Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Arrest when you have a layover in the EU for some reason, on purpose or because of an emergency.

And a default judgement.



Not a chance. The only country that has a history of such actions is the United States.


So if I ignore a law in Canada or the EU (extradition request, default judgement, etc) as an officer of a corporation, I wouldn't get arrested when I show up on the border? Really?


For ignoring the GDPR as a small business owner operating on the internet the chances of individual consequences are nil.

High profile cases would have a much higher risk and companies that went out of their way to advertise the fact that they are going to break the law would run a significant risk.

Show me just one example of a company located outside the EU without a legal presence inside the EU that had an executive detained upon entry for breaking an EU law that does not normally result in criminal prosecution.


Does the EU have any other extra-territoral law as far reaching as the GDPR? Or any other extra-territoral law? A business shipping something to the EU doesn't count.

The only other extra-territorial laws I know of currently is FATCA and the FCPA, which are from the USA.


The GDPR is not an extra-territorial law. It merely concerns itself with EU citizens.


If the law applies outside the EU (for instance, if EU citizens travel to a non-EU country), then it is an extra-territorial law. As far as I understand the discussion here (which may or may not correspond with the actual law), the GDPR goes with the person. Wherever an EU citize goes, that EU citizen must be able to be forgotten, despite if the location they are in is outside EU jurisdiction. That is practically the definition of extra-territorial.

Now, would an EU court rule that someone who kept permanent records of an EU citizen be violating the GDPR if the business has no EU presence? In the American system (imagining if the US passed a GDPR and prosecuted a non-US citizen), no, because the government would not have standing to sue: the violation took place outside of US sovereignty. If the EU takes a similar approach, then the law is not extra-territorial in enforcement, otherwise it is.


EU citizens outside of the EU are out of scope for the GDPR.


Could you point at the language that unambiguously says that?

Edit: GDPR Recital 23, Article 3(2)(a). Excellent!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: