...
Your service provider and data controller is now Google LLC: Because the UK is leaving the EU, we’ve updated our Terms so that a United States-based company, Google LLC, is now your service provider instead of Google Ireland Limited. Google LLC will also become the data controller responsible for your information and complying with applicable privacy laws. We’re making similar changes to the Terms of Service for YouTube, YouTube Paid Services and Google Play. These changes to our Terms and privacy policy don’t affect your privacy settings or the way that we treat your information (see the privacy policy for details). As a reminder, you can always visit your Google Account to review your privacy settings and manage how your data is used. If you’re the guardian of a child under the age required to manage their own Google Account and you use Family Link to manage their use of Google services, please note that when you accept our new Terms, you do so on their behalf as well, and you may want to discuss these changes with them.
https://www.hipaajournal.com/does-gdpr-apply-to-eu-citizens-...
https://ec.europa.eu/info/law/law-topic/data-protection/refo...
Otherwise there would be no way to know who you are without having your data in the first place which means the law is a catch 22. The only working interpretation is based on physical location.
Surely my physical location is no less part of my data than my citizenships? I guess if it's being processed immediately when it's collected it's possible to gdpr it or not, but if it's an offline process, then how can you do that?
Anyways it's based on physical location. There are lots of specifics around what PII is but in this case: 1) your location alone cannot identify you individually, and 2) nothing specific is stored and IP/network to region lookup for applying GDPR rules is acceptable.
Also, hat part of my comment do you believe that you quoted? The only quote I see if from the article I linked to in the revised comment.
Incidentally, when it comes to the GDPR, the term is "personal data", not "personally identifiable information" which is a US term.
2) The point of location data not identifying you is in response to the parent comment saying that location could also be considered personal data. It can, but only if used in conjunction with enough other data to uniquely identify you; not to just check if you're currently in the EU.
3) Using a VPN prevents GDPR enforcement if your location is inaccurate. Again it comes down to the law preventing your personal data from being used before you consent, so whether your location is a fact or not doesn't matter when the service provider isn't allowed to use it in the first place and must rely on network lookup for a best guess.
Now the question is if any random corner store in Indonesia is going to respect the EU decision.....
I also looked at the text in Article 3, "Territorial scope"[1], and that says it only applies to EU-based organisations and "data subjects who are in the Union". It seems to me that "in the Union" means "residing in", and not "citizen of"?
The third clause says it applies to "a place where Member State law applies by virtue of public international law", but I don't think this applies to Indonesia?
IANAL, but I think that is primarily a reference to member state embassies, consulates, overseas military bases, ships having member state flag in international waters, aircraft registered in a member state, and spacecraft operated by a member state. So GDPR would apply to data kept in a member state embassy/consulate in Indonesia.
In practice, a lot of the work embassies/consulates do may fall into one of the exemptions from the GDPR – national security, etc. But embassies/consulates often also do other stuff, like host conferences, workshops, dinner parties, etc. GDPR may well apply to data collected for those purposes.
Also the law is based on physical location (either companies or people in the EU at the time), not your nationality or citizenship which would be unknown without access to the very data the law is trying to protect.
If you're a foreign company selling to EU citizens you can be subjected to EU fines because there's usually a trade deal that says so.
But yes, checking the nationality of all your customers isn't feasible, but I bet the waters get murky when requests, such as data access or deletion requests, come after the fact, with proof of EU citizenship.
As for trade deals, the Safe Harbor agreement that would have allowed this was repealed before (and partly because of) GDPR. The only deal in place now is Privacy Shield which is completely voluntary and has no cross-border enforcement.
If none are then the GDPR does not apply