They obviously don’t have a valid claim to be able to tell everyone who wants to put a website on the internet that they have to do it the EU way, which is what we’re actually talking about.
I’ve got a bunch of sites that can be viewed from (checks notes) the internet. If people in Europe don’t like that, they can block it, or choose not to visit it. In the meantime, you’ve proven exactly what I first said, which is that they are claiming it applies worldwide. Here I am, just putting a site on the internet, and you’re telling me I have to follow EU laws concerning it. Nope. I don’t.
Oh, yeah, no. I’m not providing my webpage in the EU. I’m providing it on the internet.
I let people create accounts, so there might be some personal data. Depends on what the GDPR considers personal. I have no idea. Couldn’t care less.
I’m not demanding anything. Like I said, I put my site on the internet. If the EU doesn’t like my site, they can block it. I’m not demanding they allow my site in the EU.
In the meantime, you are trying to convince me I’m prohibited me from putting a site on the internet unless I’m willing to figure out GDPR’s requirements.
No they don’t. The GDPR is location scoped so the data of an EU citizen given to an hotel while on vacation in the US isn’t protected by GDPR but the data of an US citizen giving their data to a hotel in the EU while on vacation is.
That is my understanding as well. Not a lawyer but recently looked into it since we have US, EU, and non-EU European employees and we were looking at token usage tracking tools (which would appear to potentially fall under employee surveillance or at the very least require explicit consent)
Not sure the exact legalese but legal put together a consent form for anyone wanting to do the PoC