The businesses who care about taking money from Europeans care. I worked at an American healthtech company and we weren’t GDPR-compliant because 1) we weren’t targeting Europeans, and 2) GDPR and HIPAA are incompatible so we picked the relevant one.
Since my server doesn’t do business in EU, I couldn’t care less about GDPR or other local laws, even the ones I think are good ideas.
American law doesn’t apply to someone running a server in Brussels. The converse is also true.
Which rules it out almost entirely for HIPAA covered entities. Quick example: right to be forgotten vs record retention laws. A European who receives healthcare in the US can’t demand that the provider delete their medical record afterward because HIPAA says they must retain it.
> Quick example: right to be forgotten vs record retention laws.
Record retention laws win, as explicitly stated in the GDPR.
Same reason a murderer can't (successfully) issue a right-to-be-forgotten request to the cops investigating them.
(There's also "processing is necessary for the purposes of the legitimate interests pursued by the controller" as another exception, which allows, for example, your bank to retain the fact that you owe them $100k on your house still, even if you don't want them to.)
Record retention laws are not the only exception. E.g. you can execute your Hausverbot right only if the person you refuse to serve cannot demand that you forget them. This position was already confirmed by German regulator at least once.
And they couldn't demand that the provider deletes it in EU either, because maintaining medical records is a legal requirement, which overrides the right to be forgotten.
But it does require you to document that requirement and make sure that the data isn't shared beyond that requirement without consent.
HIPAA and GDPR aren't conflicting, they're orthogonal and cover different things.
The right to be forgotten has an explicit exception for circumstances where there's a legal obligation on retention, although it does reference Union and Member State law and not other international entites.
https://gdpr-info.eu/art-17-gdpr/
A European who receives healthcare in the EU can’t demand that the provider delete their medical record if the provider has a legal allowed reason to keep the record.
This is a fundamental aspect of GDPR and part of the central message in the regulation. Companies and organizations are only allowed to keep personal information if they have a legal allowed reason to do so, and must honor requests for deletions unless they have a legal reason not to do so.
What is and what isn't a legit reason depend on circumstance. What companies generally object with GDPR is that generate revenue through personal advertisement is not an legit reason to keep personal data.
Since my server doesn’t do business in EU, I couldn’t care less about GDPR or other local laws, even the ones I think are good ideas.
American law doesn’t apply to someone running a server in Brussels. The converse is also true.