you are viewing a single comment's thread
view the rest of the comments
[–] 10 points 3 months ago (1 child)

they must first comply with the Patriot Act, the FISA amendment Act, and the Cloud Act, because they are in the same jurisdiction as them... then, maybe the EU GDPR. in that order. always.

  • source
  • parent
  • hideshow 2 child comments
  • [+] 1 point 3 months ago (2 children)
  • [–] 5 points 3 months ago

    well it's standard "hierarchy of norms" theory of the law, when regulations of different nature piling up...

    Also Patriot, FISA-A, and Cloud acts all pretend to be justified by "national security" which times and times again has been considered in the US be a higher imperative in the hierarchy of the norms (in many cases justifying to even bypass the constitution when it comes to spying on US citizens, etc.).

    Whichever way you look at it: the NSA and the CIA (and countless other agencies) who have been granted unlimited, unregulated, untraceable access to all data processed by any US company are not subjected to the EU GDPR.

  • source
  • parent