Its quite interesting putting in various peoples email addresses to see what sites they are linked to. Maybe once he has made some money out of it, a GDPR claim and financial settlement can be made as he's made no steps to control the data privacy of Europeans.
I'm curious if my naive understanding of this is wrong.
It’s a grey area at the very least.
No it isn't. It covers my data no matter how you got it, with a few exceptions.
EDIT: Please feel free to point to the legislation showing that GDPR only applies to data supplied by the subject.
An operation like this levels the playing field and lets us collectively hold companies to their responsibilities.
"The regulation applies if the data controller (an organisation that collects data from EU residents), or processor (an organisation that processes data on behalf of a data controller like cloud service providers), or the data subject (person) is based in the EU. Under certain circumstances,[2] the regulation also applies to organisations based outside the EU if they collect or process personal data of individuals located inside the EU. The regulation does not apply to the processing of data by a person for a "purely personal or household activity and thus with no connection to a professional or commercial activity." (Recital 18) "
The EU laws apply to people and entities outside of the EU, he is not immune from these EU laws because he is affecting the lives of every European who has an email address in this website.
Wrong, wrong, wrong.
GDPR covers the processing of any data about an identified or identifiable individual.
Do you think GDPR fines go to the person, and not the regulator?
Administrative fines levied by a supervisory authority generally don't go to people who have had their personal data processed illegally, though.
Oh wait: https://www.troyhunt.com/free-course-the-gdpr-attack-plan/ https://www.troyhunt.com/new-pluralsight-course-the-state-of... https://twitter.com/troyhunt/status/1017679101698572295