That said, it's an interesting thought experiment to understand what the implications would be if it was hosted in a GDPR country.
That said, it's an interesting thought experiment to understand what the implications would be if it was hosted in a GDPR country.
> In May of 2018, a major upgrade to Europe’s overarching data protection framework becomes enforceable. This will be followed by a companion piece of legislation pertaining to data in transit. The extraterritorial nature of these two frameworks — they protect the privacy rights of people in Europe regardless of where their data is collected — means that they will become the de facto standard for privacy around the world. [1]
[1] https://www.smashingmagazine.com/2018/02/gdpr-for-web-develo...
Someone more knowledgeable than me please correct me if I am wrong.
In that case, either the tourist who bought it is the one in the wrong and will need to forfeit it at the border, or the law does not apply.
I see no reason why the conclusion about the GDPR cannot be "EU companies on EU soil need to comply, but EU citizens touring the internet via non EU sites are on their own and proceed at their own risk, without protection from the GDPR."
IANAL, but I have had a couple of law classes. Also, one of the things I do know is that we have no world government and laws regarding international internet stuff are breaking new ground daily because it is an unprecedented circumstance that doesn't one-for-one compare to historical legal precedents.
I imagine if we ever get a world government, it will be an emergent event and it will grow out of the current trend of multiple countries joining together to form blocks like the EU. But I see absolutely no reason why any country outside the EU should be presumed to be subject to EU laws just because EU citizens are capable of accessing their sites via internet.
If someone has an article that shows this has been established as a precedent the world accepts, I would be interested in seeing it. But I am not aware of any established precedent suggesting the EU will by default be accepted as having the authority to dictate standards across the globe.
> Under the GDPR, organizations may be in scope if (i) the organization is established in the EU, or (ii) the organization is not established in the EU but the data processing activities are with regard to EU individuals and relate to the offering of goods and services to them or the monitoring of their behavior.
- https://stripe.com/guides/general-data-protection-regulation...
Having said that, what about CDN's? I'm certain that lots of comment data is located in CDN's across the EU, US, and Asia.