# SDMB Privacy Update - GDPR?

**URL:** <https://boards.straightdope.com/t/sdmb-privacy-update-gdpr/815788>\
**Category:** About This Message Board\
**Created:** [June 9, 2018, 11:43pm UTC](https://boards.straightdope.com/t/sdmb-privacy-update-gdpr/815788 "2018-06-09T23:43:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Duckster](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/duckster/32/1244_2.png) [@Duckster](https://boards.straightdope.com/u/Duckster)\
**Post date:** [June 9, 2018, 11:43pm UTC](https://boards.straightdope.com/t/sdmb-privacy-update-gdpr/815788/1 "2018-06-09T23:43:19Z")

</div>

With the enforcement of the [General Data Protection Regulation](https://en.wikipedia.org/wiki/General_Data_Protection_Regulation) as of May 23, 2018, is the SDMB going to update its privacy policy for our European Dopers?

> [@](#):
>
> The lead-up to the effective date of the GDPR led to many companies and websites changing their privacy policies and features worldwide in order to comply with its requirements, and providing email and on-site notification of the changes, despite having had at least two years to prepare and do so.
> 
> \<snip\>
> 
> On the effective date, some international websites began to block EU users entirely (including [Instapaper](https://en.wikipedia.org/wiki/Instapaper),[[61]](https://en.wikipedia.org/wiki/General_Data_Protection_Regulation#cite_note-62) [Unroll.me](http://Unroll.me),[[62]](https://en.wikipedia.org/wiki/General_Data_Protection_Regulation#cite_note-63) and [Tronc](https://en.wikipedia.org/wiki/Tronc)-owned newspapers, such as the _[Chicago Tribune](https://en.wikipedia.org/wiki/Chicago_Tribune)_ and the _[Los Angeles Times](https://en.wikipedia.org/wiki/Los_Angeles_Times)_) or redirect them to stripped-down versions of their services (in the case of [National Public Radio](https://en.wikipedia.org/wiki/National_Public_Radio) and _[USA Today](https://en.wikipedia.org/wiki/USA_Today)_) with limited functionality and/or no advertising, in order to remove their liabilities.

4 Steps to Make Your Website GDPR Compliant - [https://www.securitynow.com/author.asp?section\_id=695&doc\_id=740805](https://www.securitynow.com/author.asp?section_id=695&doc_id=740805)

---

<div class="post-metadata">

**Author:** ![Cleophus](https://avatars.discourse-cdn.com/v4/letter/c/a88e57/32.png) [@Cleophus](https://boards.straightdope.com/u/Cleophus)\
**Post date:** [June 10, 2018, 12:13am UTC](https://boards.straightdope.com/t/sdmb-privacy-update-gdpr/815788/2 "2018-06-10T00:13:25Z")

</div>

The SDMB is owned by a US entity and is likely based in a US datacenter, with no EU presence. Would it be subject to EU regulations in the first place? What mechanisms in US law would make the Reader liable to attempted enforcement?

---

<div class="post-metadata">

**Author:** ![Inner\_Stickler](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/inner_stickler/32/318_2.png) [@Inner\_Stickler](https://boards.straightdope.com/u/Inner_Stickler)\
**Post date:** [June 10, 2018, 3:47am UTC](https://boards.straightdope.com/t/sdmb-privacy-update-gdpr/815788/3 "2018-06-10T03:47:57Z")

</div>

According to the [GDPR](https://gdpr-info.eu/art-50-gdpr/):

> [@](#):
>
> (1) In relation to third countries and international organisations, the Commission and supervisory authorities shall take appropriate steps to:
> 
> a) develop international cooperation mechanisms to facilitate the effective enforcement of legislation for the protection of personal data;
> 
> b) provide international mutual assistance in the enforcement of legislation for the protection of personal data, including through notification, complaint referral, investigative assistance and information exchange, subject to appropriate safeguards for the protection of personal data and other fundamental rights and freedoms;
> 
> c) engage relevant stakeholders in discussion and activities aimed at furthering international cooperation in the enforcement of legislation for the protection of personal data;
> 
> d) promote the exchange and documentation of personal data protection legislation and practice, including on jurisdictional conflicts with third countries.

Which suggests to me that they are not bothering themselves to write anything explicit into the GDPR, but instead figure it out if they ever actually decide they need to fine someone and most likely counting on the risk of the fines (20 million euros or 4% of total global turnover whichever is greater) to help companies decide it’s ultimately cheaper to just be compliant.

---

<div class="post-metadata">

**Author:** ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)\
**Post date:** [June 10, 2018, 12:39pm UTC](https://boards.straightdope.com/t/sdmb-privacy-update-gdpr/815788/4 "2018-06-10T12:39:04Z")

</div>

> [@Cleophus](#):
>
> The SDMB is owned by a US entity and is likely based in a US datacenter, with no EU presence. Would it be subject to EU regulations in the first place? What mechanisms in US law would make the Reader liable to attempted enforcement?

The EU doesn’t care one bit where an Internet company is located. If a single person in the EU visits the web site, then the SDMB is subject to their laws.

Going about enforcing their laws on the Reader or whoever is something else entirely.
