Directly from the EU:
> Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR.
(https://ec.europa.eu/info/law/law-topic/data-protection/refo...)
Directly from the EU:
> Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR.
(https://ec.europa.eu/info/law/law-topic/data-protection/refo...)
Does that mean that (e.g.) German bloggers are not bound to the GDPR when they just add "made for the Swiss" to their header?
If someone is gathering and storing email addresses and ip addresses it seems reasonable to ask them to take industry standard measures to protect that data, and to let users know that the data is being collected.
According to the GDPR, they are. https://eugdprcompliant.com/personal-data/
"The conclusion is that the GDPR does consider it as such."
One requirement, imho, is quite ridiculous, however. That is the need for entities which need to abide by the GDPR but do not have a presence in the EU to assign a representative in the EU.
This part definitely needs some relaxation. Just complying with the regulation ought to be enough as the first step, especially for start-ups.
It is enough; most start-ups won't need a representative.
That requirement only applies to large-scale processing of special categories ( i.e. sensitive ) of data or that relating to criminal convictions and offences.
Article 27 applies: http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELE...
It's basically to prevent big data processors from claiming 'we don't have an EU presence so you can't fine us'.
The main problem overall is that the EU appears to consider information about someone as being owned by that person. That is quite foreign from a US individual perspective and having some blogs. I don't see how the learning I have acquired about people places and things, which I acquired without any promise of confidentiality, can be owned by anyone but me. Are libraries and newspapers required to scrub their shelves and archives? And if not, what is the limiting principle?
But indeed that can go both ways - the website of a newspaper might be required upon request to remove a 20-year-old crime blotter item reporting a single petty theft conviction for an otherwise law-abiding non-celebrity; they wouldn't be required to do that for a 2-year-old murder conviction.
Do you have to provide proof that your site doesn't specifically target its services at individuals in the EU?