Show a basic level of respect for your users' privacy whether or not it's not a legal requirement.
Do you have a compliant privacy policy, data retention policy, breach notification policy? Have you named a data privacy officer? Do you have a written process for erasure requests?
You’re probably right that the ads are a problem but ain’t nobody getting GDPR compliance for free.
Besides, most websites need to update their privacy policy to be accessed in California anyway. The Californian privacy protection rules aren't as strict as the GDPR, but they are very similar. I don't really buy the "it's expensive to comply" argument a lot of American companies seem to use because of this.
The companies want to collect and trade your personal information to the highest bidder, the GDPR got in their way and now these companies are acting out.
You may want to be nice to the foreign visitors otherwise and comply with the foreign laws, but that's it.
Exactly. If you're operating in the EU, you are bound by the EU laws. But "operating" doesn't mean you have to sell something:
> The GDPR applies to US businesses, regardless of their size in terms of revenue or staff, if at least one of the following two conditions are met:
> 1. The company offers good or services (even in the absence of commercial transactions) to EU/EEA residents.
> 2. The company monitors the behavior of users inside the EU/EEA.
So yes, if the news website in this thread tracks me without my consent, they are violating my rights and the EU laws. I am not sure how realistic enforcing this law actually is, though, unless they have a EU branch (what you described as jurisdiction).
Source: https://termly.io/resources/articles/gdpr-in-the-us/
> Although such a website would likely track the user behavior of EU/EEA citizens, as the website would attract native speakers of several European languages, the GDPR does not apply here because:
> the service does not target EU/EEA residents, and
> the tracked user behavior is not occurring within the EU/EEA.