This is nonsense. The GDPR only applies if you actively target users in the EU, such as by offering French/German/Swedish translations, or supporting the Euro currency in your shop.
From the horse's mouth (https://gdpr-info.eu/recitals/no-23/):
the mere accessibility of the controller’s, processor’s or an intermediary’s website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention
And I've actually put that to the test. For some medium size websites I manage that get about 30% of traffic from EU countries, instead of an annoying cookie banner, I have a banner saying the GDPR does not apply as the server is not hosted in the EU, they are free to adjust their browser settings as they like, and they're free to file a GDPR complaint and take action. And there's only an 'I accept' button, by design.
So far, nothing has happened, and I doubt it ever will.
"The whole point of the GDPR is to protect data belonging to EU citizens and residents. The law, therefore, applies to organizations that handle such data whether they are EU-based organizations or not, known as “extra-territorial effect.”"
Does Chinese law apply in France to Chinese citizens that have emigrated there? China would say yes, they even set up secret police stations to enforce it. But does that make it so?
The GDPR doesn't only apply to commerce sites.
I agree with you the EU is probably not going to prosecute you, but that doesn't mean it's legal.
If you don't think that analogy is accurate, can you explain why?
Regarding the censorship, obviously the laws apply inside Chinese territory. France is not China so the laws do not apply.
But regarding GDPR, the EU user is still inside EU territory when visiting your website and giving you his personal data. If this user was, I don't know, in Indonesia while visiting your website, then Indonesian laws would probably apply. Which is why the analogy of a foreign company doing some activity in the EU (like selling a product) seems more apt.
Again, IANAL and this is just my superficial impression.
This is exactly my point! EU laws apply within the EU. The US is not the EU, so EU laws do not apply.
> Again, IANAL and this is just my superficial impression.
Fair enough, I see your position now, thank you for explaining.
I think it's a pretty terrible precedent to try and enforce laws from the visitor's country on to the hosting providers country though.
It's not that far-fetched to think some countries with poor human rights records could post some laws that would work the same way you describe, and I don't think you would want them upheld.
The only thing that makes sense to me is enforcing laws for users within their own borders, and same for hosts. If the EU doesn't like something outside of their control, they should setup the Great European Firewall.
https://www.enforcementtracker.com/
Ireland is the biggest one in terms of money fined because Google etc have their subsidiaries incorporated there. But I don't see any fines directly to a US company.
If it can't be enforced uniformly, then it's fine for people to not take it seriously, or for it to be enforced selectively, both of which I think are problems.
As long as you never go to Europe for any reason, there's no way for the EU to get you. At worst your website will get blocked inside the EU. And, of course, any companies using your services to service EU countries would be violating the GDPR themselves so may lose out on some potential customers.
I don't see the point in claiming the law doesn't apply to you, though. If it doesn't, you don't need a cookie banner.
What is the point in claiming a law applies if they can't enforce it?
Would it not make much more sense for the GDPR to have a provision blocking sites they can't control, or to allow for treaties between countries? It may allow both of those things already, in which case, it's even more perplexing to try and claim global jurisdiction as they do.
And I don't need a cookie banner. The one I have is a subverion to make a point.
Actually, GDPR applies to (1) people who are "in the Union", and (2) people whose data is being processed by processors who are "in the Union". Citizenship has nothing to do with it.