No one claimed otherwise.
It's still fascinating (and, I believe, a first) that the EU thinks they have extraterritorial jurisdiction just because their citizens are affected.
No one claimed otherwise.
It's still fascinating (and, I believe, a first) that the EU thinks they have extraterritorial jurisdiction just because their citizens are affected.
In general countries may well claim that their law applies even if you believe it doesn't, you then break that law at your own risk, and given that the penalties can be pretty serious I would caution against this without having consulted with a lawyer.
Note that I'm perfectly fine with the EU protecting the rights of its citizens, being one of those myself, and that I'm also perfectly fine with the US protecting the rights of its citizens.
I'm a bit weirded out by how the US taxes its nationals even when they live abroad but if that's the law then that's how it is for now.
So what? We're discussing the GDPR. Pretty sure the US has no similar law at all. GDPR was considered a first.
> In general countries may well claim that their law applies even if you believe it doesn't, you then break that law at your own risk
You're trying to compare GDPR to general prinicples and it doesn't work. GDPR was a new type of law.
See https://www2.deloitte.com/ch/en/pages/risk/articles/gdpr-ext...
"Let’s say for example that you are a Chinese web shop with a website that is available in German, French and English as well. You also process multiple orders a day from individuals within the EU and ship your products to them. This will make you fall in the scope of the GDPR, even though you have no establishment in the EU and are not performing any data processing activities within the EU."
Yeah, that's unprecedented.
https://oag.ca.gov/privacy/ccpa
> You're trying to compare GDPR to general prinicples and it doesn't work. GDPR was a new type of law.
No, it's a law like every other. You abide by it or you end up dealing with the business end.
> "Let’s say for example that you are a Chinese web shop with a website that is available in German, French and English as well. You also process multiple orders a day from individuals within the EU and ship your products to them. This will make you fall in the scope of the GDPR, even though you have no establishment in the EU and are not performing any data processing activities within the EU."
> Yeah, that's unprecedented.
No, it isn't unprecedented.
https://en.wikipedia.org/wiki/Unlawful_Internet_Gambling_Enf...
And that's before we get to AML and ATF legislation that the US has enacted and basically enforced all of the world of finance.
If I want to sell data in the EU, I can. I'm not subject to their laws unless I have a presence there.
GDPR tries to change that.
See https://www2.deloitte.com/ch/en/pages/risk/articles/gdpr-ext...
This is more like me deciding to try and sue people in other countries because they said something I didn't like on the internet.