Data Controllers an Data Processors.
Are Dutch citizens in Oklahoma protected by Dutch narcotics laws? Of course not. They are subject to the jurisdiction in which they are physically present.
However, a US citizen can be subject to US laws overseas, however, that’s between the American and the US government — the intermediary country has no involvement unless it’s an extradition request.
This idea that EU citizens are protected worldwide is just ridiculous. EU jurisdiction doesn’t extend beyond the EU. The idea that GDPR requests have to be honored by some local ecommerce company in Idaho is just nonsense and not supported by any international legal precedent.
- banks all over the world have to ask their customers if they aren't American, when signing up for an account. Even a local bank in rural Poland, which couldn't care less about international markets, has to now ask people to explicitly confirm that they are not American citizens
- if you're doing a security offering, and you happen to sell to an American, even if they live in Europe, and you're blocking IPs from U.S., you have to follow the US regulations as well
And yes - it is kind of shitty, but EU wasn't the one to start a trend of applying the local laws on foreign soil.
I'm no expert, but I thought on the whole the constitution has nothing to do with citizens -- it's a list of rules that the US government must follow. It certainly has no hold over the German government.
> This idea that EU citizens are protected worldwide is just ridiculous. EU jurisdiction doesn’t extend beyond the EU.
If you, as someone who breaks the conditions in the GDPR, have nothing to do with the EU, then you're fine.
However the GDPR applies to you, an American citizen in America who's never been to the EU, just as the DMCA applied to Dmitry Sklyarov, a Russian citizen who had never been to the U.S.
Sklyarov charges were dropped in a typical american plea-bargain
"Mr. Sklyarov agreed to cooperate with the United States in its ongoing prosecution of Mr. Sklyarov’s former employer, Elcomsoft Co., Ltd. Mr. Skylarov will be required to appear at trial and testify truthfully, and he will be deposed in the matter. For its part, the United States agreed to defer prosecution of Mr. Sklyarov until the conclusion of the case against Elcomsoft or for one year, whichever is longer. Mr. Sklyarov will be permitted to return to Russia in the meantime, but will be subject to the Court’s supervision, including regularly reporting by telephone to the Pretrial Services Department"
I see nothing about jurisdiction there.
The US has pushed the world around for along time, the world is pushing back.
This is true. GDPR would only apply there if they were "offering goods or services, irrespective of whether a payment of the data subject is required, to data subjects in the European Union". [1]
This is understood to mean they must be marketing to the EU, for example by offering their site in European languages (apart from English), using European currencies, or using a European domain.
If a small hotel in California had a French language information page, that doesn’t make that hotel subject to an EU law. If I am wrong, then where is the case law? Where is the legal precedent?
https://iapp.org/news/a/what-does-territorial-scope-mean-und...
(And - case law? Not really a thing in most countries executing the GDPR.)
You are the only person who has this view. EU citizens are subject to the local laws of whatever country they reside in. However if they are interacting with an EU company then GDPR applies to that company, no matter where they reside. But an EU citizen living in America and using an American service has no GDPR protections. Just like they have no EU right-to-work protections if they decide to work in America. GDPR explicitly states that it (generally) only applies to companies which do business with people who are within the EU's borders (citizenship is not a prerequisite of GDPR protection) or EU businesses.
There is no jurisdiction if those companies don't have a presence in the EU. None. Show us international law where this would be applicable. As the grandparent was pointing out, any country can now make any law where if any of their citizens access some internet service where ever in the world, somehow their laws magically apply to everybody in the world "doing business over some fiber".
I don't think so.
If you are doing business with people in the EU, then you have to be incorporated or otherwise have agreements (explicit or implicit) with the EU countries you are doing business with. GDPR applies to you or you will no longer be able to do business with the EU. If a company wishes to not have their ability do business with the EU revoked, they have to comply with GDPR (including its fines) as well as all other EU (and local) laws.
I really don't understand how this concept is difficult to grasp. Countries give you permission to do business with them -- if you break their laws they can revoke your ability to do business with their residents. Most large companies would probably lose much more money breaking off ties with the EU than they would complying with GDPR fines. If you continue to violate a country's laws you could be extradited and so on.
> somehow their laws magically apply to everybody in the world "doing business over some fiber".
If you are providing a service to a group of people, for money, then you are doing business with them. Pretending as though this is not the case just because the process is conducted through under-sea fiber cables rather than mail couriers is ridiculous.
While most of GDPR is common sense and shouldn't be much of a burden on companies[1], I was always confused about jurisdiction. While most larger companies have a legal presence somewhere within the EU that can be held accountable for this, I do wonder how the EU is supposed to be enforce penalties on a company outside of the EU.
[1]: well, the difficulty grows the larger your company/product is, but chances are you have more resources available to dedicate to it anyway
Realistically, they can't and won't unless it's a very large scale that's worth pursuing, for a multi-national corporation with enough money to pay a big fine. If a company is not doing business in the EU, not selling into the EU, they can of course entirely ignore the GDPR.
In the case of a large company that sells into the EU, and refuses to obey GDPR, what you'd likely see is the EU pursuing that company on its domestic turf legally. A company out of NYC for example could be pursued in a court there for fines related to GDPR violations. The larger those violations, the more likely it'd be pursued by the EU across the Atlantic. This is how it works already, there's a lot of international business precedence. The stronger the legal system in the home country you're pursuing the multi-national into, the better for the EU's case.
If I set up a business in Germany, dump large amounts of toxic waste and cause very costly environmental damage, and then (somehow) quickly flee the country leaving no assets or business behind - but back in NYC my company has vast assets, you'd find the company pursued from Germany to its home in NYC for those damages. They still have to win the case of course.
The EU fortunately wasn't dumb enough to attempt a global claim on regulating privacy. They pushed the line pretty far, but did not cross their own boundaries. I think they fully understood there was no scenario where the US and China (40% of the global economy) - or frankly most nations - were going to care about EU law projections external its jurisdiction.
IANAL but I can imagine a similar situation happening with GDPR.
In addition, authorities could for example seize local servers in the case of non-compliance. In many EU countries including Germany, data privacy violations can also be prosecuted as criminal offenses.
All of this is nothing new, it's been working like that for centuries, back when business correspondence was still on old-fashioned paper.