Remix.run Logo
qurren 2 hours ago

1. It's also a piece of cake to just not display the cookie banner for non-EU IPs

2. If you are a purely US entity with no actual business presence in the EU, you only need to comply with US laws and nothing else. If the EU doesn't like a purely-foreign website, it's on them to set up a national firewall and block it.

Case in point 1: It's not on you to comply with China's laws, it's on them to block it if they want to

Case in point 2: China's local businesses with no EU presence do not follow GDPR and do not display cookie banners even if accessed from the EU

dgellow 2 hours ago | parent [-]

GDPR applies to EU citizens data. It doesn’t matter where your business is located in the world, if you process European personal data you’re on the hook. Of course you can decide to ignore and argue the EU doesn’t have jurisdiction

qurren 2 hours ago | parent [-]

Exactly, they don't have jurisdiction outside their borders. If you don't have a presence there, they cannot subject you to their laws.

1. When is the last time you saw China enforcing its laws outside their borders? Why would EU be any different?

2. China has laws that are directly contradictory to GDPR laws; you may be required to retain data regardless of consent; if your website is based in China you have to follow local laws first before you follow contradictory foreign laws that have no jurisdiction over you.

frollogaston 11 minutes ago | parent [-]

If you have any presence in the EU, you can be on the hook for EU customers visiting your non-bannered US site.