Comment by kuu

5 years ago

I understand it as: if you're taking my data as European citizen, that is protected; even if you're in the US I'm still European.

That’s incorrect. What matters is where you are, not whether you’re an EU citizen.

If an EU citizen accesses a site from inside the USA, the GPDR does not apply. That’s also why these sites can use geo-blocking without knowing who accesses their site (for some definition of ‘can’. Technically they can’t because geo-blocking can’t be perfect. If you access a site from the EU through a VPN in the USA, the GDPR still applies)