Hacker News new | ask | show | jobs
by mattlondon 2419 days ago
As far as I understand it, if they are processing EU citizens' data then they are liable for GDPR regardless of where they run their business from.

https://www.techrepublic.com/article/the-eu-general-data-pro...

1 comments

Then I'm curious how do they enforce it. Maybe with US there are some treaties signed, but what about a foreign country that has no treaties with the EU?
To date, the answer to that question appears to be: Sternly worded letters, which will be promptly ignored.

There's no actual enforcement mechanisms against an entity that does not exist in the EU and has no financial exposure to it. That includes with the US, as far as I can tell.

Go for the payment processors - seize any funds destined for the target company, for example.