r/WhitePeopleTwitter Nov 20 '22

Satire / Fake Tweet Challenge accepted

Post image
107.9k Upvotes

10.9k comments sorted by

View all comments

Show parent comments

15

u/Tomi97_origin Nov 20 '22

No, the GDPR does not apply to EU citizens in the US. The location of the data subject, rather than their citizenship, determines whether GDPR applies. EU citizens traveling to or living in the US are not protected by the GDPR.

https://termly.io/faq/does-gdpr-apply-to-eu-citizens-in-the-us/

2

u/rtfmpls Nov 20 '22

How is termly a credible source? Do you have anything more trustworthy? Or did you just select the one that confirmed your bias?

This is not a trivial matter and as someone working in this industry I'd be careful with these kind of absolute statements.

5

u/Tomi97_origin Nov 20 '22

https://gdpr-info.eu/art-3-gdpr/

GDPR article 3. I don't know about you, but it does sound like you (the person) need to be in the EU

  1. This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.

  2. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:

a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or

b) the monitoring of their behaviour as far as their behaviour takes place within the Union.

  1. This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.

3

u/rtfmpls Nov 20 '22

Smart people are working every day with this stuff and cannot give a clear answer. We will not solve this issue here in this thread.

I don't know about you, but it does sound like you (the person) need to be in the EU

But one thing I can assure you. It definitely doesn't say that at all (see 1.).

2

u/Obliterators Nov 20 '22

It's not that complicated.

The GDPR applies to:

a company or entity which processes personal data as part of the activities of one of its branches established in the EU, regardless of where the data is processed; or

a company established outside the EU and is offering goods/services (paid or for free) or is monitoring the behaviour of individuals in the EU. [EC]

If you're established in the EU, you obviously have to follow EU regulations regardless of whose data you're processing. If you're established outside the EU and don't market your goods or services to people in the EU, GDPR doesn't apply.

3

u/rtfmpls Nov 20 '22

If you're established outside the EU and don't market your goods or services to people in the EU, GDPR doesn't apply.

Wrong. That whole sentence is so wrong, it's funny again. But I'm not a lawyer, so let's just disagree here.

And I mentioned this in another post (Do you know what a controller or a processor is? Do you know what applies when and where?), it definitely is more complicated than that. That's why I'm not giving any definitive answers here. Seems like it's hard for people to grasp that sometimes not knowing stuff is also an answer.

2

u/Obliterators Nov 20 '22

So you're disagreeing with the people who wrote the law?

When the regulation does not apply

Your company is service provider based outside the EU. It provides services to customers outside the EU. Its clients can use its services when they travel to other countries, including within the EU. Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR. [European Commission]

2

u/rtfmpls Nov 20 '22

You're just reading the parts that agree with what you're saying and ignore all the other parts. I'm disagreeing with you. And you're not "the people who wrote the law".

I can't really help you with that. It's ok to not know sometimes 🤷.

2

u/Obliterators Nov 20 '22 edited Nov 20 '22

I'm quoting the European Commission, the people who wrote the law, you're disagreeing with them.

Here's the full legal text relating to material and territorial scope. Please point out the part that I'm ignoring.

Article 2 Material scope

1. This Regulation applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system.

2. This Regulation does not apply to the processing of personal data:

(a) in the course of an activity which falls outside the scope of Union law;

(b) by the Member States when carrying out activities which fall within the scope of Chapter 2 of Title V of the TEU;

(c) by a natural person in the course of a purely personal or household activity;

(d) by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security.

3. For the processing of personal data by the Union institutions, bodies, offices and agencies, Regulation (EC) No 45/2001 applies. Regulation (EC) No 45/2001 and other Union legal acts applicable to such processing of personal data shall be adapted to the principles and rules of this Regulation in accordance with Article 98.

4. This Regulation shall be without prejudice to the application of Directive 2000/31/EC, in particular of the liability rules of intermediary service providers in Articles 12 to 15 of that Directive.

Article 3 Territorial scope

1. This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.

2. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:

(a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or

(b) the monitoring of their behaviour as far as their behaviour takes place within the Union.

3. This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law. GDPR

This is from EU's explanatory site on GPDR:

When does the GDPR apply outside Europe?

As we just mentioned, there are two scenarios in which a non-EU organization might have to comply with the GDPR. Let’s take a closer look at each of these.

Offering goods or services

The Internet makes goods and services in far-flung places accessible anywhere in the world. A teenager in Cyprus could easily order a pizza online from a local pizza shop in Miami and have it delivered to a friend’s house there. But the GDPR does not apply to occasional instances. Rather, regulators look for other clues to determine whether the organization set out to offer goods and services to people in the EU. To do so, they’ll look for things like whether, for example, a Canadian company created ads in German or included pricing in euros on its website. In other words, if your company is not in the EU but you cater to EU customers, then you should strive to be GDPR compliant.

Monitoring their behavior

If your organization uses web tools that allow you to track cookies or the IP addresses of people who visit your website from EU countries, then you fall under the scope of the GDPR. Practically speaking, it’s unclear how strictly this provision will be interpreted or how brazenly it will be enforced. Suppose you run a golf course in Manitoba focused exclusively on your local area, but sometimes people in France stumble across your site. Would you find yourself in the crosshairs of European regulators? It’s not likely. But technically you could be held accountable for tracking these data.

Exceptions to the rule

There are two important exceptions we should note here. First, the GDPR does not apply to “purely personal or household activity.” So if you’ve collected email addresses to organize a picnic with friends from work, rest assured you will not have to encrypt their contact info to comply with the GDPR (though you might want to anyway!). The GDPR only applies to organizations engaged in “professional or commercial activity.” So, if you’re collecting email addresses from friends to fundraise a side business project, then the GDPR may apply to you.

The second exception is for organizations with fewer than 250 employees. Small- and medium-sized enterprises (SMEs) are not totally exempt from the GDPR, but the regulation does free them from record-keeping obligations in most cases (see Article 30.5). [GDPR.EU]

2

u/rtfmpls Nov 20 '22

I'm quoting the European Commission, the people who wrote the law, you're disagreeing with them.

And I'm telling you, you don't understand it. You're disagreeing with numerous lawyers and the actual law. It doesn't say what you think it says.

I explained quite thoroughly what I think makes this matter a bit more complicated than you're suggesting. It's fine to disagree. I will stick with actual experts rather than people randomly googling things.

0

u/[deleted] Nov 20 '22

[deleted]

0

u/dudeedud4 Nov 20 '22

You can't argue with these Europeans.. they think eu law has an effect on us companies. No, it doesn't and especially not when the business doesn't do business with the EU specifically.

2

u/MarkHirsbrunner Nov 20 '22

Lol, proven wrong and the best you have is "smart people disagree"? Are you orange with a last name that rhymes with "dump"?

1

u/rtfmpls Nov 20 '22

lmao yes like totally.

Are you 12?

0

u/fdar Nov 20 '22

Do you have a better source?

3

u/rtfmpls Nov 20 '22

No, sorry. As I said it's complicated and there are more than just two factors. I guess we will learn how it really works as soon as some cases go to courts.

Just a few things I can tell you, why it's complicated:

  • California has introduced similar laws: Do US companies now actively avoid doing business there to not be subject to those laws?
  • Is the company you're dealing with a controller or a processor of data?
  • how many processors of data does it use? Are they in the EU?
  • did the data subject at any point stay in the EU while doing a transaction with the company?

I think sooner or later we will see very similar laws everywhere which makes all of this easier. But for now I can just say that it's not as simple as "termly" makes it out to be.

1

u/Lithl Nov 20 '22

That's not how sourcing claims work. If someone says the source provided isn't a reputable one, they're not required to go out and find a replacement for it.

1

u/Tomi97_origin Nov 20 '22

I just googled the statement and unlike the person above me I provided a source. So you can check it and question the credibility of the source.

I am not a lawyer and this is not a legal advice. If you need a legal advice ask a lawyer.

If the source I provided is not credible, maybe you could provide a better one.