Morality aside... what I'm curious about is, what gives California any jurisdiction over a company registered in another country, and operators residing in other states?
So, the question is, is there anything in those limitations which would deny California authority here?
I do hope that the GDPR succeeds at putting some checks on our surveillance overlords, but it's definitely resting on some busted-ass reasoning regarding nexus.