Hacker News new | ask | show | jobs
by nabla9 3013 days ago
U.S companies have option to either do legally binding self-certifications or outside compliance reviews.

If they don't do that, they have no authority to collect data from EU Citizens (no user accounts or customers from EU).