So they are fine with taking French money, but want to be above their laws?
So they are fine with taking French money, but want to be above their laws?
One of the things that stops GDPR from being a total clusterfuck is the so-called "one-stop shop mechanism." Each country has its own regulator, so GDPR is enforced by 27 different government agencies. BUT, anyone only ever has to deal with one. For EU residents, the regulator of the country where they reside. For businesses, the regulator of the country of their primary establishment. Regulators are supposed to cooperate in such a way that a company has a single, local point of contact.
(Related: If US companies push for federal privacy regulation, it's because they would rather have 1 law to follow rather than 50 different ones.)
Almost all US companies establish their EU subsidiaries in Ireland for tax reasons. As a result, the Irish regulator is basically in charge of GDPR enforcement against US companies. This is... not ideal. Ireland a conflict of interest, because of the tax stuff.
(I'm not an expert on this. My understanding is that the Irish regulator seems to be operating in good faith, but is under-funded, and is going up against the legal defense teams of Google, Facebook, Amazon, etc., simultaneously, all on its lonesome.)
Several of the larger and more privacy-focused countries, like Germany and France, have been openly critical of Ireland's slow enforcement of US tech giants. In the past, CNIL (France) has said that Google's establishment in Ireland is a legal fiction rather than a legitimate business establishment. But if this gets appealed to an EU court, this is going to be a huge point of contention.
(Possibly the only point of contention, because I don't see any way that Google's actions are in compliance with GDPR/ePrivacy Directive.)
Taken from: https://www.dataguidance.com/opinion/eu-one-stop-shop-under-...
It could be that Ireland did not react within the one-stop-shop allowed time frame, freeing France to start the procedure.