I've been hit with a whole bunch of work this month figuring out my companies VAT bill (VAT MOSS issues). On top of that I just realised that this whole SCA thing applies to European businesses only. Not only is SCA a pain in the butt to implement but it could also make an impact on my bottom line.
Being based in the US I wouldn't have had to do any of this.
When is enough, enough?
Noticed more and more founders moving their businesses to Singapore. Definitely starting to feel like this is something to seriously look into.
Agreed. EU is a clusterfuck of regulations. I moved my company to HK and moved myself to escape this.
Such a simple action as taking money from your customer, is so complicated... every country have their own tax laws that one needs to know.
Moving HK would not stop the SCA requirements and etc which you need to follow if you want to charge a EU customer anything. And VAT shouldnt be that big of problem, all you need to do is first register with your tax authority to get VATMOSS. And second, track if your customer is VAT-reqistered and from which country they are from. And lastly, send the information to your tax authority and pay the required tax.
I am curious about HK. I read tha costs of living are really high, do you need to be a resident to move your country? What's the tax rate and the VAT?
Yeah, HK is quite expensive. I just registered my company there, but reside in Thailand.
SCA is a bit of a pain for subscription products but Stripe have made it very easy. Still, it’s been a pain in the ass for me this week 😃
Haha I'm tackling it this week too. I wouldn't call it easy though (you're probably just a much better dev than me! ha).
Are you doing it for subscriptions or one-off payments?
Both :)
EU is a nightmare for business, but VAT isn't the worst problem.
Taxation and VAT levels are, on average, insane. I am lucky enough to be Italian too, the country with the highest tax burden in the entire European Union and one of the highest in the world.
I am looking to move my businesses outside of the EU. I am evaluating Singapore and Taiwan at the moment, but I am open to any suggestion.
It's frustrating because I would much rather pay company tax to the country I live in. But it's getting beyond ridiculous and who know's what else is round the corner...
You can exactly do that, first regster VATMOSS after that track your customers VAT-status and where they are from. Then all you need to do is send that information to your tax authority and pay the tax.
Feel the same way. I have a little IOT business, so import tax and VAT impacts us a lot. Just moved from Australia, where import GST was 10%, back to the UK, where import VAT is 20%.
I feel like a lot of people take the good that businesses bring to a country for granted and aren't worried about managing/encouraging the incentives of carrying out such an undertaking.
On a slight tangent:
Traveling in the EU at the moment. Their cookie policy has made using the internet from a small mobile device a giant pain.
The UX is entirely in the hands of the company's websites you're visiting. GDPR laws are for the companies to let the users know about what kind of data the company is tracking.
Is there a solution for which generates GDPR privacy policy for you?
I know a solution that helps ;) been working on privacy policies for 6.5y now https://www.iubenda.com. p.s. I'm not following the term, I just came here to see what other people think about good old European law.
Do you vote? Can you write to your representatives or start a petition? You might find a lot of others who share your experiences.
Yeah I agree this is very annoying. Though afaik the SCA implementation applies to anyone charging EU customers, also non EU companies.
I thought this as well originally. However Stripe says:
"For online card payments, these requirements will apply to transactions where both the business and the cardholder’s bank are located in the European Economic Area (EEA). "
It's quite confusing, but I believe SCA is required for anyone with EU customers. From https://stripe.com/docs/strong-customer-authentication
*Your business is based in the European Economic Area (EEA) or you create payments on behalf of connected accounts based in the EEA
*You serve customers in the EEA <--- This one
*You accept cards (credit or debit)
Incorrect (I think). We're a bunch of intelligent people on here. Just goes to show how confusing this all is. Here's the whole statement you quoted:
"Prepare for SCA and update your Stripe integration if all of the following apply:
-Your business is based in the European Economic Area (EEA) or you create payments on behalf of connected accounts based in the EEA
-You serve customers in the EEA
-You accept cards (credit or debit)"
Importantly, it says if ALL of the following apply. Therefore it is only EU -> EU.
I think you're right. I thought I fell under this due to the OR clause of the first point "or you create payments on behalf of connected accounts based in the EEA" plus points 2 and 3, but after re-reading it 10 or so times I don't think it applies to me anymore. I'll need to do some more Googling.
Yes, as an entrepreneur I sometimes envy US founders for their lack of GDPR, easier VAT handling and several other things that make business life less cumbersome. But as a consumer and citizen I highly appreciate what the EU is doing.
VAT is handled by payment providers for a really small rate. I'm using Paddle, but Fastspring and Gumroad seem to offer the same thing. For that reason, I had not contact with SCA so far. And don't forget that the EU is doing a lot to harmonize 28 different markets. Without the EU it would be way more complicated to do business in all of those countries.
GDPR is not something that US companies don't have to comply with. Everyone serving EU customers has to comply. That's why some sites just blocked EU visitors when GDPR came into affect.
Same goes for a lot of other EU regulations.
Consider this common scenario:
A German goes to China and signs up for an account on WeChat which, due to local law, cannot legally comply with GDPR.
How the heck does the EU enforce its regulations outside its jurisdiction? It doesn't. Neither can the US, China, India, Russia or any other country, even a large country, enforce laws dictating how EU companies collect and share data about their citizens within the EU's jurisdiction.
This kind of thing generally works through treaties.
I'm still waiting to see what happens when they try to enforce against a US company.
I'm getting the feeling it will be a "laughs in american" situation
Will certainly be interesting!
They already have attempted it: https://www.theguardian.com/business/2019/jul/09/marriott-fined-over-gdpr-breach-ico
Marriott are appealing so it's not over yet, we'll have to wait and see how this kind of thing will be resolved.
This is really interesting!
Since I'm based in the US, I refuse to implement the EU cookie or privacy policies on any of my websites.
I also am not going to block EU visitors from my sites, since I don't think it's very nice. It's not the citizen's fault.
I guess if the EU has a problem with it they can just give me a call!
No typical small-scale founder from the US that happens to get customers from Europe has to comply to EU regulations. Of course, he should comply, but there are practically no consequences if not doing so. If your business grows bigger, it's comparably easy to deal with those regulations. So, in practice, this is a huge difference.
Not sure why you got downvoted - you're completely correct. @Stefan22 is probably correct that being small and US based will reduce the odds of being fined but it doesn't mean it can't happen.
List of fines here for anyone interested: https://github.com/lknik/gdpr/tree/master/fines
This comment was deleted 6 months ago
This comment was deleted 7 years ago