Europe's highest court has rejected the 'safe harbor' agreement
uk.businessinsider.com
uk.businessinsider.com
These bit jumped out at me: >Furthermore, national security, public interest and law enforcement requirements of the United States prevail over the safe harbour scheme, so that United States undertakings are bound to disregard, without limitation, the protective rules laid down by that scheme where they conflict with such requirements. The United States safe harbour scheme thus enables interference, by United States public authorities, with the fundamental rights of persons, and the Commission decision does not refer either to the existence, in the United States, of rules intended to limit any such interference or to the existence of effective legal protection against the interference.
>This judgment has the consequence that the Irish supervisory authority is required to examine Mr Schrems’ complaint with all due diligence and, at the conclusion of its investigation, is to decide whether, pursuant to the directive, transfer of the data of Facebook’s European subscribers to the United States should be suspended on the ground that that country does not afford an adequate level of protection of personal data.
My reading (not a legal expert) is that data residency is the important bit here. Which in my view is a small step but not sufficient.
This means that a lot of US companies are now exposed to EU privacy regulations where previously they only had to account for US privacy regulations.
The US privacy regulations are no longer considered compatible with the EU privacy regulations. That has much more impact than just data residency.
In the financial sector, the extra-territoriality of US laws has been a problem for decades. Securities issued in the EU, by EU entities and marketed to EU investors end up having some language referring to which US regulation they fall under out of fear that a US person will end up buying it, and the US applying their laws and regulations.
De facto, it's when you take money from EU customers and/or have an official office in some EU country.
The same reason that if, say, Texas introduce a law that says everyone commenting on a texan website needs to be polite and I post a comment with some name calling, suing me as someone not from Texas nor the US would not be very doable, even though I technically infringe on that law.
It's been done: https://blogs.ch.cam.ac.uk/pmr/2010/11/21/english-libels-law...
The libel situation has slightly improved since then.
So, a non-profit that took monies from EU citizens I think would still possibly be affected, unless there's EU laws that make non-profits a different class of business subject do different laws.
There are non-profits that make millions of dollars in positive cash flow. All that term means (At least in the US) is that it doesn't ever pay dividends to shareholders.
I'll be intentionally vague because I don't want to stray too far afield but there are some large organization that make a lot of money but are classified as non-profit. They can pay excess revenue as bonuses to directors and executives.
Note that the original point of the cookie banner law was not to ban cookies, but to inform users about it and allow users to avoid websites storing information about them. That consequence of that law is terrible and we all know that with the banners everywhere, but at no point was it "cookie are forbidden, but you can bypass it with user approval", it was "cookie are allowed but require approval".
Storing EU citizen data without respecting the data privacy directive is forbidden, period.
The issue at the core of the Schrems case is that Facebook for example is not bound to respect this, or any other fundaments of EU data protection law.
However, if you register with a website that is clearly and overtly outside your data protection jurisdiction then it is "you" who is freely providing that data. Just as you might give personal information over a transatlantic phone call.
The EU has no jurisdiction where the company is not in the EU, and cannot prevent an individual from sending their private information outside the jurisdiction if they want to.
But various of these multinationals such as Facebook are in the EU for various operational reasons and as such the EU does have jurisdiction over them.
The relevant provisions are articles 25 and 26 of the Data Protection Directive [1] and their implementations by the member states.
[1] http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:...
From what I see in the ruling, it keeps stating "under the directive" (Data Protection Directive).
The current Directive, does indeed give national governments the right to decide how it's implemented. However, the new Directive (or regulation actually, meant to pass this year) will unify the directive for all countries. So I believe this "bureaucracy" issue, at least in regards to having to follow 27 different laws, will not be an issue anymore.
There might be some bureaucracy to ensure that you really count as being hosted there (e.g. possibly ensuring that the parent company cannot access said data - which would be problematic for some companies), but AFAIK (IANAL) there's no legal distinction between EU and non-EU companies in this kind of rule.
For example it could let games circumvent online gambling laws.
This is a problem for the internet that has long been present but is increasing: multiple jurisdictions with global reach. Historically the First Amendment has shielded the internet from a lot of attempts to interfere with it, but there's no particular reason why only the US should claim that its laws apply globally. Why not Franco-German laws against Holocaust denial? English libel law? Saudi blasphemy law? Chinese censorship law?
Sooner or later someone's going to find themselves in a Kafkaesque situation where two global jurisdictions demand incompatible things.
http://arstechnica.com/gadgets/2015/09/report-google-will-co...
That's exactly what we're already talking about here: companies are unable to obey both EU rules concerning privacy, and US laws concerning law enforcement access to data.
And that's basically why borders between internet jurisdictions are now being drawn up.
> The Court adds that legislation permitting the public authorities to have access on a generalised basis to the content of electronic communications must be regarded as compromising the essence of the fundamental right to respect for private life.
> Likewise, the Court observes that legislation not providing for any possibility for an individual to pursue legal remedies in order to have access to personal data relating to him, or to obtain the rectification or erasure of such data, compromises the essence of the fundamental right to effective judicial protection, the existence of such a possibility being inherent in the existence of the rule of law.
http://bits.blogs.nytimes.com/2014/07/31/judge-rules-that-mi...
Canadians working in the U.S. have had fun with IRS because a type of Canadian registered (tax-advantaged) savings account is not recognized by the IRS as a registered savings account but rather a "passive foreign investment company" and IRS loves to make people fill out lots of paperwork. This is apparently because IRS rules haven't been updated in the 10 years since the account type has been created.
It's such a bureaucratic clusterfuck for a small business or consultant.
Unfortunately, there's little chance of normalizing the laws with international custom, since I can already see the attack ads about tax breaks for the wealthy.
A lot of countries tax foreign-earned income, but still US is a outlier along with Eritrea, with taxing foreign income of nonresident citizens.
Ahh, and I forgot to specify "non-resident". Sort by "taxes foreign income of non-resident citizens": http://i.imgur.com/hSsVmwd.png
Sorry.
Hopefully they'll restrict that and require a higher threshold for consent than someone clicking "I agree" to 100 pages of dense legalese.
You could just add it to the cookie permission widget!
Maybe I'm missing something here.
My understanding is that the Safe Harbour agreement wasn't a mechanism for US companies to avoid EU data protection regulations... it was a certification that they did comply with EU data protection (particularly in situations where that data was transmitted outside the EU).
Now it's gone, EU customer data held by US companies will be governed by national data protection laws instead, so may end up having to be stored within the EU.
> The US privacy regulations are no longer considered compatible with the EU privacy regulations
I don't think they ever were, which is why the Safe Harbour needed to exist in the first place.
In order to avoid that each EU member state would have to approve Google, Microsoft etc. one by one, the safe harbour framework was set up to let US companies self certify that they complied with the rules:
"In order to bridge these differences and provide a streamlined and cost-effective means for U.S. organizations to satisfy the Directive’s “adequacy” requirement, the U.S. Department of Commerce in consultation with the European Commission developed a "safe harbor" framework. The U.S.-EU Safe Harbor Framework, which was approved by the EU in 2000, is an important way for U.S. organizations to avoid experiencing interruptions in their business dealings with the EU or facing prosecution by EU member state authorities under EU member state privacy laws. Self-certifying to the U.S.-EU Safe Harbor Framework will ensure that EU organizations know that your organization provides "adequate" privacy protection, as defined by the Directive."
http://www.export.gov/safeharbor/eu/eg_main_018476.asp
That was obviously a broken system, partially because the certified companies didn't live up to the EU standards, partially because the US government violated the rules systematically through CIA, NSA etc.
The fault here is really European as much as American. By relying on the wolf to guard the sheep we very much had it coming.
The agreement was that US companies sign a list with the US Dept. of Commerce that they considered themselves in compliance with EU regulations when handling EU citizen data and that would give legal immunity to them and their subsidiaries in the EU.
This ruling means that EU countries are now allowed to check if they are lying or not.
As, obviously, this ruling means no one – not even your website – may give out my data to US entities, including Google. So any type of tracking like that is now illegal.
IANAL.
Max Schrems, an Austrian lawyer and privacy activist, has
done everything he can over the last several years to be a
thorn in Facebook’s side.
My alternative perspective: Max Schrems, an Austrian lawyer and privacy activist, has
done everything he can over the last several years to protect the
rights of European citizens whose privacy has been abused and
invaded by US firms."Governments in Australia, the United States, New Zealand, Canada, Singapore, Vietnam, Malaysia, Japan, Mexico, Peru, Brunei, and Chile will be unable to force companies from those countries to store government data in local datacentres ... governments will not only be prevented from mandating data sovereignty provision, they will also be unable to demand access to source code from companies incorporated in TPP territories."
Restricting laws are always costly: Environment laws for example -- how costly it is, not to be able to pollute the air, the water, the people. Have filters, have restrictions, use of alternative fuels ... this all costs. And reduces the growth rates of our economies .... Better remove those laws and instead install strict intellectual property laws with unrestricted duration of protection.
That is, how (capitalistic) economy works: Put the costs of the business on the shoulder of many (the people of the country) and the benefits (the profits) on few people.
What does this even mean? I can't tell if you're replying to the comment or talking about the migratory patterns of seabirds.
Unless I'm missing something, the US government (and NZ, and Australian, etc) just completely sold out their citizen's privacy to a whole bunch foreign nations including a communist dictatorship. Wow.
My guess is that what it really means is that such companies are allowed to operate. OK, fine. But no one is forced to use them. So the US might say "Nice service, Vietnam. But we won't buy it unless you put servers in the US." They aren't forcing anyone to do anything.
The end user doesn't get a choice. The US has no general data protection law. Customer loyalty cards, credit records, ad tracking data: all of these may already be kept overseas.
(There are some narrowly focused privacy laws like HIPAA)
https://www.fdic.gov/regulations/examinations/offshore/ :
> "Few legal restrictions exist on financial service companies sending customer data to foreign countries. Financial institution customers may not opt out of these information transfers to nonaffiliated service providers if the transfer is for a purpose described in section 502(e) of the Gramm-Leach-Bliley Act (GLBA). For example, the opportunity to opt out does not apply where the information transfer is to: (1) service or process a financial product or service that the customer requested or authorized; or (2) maintain or service the customer's account."
No it doesn't de facto because the biggest (by user count) internet services are based and operated from USA, e.g. Google, Apple, Microsoft, Ebay, Youtube, Twitter, Uber etc. And it probably will not change in the future. So keeping current situation is good for USA and bad for everyone else.
It is better to have local services so the money and personal data don't go overseas and help local economy. The current situation is obviously wrong. There are customs duties that protect local companies and there is nothing to protect them in the internet. So we have USA taking over this new market. This should be changed.
China is an example of a country that has their own search engine, blogging platforms, video sharing sites and most of people prefer them over USA based websites.
> just completely sold out their citizen's privacy to a whole bunch foreign nations including a communist dictatorship.
No they did not because nobody uses services from those countries.
Stated that way, it sounds far more reasonable. Source code, yeah of course. You don't want country X being able to demand country Y's company's source right?
And the data centre requirement also makes sense. You can't lock out online competitors on grounds that they aren't setting up local servers. But I don't see anything that mandates you must buy from such a service. If Mexico starts a cloud hosting company and refuses to run Canadian servers, Canada is under no obligation to buy such service. They just can't ban the service for not having Canada-based servers.
The article states that Russia's law requiring Russian personal info to be stored in Russia would be banned if Russia was in the TPP. But they don't state the language used there. It wouldn't be surprising if all other rules and regulations apply. It wouldn't make sense if, say, HIPAA didn't apply to foreign-country clouds under TPP. And if HIPAA applies, then why wouldn't other privacy regs?
If it's a public safety matter, then yes I do actually.
Does this mean that, due to TPP, the EPA can not force VW to give them their source code?
I do. Company X is totally free to not operate. My citizens well being or my ability to oppress my own people - depending on the type of country, trumps Y's company rights to make profit from my people.
At the very least we may see that the TTIP Tribunal would override ECJ rulings (terrible idea for obvious reasons), but I'm hoping that if such an agreement is passed, the ECJ would also rule it invalid for not being in accordance with EU regulations and the fundamental charter of human rights.
Amazing to see what one determined person can do!
There is no safe habor inside the EU because EU privacy law already applies there and the regular legal mechanisms apply.
If I host a website that has user accounts in the US, and do not stop people from the EU from registering, do I, with no offices outside the US, need to do something different because of this ruling?
> For the purposes of this Directive:
> (a) 'personal data' shall mean any information relating to an identified or identifiable natural person ('data subject'); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural or social identity;
http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELE...
If your user is submitting their own personal information to servers outside the EU, that's their lookout. That's what seems to apply to you. Carry on. Nothing to see here.
But if they're submitting to one of your nodes within the EU, they can consider that the data will continue to benefit from the protections being in the EU affords it. Moving it to the US without their permission does not abide the EU protections.
Then (from the company's perspective) I've accomplished the same ends, at a cost to the user (latency), and gone from illegal to legal.
That seems pretty ridiculous.
This would perhaps include deleting data that customers ask you to delete, not storing personal data without direct permission, nor when you no longer need it to provide your service, etc.
This only comes into effect if the data is at any time stored within EU jurisdiction.
Border control with data is the worst idea ever.
Think of it: my Facebook friends lists has EU and US people in it. This list can't reside in EU or US. This webpage can't be served by either a EU or US web-server. By law. LOL
Plus I'm a EU citizen, and I can choose to give my data to whoever I want... no more. That's sad.
This ruling only shows the dismal tech knowledge of lawyers and lawmakers. It's impossible to implement Facebook with data spread between EU and US. Same for Tweeter and others. Say goodbye to social networks. Because of model denormalization, because of network latency and intercontinental bandwidth.
Some mention cloud zones, but they're only useful with replication, which IS data transfer.
OR... social networks will cheat. And one day, they'll be sued for cheating the impossible regulations (think VW...)
This is plainly wrong, a reference tyo an user in a list is not the user data
Have you read the ruling?
Without intercontinental replication, you'll be facing latency and bandwidth problems which will make social networks impossible.
note: when I say bandwidth, I mean intercontinental bandwidth, not your local internet bandwidth.
It's not bidirectional: you could keep it in the EU and serve it from there.
I think you're misunderstanding the ownership of the data, hence the down votes. If I as an EU citizen create a private friends list like this, that list belongs to me. If I live in the EU but create the list using a US service with servers in the US, there is no problem. US privacy laws apply. If I create the list using an EU service on EU hosted servers there is no problem, EU privacy laws apply. However in this second case if the internet service company wants to transfer the list from their EU servers to their US servers without my explicit permission, that's a problem.
A cache is not that, and you need only look at something like the EU e-commerce directive to find exceptions for caches and networks on the basis of being a "mere conduit" for the communication.
It is not as if the data is now toxic and cannot be cached or communicated outside of the EU, only that the data must be stored in the EU and should not be replicated to any database or storage outside of the EU that would prevent EU privacy law taking effect. That's important as EU privacy law already has enough exceptions to allow reasonable scenarios like caching to function.
And if you are going to say "well I could just query my cache", then I'd suggest that if your cache is able to do much more than a single key|value lookup to retrieve the cached item then it is in fact a database you'd lose the protections of being a cache and you're back in the world of not storing EU data outside of the EU.
Also, it doesn't bar the NSA from consulting the information from the USA... which is supposed to be the goal of the whole thing.
Actually the only way to surely block the NSA is probably to disconnect Europe from the Internet. LOL
That doesn't make it impossible for Facebook to do business. It just means Facebook needs to be more careful with what they gather and store.
I don't think you have any expectation of privacy with respect to your name, not anymore than a profile picture.
Relevant quote:
> Individuals regularly disclose personal information such as their names, photographs, telephone numbers, birth date and address while engaged in a whole range of everyday activities.This personal data may be collected and processed for a wide variety of legitimate purposes such as business transactions, joining clubs, applying for a job, and so on.
> Nonetheless, the privacy rights of individuals supplying their personal data must be respected by anyone collecting and processing that data.
[1] http://ec.europa.eu/justice/data-protection/data-collection/...
When I publish something in Europe, my friends needs to see it too in the USA. And you can't build a Facebook wall with intercontinental latencies. You need replication.
It's a social graph, and you can't split it between US and EU: data has to be replicated across borders (or face massive latency and bandwidth).
I have yet to see a Facebook wall in under 0.133 seconds, I'm not sure intercontinental latencies are the biggest problem in web performance these days...
There's also the problem of bandwidth (if you can't cache data locally).
Again, bandwidth pales in comparison to megabytes of Javascript and images getting pushed all over the place. On my nearly-blank test account loading Facebook.com fetches ~4 MB, including ~3 MB of Javascript with instructive names like https://static.xx.fbcdn.net/rsrc.php/v2/y0/r/64jGxSfxJ36.js and https://static.xx.fbcdn.net/rsrc.php/v2/yp/r/K6ojr4ngQRr.js
In face of that, suggesting having to store some data 0.05 s away is problematic is a bit of a waffle
You're completely missing my point. Your facebook user name isn't personal private data, it's explicitly public. If people in the US have your name in their friends list that list belongs to them, not you. Not even the bit of it with your username.
Those words don't actually mean anything.
But the article says "Facebook and Twitter [...] could be forced to host European user data in Europe".
That's way more agressive than just a contract change and poses a threat of technical blocking problems.
Sure, you want to host customer data from europe in europe (latency-wise) anyways, but now that this will be more or less required it will be interesting to see how people will solve this. The good thing is, with "the cloud" you have a lot of option (locations) to choose from.
It is already an interesting experience trying to explain to off-shore companies that they cannot just take our data like that.
Well they can in practice, but then better prepare some good explanations in case the company gets a security audit from the local government.
I know that if I use Yandex, at least some of my data is going to reside in Russia. If Dailymotion, France. I consider it up to me as a consumer to decide whether that's what I really want. I don't consider it my local government's job to force those companies to change their business models.
This is a ridiculous position to take, because it requires a humanly impossible amount of research to know whether the privacy of your data is protected. And that's when the information is even available.
Privacy is a basic human right. When corporations collect your data it becomes the responsibility of those corporations to protect your privacy. Individuals simply do not have the resources to enforce this, which is why we elect people to enforce this. This isn't some crazy responsibility for governments: this is the fundamental reason why governments exists: to protect the interests of their citizens collectively when it's infeasible to protect those interests individually.
How about looking at this from another angle? Why the heck should your browser and Internet connection leak anything that allows to single you out as an individual to any corporation or individual in the world?
The focus should IMO be on providing secure tools to end users for browsing the web.
Just look at the idiotic E.U. cookie rule.
I also didn't talk about startups, i mean small business in general.
This could be a reason not to launch your business in europe, if the cost of "deployment" is to high. Sure, someone else will fill that hole for you, but that's less money in your bank account. :)
There will be an enormous burden on new businesses satisfying these laws - previously we've got away with privacy policies but could still code the same. If we need to maintain N servers for N countries customers could be from, that's a massive operational overhead that is bound to do nothing other than stifle innovation.
Now, I'm all for privacy, but if each country starts fragmenting the internet on country boundaries - to the level of physical servers and data storage locations, bringing a new idea to market is going to much much harder. This is different to, e.g. different tax regulations, etc, because you can still benefit from centralised computation while processing orders for different localities.
And while today this might be just about Europe, it sets a trend. Before it was just Russia and China. How long before all countries want to see the code a la the Chinese?
So the NSA has screwed things up for all of us now who are trying to start businesses.
If my costs go from: developer -> developer + global devops team + legal, etc., that's a massive burden that will affect the "bedroom/garage" startups.
Plenty of popular apps don't require anything like bank account/post code, etc. that could be assumed to prove which country someone is from.
Now, if your app does not become popular in Italy, you just have five users there, do you still have to comply? No you don't, because de minimis non curat lex.
China is good example of how that works: they have their own search engine, blog platforms, website analytics software, video sharing sites, IM software. So Chinese users do not send their data (and money) to USA and goverment can protect personal data from NSA while EU cannot.
Of course I do not approve other things like censorship in China but having local services is a good thing both economy-wise and privacy-wise.
Basically the EU is creating a PR stunt that in theory could force them to enact some minimum veneer of standards and that PR stunt is going to have higher short term costs for the small private sector players than the large ones.
It is entirely possible the stunt will instead pay off for the other EU governments and against the privacy of their population by getting them invited further into the club.
Are you saying that the ECJ ruled without looking at the case merits?
I am also very skeptical that private data in Germany was or is any safer from the problems with the safe haven as far as data intentionally illegally shared with institutions in the US, not due purely to issues on the ground when defending the data in good faith.
Collecting data which is routed internationally is a well documented method that NSA et al have used to skirt domestic law and grab/share the data. If you already live in country "C", and by statute your data must never leave country "C", then your data are more protected than if it had been sent outside the legal jurisdiction of country "C"'s courts.
With prevalent encryption on-the-wire, fibre tapping is less useful. So the way people get their privacy leaked is via hacking or other compromises. Saving to disks in a person's country of origin is probably rather far down on threats to their privacy. (Yeah, I know, if you host it all on disks in the US, then the FBI can come steal those disks. But that's less a risk than a hacking group dumping your DB on pastebin.) And a compromise to the company will compromise the data no matter where the disk are.
If countries were really concerned, they'd mandate strong security for personal info. Not like PCI where technical details are spec'd, but somehow offload it so that companies must make reasonable steps. Then have enforcement to fine companies that misbehave. Perhaps make it something where companies will want to get insurance.
That way, a startup, instead of grabbing everything, they'll ask themselves: "Hey, do we really wanna capture this info?" Just like PCI shot a lot of plans to store card numbers and CVV, a strong law could make companies think twice and plan around handling private info.
Location of storage devices might end up on the list of requirements, somewhere. Like once you store info on more than X people, you're required to address how you handle differing jurisdictions or something.
EDIT: fixed wording
At this point, upvotes and downvotes are mostly driven by a reddit-esque crowd with political grudges.
As an employee of a small software startup, but also as a citizen, I welcome this move.
(for some context, I'm a French SaaS bootstrapper; I am as careful with my customers data as I can be, and found that starting a SaaS has been a major pain already - VAT rules, finding a SafeHarbor provider which doesn't suck at security, too etc).
I was talking about this to someone just now and it strikes me that all these regulations are very much wasted on startups during their creation. Maybe what we need is a way for startups to be able to playtest their idea and only have to worry about all the extra responsibilities once they're more certain about the results.
How many times a day is this phrase written in Hacker News? How many times is it found on reddit?
The poster, in this specific case is not being downvoted.
The issue I think is understanding about how commenters and viewers use HN and reddit and upvote and downvote over time. If you understand this process you will no longer want to write "I don't know why" because you will understand the process.
I hope more people would understand the voting processes of these various discussion forums.
I almost never complain about downvotes (as mentioned in HN guidelines), yet felt that there was a misunderstanding and a lack of full perception of the implications of what the downvoted message conveyed.
Truth is (again, as someone who is privacy-sensitive, and running a EU SaaS) this is going to be complicated to run an international SaaS, as a bootstrapper.
Because they are two different things.
You build houses - think of it like fire safety rules. "What do you mean I have to keep track of all the fire safety rules for the country I build the houses in? Can't I just keep track of a set of rules of my choosing instead?" -- well, no, for one and even if you could, that'd be a bad idea. Almost universally, there's good reasons behind specific rules in the fire code. (And in the rarer cases the rules really are broken, that's a problem with the law, but not one that can't be fixed).
Unfortunately, most companies don't give a rat about their customers' privacy (we care deeply about it we swear). What really should happen instead is that US customers demand laws like the ones we have in Europe.
It screams laws written by politicians for special interest groups none of whom have the first clue about technology or how it works.
You could just have the web browser show an alert when a site wants to set a cookie and the user can click that alert or always allow it. Which is what we used to have in every web browser. Until users got sick of seeing the stupid warning because every single website uses cookies. And they got blind to the warning and paid no attention to it. Which made any other warning a browser shows more likely to just be clicked through.
So browsers removed the warning because we all realized it was stupid and pointless and ineffective and served no purpose any longer. But politicians with no idea how the technology works and no understanding of the fact that we already went through all this decide that everyone should see the dumb, stupid, ineffective warning on every single website and have it show up every single time for the people who understand how to manage their cookies and only show up once for the people who have no idea how to use their cookies. Just brilliant. It serves no purpose and everyone just clicks it away just like any other popup ad.
Fun fact, the EU excluded "third-party social plug-in content-sharing", which are used for more tracking than any of the other cookies.
Cookie notifications and censorship of the news under the guise of the "right to be forgotten" come to mind as obvious counterexamples.
Or just host everything in Europe.
Or lobby Congress to stop shitting all over privacy so that the US can be considered a safe harbour again.
And think about it: is there a really huge increase to privacy? What exact attack scenarios does this defeat, and how likely are such scenarios compared to run-of-the-mill privacy breaches (lax security)?
http://www.theguardian.com/technology/2014/apr/29/us-court-m...
Those are two entirely different scenarios. There's no reason both couldn't (and shouldn't) be handled in parallel. For example starting next year companies within the EU are held liable for data loss, with up to IIRC 3% of their global revenue. That policy handles the lax security concerns; no reason to not tackle other problems, like the one described on this thread.
It's sad to see how the judges of the courts are more on the side of the people than the politicians they elected...
Judges usually have tenure, this makes a huge difference to someones impartiality.
Without replication between locations, you're stuck: replication IS data transfer.
With such a ruling, you can't implement an intercontinental social network anymore.
If my actual name is stored in Europe, my US friend must request the data from the USA just to show his friends list on an HTLM page... (is that a transfer too? is it forbidden too?)
I'm not sure if it means anything for them. If a company does not have a business presence in the EU, it likely isn't subject to EU jurisdiction at all. This case happened because Facebook is a multinational company with a European subsidiary in Ireland and was sued before the Irish courts. Companies that may be affected by this are:
* Multinationals that exchange personal data between their US and their EU branches.
* Companies in the EU that are in a business relationship with companies in the US and as part of that business relationship send personal data to the US.
* Companies in the EU that avail themselves of US data centers and store personal data in those data centers.
Actually they were sued before the European courts. Specially the European Court of Justice, which is in Luxembourg. I don't believe there was any case in the Irish courts.
In most cases (such as this) a national court refers the case to a european level if european directives and interests are involved.
Fun fact: the EU commission/parliament has also not the power to pass any binding laws. They pass directives which are than implemented into national laws by the legislative bodies of it's member states and can also be overthrown by courts of each state individually (e.g. happened in germany with EU data preservation directives)
Non-European companies that get paid for services rendered to EU citizens or countries.
If found to be violating laws, the ECJ can order banks to block payments made to those companies from within the EU, which harms their bottom lines between nothing and a lot.
"Look, the EU is reasonable and wants to get rid of the cookie ruling and the high bar for startups on geographical server requirements - TTIP would allow all this to happen!"
Somehow the tech industry seems to think it should be exempt from that, even if it means being allowed to piss all over the basic civil rights of citizens of modern Western democracies.
Yes, this is a problem that needs to be solved given the reality modern cross-border online services. But it can't be solved by the corrupt political elite simply selling their citizens hard fought rights to corporations operating from countries that lack respect for such rights.
And you wonder why it's tougher to do startups in Europe...
I'm pleased by what the ruling says about the NSA and the pressure it puts on the need for reform, but less than pleased about the practical implications.
This said: Probably yes. EU data laws are mostly about private information, for example private chat messages, etc.
If you only store email accounts, you might get around the laws, but if you store anything like payment information, communication between users, etc, you effectively now have to follow EU data laws, which mean: You can’t give any third party (not even your government or hoster) access, you can’t store it in countries where the government might just seize your data (like the US), etc.
Question: Why do companies HQ themselves in the US? Why not pick a friendlier country, then turn their US parts into a simple contractor that supplies software development and engineering resources? Then the US company would not have actual ownership of any data. Forcing them to reveal customer records would be the same as forcing an individual to steal data right?
Nowadays that's not true but the US startup VC is a lot stronger in the US for a bunch of reasons, so new startups tend to be established there much more often (with the financial tech field being the exception I believe). If you're making a new company you're going to make it where you live just out of sheer convenience.
Today you get to learn about: American Exceptionalism!
It is important to realize that, within the US, there is essentially a universal belief that the US is the best place to live, work, or be in the entire world. The debate is not so much whether the universe revolves around the United States, but which city exactly the axis passes through -- New York, DC, San Francisco, LA. It is very important that a universal axis has a commonly used two letter acronym, which is why not even a Chicagoan seriously believes the axis is through Chicago.
When the EU makes privacy complaints against US companies, the common perception -- even among US citizens who disapprove of domestic spying programs -- is that something is wrong with the EU. The idea that the EU could be right to hold a US corporation accountable to their laws never even occurs.
No American could ever conceive of establishing the HQ of a US corporation outside the US -- except maybe as part of a skeevy tax dodge. The US is the best place in the world to live, work, and run a business. Why would you want to go anywhere else? To be fair, most of the US companies that do establish some sort of off-shore setup are engaging in some sort of skeevy tax dodge.
Maybe incorporation in US really is better, at least for US citizens. It's easier to deal with local courts than foreign courts. If your European subsidy runs afoul of some regulation in a major way then they probably can't take your assets from your US based parent company. Then US is arguably more business friendly in many ways.
At least in the tech sector...because the U.S. currently has, by far, the most venture money [1] and the largest addressable market[2].
[1]http://pitchbook.com/pr_20150109_1.html [2]http://techcrunch.com/2011/12/23/flurry-largest-addressable-... (slightly old)
And little stops a company overseas to do business in the US, right?
I think legally, no, but for better or worse, there are a ton of tools that are U.S. only - an example from today: Microsoft Hololens developer edition is available only to the US and Canada.
> However, US companies that obviously aided US mass surveillance (e.g. Apple, Google, Facebook, Microsoft and Yahoo) may face serious legal consequences from this ruling when data protection authorities of 28 member states review their cooperation with US spy agencies.
Can't wait. This is going to be good.
* Will we need to partition user data based on location, even if they are in the same organization?
* What happens when a user in EU sends a message to one in US? So right now the chat history for one-on-one conversation pairs is stored in one place, does this ruling mean that now we have to duplicate this chat history for both the users?
* Even worse, what if multiple EU and US users are part of the same chat group? Is there any way we can store the group's chat history in one place?
Even if the NSA (and GCHQ) wasn't collecting everything, US law still wouldn't provide enough protection to comply with EU privacy norms.
http://www.politico.eu/wp-content/uploads/2015/10/schrems-ju...
Updating your name, birthday and other personal information would take an extra 100 ms in order to POST to the US, but it could then be replicated back out to the EU for reads if necessary for performance.
What has to do the business model with a ruling that states that user data can't be transferred?
How is different iCloud than Google Drive?
Honestly, if you think G+ is bad, or Adwords, but the appstore is not (Or iCloud, iwatch, Siri, Amazon Echo, Whatsapp, etc.) you will need to do a reality check. All of those are very privacy intruding and every company will do it's best to make money of your data. And pretty much all of those services is made to collect as much information as possible about you.
Use Apple or Google or Facebook and store your private data to be datamined and monetized but please don't fall for marketing speech and all that "don't be evil" bullshit every mega corporation is telling you.
Being in compliance is fairly easy for large companies, but it's going to be a challenge for startups.
And you have said that ALL the behavioral data collection must be forbidden. Even if the user agrees with that?
By the way, spying is already illegal. If you know about that behavior you can sue those companies
This is what I´m asking, an example of one of those companies "spying"
The proposals include being able to levy a fine up to €1,000,000 or up to 5% of the annual worldwide turnover (whichever is greater) if they fail to comply with EU data protection rules.
[0] https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
This is not a blanket-panic for all US/EU companies as the media are projecting.
If I ask Facebook to delete my data, they are absolutely bound by this. There is no legal way anymore to just hide the data from me.
http://www.salesforce.com/company/privacy/data-processing-ad...
What if I don't want my data going to the US though?
The proposals include being able to levy a fine up to €1,000,000 or up to 5% of the annual worldwide turnover (whichever is greater) if they fail to comply with EU data protection rules.
[0] https://en.wikipedia.org/wiki/General_Data_Protection_Regula....
this ruling ignores the decentralized nature of the internet.
worst case is Europe being shut off from any tech advances, while the Pacific region from Cali to China takes off.
These countries are demanding we run our services in their countries. This is a money grab.
Note that these same countries expect the United States to act as World Police, and do not contribute as much money as they should. They want the US to know about attacks ahead of time. I wonder how the US could possibly know about attacks ahead of time?
I deplore mass surveillance. I really do. But I think wiretapping with a warrant is a necessary tool for fighting crime, and terror, and bad state actors.
There's a part of me that desperately hopes all major internet services just shut off Europe entirely. Welcome back to the Stone Age.
Nobody (except some Americans) want this.
"I deplore mass surveillance. I really do. But I think wiretapping with a warrant is a necessary tool for fighting crime, and terror, and bad state actors."
I hate X but Y is necessary (because I said so) so let's do X anyway.
"There's a part of me that desperately hopes all major internet services just shut off Europe entirely. Welcome back to the Stone Age."
If by stone age, you mean 2006, great.
Why do you think that? And how about https://en.wikipedia.org/wiki/United_States_and_the_United_N...
I am actually appalled the Netherlands actually contributed to your shitty conflicts.
Large service providers like Google and Amazon can and will comply with the laws. It is possible that social media start-ups will be unable to operate across borders due to regulations, but this will hardly be a staggering setback to the European populace's ability to share photos of their food. I doubt there are any real implications for things like freedom of speech/expression: these types of services are already effectively illegal in places with heavily authoritarian governments.
Only large service providers will be able to comply with all of the laws. Why are we patting ourselves on the backs for this?
Why, exactly? And what are "all of the laws"? The data protection directive is not that complicated or onerous, and besides, you can avoid it wholesale: just don't store personal data.
There will be services that have not yet been invented. We cannot presume to know what they'll look like, but there's a big chance the startups that invent them will be harmed by this ruling. No, big services run by established players will not die, but that's hardly the point.
What's not legal is warantless universal wiretapping.
(Also, I don't want the US to be "world police"! Like US domestic police they are far too trigger-happy. And the US is one of the few countries not signed up to the International Criminal Court. Would you want a police without a court?)
They hand over Roman Polanski, and we're off to a good start.
> What's not legal is warantless universal wiretapping.
So punish the government of the United States - not the businesses.
> Would you want a police without a court?
That's called "a military." And yes, I want a military. And since our enemies don't bother to dress up in bright-colored uniforms, and stand in a row in a field anymore, our military needs to be a lot more nimble. And since our international efforts (the UN) are often blocked by one or two security council members, I'm not impressed with the UN's ability to keep the peace.
Move fast, blow up hospitals? But I'm glad you accepted that the US is not a police service (ie legally accountable to the policed, following due process) but a military (ie an occupying force that executes people at will).
The wars in Iraq and Afghanistan are wars of choice by the US, and the end result has been a total destabilisation and millions of people killed or made refugees.
No, it really isn't. It won't be effective but the judge here is not aiming for EU companies to earn more money.
> There's a part of me that desperately hopes all major internet services just shut off Europe entirely. Welcome back to the Stone Age.
Economies have becomes so intertwined that shutting Europe 'off the internet' by any other party (presumably the US or the rest of the world) is no longer feasible. It will backfire tremendously on those doing the shutting off.
Besides that, you wouldn't really shut the internet down, merely split it. Even North Korea has internet access.
> Economies have becomes so intertwined that shutting Europe 'off the internet' by any other party
BS. Google shut off China. Independent companies are free to not do business anywhere the laws are stifling. I think it would be awesome if they did it all at once. Internet Blackout for Europe.
I meant Google, Facebook, YouTube, Yahoo, Amazon, Wikipedia, Twitter, LinkedIn, Ebay, Bing.
Unless by Internet Blackout you meant blocking NNTP and Gopher?
Neither of which is relevant AT ALL to the fact that they are being hit with ridiculous laws that hurt companies - small ones in particular - and therefore hurt consumers.
Non-EU small companies will not be hurt. Companies not collecting personal data won't be hurt. Companies that don't have an office in the EU won't be hurt. EU companies won't be hurt as long as they don't mix personal data between EU and US - and knowing what we do now, why would you?
If you want to talk about things that hurt companies, you could start with NSA severely handicapping US datacentre industry.
Yes, I'm quite aware of the price differences between data centers in Europe and the US. It all depends on who you want to serve, if latency is important then paying a (small) premium is usually not a problem. Also, plenty of EU data centers (maybe not the ones that you are familiar with) are extremely competitive with their US counterparts when it comes to pricing.
As for 'their incompetence', that would need some data to back it up, I have extensive experience with both and I'd be hard pressed to say which of the two groups are the more competent ones. Both are pretty good.
> Independent companies are free to not do business anywhere the laws are stifling.
You are dangerously mis-informed about where the balance of power lies - for now.
The court's decision hurts the internet, hurts small companies on the internet, and hurts the ability of the United States to fight terrorism.
I may not have worded this opinion particularly well, but it's ridiculous that my comment cannot even be expressed.
I can understand why you don't see it that way and wouldn't claim that our decisions are all obvious or all correct. They're imprecise judgment calls.
Good. If you want to be a multinational company, then you should have to obey the laws of each country.
Good luck with that. If the US mandates you do X and EU mandates you do !X.
Are you are suggesting that one of those laws should be changed to make it easier for multinational companies to operate, even though there was a good reason for the law in the first place? Because I would say that if the company absolutely has to keep customer data then they shouldn't operate in a country where that is illegal, and if they refuse to keep customer data then they shouldn't be operating in the country where it is required.
Some big companies should finally stop talking and start acting, this is the only chance for a real change.
Cut the NSA-Brotherhood ties! These little Hitlers from all the affiliated "Clubs of Distopians" and the War-Industry completely destroyed the most important association of "USA == Freedom" in the world. Face it. Deal with it. Act accordingly.
For people interested in history: it might be interesting to look at the post-ww-2 de-Nazification process in germany to understand how hard it is to remove established circles of anti-democratic bureaucrats from power structures. This will take a very long time (if it happens at all).
The better immediate reaction would be to support progressive and freedom-oriented societies with your technical powers until "good old USA" is restored. Europe is not perfect, but what happens in USA nowadays is pure distopia, a very unhealthy development that will lead to a negative outcome for all of us.
Once people came to The USA because of suppression and lack of freedom in their home countries. Just a few generations later if you have the same sense and longing for freedom like these ancestors of you, it is now time to leave that continent as the suppressors followed your trails - come home to Europe and together we can build a better future!