That raises some interesting questions. Let's say:
• I run website W. W does not obey EU privacy and data rules, but I, my company, my server, etc., are all outside the EU in places without treaties that would allow enforcement of EU rules against me.
• I sell data from EU citizens who visit W. I sell this data to ad network N that is also outside the EU. (I'm selling N all my visitor data, not just data from EU visitors).
• Company C that is in the EU or sells products in the EU or has a presence in the EU buys ads through N. N uses the data they bought from me to show C's ads to visitors from the EU who visit websites using N's ad network.
Questions:
1. Which of the various entities in this (me, N, C) are violating EU data and privacy laws, according to the EU?
2. Which of those entities could the EU actually enforce a fine against?
3. For those entities that are violating EU laws (according to the EU) but are out of the reach of EU fines, can the EU take alternate action such as ordering EU ISPs to block access to their websites?