> where your base of operations is in the EU; where you’re not established in the EU but you offer goods or services (even if the offer is for free) to people in the EU; or
where you’re not established in the EU, but monitor the behavior of people who are in the EU (as long as that behavior takes place in the EU).
Question — IANAL, but I read a summary on a legal website (I’ll see if I can find a link) of GDPR that said it applies to non-EU companies not when you offer services to all people, some of whom might be in the EU, but when you specifically target and advertise to EU citizens. It sounded like a web app, for example, that is marketed generally toward anyone and allows connections from anywhere, would not be legally subject to GDPR, whereas if I, say, localized in German and had a campaign to get German teachers using my app, then GDPR applies.
Aside from whether adhering to GDPR is a good idea anyway, and I think it is, is that distinction correct? Can strict GDPR be avoided if I’m not targeting the EU specifically, and my customers aren’t primarily EU citizens?
EDIT: here's the link: https://ec.europa.eu/info/law/law-topic/data-protection/refo...
Here's the text:
"When the regulation does not apply
Your company is service provider based outside the EU. It provides services to customers outside the EU. Its clients can use its services when they travel to other countries, including within the EU. Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR."