Apple and Other Tech Companies Tangle with U.S. Over Data Access
nytimes.com
nytimes.com
The feds are being hoisted on their own petard somewhat here, having long argued that a foreign person's data held on a US server is subject to US jurisdiction. The logical corrollary to that argument is that data held on an Irish server is subject to Irish jurisdiction.
It is standard practise for companies in Europe (e.g. the bank I'm consulting for right now) to ensure that, when they subscribe to cloud services, their data is held stored and processed in datacentres within the EU, so that it is subject to EU legislation and, hence, the EU's data protection laws.
Absolutely. EU Data Protection Laws are so enshrined, I would argue that they are part of the culture. In the UK it's part of the educational syllabus to learn about the Data Protection Act.
If American companies cannot adhere to the act, companies will walk away from those services. I see a lucrative market opening up for "private clouds" whereby the requirement is, is the data "safe" is it vulnerable to American jurisdiction?
Is there a business opportunity here to brag about 100% none American? I don't see that being conducive to a free, open, global economy. Least of all between two of the largest economies.
There is rule-of-law in the EU and warrants do get issued and executed. The rabid pursuit of this by the US can only be counter productive in my mind. For everyone.
In theory, they might bicker a bit behind the scenes over who gets access to what data etc, but it's also in their self-interest to co-operate in their spying activities.
It's all about maintaining their rule over the masses, after all, and that's a goal they all share.
And I'd like to strengthen the point you made even further. It's not just standard practice alone - it's the law. For example, from principle 8 of the data protection act:
Personal data shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.
In my experience (with retail and banks), this means either hosting the data in a place where the law is the same (the EEA or acceptable countries), putting data under contract (EU Model contract), or using an acceptable scheme (such as US safe harbour).
At the moment, companies get around it as you said, by putting into the contract that the hosting has to be in the EU. However, if the US government win this court case, a lot of UK businesses will legally have to reconsider their use of US cloud companies at all.
For instance, suppose I only have US customers, and I have my data primarily in Amazon's cloud in the US West region. I want to have a backup someplace far away from US West.
Does the data protection act mean that I cannot use EU Ireland or EU Frankfurt for my backup, because if I ever had to restore from that backup I would be transferring it to a country or territory outside the EEA that does not ensure adequate protection?
The US has been throwing its weight around for a while now, so it wouldn't surprise me if it demands "special" treatment, even when it contradicts its past arguments. Without more evidence, I wouldn't rule out any possible outcome.
This whole revival of the Crypto Wars smells strange.
Things can be subject to multiple jurisdictions simultaneously. That's one of the things that makes international commerce interesting.
The US has reinvented the concept of borderlines on the Internet with what the NSA/TLAs have been up to. I'd say that's a distinct step backwards.
But then there are plenty of people on HN who should know better who are outraged, OUTRAGED to discover the US is spying on people, but seem to have no issues with their own and other governments spying on them. So it's ignorance and hypocrisy all-round.
What competence?
For instance, suppose you and I are both US residents, residing in the US. You loan me some item. I fail to return it and you sue me. The court orders me to return the item to you.
If I had that item in a storage locker in Los Angeles, there is no question that the court would have the authority to order me to retrieve that item and turn it over to you or to the court.
Suppose, however, I have taken the item to Mexico and have it in a storage locker there? Can I now get away with telling the court that since the item is in Mexico, the court does not authority to order me to retrieve it (or to order me to instruct the storage facility to retrieve it and ship it to me)?
Similar question for physical documents. For instance, if GM set up a documents storage facility a few miles away from its headquarters, across the border in Canada, and kept all documents not actively in use at the Canadian facility, would they then be able to fend off document subpoenas from US safety investigators this way?
You are within the jurisdiction of the U.S. And can be held in contempt, charged (even in absentia), etc.
The object is now within the jurisdiction of Mexico so it gets complicated. A Mexican court can be petitioned to require the entity that (unwittingly or not) possesses it to turn it over, etc.
The difference with data Ina server is that a company has the power to turn it over regardless of where it's stored and the U.S. Government is having their hat on that.
By physically locating servers in other jurisdictions you have to comply with their laws too and that gets complicated. You can end up Ina situation where one government doesn't recognize the authority of the other and you're damned if you do, damned if you don't.
Personally I find the constant overreach of the U.S. Government to be appalling and entirely short term I it's thinking.