I complained to their data protection officer, who basically fobbed me off and told me they did nothing wrong. A few months down the line I finally found the time to recap everything and collect the proof and complaint to the ICO?
Their response? They threw the complaint away on a technicality because it's been more than 3 (or 6, can't remember) months since my last contact with the company despite them persisting with the behavior.
Only if you have an office in the EU.
Not any more than US companies need to comply with arbitrary Chinese laws, or Japanese companies need to comply with arbitrary Saudi Arabian laws. Why does the EU have special status in being able to impose laws on the US?
The EU can feel free to block the website if they don't like it. (But we know their citizens would throw a riot if they started censoring the internet, sshhh...)
However, independently of GDPR, I agree that it's wrong and that you shouldn't be saving contact information by deception. You'd lose me as a customer if you did that.
Of course the main problem with the GDPR is that it's so far not really been enforced, so people feel free to contravene it at will.
- (a) not do business in the EU, but leave your website accessible throughout the world. It's upto the EU to block it if they hate it
- (b) invite people from the EU to do business with you on US soil, where they would be subject to US laws instead of EU laws