It's unclear to me how the EU would be able to enforce a law on non-EU citizens. Does anyone understand how that would be possible? I know the law technically applies to companies outside of the EU, but how could a US company even be punished?
This is a decent right up the matter:
https://politics.stackexchange.com/questions/30509/how-are-gdpr-fines-actually-enforced-for-us-companies-with-no-physical-presence
If you have EU citizens as your customers (website visitors), you need to comply with the laws. I guess you could simply not allow anybody from the EU region to become your customer and you don't have to comply :D
Right, I understand that I "should" comply (and I am complying just to be safe), I just don't understand how the EU could enforce any law outside of the EU.
I guess technically they are not enforcing it outside of the EU. It's in the EU, meaning that if you product or service is available in the EU, you have to comply.
So the GDPR are laws that define rights for EU residents. That's the problem: not that there's a specific mention saying "these laws apply to any region", but that's implied because an EU resident can visit a US website.
If a non-EU website decides to allow EU visitors -> they need to comply and protect the EU resident's rights.
Much broader question.
Business as usual: start with a warning, demand compliance, fine for non-compliance. If you then never comply, never pay up and don't want to listen to the EU, they can ask the US to enforce their privacy laws.
It's very unlikely that the US would choose to ignore one of the EU's most important data privacy laws and compromise their ties just for the sake of letting a company abuse data privacy.
Cross-country/nation enforcement isn't a new thing, it happens all the time.