To be eligible for things like a GDPR Data deletion request etc, is it enough that I am a citizen or must I be a resident? ty :)

  • inlandempire@jlai.lu
    link
    fedilink
    arrow-up
    38
    ·
    edit-2
    11 months ago

    Not sure if it helps but :

    GDPR Article 3 - Territorial scope

    1. This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.
    1. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:

    (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or

    (b) the monitoring of their behaviour as far as their behaviour takes place within the Union.

    1. This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.

    From what I understand, it doesn’t really matter where or who you are, it’s about whoever collects your data doing business in the EU. BUT ALSO if you are an EU citizen, it also applies to non EU companies (someone correct me if I’m wrong)

  • Cheesus@lemmy.ca
    link
    fedilink
    arrow-up
    37
    ·
    11 months ago

    Mildly on topic: I recently moved to France from Canada, I’m not an EU citizen, and google isn’t really sure if I’m on vacation or if I’ve moved permanently.

    Every single website now asks me about cookie settings. Most have a reject all button, but occasionally I have to manually uncheck some sliders to protect my data. Time well spent.

    My parents back in Canada always think it’s some voodoo magic when Facebook shows them ads about stuff they’ve recently been 'talking about (AKA searching on Google.) Duhhh. Thanks EU!

    • Pantherina@feddit.de
      link
      fedilink
      arrow-up
      2
      ·
      11 months ago

      In the EU it is illegal to save unnecessary Cookies without active consent. So the best you can do for your privacy is use Ublock origin with a cookiebanner list!

      But this should only be for EU I guess

    • PupBiru@kbin.social
      link
      fedilink
      arrow-up
      8
      ·
      11 months ago

      only sort of correct: the GDPR applies globally (see this comment: https://jlai.lu/comment/4089576), however if you don’t ever plan on visiting or doing business in the EU it’s probably one of those things that people would ignore because it’d be too difficult/impossible for the EU to actually follow up on

      • anti-idpol action@programming.dev
        link
        fedilink
        arrow-up
        2
        ·
        edit-2
        11 months ago

        off-topic but also the reason why people in the US need to use TOR to look up anything health related that isn’t on wikipedia, because the insane amount of data from tracking on the health websites hosted in the States are then sold to insurers and hence these websites are often not available in the EU because they aren’t GDPR-compliant. fucking dystopian

  • fiat_lux@kbin.social
    link
    fedilink
    arrow-up
    5
    ·
    11 months ago

    Legal advice given to me by an employer treated all citizens as eligible. Their advice tends to err on the side of caution at the best of times, but I have no reason to disagree that it’s at the very least legally contentious even if not yet officially contested.

    Tl;dr I wouldn’t want to rely on it in court, whether everyone else is happy to risk that is whatever.

  • just_another_person@lemmy.world
    link
    fedilink
    arrow-up
    7
    arrow-down
    10
    ·
    11 months ago

    GDPR can only extend to their borders, the same that any country’s laws extend to theirs. Why would you expect another country to honor your “home rules”?

    • driving_crooner@lemmy.eco.br
      link
      fedilink
      arrow-up
      7
      ·
      11 months ago

      It does. When GDPR was about to be placed in effect, the company I worked for in Brazil, send a communication to all our clients saying that they needed to communicate us if they were in Europe for us to process their claims (life insurance) with a third party European partner because the Brazilian office would not be able to comply with European regulations and the company would not even going to answer emails from clients located there. Eventually Brazil made their own data protection laws based on the European one and the company re opened contact with their clients located there.

    • MudMan@kbin.social
      link
      fedilink
      arrow-up
      6
      arrow-down
      1
      ·
      11 months ago

      Borders on the Internet get weird. Effectively, as quoted above, GDPR applies if you do business in the EU even if you aren’t there. Things are murkier if you’re not in the EU when the data gathering takes place and the operator is outside as well, though.

      Also, not technically a country.