I mean this seems pretty suspect for anyone privacy focused.
I mean this seems pretty suspect for anyone privacy focused.
> Part b. omg.lol does not believe its processing of limited personal data of those outside the United States (if any) brings it within the jurisdiction of these laws.
That's a hard disclaimer if there's any.
I read that as: if you're a European user, we do not believe you can legally enforce us to honor your rights, even though we operate within the EEA.
> Article 3.2 goes even further and applies the law to organizations that are not in the EU if two conditions are met: the organization offers goods or services to people in the EU, or the organization monitors their online behavior. (Article 3.3 refers to more unusual scenarios, such as in EU embassies.)
https://gdpr.eu/companies-outside-of-europe/
Which is pretty much what happens given that they allow EU citizens to buy a 20 USD subscription.
If enough people do it they will act.
https://commission.europa.eu/law/law-topic/data-protection/r...
If one does not like EU law, one should just not do business here.
This is largely a moot point as long as omg.lol remains some guy's side project but given that the ToS explicitly mentions the possibility of a merger or buyout, this feels like it's poisoning the well a bit. If there's any upside to this, it's that this makes a buyout far less likely because he's essentially saying "yeah, we collect a ton of personal information but we don't have the legal consent for any of it and explicitly told users we're not complying with their regional data protection laws when it comes to gathering, processing or storing their personal information". Fair enough for the MySpace era of Web 2.0 privacy abuse but no longer workable in a world with the GDPR and its many regional equivalents.
Oh dear. That is definitely not correct. The only way for omg.lol to not fall under the jurisdiction of the GDPR is to not offer their services to people living where it applies.
How did we get here? To where If I spin up a webserver and charge for access now I'm suddenly forced to lick your middle finger because you have laws in your country saying so?
If I surf over to another (Internet surfing) country because the server is physically located in that country, I again am forced to follow the laws that apply there.
It does seem illogical to have such setup especially since physical I haven't moved.
Now it seems that I can take my laws with me when I visit a server in another country. Making everything even more confusing.
Unfortunately that does not apply to physically traveling to another country: that country doesn't care two bobs for my countries laws.
Edit: INAL.
on the other hand if you go set up a business that sells to citizens of that other country do you have to follow rules to be allowed to sell stuff there? You see how the analogy is a little closer aligned?
Same kind of deal, omg.lol have my servers located in the United States, payment processing happens in the United States, in United States Dollars. In no way is omg.lol making a special usecase to handle European customers.
Now, Europe is free to attempt to excise their laws againt omg.lol, however they wouldn't get much further than "you're blocked in the EU" and having to get ISPs and transit networks to blocke their traffic, and payment networks to stop serving EU customers for that particular merchant ID.
Is this usually followed in small scale shops? Almost never in my experience, though if the shop gets big enough or if the business is sold those tax liabilities are still technically owed. Many countries do have a minimum revenue before you have to pay taxes, and some have a minimum before you're supposed to report sales via tax filings even if you don't owe, but you better keep the operation small if you never plan to pay foreign sales tax.
That's the situation with privacy protection laws: the user brings the laws with them.
If you scam people in country A from country B, you're criminally liable to country A even if it's not a crime in country B. Same if it's espionage (cf. Assange), piracy (cf. TPB) and so on. Why should infringing on privacy rights be any different?
There are plenty of sites that only cater to US users and have signup forms requiring data like postal addresses or payment methods that contain regional information. Heck, some US sites even exclude users from certain states for various reasons. This service costs money so they need the user's billing address anyway. Just restrict access there and then like the rest.
The guy who created omg.lol did not "spin up a webserver and charge for access", they run a company that collects, stores and processes their users' behavioral data and personally identifiable information. It's more like a hosting company except it's apparently cobbled together from various third parties without any due diligence about how they operate. And it even uses the phrase "privacy-focused" in various parts of its claims. Yeah, I'd say it's reasonable to expect a company like that to provide basic information like what data it collects, how it ensures that data is protected and how a data subject can get that data deleted or corrected.
We have laws preventing corporations from selling products that are unfit for purpose or food that is blatantly toxic and we have laws preventing corporations from offering you contracts that demand personal harm or indentured servitude. In places like the EU we also have laws that prevent companies from using your data without consent and making sure you follow the best current practices when handling that data. And yeah, if you want to make a service that collects all data and monetizes the ever living fuck out of it you can still do that, you just need to ask your users for consent and allow them to opt-out if it isn't essential to doing what the users would want to use the service for (i.e. no bait and switch).
I don't know why some people find it so hard to understand the idea of informed and non-coerced consent.
You do business somewhere, you have to abide by the laws of that somewhere.
As to how did we got here? I don't know. It probably happened sometime around year 500 BC?
If omg.lol does not have any business in EU it is probably not going to actually be a problem for them because EU is unlikely to go to U.S court to try to get money - also because I believe that probably wouldn't work.
However
1. if they are trying to get purchased by someone they probably should consider potential buyers probably don't want to buy a bunch of EU liability.
2. they should probably refrain from any sort of ambition that would give them such a business in the future because regulators can be really mean when someone does this kind of funny stuff.
3. if they don't pay if called on it maybe there would be a situation where they would get blocked - not sure about that but seems reasonable reaction.