"T Mobile US refuses to apply GDPR".
"T Mobile US refuses to apply GDPR".
"This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not."
https://gdpr.eu/article-3-requirements-of-handling-personal-...
" The whole point of the GDPR is to protect data belonging to EU citizens and residents. The law, therefore, applies to organizations that handle such data whether they are EU-based organizations or not, known as “extra-territorial effect.”" (gdpr.eu)
I don't see anything in GDPR or the recitals that limits that only to their processing of data of people in the Union. The recital for Article 3 section 1, recital 22, says:
> Any processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union should be carried out in accordance with this Regulation, regardless of whether the processing itself takes place within the Union. Establishment implies the effective and real exercise of activity through stable arrangements. The legal form of such arrangements, whether through a branch or a subsidiary with a legal personality, is not the determining factor in that respect.
Note it says "Any processing".
If what is being done with his data counts as Deutsche Telekom processing the data, then GDPR will apply regardless of his citizenship or location.
Note also that recital 22 says that it woulds still apply even if Deutsche Telekom were doing the processing through a subsidiary and even if the processing were not taking place in the Union. But I think that is only relevant if the processing is being done for Deutsche Telekom or under their direction, which doesn't sound like it is the case here.
For controllers and processors not established in the Union (which is what I think T-Mobile would count as) is covered by Article 3 section 2. That one is limited to data subjects who are in the Union, and applies when either of the following conditions hold:
a. the processing activities are related to the offering of goods or services (including free goods and services) to data subjects in the Union, or
b. the processing activities are related to the monitoring of data subject behavior as far as their behavior takes place within the Union.
The first requires some level of targeting data subjects in the Union. The mere fact that someone in the EU can reach your website and buy your goods or services is not sufficient. The way the relevant recital puts it they need to envisage offering goods and services in the Union.
In summary then, GDPR can apply to the processing of data of data subjects outside the Union, but only in the context of the activities of a processor or controller established in the Union (even if the processor of controller is having an entity not established in the Union do the processing). I don't think that is the case here though, so I don't think he's got much of a GDPR argument.