Threads like this make me like GDPR more and more. Arrogant Americans coming in 'It doesn't have jurisdiction over American companies'. Wholly misinformed.
How do you expect the EU to enforce the GDPR extraterritorially? Like, do you expect the USA to comply with an EU request to impose a fine? Or do you think they'll be successful in pushing enforcement out through the target's customers and vendors, similar to US extraterritorial application of its financial laws on banks? My personal guess is that everyone with shady business models will move offshore, and the EU wil…
>Or do you think they'll be successful in pushing enforcement out through the target's customers and vendors, similar to US extraterritorial application of its financial laws on banks?
At least somewhat of a deterrence. As if American KYC & AML laws are completely ineffective.
>My personal guess is that everyone with shady business models will move offshore, and the EU will play a marginal game of whack-a-mole trying to coerce them through their vendors and customers, especially payment processors, similar to American enforcement of online gambling laws. I expect the GDPR to be effective on large companies that want to portray themselves as respectable, and ineffective on everyone else.
Implying the big companies aren't the ones with the 'shady business models'? My view is that this is specifically made for the big companies.