Skip to content

Comment on UK to overhaul privacy rules in post-Brexit departure from GDPRparent

Comments

Unless you ban EU citizens visiting your website and your website doesn't make business with other businesses in EU.

You can simply break the law and ignore the EU. The cookie popup sanctions are not criminal and unless you are very high profile business, nobody cares about you. Nobody is going to come after you.

The only regulator that international developers need to worry is the SEC from United States, because they pursue for US victims cross border. But the get on the bad side of the SEC you need to do something really stupid.

The maximum fines for breaking the GDPR is up to 4% of your global turn over. If it gets to that they can seize any assets in the EU, including any revenue earned in the EU up to the amount of the fine. Potentially directors can attract criminal risk by refusing to pay the fine(s), leading to an international arrest warrant. Obviously this is the most extreme case, but it is generally is easier to just comply with the law like a reasonable person.

Nobody is going to come after you.

You should doubt this.

I filed several complaints with unauthorized newsletters and failing to comply to my GDPR requests. German officials went after the companies and asked them to provide the necessary information. For sure it took its time but it worked and for the companies it's been a warning shot.

But you know that with asking the right questions you are able to receive evidence that the company is committing a criminal offense.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.