Earlier quoted context omitted.
+1 for fair user treatment, but the way the laws are written, companies that serve users globally from within the EU will have a hard time competing with their international competitors under the new regulation. I just wonder if European law makers have thought this through.
I think in the current situation, having strong privacy for all users will be a feature you can bring to the market, especially for US users it can be a big plus since the US doesn't have any comparable privacy law.
2018 reform of EU data protection rules
61–70 of 150 posts
Re: 2018 reform of EU data protection rules
#62Edit: Especially in the context of a company that does not handle/store customer data, but only employee info.
Re: 2018 reform of EU data protection rules
#63Enforcement factsheet: https://ec.europa.eu/commission/sites/beta-political/files/d... Pretty clearly primarily enforced by national regulatory agencies, who are the only ones who can apply fines . It mentions citizens taking companies to court, but https://ec.europa.eu/commission/sites/beta-political/files/d... says that's for monetary damages, not for fines. This is unchanged from previous laws. Can people stop fre…
In Germany offenses against the GDPR can cause a "Abmahnung" which do not result in a fine but a charge. There a legions of filthy lawyers waiting for the 25.5.
Re: 2018 reform of EU data protection rules
#64Earlier quoted context omitted.
You're not wrong, but, what internet company doesn't operate within the EU? If you operate in the EU, and handle EU citizen's data, you have to conform to the GDPR. I don't think there's many internet companies that would not serve the EU because of it. Although, Google did pull out of China due to the censorship demands and the like.
Hmm. You just agreed with me and then disagreed me :) Again, I say this as someone who is implementing GDPR for a US-based company, and is also a EU citizen (Irish) and has sat more meetings with various legal groups than I care to remember (again, stress I'm not a lawyer). It is all about a companies appetite for risk and how tied the are __PHYSICALLY__ to the EU (offices/employees/parent-companies/subsidiaries). Th…
BTW it's important to understand the real enforcement vector here. It's not like you'll have "EU cops" knocking on doors in America. Nor will anybody waiting for you to get off the plane in Germany. (I've actually seen this nonsense on HN in recent days.) The very real power they do have is over banks and payment processors. It's quite possible that if you're doing business with EU customers and you have bank accounts in EU or work with EU banks or EU payment processors then they'll be able to exert significant leverage against your business. But if you have no direct contact with the EU financial system and your website is hosted in the US in English (or even if it's in French but it's clear you're pursuing US customers) there's little they could do to you even if they wanted to.
Re: 2018 reform of EU data protection rules
#65This guide does not clarify one important question: Does a company in the EU have to apply gdpr guidelines for none European users. If so, this would be a significant disadvantage for all European companies since their none European competitors obviously only have to comply for European users. One scenario in which this would be very relevant: A website needs to show a very long consent form to users that want to use…
> This guide does not clarify one important question: Does a company in the EU have to apply gdpr guidelines for none European users. Yes, the GDRP applies to anyone "in the Union". Someone on vacation from the US would be covered _while they are in the EU_. If your company is based in the EU, then you must comply for all users, regardless of their current country or citizenship.
Re: 2018 reform of EU data protection rules
#66First, I am not a lawyer. I don't even play one on TV. The big question I keep hearing is; I'm in the US (or other non-EU country), does GDPR apply to my company or organization? The shortest possible answer is: Maybe :) The answer is: YES if your company has a physical or legal presence (like an office, employee, parent-company, subsidiary, etc.) in an EU country. The GDPR applies to you and you need to to start rea…
Re: 2018 reform of EU data protection rules
#67This guide does not clarify one important question: Does a company in the EU have to apply gdpr guidelines for none European users. If so, this would be a significant disadvantage for all European companies since their none European competitors obviously only have to comply for European users. One scenario in which this would be very relevant: A website needs to show a very long consent form to users that want to use…
For a long time already, it's been common practice to avoid Chinese services, because of the surveillance that the Chinese government does. And there's a growing number of people who avoid US-based services, too. The recent CLOUD Act certainly doesn't weakening their position either.
Re: 2018 reform of EU data protection rules
#68Earlier quoted context omitted.
Maybe if you don't have ads on your site, otherwise its going to be a problem.
Why do you think so? After you document/publish what information you pass to which network, what problems do you expect related to the ads?
I'm not doing anything shady: all the information I collect and why I collect it has always been in my privacy policy. But making people have to opt-in to see ads on the site is a big problem.
Re: 2018 reform of EU data protection rules
#69First, I am not a lawyer. I don't even play one on TV. The big question I keep hearing is; I'm in the US (or other non-EU country), does GDPR apply to my company or organization? The shortest possible answer is: Maybe :) The answer is: YES if your company has a physical or legal presence (like an office, employee, parent-company, subsidiary, etc.) in an EU country. The GDPR applies to you and you need to to start rea…
They explicitly contradict you. https://ec.europa.eu/info/law/law-topic/data-protection/refo... The law applies to... 2. a company established outside the EU offering goods/services (paid or for free) or monitoring the behaviour of individuals in the EU. Do you have any evidence? You're doing business with EU citizens. You allow them to connect to your site. Wouldn't this operate similarly to how extradition by the U…
"Whereas the mere accessibility of the controller's, processor's or an intermediary's website in the Union, of an email address or of other contact details, [...], is insufficient to ascertain such intention, [...]" (https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...)
Re: 2018 reform of EU data protection rules
#70First, I am not a lawyer. I don't even play one on TV. The big question I keep hearing is; I'm in the US (or other non-EU country), does GDPR apply to my company or organization? The shortest possible answer is: Maybe :) The answer is: YES if your company has a physical or legal presence (like an office, employee, parent-company, subsidiary, etc.) in an EU country. The GDPR applies to you and you need to to start rea…