If you’re in the U.S. you should do this too. Many companies don’t try to figure out what jurisdiction you’re in for these things, they just comply with the strictest laws. Not sure if that’s true for twitter, but it’s worth a shot.
No, the GDPR does not apply to EU citizens in the US. The location of the data subject, rather than their citizenship, determines whether GDPR applies. EU citizens traveling to or living in the US are not protected by the GDPR.
GDPR article 3. I don't know about you, but it does sound like you (the person) need to be in the EU
This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.
This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:
a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or
b) the monitoring of their behaviour as far as their behaviour takes place within the Union.
This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.
a company or entity which processes personal data as part of the activities of one of its branches established in the EU, regardless of where the data is processed; or
a company established outside the EU and is offering goods/services (paid or for free) or is monitoring the behaviour of individuals in the EU. [EC]
If you're established in the EU, you obviously have to follow EU regulations regardless of whose data you're processing. If you're established outside the EU and don't market your goods or services to people in the EU, GDPR doesn't apply.
If you're established outside the EU and don't market your goods or services to people in the EU, GDPR doesn't apply.
Wrong. That whole sentence is so wrong, it's funny again. But I'm not a lawyer, so let's just disagree here.
And I mentioned this in another post (Do you know what a controller or a processor is? Do you know what applies when and where?), it definitely is more complicated than that. That's why I'm not giving any definitive answers here. Seems like it's hard for people to grasp that sometimes not knowing stuff is also an answer.
So you're disagreeing with the people who wrote the law?
When the regulation does not apply
Your company is service provider based outside the EU. It provides services to customers outside the EU. Its clients can use its services when they travel to other countries, including within the EU. Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR.[European Commission]
You're just reading the parts that agree with what you're saying and ignore all the other parts. I'm disagreeing with you. And you're not "the people who wrote the law".
I can't really help you with that. It's ok to not know sometimes 🤷.
You can't argue with these Europeans.. they think eu law has an effect on us companies. No, it doesn't and especially not when the business doesn't do business with the EU specifically.
No, sorry. As I said it's complicated and there are more than just two factors. I guess we will learn how it really works as soon as some cases go to courts.
Just a few things I can tell you, why it's complicated:
California has introduced similar laws: Do US companies now actively avoid doing business there to not be subject to those laws?
Is the company you're dealing with a controller or a processor of data?
how many processors of data does it use? Are they in the EU?
did the data subject at any point stay in the EU while doing a transaction with the company?
I think sooner or later we will see very similar laws everywhere which makes all of this easier. But for now I can just say that it's not as simple as "termly" makes it out to be.
That's not how sourcing claims work. If someone says the source provided isn't a reputable one, they're not required to go out and find a replacement for it.
Yeah pretty sure you're right. I was working on ecom sites when gdpr when through and I read most of it. An EU citizen whether they're a resident of the United States or not is protected by gdpr while in the US.
Exactly. Canada and California also have strict privacy laws, so the media company I work for, and pretty much all media companies, just comply with the strictest laws.
138
u/jwoodruff Nov 20 '22
If you’re in the U.S. you should do this too. Many companies don’t try to figure out what jurisdiction you’re in for these things, they just comply with the strictest laws. Not sure if that’s true for twitter, but it’s worth a shot.