For larger companies with offices in the EU (especially the ones headquartered there for tax purposes), they obviously have no choice to comply. But what about a small startup, with its only domicile and employees in the US?
What exactly could the EU do to punish a startup in that case? Unless they have some enforceability treaty with the US, I don’t see how they have any legal ground to extract fines for arbitrary laws defined in their jurisdiction. The worst they could do is ask EU ISPs and/or payment networks to block the offending sites, right?
Such a suit could be ignored too, but it would certainly be a PITA for vacationing executives who get locked up in Italy for an outstanding summary judgement.
It's a good thing there are a lot of beautiful parts of the world other than Italy.
I suppose when I asked the question, I am assuming internet businesses for the most part don't isolate themselves to a specific region, so their reply probably makes more sense for the businesses that operate in a small locality. Perhaps they have such a business. I should have considered that prior to asking.
Where this might start to get interesting is if people use infrastructure that is in multiple regions and that infrastructure provider has an agreement to block companies that do not comply. So if AWS for example had such an agreement, then non compliant companies could find their sites broken, even if they are only hosted in the U.S., not that this would ever happen, but it could.
[0] - https://userstyles.org/styles/9038/hide-down-vote-arrows-and...
If it's the latter, then someone with both US and German citizenship could be covered even if they've never been to the EU.
Which is to say your hypothetical dual citizen would have zero rights under GDPR in their dealings with purely US entities.
While GDPR is a good idea, its legal impact can only be for business conducted within EU boundaries, or we are going to open up a Pandora's Box like this.
Come on: you're whining but you're doing that kind of extra-territorial stuff for decades!!!
Geoblocking is not enough. A user in Europe that bypasses an EU block with a VPN is still covered (this has been explicitly stated).
https://gdpr-info.eu/art-3-gdpr/ Art 3 (2b)
People (regardless of EU citizenship status) who are physically in the EU.
This isn't so hard.
There are precedents for the opposite. If you have a grandparent born in some EU countries, you have EU citizenship according to the law of that EU country, even if you never set foot on that country and have no contact at all with the EU. There is a (non-EU) country which says that if you're a citizen of that country, you have to pay income taxes to it, even if you never set foot on that country and have no contact at all with it. At least one country says that its law applies to buyers of widgets manufactured in that country, even if they are sold by someone who never set foot on that country and has no contact at all with it, to someone who likewise has no contact with it. And so on.
An expat living in the EU is protected because they reside in the EU. If you are living in the USA, you must follow American laws.
It's a basic idea, and HN prides itself on being smart, but there aren't global laws. No one gets to enforce civil penalties outside of their jurisdictions, without exceptional circumstances. If they fine you and you don't have offices there just ... don't pay? The EU might not exist in 10 years anyway.
Recital 23 (referring to Article 3, Territorial Scope)
> In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union.
An attempt to prevent EU users from accessing the site at all is about as strong a signal as it gets regarding this. When you're blocking all of Europe by IP, it's pretty fucking obvious you're not envisaging offering services there.