EU parliament calls for Privacy Shield to be pulled until US complies
techcrunch.com
techcrunch.com
From the article: (the EU parliament) "takes the view that the current #PrivacyShield arrangement does not provide the adequate level of protection", "calls therefore on the Commission to suspend the Privacy Shield until the US authorities comply" https://twitter.com/bendrath/status/1014832868969910273?ref_...
My personal opinion is that this isn't tradewar politicing by Europe, it's the result of a genuine interest in citizen's privacy, but I can see why it could be taken as such.
It's not just the administration. Every time the EU has levied fines against Google a lot of Americans on HN claim that the EU is doing it because they're jealous of how successful American businesses are.
The US generally doesn't give a damn and will usually do what it wants anyway.
In the case of Karl and Walter LaGrand there was a clear violation of the Vienna Convention, a binding verdict by the International Court of Justice, a sympathetic US President, but the Governor of Arizona didn‘t care, and America just said „too bad, we signed this convention, but if a state doesn‘t want to comply, what can we do?“. And SCOTUS confirmed that stance.
That really ought to be taken into account in the treaty negotiations. If a company signs an agreement the company can't legally comply with, that tends to have the effect of nullifying the agreement more than forcing the company to change. (Tends to. Generally.)
There's an obvious solution for Facebook et al. Host their primary data centers in the EU and move their US user data there, instead of vice versa.
The massive downside for me as EU business:
1. Lost time and money having to migrate. 2. Usually european companies providing the same service are worse, leaving me and my customers worse off.
In general, Members of the European Parliament have less understanding of business and trade than businesspeople and traders, and in my view[0] tend to follow their emotions more in those areas.
Some also have a streak of anti-Americanism, in varying degrees. As the heat increases, this sort of resolution may occur more frequently.
I'm sceptical of the notion that MEPs all voted according to their devotion to fundamental rights.
None of this means that I believe pursuing the resolution into legislation is a bad or a good idea. I'd have to see (and understand the consequences of) the proposed measure.
[0]This is an impression; I have no empirical data
This is what it comes down to, your disbelief that MEPs could have a genuine interest in their constituents' privacy.
Sure it does, but so do all the loopholes they wrote into those laws so EU member states could continue their own surveillance programmes and data seizure powers, and for that matter all the then-illegal spying programmes that were retrospectively legalised when Snowden et al brought them to light. Let's not pretend the EU and its members are whiter than white in this area, nor that the EU is above attacking the US tech sector through non-technical means.
or probably just general dissatisfaction with the U.S.
There’s certainly plausible deniability that it isn’t, I’ll give you that. Is it extra leverage that will almost certainly come into play? Yes, it’s also that.
According to the article, the only implementation on the US side was by presidential policy directive. So our faith in the US implementation of the 'privacy shield' is only as good as our faith in the integrity of said Directive.
Even starting from a low point where it's quite clear Trump is interested in tearing up anything Obama put his name to; his increasingly reckless approach to international relations lowers our faith in any presidential directive by the day. At this point 'privacy shield' either needs to make it into law proper, or we should just assume its days are numbered.
So all you would have to do is have every EU business renegotiate contracts with or review new terms with every US business they work with where personal data transfer is involved? No big deal.
The question is if they offer a good enough level of protection if the US government can demand access to data anyway.
Right. But since essentially the same concerns arise when dealing with businesses based in the EU, let's be honest and acknowledge that this isn't really an ethical question and doesn't really have much to do with either privacy or security either. It's just a matter of the EU and its privacy legislation considering EU prying to be acceptable but not US prying, which is a political decision.
Why should the EU parliament care about that?
Plenty of EU business interests use AWS and Gmail.It's obvious why Google wouldn't be interested in a similar model for their products.
The development is certainly positive and the GDPR is also very similar to pre-existing German privacy laws in many aspects, so I'm not complaining.
AWS recently wrote me an email, that because my billing address is in the EU, my contract has been transferred to a newly founded company AWS EU, which in turn has subsidiaries in most EU countries.
I have no significant business with AWS and have not investigated what this all means.
But I wouldn't be surprised if Amazon sees the risk that with the current US administration they don't want to rely on international business anymore. Having only national (or intra-EU) contracts with their EU customers seems just the safer option. Dealing with investments and profits inside a group of fully owned subsidiaries is probably much easier than dealing with two fundamentally different systems in every single customer contract. The EU striving for data-protection and the US insisting that foreigners have no rights and international treaties are bad unless they unilaterally favor the US.
Since AWS EU presumably shares the same infrastructure as AWS US it's probably more of an accounting trick (but keep in mind any GDPR fines would apply to the entire group, not just the individual corporation, so it's not really a financial protection).
Because many thousands if not millions of smaller businesses across the EU depend on US businesses as well, and sharing some sort of personal data with them is often necessary for the provision of the relevant service.
Given the hassle and costs we've all just had with GDPR, the EU going all-in on undermining Privacy Shield would not be a welcome development for businesses.
Privacy Shield is a fig leaf more than anything. Using any US company (or non-EU company from a country without adequacy) is a major risk for compliance.
This is a bit like when people complained their companies were going bankrupt because Facebook/Apple/Twitter/Google shut down an API without warning. If you build your business on such a wobbly foundation, it's a calculated risk and you need to be aware of it.
It is entirely unconstructive to call US-based foundations wobbly when the EU-based equivalents (a) sometimes don't exist at all, and (b) where they do exist, suffer from analogous privacy concerns around government snooping.
The allegation here isn't that, to pick one relevant example, Stripe is abusing the personal data they process when they collect payments from our customers. The objections to Privacy Shield, like Safe Harbor before it, are mostly about the US government itself having rights under US law to gain access to that data, regardless of the actions or intentions of US-based businesses.
Now, I don't like the current heavy-handed approach to data hoarding by governments under the guise of national security any more than the next HN reader. But let's be clear: the EU and its member states do essentially the same thing, routinely writing special cases into privacy laws that exclude governments when they want to pry for supposedly security-related reasons. It is the height of hypocrisy for the EU authorities to allege that processing data in the US is unsafe because of the risk of US government interference, while at the same time turning a blind eye to what's going on in their own back yard.
In any case, since sadly there is little prospect of any of the governments involved on either side of the Atlantic giving up these powers any time soon, undermining otherwise reasonable privacy laws because of them serves no useful purpose. It just hurts businesses who are trying to do reasonable things, even if they are careful and considerate in how they handle personal data, and by extension it also hurts both their customers and the economies they operate within.
No, and I rarely hear that as the main concern.
The main concern with Safe Harbor et al. (where US businesses are dealing with EU businesses and – more importantly – EU people) is commercial abuse of data (Facebook!) and data breaches.
Government access isn't seen as particularly problematic in criminal and anti-terror cases, but in mass surveillance of Internet and telephone connections, as well as in the context of industrial espionage.
For the record, we have heard very different concerns then. One big concern I have seen expressed, particularly in the more recent context of the GDPR, is that the government surveillance powers constitute a legal obligation on businesses, but only EU versions of such powers are recognised as legal obligations on EU businesses. Thus EU businesses cannot avail themselves of that lawful basis for processing if they export data they control to a US business (even one covered by Safe Harbor before or Privacy Shield now) for processing and the US government then grabs the data.
The logical conclusion if all such schemes are struck down is that exporting any personal data to the US for any reason will become illegal, with obvious catastrophic consequences if the law is then enforced to the letter.
The main concern with Safe Harbor et al. (where US businesses are dealing with EU businesses and – more importantly – EU people) is commercial abuse of data (Facebook!) and data breaches.
The entire point of Privacy Shield, like Safe Harbor before it, is to give EU businesses reassurance that they are not breaking data protection law by transferring personal data to a compliant US business. Businesses that are doing things with the data that would not be permitted under the stronger EU regulatory regime aren't supposed to qualify for Safe Harbor/Privacy Shield status in the first place.
Exactly, I didn't mean that Privacy Shield is the problem, but that it is trying to address that problem, but I can see that I expressed myself ambiguously.
> The logical conclusion if all such schemes are struck down is that exporting any personal data to the US for any reason will become illegal
But that's good! Not in the sense that we should wish for that outcome, but in the sense that the US should offer real assurances to us that allow us to enter such an agreement..
I understand the principle you're aiming for. However, as a practical matter, it is constitutionally impossible for the US to enter into the sort of binding agreements that would give you the assurances you seek, and there is no realistic prospect of literally amending the Constitution of the United States to make it more subservient to international interests so that it could give those assurances. Pursuing the strategy you advocate could only end in crippling large numbers of EU businesses, setting back the already lagging development of our tech and creative sectors by years more, and catastrophic effects on our economies.
A good general tries to fight only battles he knows he will win, but it's a crazy general who tries to fight battles he knows he can't win.
It doesn't prove a business implements privacy by design or takes any steps to ensure data protection. It just proves the business was willing to pay the registration fee and sign a bunch of legal documents that may or may not result in fines if proven to be violated.
Ha...this I doubt will ever be provided. And if it is provided, will it be seen by the citizenry? They're either going to have to cave on the "no indiscriminate collection" requirement, accept an invalid definition of "indiscriminate" or "collection", or flat never re-agree to the agreement. Because, sadly, indiscriminate collection of data isn't stopping.
I live in the US; I have many friends in Europe; how exactly is Facebook/Google/etc going to separate our data geographically while still displaying it in our feeds/inboxes/etc?
There really seems to be only one realistic endgame: The end of the multinational corporation. Pick a jurisdiction, keep your servers & employees inside, and tell the rest of the world to get soaked. If Europe really wants to control their citizen's data, they're going to have to start firewalling, China-style.
I'm guessing privacy advocates imagine the world will homogenize on a set of Euro-compatible policies and everyone will live happily ever after? That seems far less likely than a set of mutually-incompatible enforcement regimes, like we already see with China and Russia.
So what does Facebook/Google do? Disallow friending/email/communication across political boundaries?
My evidence for this claim? Very few nation-states if any are growing as fast (in terms of net worth) as the largest multinationals, but the multinationals are still relatively agile (read as able to mobilize their strength behind a common agenda). Sure at the moment, the largest multinationals have only as much net worth as some of the poorest countries. However, look at how cities and states try to out compete each other in order to have companies like Amazon and Foxconn set up their headquarters. How soon will it be until countries start competing with each other for something similar (building your next regional data center in EMEA? here are the contenders). If the multinationals really wanted to milk it, then they could totally make a game show out of it à la Eurovision.
Multinationals don't have borders and don't have exclusive access to people and they don't (currently) wish to because they sell different products and it would be pointless for them and for people to be able to buy from only one company.
So that endgame would work only if multinationals take over and rule the world together. That happened in Continuum https://en.wikipedia.org/wiki/Continuum_(TV_series) a Canadian dystopian sci-fi TV series.
This is easily solvable - and certainly far easier than splitting up the corporation. At worst some features don't get made.
The EU27 are better aligned without the UK, and will move forwards more quickly in many areas the UK would have held them back. Ongoing integration is very much still the plan.
In the meantime, the UK will have to stay very close to EU rules in order to continue to trade with its largest market. However, it already has little/no say in future rules, and that will stop altogether in March.
Brexit aside, will they? They don't have a track record of doing so previously.
If any other country was going to do it, it might have been Greece during the financial crisis, but ultimately the same pressures apply: no country can pull up the drawbridge. Dependency on trade, investment, and migration of skilled staff is the backbone of a modern society. And leaving the EU does not make Europe go away, it just removes that country from the decision-making process.
For most other members of the EU, leaving it would be extremely painful, due to much higher levels of integration. Issue a new currency, which will probably rated worse than the Euro, see bond rates spike, have to close borders again, for both people and capital. For most EU members leaving the EU would send their GDP tumbling double digit figures.
So while I absolutely hate to see it happen because I've got lots of friends in the UK, this is either going to hurt badly (hard Brexit), or the UK will simply lose any ability to shape the future of the EU while accepting most of its rules. Don't see any middle ground as the middle ground would massively hurt all other EU countries so its not going to happen.
Exactly. The UK's main leverage in negotiations was "do what we want or we leave". Now that they're leaving, there's nothing left.
As for the UK, there are other ways for it to survive and even thrive, but whether it will be good or not so much for most of its citizens, remains to be seen.
Italy is helmed by Eurosceptical parties. They're committed to playing nice for now. But if their economic policies hit the rocks, it may be easier to blame the EU than structurally re-organise the Italian south.
At least the UK could argue that it may get better trade deals, but what's in it for Italy?
This is not clear, particularly if a sovereign Italy ends up being much more aggressive with detaining, punishing and deporting unwanted entrants.
> At least the UK could argue that it may get better trade deals, but what's in it for Italy?
I don't think there's a rational reason that outweighs the downsides. That doesn't mean it won't be politically advantageous for the party in power.
I'm not arguing for Italy's exit. Just against the assertion that "there's no sign of anyone" other than Britain "leaving" [1].
I also never understood why Americans think that is bad. The EU is making their market less attractive, so shouldn't Americans be happy about that?
The EU has no interest in kicking anyone out, for as long as they pay taxes in the EU.