Otherwise, Zoom only needs to obey the laws of USA and wherever else they have offices.
Disclaimer: IANAL
Also: I'm not arguing for Zoom's sketchy practices but just saying that GDPR might be the wrong card here. The EU isn't the world police.
Otherwise, Zoom only needs to obey the laws of USA and wherever else they have offices.
Disclaimer: IANAL
Also: I'm not arguing for Zoom's sketchy practices but just saying that GDPR might be the wrong card here. The EU isn't the world police.
If the target is big enough, EU regulators will ask for help from other countries.
Zoom operates offices in a few EU countries[0] so they'll definitely have some sort of entity(ies) setup - regulation pressure can be applied.
GDPR is only strictly enforceable in EU countries. All the other countries, it's up to whether they want to cooperate.
Example - EU cannot force China to make Tiktok/Bytedance to follow GDPR practices in China for EU citizens. They really they can only wave a big finger and claim Bytedance is out of compliance.
Sure, EU can sue Bytedance cross border in China, but it carries no weight/teeth. At which point, EU has to escalate... trade relations? sanctions? war?!
So practically - they have to ask for help.
I suppose then they have the choice of doing Google's playbook in China and just close their EU offices if they wanted, instead of complying. I mean, China wanting censorship and EU wanting GDPR aren't any different. Without arguing for or against either, China's censorship and GDPR are both local laws and foreign-based companies with no local offices don't need to comply. Foreign companies may be blocked, that's all.
Not that I'm advocating for Zoom violating privacy, but I'm not in support of EU unilaterally setting rules for the world or their right to police EU laws outside their borders. They should set up a GFW if they don't like certain things being sent into their country borders over the web, but they can't tell me what to do if I haven't set foot in their jurisdiction. (Neither can Iran, Russia, or North Korea, so why does EU get a pass to police you? If Kim Jong Un sent you a fine for $1 million would you pay it?)
True, but if you have offices and do business in their jurisdiction, then you get to follow their laws.
By accepting customers from the EU you are setting a foot here albeit economically and not physically. You are free to not serve european costumers if you do not want to deal with the GDPR.
That’s not how the world works. Non US citizens have been arrested in the US for breaking US law when they aren’t in the US. Hell the US has tried to extradite people to the US who have never been to America.
Disclaimer: IAANAL
The EU can do the same thing and set up their own firewall if they wish to enforce GDPR on foreign websites.
The fact that their citizens would revolt over the idea of internet censorship, is irrelevant. The point I'm trying to make is that EU saying "you can't serve X to our citizens" and China saying "you can't serve Y to our citizens" is no different and it's upto them to enforce it within their borders if they wish. The EU doesn't get to play world police any more than China's government does.
FWIW baidu.com and tencent.com are both pretty damn GDPR incompliant and the EU isn't doing anything about it. And yes there are Chinese-speaking EU nationals that use these companies' services.