What is the deal with the GDPR vis-a-vis US companies? If we have a company incorporated solely in the USA that has web content that violates the GDPR but shows a popup and states in its ToU that the website is not to be used by any person or entity in countries that follow the GDPR, can our company be fined under the GDPR? In other words, do GDPR countries claim jurisdiction over non-GDPR countries' websites?
Oddly enough, the disclaimer might actually increase the chance that you're subject to GDPR. The relevant part of GDPR is Article 3, and Recital 23 (full law text in the links below--read them, they're short!). GDPR applies to a non-EU website that "envisages offering services to data subjects" in the EU. Recital 23 explicitly says that a website merely being available does not count. Offering localized content (e.g.…
Intent to issue €2.5M fine to Disqus over GDPR breaches
31–40 of 123 posts
Re: Intent to issue €2.5M fine to Disqus over GDPR breaches
#32That meant that websites that had enabled a specific setting ("Enable anonymous cookie targeting") in Disqus were tracking Norwegian without informing them. Most of the websites in Norway and elsewhere did not know they were sharing users data through Disqus.
Major sites like the Wirecutter, The Hill, 9to5mac, Breitbart had enabled the setting in 2019. Of the 23 websites I contacted, all 11 that responded told me they were unaware of the tracking and had turned the setting off.
(I wrote the investigative articles in 2019 for the Norwegian public broadcaster NRK.)
A thread in English from then explains most of the findings: https://twitter.com/martingund/status/1207327648093003777
Re: Intent to issue €2.5M fine to Disqus over GDPR breaches
#33What is the deal with the GDPR vis-a-vis US companies? If we have a company incorporated solely in the USA that has web content that violates the GDPR but shows a popup and states in its ToU that the website is not to be used by any person or entity in countries that follow the GDPR, can our company be fined under the GDPR? In other words, do GDPR countries claim jurisdiction over non-GDPR countries' websites?
Yes. Any EU citizen in our out of country has their PII protected by EU law, regardless of who processes that data. A pop-up or ToU would not skirt the visitors rights, regardless of what the message said and regardless of the action the user took as a result of the message
That's a common misconception. GDPR applies to "data subjects who are in the Union". Whether or not the data subjects are EU citizens is irrelevant.
It also applies to all data processing of processors or controllers who are in the Union, regardless of where the processing takes place or whose data is being processed.
For processors or controllers not in the Union processing data of a subject in the Union it applies if (1) the processing is related to the offering of goods or services in the Union, or (2) the monitoring of behavior that takes place within the Union.
Some examples:
If I, a US citizen who has never set foot outside the US, has some interaction with a German company then GDPR applies. The German company is in the Union so it applies to all their data subjects regardless of citizenship or location.
If a French citizen comes to the US and some local US business gathers all kinds of personal information about them GDPR does not apply. The data subject is not in the Union and the processing is not being done by an entity in the Union, so no GDPR.
Re: Intent to issue €2.5M fine to Disqus over GDPR breaches
#34Earlier quoted context omitted.
On the other hand, geoblocking e.g. by ip address (and then completely not letting EU visitors access the website) would probably work, but somehow most companies don't want to do that.
What if I (as a European visitor) access the website through a VPN, something I'm legally allowed to do?
It doesn't have to be bulletproof, it just has to support the claim.
Re: Intent to issue €2.5M fine to Disqus over GDPR breaches
#35What is the deal with the GDPR vis-a-vis US companies? If we have a company incorporated solely in the USA that has web content that violates the GDPR but shows a popup and states in its ToU that the website is not to be used by any person or entity in countries that follow the GDPR, can our company be fined under the GDPR? In other words, do GDPR countries claim jurisdiction over non-GDPR countries' websites?
Yes. Any EU citizen in our out of country has their PII protected by EU law, regardless of who processes that data. A pop-up or ToU would not skirt the visitors rights, regardless of what the message said and regardless of the action the user took as a result of the message
No, that's wrong.
First of all, the GDPR does not take in to consideration citizenship, at all. The Regulation targets location rather than nationality. In other words, if either the data subject or data controller are in the EU/EEA then the GDPR applies, even if the other party is not in the EU/EEA (The UK GDPR is the same, but replace "EU/EEA" with "UK").
Secondly, the GDPR regulates the use of Personal Data, not PII. PII is a US legal term and has multiple definitions. Personal data is a broader concept than PII.
Re: Intent to issue €2.5M fine to Disqus over GDPR breaches
#36"Norwegian internet users were tracked by Disqus because the company did not know that Norway introduced the common European privacy regulation GDPR in 2018. It thus took 511 days before Norwegians were incorporated into the company's "privacy mode" for GDPR countries and previously collected information was deleted."[0] It seems that there was some setting that is enabled by default in all other countries than count…
Re: Intent to issue €2.5M fine to Disqus over GDPR breaches
#37What is the deal with the GDPR vis-a-vis US companies? If we have a company incorporated solely in the USA that has web content that violates the GDPR but shows a popup and states in its ToU that the website is not to be used by any person or entity in countries that follow the GDPR, can our company be fined under the GDPR? In other words, do GDPR countries claim jurisdiction over non-GDPR countries' websites?
If you are transparent about what tracking you do and don't do stuff that people don't want, all that's left is including some boilerplate text like "you have rights X, Y and Z and you can contact us at our@email" and you're GDPR compliant.
To me at least, 95% of GDPR compliance is just acting ethically.
Re: Intent to issue €2.5M fine to Disqus over GDPR breaches
#38From the link "We consider the infringements to be serious. Disqus has tracked which news sites and articles readers in Norway have visited. Additionally, this has happened without the users’ knowledge." Based on that statement a lot will follow.
Not so long ago I stumbled on https://data.disqus.com , which basically outlines what they were fined for. They should probably take that site down soon...
Re: Intent to issue €2.5M fine to Disqus over GDPR breaches
#39What is the deal with the GDPR vis-a-vis US companies? If we have a company incorporated solely in the USA that has web content that violates the GDPR but shows a popup and states in its ToU that the website is not to be used by any person or entity in countries that follow the GDPR, can our company be fined under the GDPR? In other words, do GDPR countries claim jurisdiction over non-GDPR countries' websites?
It's not that uncommon. As a concrete example, I know that US expats in Germany are having problems with some banks because FATCA[1], a US law, imposes more controls over every bank in the world dealing with US citizens. At least one German bank [2] has stopped taking US citizens as customers, and I have informally heard of more.
[1] https://en.wikipedia.org/wiki/Foreign_Account_Tax_Compliance...
[2] https://americanexpatfinance.com/news/item/612-german-bank-t...
Re: Intent to issue €2.5M fine to Disqus over GDPR breaches
#40Earlier quoted context omitted.
We part of the European Economic Area (EEA) which is quite close to being a EU member, but without voting rights. Norway voted two times on membership and the compromise was EEA.
To add to this: almost all EU regulations and rights – except those pertaining to agriculture and fisheries – apply to the whole of the EEA, meaning all of the EU + Norway, Iceland and Liechtenstein (in addition, many also apply to Switzerland, but in that case through a complicated set of bilateral Swiss-EU agreements that sorta-kinda emulate EEA membership, but isn't).
Some documentaries even call it the worlds most toxic food.