Hacker News new | ask | show | jobs
by snowwolf 2952 days ago
That is incorrect.

GDPR makes no mention of EU citizens or residents.

The 2 main groups it applies to are:

1. activities of an establishment of a controller or a processor in the Union (so if the company is in the EU, ALL processing has to be GDPR compliant regardless of where the user is)

2. processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union (if the company is not in the EU, processing of data of people in the EU - note they just have to be in the EU and not residents or citizens - so if you are from the US and on holiday in the EU and you order pizza delivery to your hotel, that personal data has to be handled in a GDPR compliant way, notwithstanding that the pizza company is probably in group 1 anyway but hopefully you get the point. And the converse of that, if you live in the EU and are on holiday in America and order pizza, that personal data does NOT need to be GDPR compliant as you are not IN the EU)

There are a few other scenarios included too.

Edit: It's worth pointing out that 1 seems to have been completed missed in almost all GDPR coverage I have seen, possibly because most of the coverage has been heavily US centric. If the company is established in the EU, it has to comply with GDPR for ALL users, not just people in the EU. This is why Facebook [1] and others changed their terms so that only EU users have a contract with Facebook Ireland, and everyone else now has a contract with Facebook Inc (US) - previously everyone had a contract with Facebook Ireland.

[1] https://www.reuters.com/article/us-facebook-privacy-eu-exclu...

1 comments

And that's the companies' out. Make shell companies that exist only in Europe to exfiltrate liability for the multinationals.

There's no real difference in "Facebook US" and "Facebook Ireland". The only difference is this methodology skirts the law.

Hopefully, the EU will climb up these jokes of shell companies and rightly smack them down.