|
|
|
|
|
by Daho0n
1961 days ago
|
|
This gets repeated over and over on HN but it isn't true. I feel this is because so many try to make GDPR seem too hard and breaking everything (likely people with something to lose). GDPR is for data in the EU. That is it. Not data outside the EU and not people outside the EU. An American in the EU is covered, an EU citizen in the US is not. What you are saying would require that the EU could create laws that were above the Supreme Court in the US for example. It simply isn't true. |
|
Or people who wish to extend the reach of GDPR so that others outside of the EU are protected too.
> What you are saying would require that the EU could create laws that were above the Supreme Court in the US for example
This is not true for multiple reasons. Check out https://en.wikipedia.org/wiki/PROTECT_Act_of_2003 specifically "Authorizes fines and/or imprisonment for up to 30 years for U.S. citizens or residents who engage in illicit sexual conduct abroad". The EU could punish US companies that have offices in the EU or income from the EU. Alternatively it could sanction them.