This article is really confusing. Basically the point is that under the current terms of service they tell you that if you are outside of the US then you are doing business with their Ireland office. Since the Ireland office is in the EU, it is subject to the GDPR. So that means that everybody outside of the US will be covered by the GDPR (because they are doing business with an EU company). They are changing their t…
Not contradicting, worth pointing out for the Americans in the audience: even if you have an exclusively US-based company, working with any EU users means you are in scope for GDPR. The consequences for violating GDPR are quite severe -- up to 20 million euro, or 4% of global turnover, whichever is greater . Again, this applies to US companies even if it's a single record of EU personal data. Furthermore, individuals…
If you are a non-EU company and you don’t have any legal entities in the EU even if you deal with EU customers (retail) the application of GDPR isn’t going to be relevant at least initially.
(The fear for example is that PayPal etc. will force you to comply in the usually blind and deaf PayPal manner for fear of EU retaliation)
If you are a non-EU company with no legal entities in the EU but you are dealing with EU companies and process data for them those companies would have to ensure you are compliant this is a purely B2B route.
If you are a non-EU company with EU legal entities this is the vector the DPAs will use to go after you.
The GDPR is currently in a retarded state with near zero official guidance and definition for things that matter. And as far as non-EU companies go GDPR is well in a though spot. GDPR does not trump lawful data retention and data access requirements in the EU those fall under then final jurisdiction of the high court but there is no way for them to influence non-EU law.
And SOX is a terrible example SOX affects a tiny portion of companies and those who need to comply are huge and there are clear definitions, requirements and arbitration channels which the GDPR lacks.
P.S. we’re talking so far about the periphery of the EU, Canada, Australia The US etc... when you’ll find a way to make Alibaba and China at al comply let me know please.