Forget all the stuff out there that says the GDPR protects EU citizens. This is a question of jurisdiction and enforcement. Say I run a blog under a business registered in the US funded by advertisers in the US. A EU citizen that comments on posts issues a GDPR request that I ignore. Their government fines me. I tell them to get bent, I am out of their jurisdiction. What can they do at that point?

  • FlowVoid@kbin.social
    link
    fedilink
    arrow-up
    2
    ·
    1 year ago

    This is a good article on whether non-EU websites have to obey the GDPR. It boils down to two criteria:

    If your business is offering goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the EU

    or

    If your business monitors the behavior of EU citizens and their behavior takes place within the union.

    The latter includes use of advertising cookies, location tracking, etc.

    If neither of those apply, you can probably ignore the GDPR.