Forget all the stuff out there that says the GDPR protects EU citizens. This is a question of jurisdiction and enforcement. Say I run a blog under a business registered in the US funded by advertisers in the US. A EU citizen that comments on posts issues a GDPR request that I ignore. Their government fines me. I tell them to get bent, I am out of their jurisdiction. What can they do at that point?

  • FlowVoid@kbin.social
    link
    fedilink
    arrow-up
    1
    ·
    2 years ago

    Incorrect.

    The current data agreement between the US and EU is neither a law nor a treaty. It is an executive order, which means it did not pass through Congress and simply reflects the policy of the current administration. Like any other executive order, it could be ignored or overturned by a subsequent administration.

    Furthermore, it does not mean “GDPR is actually the law in the US”. It means that the current US administration will cooperate in enforcing certain privacy rights against US law enforcement and the intelligence community. It does not give EU citizens the same rights they have in the EU under the GDPR. For example, it does not allow private individuals to sue US companies for damages in US courts.