Earlier quoted context omitted.
> Nobody is touching other countries' servers. Not even close. No one claimed otherwise. It's still fascinating (and, I believe, a first) that the EU thinks they have extraterritorial jurisdiction just because their citizens are affected.
It's not extraterritorial. If an international company wants to sell goods or services in a country, it must abide by the country's laws.
If I want to sell data in the EU, I can. I'm not subject to their laws unless I have a presence there.
GDPR tries to change that.
See https://www2.deloitte.com/ch/en/pages/risk/articles/gdpr-ext...