What if they give you only part of what they know? How would you be able to tell if they know more? And even if you could, how would you convince authorities that something is wrong?
I think we're probably talking about national chains here.
I would imagine stores will use the loyalty cards to profile users, and if they've every stored any of the profiling data then this data will be the data you will be getting.
Right now, for example, if you are a US business with no offices or employees in EU jurisdiction then there is little the EU can do if you are not GDPR compliant - regardless of whether you deal with EU traffic or not.
The EU might wish their laws were global, but that doesn’t make it so.
#notalawyer
I don't think there's many internet companies that would not serve the EU because of it. Although, Google did pull out of China due to the censorship demands and the like.
As such, effectively it is not in scope and does not need to be considered.
However there are cases where you might still run into trouble. For example, if you accept payments from people in the EU, you may well end up being forced to comply via the payment networks' presence in the EU.
Again, I say this as someone who is implementing GDPR for a US-based company, and is also a EU citizen (Irish) and has sat more meetings with various legal groups than I care to remember (again, stress I'm not a lawyer).
It is all about a companies appetite for risk and how tied the are __PHYSICALLY__ to the EU (offices/employees/parent-companies/subsidiaries).
This also gets into areas of Extraterritorial Jurisdiction. Any country can claim this over any other territory they wish. But, for the claim to be effective (except by use of force), it must be agreed either with the legal authority of the country.
Right now there appears to be none. No one is clearly citing any treaty with the EU as giving them this authority.
BTW it's important to understand the real enforcement vector here. It's not like you'll have "EU cops" knocking on doors in America. Nor will anybody waiting for you to get off the plane in Germany. (I've actually seen this nonsense on HN in recent days.) The very real power they do have is over banks and payment processors. It's quite possible that if you're doing business with EU customers and you have bank accounts in EU or work with EU banks or EU payment processors then they'll be able to exert significant leverage against your business. But if you have no direct contact with the EU financial system and your website is hosted in the US in English (or even if it's in French but it's clear you're pursuing US customers) there's little they could do to you even if they wanted to.
Right now, everyone is in "wait and see" mode on how this will play out.
It will be interesting to see how the mechanisms of enforcement play out but I imagine there are plans for direct and indirect implementation in situations that warrant the harshest options (ban on processing and/or monetary fine). E.g. getting cooperation from payment or logistics processors to stop processing EU sales of a offending foreign company. A halt on sales or delivery of goods to such a large region could be crippling for a company.
This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:
- the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or
- the monitoring of their behaviour as far as their behaviour takes place within the Union.