European data, European rules.
European data, European rules.
I'm still waiting to see how well that holds up in court.
Companies can either adapt to the ruling or take their business elsewhere.
No one claimed otherwise.
It's still fascinating (and, I believe, a first) that the EU thinks they have extraterritorial jurisdiction just because their citizens are affected.
In general countries may well claim that their law applies even if you believe it doesn't, you then break that law at your own risk, and given that the penalties can be pretty serious I would caution against this without having consulted with a lawyer.
Note that I'm perfectly fine with the EU protecting the rights of its citizens, being one of those myself, and that I'm also perfectly fine with the US protecting the rights of its citizens.
I'm a bit weirded out by how the US taxes its nationals even when they live abroad but if that's the law then that's how it is for now.
So what? We're discussing the GDPR. Pretty sure the US has no similar law at all. GDPR was considered a first.
> In general countries may well claim that their law applies even if you believe it doesn't, you then break that law at your own risk
You're trying to compare GDPR to general prinicples and it doesn't work. GDPR was a new type of law.
See https://www2.deloitte.com/ch/en/pages/risk/articles/gdpr-ext...
"Let’s say for example that you are a Chinese web shop with a website that is available in German, French and English as well. You also process multiple orders a day from individuals within the EU and ship your products to them. This will make you fall in the scope of the GDPR, even though you have no establishment in the EU and are not performing any data processing activities within the EU."
Yeah, that's unprecedented.
https://oag.ca.gov/privacy/ccpa
> You're trying to compare GDPR to general prinicples and it doesn't work. GDPR was a new type of law.
No, it's a law like every other. You abide by it or you end up dealing with the business end.
> "Let’s say for example that you are a Chinese web shop with a website that is available in German, French and English as well. You also process multiple orders a day from individuals within the EU and ship your products to them. This will make you fall in the scope of the GDPR, even though you have no establishment in the EU and are not performing any data processing activities within the EU."
> Yeah, that's unprecedented.
No, it isn't unprecedented.
https://en.wikipedia.org/wiki/Unlawful_Internet_Gambling_Enf...
And that's before we get to AML and ATF legislation that the US has enacted and basically enforced all of the world of finance.
If I want to sell data in the EU, I can. I'm not subject to their laws unless I have a presence there.
GDPR tries to change that.
See https://www2.deloitte.com/ch/en/pages/risk/articles/gdpr-ext...
This is more like me deciding to try and sue people in other countries because they said something I didn't like on the internet.
It’s trying to regulate the data collection and processing of users in its territory.
On the other hand, CLOUD act was trying to regulate data on foreign servers.
This isn't just my take by the way, it's common knowledge and was the cause for much discussion and speculation.
https://www.pinsentmasons.com/out-law/guides/international-t...
I'll wait to see how it holds up when the EU tries to enforce it against a US website with no presence of any kind in the EU.
That's called moving the goalposts.
But even in that case: the EU has a lot of power and no matter what you are still required to have a legal presence in the EU if you want to serve EU customers. Breaking the law is generally not the best course of action for any company that wants to stay in business over the longer term.
No, it isn't. That's the test.
> no matter what you are still required to have a legal presence in the EU if you want to serve EU customers.
That's nonsense. There is nothing stopping EU citizens from buying something via my US based website while they are in the EU, and I have no obligation to have any kind of presence in the EU.
Ignorance of the law is not an excuse for breaking the law.
https://ico.org.uk/for-organisations/dp-at-the-end-of-the-tr...
https://gdpr-info.eu/art-27-gdpr/
You seem to be arguing from how you believe it should work or how you think it works without knowing how it actually works, which is quite important when you are operating a business.
Practicality > useless laws
The Deloitte page I linked to gives a Chinese web store located in China with no EU presence as an example.
It's bonkers that the EU thinks they can enforce their laws in a situation like that. But then, that's why it hasn't been tested.
It's basically a 'feel good' law with no teeth (at least the extraterritorial aspects).
It will drive Europe to a sort of digital isolationism where offshore companies will either a) dismiss and continue b) cease operations there.
I think it's like I said, it's a lot of "feel good" laws.
> It will drive Europe to a sort of digital isolationism where offshore companies will either a) dismiss and continue b) cease operations there.
I think it's more likely the US adopts a softer version of the GDPR, and it will be the EU and the US and the Commonwealth countries vs pretty much other more restricted Internet 'islands'.
I really hope we have a working decentralized alternative before that happens. It's something I want to start contributing to later this year, because I think it really needs to be a priority.
You seem maybe out of our depth in this discussion. I'm not sure why you take me pointing out that truth of the matter that the GDPR is unprecedented in its extraterritoriality as an attack, but it's not. This mistake is clouding all of your replies and input into this discussion.
I'm fully aware of the law. That's what has been being discussed up until this point. The whole point of the law is that it isn't enforceable.
> You seem to be arguing from how you believe it should work or how you think it works without knowing how it actually works, which is quite important when you are operating a business.
No, I'm arguing that the GDPR is unprecedented, and EU has tried to claim jurisdiction in areas that they simply can't enforce.
If you believe otherwise, that's fine, but almost all of the legal community disagrees with you.
That's baseless rambling, sorry.
Do you have anything to contribute other than misguided insults?