I'd certainly never consider visiting normal US news sites unless - like in this case - they were linked to by HN or some other aggregator I do frequent.
Thus, it really makes no sense for them to comply with the GDPR.
Even then a non-EU company may not explicitly target a EU audience but EU moral or physical person may still find interest for whatever personal reason and still be protected by GDPR.
As for jurisdiction, I suppose such conflicts are resolved using international law, but if a company is reachable from the EU by individuals protected by EU laws I’m pretty sure there is applicable jurisdiction (not saying it’s an easy thing)
> 2. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: > (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or > (b) the monitoring of their behaviour as far as their behaviour takes place within the Union.
This makes perfect sense from the perspective of some old politician: It's like shooting someone over the country border. It fails to address the fact that unlike in physical space, on the internet it's not that obvious to see where someone is connecting from (in fact, it's impossible to really say with complete accuracy)
But in my opinion, it's not the wrong choice to assume that, if you're operating on a scale where you can spy on your users and sell their data, you'd be capable of figuring out whether they're in the EU. And, honestly, it's not hard. There's third party software that you can just embed in your website and it automatically generates the cookie warning and even blocks cookies until you've accepted it.
Blocking the few European users is probably the right decision from an economic perspective.
Let's see just how much they like that.
(That was the sound of the joke going over your head)
Want to store logs? Now you need to make sure you're scrubbing any type of personal information from the logs. Want to use a third-party service? Now you need to make sure that you are using their GDPR-compliant plan, and that you are using their Amsterdam endpoints. Maybe you need to renegotiate your contract with them.
You can put the IP in your security logs because that is necessary to secure the service. Just have a routine to scrub the logs once they are too old to be useful anymore.
You can't put the IP in your shadow profile database and sell it to shady marketing companies, unless the user has explicitly agreed to that.
The question isn't only whether something is personal information or not, it is also a question of what you intend to do with the data.
Not exactly; it's up to the judges to decide whether IP addresses count as personal information as defined by the GDPR (in my opinion they're not, but I can see why one would think differently), so the flaw isn't as much inherent to the GDPR as to the fact that people just don't understand the internet.
While the wording of the Recital leaves some ambiguity as to whether an IP is automatically Personal Data under the GDPR, its specific call-out would make arguing that it is not difficult. This would particularly be the interpretation of American lawyers, who tend to assume that no connection is too tenuous to be held against their client by a shrewd prosecutor or regulator and will thus advise their client to treat all IPs in all situations as Personal Data.
So can Amazon/whoever if they saved the IP alongside other customer information.
But a naked ip->person lookup would require a warrant.
Have a look at the list of companies and other websites this service uses/shares data with.
No wonder some websites rather block users all together instead of showing that they are selling data left and right.
What?! I'm not allowed to store my users name, address and credit card number in my unencrypted syslogs anymore? HOW DARE THEY, THOSE DAMN BEUROCRATS!
Seriously though, while there are problems (like IP address being considered personal information, which they really aren't), the general idea is very positive. You shouldn't be able to store just any information of a person that only gave you this data for a specific purpose. Servers do get hacked, employees do abuse their access to systems and old hardware doesn't always get disposed of properly.
When I'm done using a service, I want my data gone from their servers ASAP, no buts.