|
|
|
|
|
by jiveturkey
2356 days ago
|
|
Well Travelex is a gigantic company, well-run (business-wise if not infosec-wise :P) and would comply with any imposed fines etc. But your question is interesting. Imagine an onion service, theoretically perfectly shielded, that took Personal Data from it users and then sold it. Or even a normal Internet service, based in North Korea. GDPR would be unenforceable. Ultimately we depend on the norms of international agreements, the desire and need to interoperate with global banking systems, etc. |
|
The GDPR text basically says "we'll ask other countries nicely and negotiate with them".
I'll be interested to see how the first real case goes against even a US-based entity that doesn't operate in the EU, much less one based in a country like North Korea.