I can concede that maybe I have not expressed myself well or articulated my points clearly. Allow me to try and clarify.
> GDPR is unique, because it exerts extraterritorial jurisdiction over servers whenever EU citizens are affected.
It's not simply the extraterritorial jurisdiction, it's that combined with how far-reaching and broad the GDPR is. The other examples people have given were either a seizure after an act was committed via a court order, or far more narrow in scope.
> However, you won't relent
Regarding COPPA, I provided references showing that a) the legislation itself does not assert extraterritorial jurisdiction in the way the GDPR does, b) that the wiki claims the FTC asserts extraterritorial jurisdiction but I can find no actual link to the FTC asserting that, and c) that legal scholars and the legal community seems to be of the opinion that COPPA is only applies domestically.
Why should I relent when those points show that COPPA is indeed quite different from GDPR? What's the flaw in my reasoning here?
> But you never ask yourself WHY ByteDance has a US presence in the first place? We could ask similar questions: Why does Facebook have a EU presence (on Ireland), why does Google?
But that's the point! The US sued someone via COPPA when they had a US presence, and it was in a US court. There was nothing extraterritorial about it!
GDPR is saying they could take action against one lone Chinese person operating a small business from home within China, someone who has never even left China, just because they collected data on someone in France.
That's frankly ridiculous, and I maintain, unprecedented.