(Have an office in the UK? Use a SaaS/PaaS subject to UK? Have users from UK? Want your iOS or Android app to be available from the official store to UK users? Want your DNS and routing to work in UK?)
(Have an office in the UK? Use a SaaS/PaaS subject to UK? Have users from UK? Want your iOS or Android app to be available from the official store to UK users? Want your DNS and routing to work in UK?)
Yes, that means it applies to you if you run a Telnet server and a British person logs in to it and might find a text file created by someone from the US there. You need an age gate in front of the login, unless you can satisfactorily demonstrate that you have few under-18s as users. How to prove that? The law doesn't say.
The UK doesn't get to enforce its law everywhere just because it says its law is enforceable everywhere.
There's already precedent here:
https://en.wikipedia.org/wiki/SPEECH_Act
> The Securing the Protection of our Enduring and Established Constitutional Heritage (SPEECH) Act is a 2010 federal statutory law in the United States that makes foreign libel judgments unenforceable in U.S. courts, unless either the foreign legislation applied offers at least as much protection as the U.S. First Amendment (concerning freedom of speech), or the defendant would have been found liable even if the case had been heard under U.S. law.
> The act was passed by the 111th United States Congress and signed into law by President Barack Obama.
[snip]
> The act was written as a response to libel tourism.[1] It creates a new cause of action and claim for damages against a foreign libel plaintiff, if they acted to deprive an American (or certain lawful aliens) of their right to free speech.[2] Despite its goals, it is seen as a weak response to the problem of libel tourism as, although it establishes a new cause of action in § 4104, and allows for the collection of "reasonable" attorneys' fees in § 4105,[note 1] it does not allow for damages to plaintiffs in contrast with stronger provisions in proposed bills which did not pass such as the Free Speech Protection Act of 2009 (H.R.1304, 111th Congress).[3]: 22
> It was inspired by the legal battle that ensued between Dr. Rachel Ehrenfeld and Saudi businessman Khalid bin Mahfouz over her 2003 book Funding Evil.[4]
Just to make it even clearer: "Libel tourism" basically means taking your case to British courts, which are hilariously pro-plaintiff when it comes to libel. That's what happened with Ehrenfeld.
(As your profile is empty, for all I know you've an actual lawyer in this specific field — NH is this kind of place after all — but most of us aren't, and I've been surprised by legal principles that LegalEagle has described as "law school 101, and I mean literally I taught XYZ in a 101 class").
I mean I break Chinese law all the time; I have a blog without the necessary permits delivered by the PRC bureaucracy.
How is this UK law any different? Unless you have some kind of tie to the UK why should you care? What are they going to do? They can’t fine you nor put you in jail. Are they going to block your sites? Then everybody in the UK will use VPNs (just like China) undermining the ability of the government to enforce such laws even further.
GDPR was a EU law (much bigger than UK), it was not as tedious to comply with, and the PR would have been bad for any company breaching it. None of this is true here. The PR is actually good if you don’t follow this law; you can say you’re defending human rights and stuff.
As a UK resident, I hope this will go the way of anti-piracy legislation - i.e. enforced against big services only while everyone else just continues to do whatever they want.
If the law won't be enforced on you in particular, it's because the UK government does not care enough to enforce it on you in particular. It has very little to do with where you live or what courts have "jurisdiction" over you.
I doubt that social media execs would avoid traveling to the UK of all places in order to not piss off the handful (and I say this as a long-time EFF member) of people who really care about this law. To make things worse, major services tend to have presence in almost every country, especially the UK, and leadership tend to have personal connections and property in these places. They will just comply (as long as not offering their service in certain locations is an acceptabpe form of compliance, they might opt to do that if the financial calculus works out, but it's not necessarily an option at all). They don't even have to go straight to physical or financial punishment: if a service accept any kind of payment, they can get compliance by ezerting influence through various international card networks as well. If they don't have to comply, and can keep offering their service anyway, it's only because the UK didn't squeeze hard enough: but they could, and if they do, there'll be nothing your government or geographical location will do to protect you.
There is no such thing as a sovereign entity "not having jurisdiction" over you: that would be an oxymoron, they do as they please by definition. If they don't make you comply with their orders, it's only because some economic factor prevents them from doing so.
* execs are liable for breaches of the law if/when they travel to the US. * companies in the US are forbidden to do business with companies in Germany that breach the US law
There are a handful of small companies doing direct sales that are small enough that they do not have US partners. The rest complies because doing otherwise is financially disadvantageous.
They’d fine you as well but that’s probably less enforceable.
- Show that you are aware of the regulation
- Implement some kind of thing to comply with the regulation. The degree of that is debatable and ultimately can only be decided by a court.
Just pointing to a ToS is not enough, because nobody reads them.
Implementing a geofence and denying service to UK ip addresses is probably a good start. If UK citizens want to access your service, they could still use a VPN, but then the "malice" is on them.
The bigger/widespread your service, the more effort you might have to put in to prevent malicious intent.
Think about this way: You are liable for the services you offer. You must comply with local laws. It's up to you how much liability you want to carry. If your compliance with laws is extremely weak, your liability is high.