>But the EU only enforces that for transactions involving EU citizens. If you want to grab all the data from US visitors, go for it, the EU will not complain (as long as you don't do it to EU visitors).
>your company processes personal data and is based in the EU, regardless of where the actual data processing takes place
>your company is established outside the EU but processes personal data in relation to the offering of goods or services to individuals in the EU, or monitors the behaviour of individuals within the EU
Notice how they emphasized EU citizens? Yeah, neither did I.
Reading over the post I realize they meant that companies in the U.S need to handle EU citizens data properly but they can do what they want with U.S citizens data, which I misunderstood so my apologies on the misunderstanding.
which of course is not an exactly correct understanding - no American company without holdings in Europe needs to worry about what they do with their websites accessed by European citizens.
The don't emphasize citizenship because it is enough to live in the EU for the law to apply, i.e. immigrants etc. are included.
If you look into the actual GDPR, you will find the phrase "data subjects who are in the Union", which are "natural persons", for whom the data protection laws apply.
>you will find the phrase "data subjects who are in the Union", which are "natural persons", for whom the data protection laws apply.
tourists who are in the union also apply, there is no idea that you can figure out if that person is just traveling through the EU for some months you can do what you want with them.
>Data subjects in the Union means any person in the Union whose information is being collected at that moment, regardless of their nationality or legal status. That means EU citizens and residents are squarely in scope. And someone in the EU, even a US tourist using an app in the EU, is a data subject in the Union for purposes of the GDPR.
on edit: if you were just clarifying/backing up my original point, sorry, I thought it seemed you were going with interpretation of the person who I was replying to an EU company can do what they want with any U.S citizen's data.
https://europa.eu/youreurope/business/dealing-with-customers...
>The GDPR applies if:
>your company processes personal data and is based in the EU, regardless of where the actual data processing takes place
>your company is established outside the EU but processes personal data in relation to the offering of goods or services to individuals in the EU, or monitors the behaviour of individuals within the EU
Notice how they emphasized EU citizens? Yeah, neither did I.