Just because I'm a Britsh person living in the US doesn't mean I'm not subject to the death penalty or am exempt from having to buy health insurance, for example.
EU citizen works in the UK for 2 years then goes to Turkey for a vacation but likes the place so much, decides to stay for longer when still remote working for the same London company.Also connects through VPN because the Turks love banning websites.
Where this person residence is? Are the UK, USA, EU or Turkish rules apply? How FB would know about it?
That’s not an extreme scenario BTW, it happens all the time.
Tax residency is separate and the rules are a bit different and again vary by country.
Usually residency is self declared or based on where you have spent the majority of the year working in.
This is already handled, by lots of people, when they declare residency already, for where they currently live/work/are covered by taxes under.
This isn't a new thing.
Can you vote in Glasgow's local elections if you live in Manchester?
The electoral register knows I’ve left the U.K.; I had to tell HMRC separately because they don’t share info; likewise the Student Loans Company even though there is a close connection between income and repayments [0]; and when I tried to tell the DVLA, they told me they lacked the capacity to know about non-UK addresses.
[0] the repayment rules means that, for low- and mid-income people, it behaves more like a graduate tax on worldwide income than a loan — it’s a percentage of pay over a threshold, and only high earners can pay it off fully — and if you do a self-assessment tax return there is a box for student loan stuff.
In UK there's this concept called proof of address and it's usually bill or a document that is sent to your address, there's no central registry of residents.
Some countries require at least 6 months + 1 day to be considered a resident, others might have you have a resident even if you aren't there if "the country is the center of your family or economic interests".
What causes difficulties though is that the rules in different countries, even if clearly defined, can contradict each other on the question of tax residency. So you may well be liable to pay taxes in two (or more) countries at the same time.
You may even have to pay taxes in both countries on the same income or gains, unless there is a double taxation agreement that allows you to offset some of those taxes against each other [2]
[1] https://www.gov.uk/hmrc-internal-manuals/residence-domicile-...
Tax law favours a designated location for residency, for example.
The GDPR doesn't even operate on the level of residency (at least for data subjects). You're covered by the GDPR when you're physically in an EU member state[0] as regards your activity in that member state or if the data controller/processor is established in the EU. The UK GDPR will be the same, mutatis mutandis.
[0] Or somewhere where EU law applies by virtue of international law, like an embassy, an EU-flagged ship, an area of Antarctica claimed by an EU member state etc. etc.
If you're there on your 90day tourist visa, it's not your residence.
It also states that data from people in EU has to be processed and stored in the EU.
It's not a matter of citizenship nor residency. Facebook just geo-locate you IP endpoint (so endpoint of your VPN) and manage your data by doing so. So USA rules will apply.
BUT if you are browsing websites hosted in Europe, EU rules will apply to your data.
Now there's the practical question of how the EU enforces that protection against companies that have no presence in the EU, but those that do, the EU has made it quite clear they'll take enforcement action.
If the data controller/processor is in the EU, the GDPR applies.
If the data subject is physically located in the EU (even if not a citizen or resident) then the GDPR applies.
https://eur-lex.europa.eu/legal-content/EN/TXT/?qid=15288746...
Article 3.
If the data subject is physically located in the EU (even if not a citizen or resident) and the data controller purposefully targets data subjects in the union, the GDPR applies.
As per [0]:
the mere accessibility of the controller’s, processor’s or an intermediary’s website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention
[0] https://gdpr.eu/Recital-23-Applicable-to-processors-not-esta...
"factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union."
For example, almost anywhere in the world if you want to open a bank account they will explicitly ask you now if you’re an american citizen.
> 3.2 This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union,...
(Plus companies in the EU have to comply with GDPR for all subjects)
https://eur-lex.europa.eu/legal-content/EN/TXT/?qid=15288746...
For example, it also applies to people which are traveling and are currently located in EU territory (provided that a service is intended to be used by EU residents).
An American tourist in Paris is protected by the GDPR.
Of course the EU will have trouble enforcing that protection against companies that don't operate in the EU. But the protection remains, even if it's practically unenforceable.
I don't know why people keep repeating this myth. Laws like these are old as dirt. It could as well have been about blood samples from Denmark used in research in the US: the samples are protected by Danish law and to use them in the US you have to agree to certain rules. Again an example of you saying you will follow certain rules to be allowed to transport and use the samples outside Denmark, not Denmark forcing their laws on anything in another country. You are free to not sign anything and not use or move the blood samples or PII anywhere.
I have never applied for an Irish passport but I am automatically an Irish citizen based on my ancestry. Does Facebook know this? Do I need to inform them to benefit from GDPR protections on an ongoing basis?
How the hell is any of this enforceable?
That depends on what you want to do. What GDPR protection are you trying to benefit from?
> How the hell is any of this enforceable?
You can try to reach out to the regulator if you believe your GDPR protections are being violated,
https://www.dataprotection.ie/
My experience with the ROI is that they are unlikely to jeopardise Facebook pulling out of Dublin.
If you're physically in an EU country then EU GDPR applies to you there; if you're physically in the UK then UK GDPR applies to you there.
That is not correct. Specifically, the counterexample is if you are a EU citizen living in an EU country and the actual bits are stored in a datacenter in Texas. GDPR still applies in this case, as long as the website owner accepts EU users. If the website specifically doesn't do business in the EU, things are different.
Since the data originates where you are, the data has crossed a border to get to Texas and is therefore subject to GDPR (extra-territorially), I agree.
If you were in Texas when that data was collected from you, and you returned to the EU, I doubt that GDPR would apply to that data.
The only reason the EU is able to get away with this to a degree is the american governments wish cooperation to a point and our treaties. However, I suspect america will only tolerate so much push from the EU.
If you do actual business in the EU they can block financial transactions, and if you don't do business in the EU, there isn't really any incentive to (ab)use the data GDPR covers?
As a startup though, it's absolutely part of your calculus. If you are worried about GDPR compliance, you can choose to just not launch in the EU (actually that might not be enough, I believe you may need to actively refuse EU users) until after you've proven the concept. Although with California's CCPA, depending on the specifics of your situation, you may as well just carve out some time to deal with compliance.
I believe that is still covered by GDPR, but I'll openly admit that I specifically chose the counterexample in order to stay within my factual memory of the law.
Afaik GDPR covers EU citizens traveling abroad, as well as non-EU citizens in the EU.
Edit: It does not cover EU citizens traveling abroad, see thread below.
https://eur-lex.europa.eu/legal-content/EN/TXT/?qid=15288746...
- People in the EU
- Any data being processed in the EU, regardless of where the person is located
This is overall a good move by FB that puts a lot of pressure on EU/UK to come up with more sensible laws. Note that EU/UK has barely produced any major company operating in consumer web/app. It is for a good reason.