If the controller or processor is established in the Union (regardless of where they actually process data), then GDPR applies to all processing of personal data regardless of citizenship or location of the data subject.
If the controller or processor is not established in the Union, GDPR applies to processing of personal data if (1) they are offering goods or services to data subjects in the Union, or (2) they are monitoring behavior of such data subjects that takes place in the Union.
See Article 3 for details.
If a US site that is not also established in the Union is trying to block access from the EU, and someone uses a VPN to get around that, the site would probably not be subject to GDPR, as they are probably not offering goods or services to data subjects in the Union. Recital 23 explains that offering goods or services means more than just their site can be reached from in the Union:
" In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union. 3Whereas the mere accessibility of the controller’s, processor’s or an intermediary’s website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union."
That's incorrect. That is the attempted naive reach of the EU in action. The correct formulation is: the EU would like for GDPR to apply to all EU citizen data globally.
US sites/services with no business reach into the EU, do not need to comply with EU privacy laws. 99% of businesses around the world (most small businesses), those outside of the EU, will entirely disregard GDPR - because they have no business dealings with the EU.
The EU has no jurisdiction over the US economy or its laws. That will remain the case. The EU also doesn't control China, or India, or Japan, or Brazil, or South Africa.
A simple example for illustration: I can establish a new US service that is ad based (with eg 100% of revenue being derived from the US market), I can keep all of my infrastructure & business operations outside of the EU, I can take on EU users at will, and I can do anything I want to - in compliance with US law - with their information without concern for GDPR: because the EU does not lord over the US, their laws do not rule the US. This is legally how GDPR actually works, despite the amusing propaganda campaign to pretend GDPR requires global compliance.
The number of people who have lost sight of this is unbelievable. It actually seems especially rampant on HN, which is kind of surprising, to be honest.
But aside from that, I can't understand how EU users are unable or unwilling to separate the intent of this specific law from the broader principle that it represents, and how other countries might misuse this principle.
If any jurisdiction in the world can pass a law no matter how ridiculous that forces any business in the world with a website to comply with, on the chance that a user from that jurisdiction might stumble on that site, AND there's any kind of enforcement mechanism, then the Internet will cease to exist. Either that or become ultra-balkanized, where every user has an identifier that will ONLY give them access to sites which are fully compliant with their jurisdictions.
What if the US to passes a law that Americans are too fat and are no longer allowed to be sold gelato (they're allowed to buy gelato, but no longer allowed to be sold gelato), and then levy a multi-million dollar fine against every gelato shop in Italy where Americans visit on vacation?
That makes as much sense to me as this does.
But Europe is full of people who aren't so in thrall to the EU as an idea, as evidenced by one of its most important countries voting to leave despite the population being threatened with massive chaos and severing of all cooperation and trade relationships with their neighbours should they choose to do so. Bad regulation was one of the most common talking points during the Brexit campaigns and GDPR is a good example of why.
These sort of people aren't posting so much on HN but they are quite common.
They don't exist. The EU loves to dress itself in the clothes of nation states, that which it so desires to become, but ultimately the concept of "citizenship" in the EU sense has nothing to do with the normal concept of citizenship.