From the article: (the EU parliament) "takes the view that the current #PrivacyShield arrangement does not provide the adequate level of protection", "calls therefore on the Commission to suspend the Privacy Shield until the US authorities comply" https://twitter.com/bendrath/status/1014832868969910273?ref_...
My personal opinion is that this isn't tradewar politicing by Europe, it's the result of a genuine interest in citizen's privacy, but I can see why it could be taken as such.
It's not just the administration. Every time the EU has levied fines against Google a lot of Americans on HN claim that the EU is doing it because they're jealous of how successful American businesses are.
The US generally doesn't give a damn and will usually do what it wants anyway.
In the case of Karl and Walter LaGrand there was a clear violation of the Vienna Convention, a binding verdict by the International Court of Justice, a sympathetic US President, but the Governor of Arizona didn‘t care, and America just said „too bad, we signed this convention, but if a state doesn‘t want to comply, what can we do?“. And SCOTUS confirmed that stance.
That really ought to be taken into account in the treaty negotiations. If a company signs an agreement the company can't legally comply with, that tends to have the effect of nullifying the agreement more than forcing the company to change. (Tends to. Generally.)
There's an obvious solution for Facebook et al. Host their primary data centers in the EU and move their US user data there, instead of vice versa.
The massive downside for me as EU business:
1. Lost time and money having to migrate. 2. Usually european companies providing the same service are worse, leaving me and my customers worse off.
So all you would have to do is have every EU business renegotiate contracts with or review new terms with every US business they work with where personal data transfer is involved? No big deal.
The question is if they offer a good enough level of protection if the US government can demand access to data anyway.
Right. But since essentially the same concerns arise when dealing with businesses based in the EU, let's be honest and acknowledge that this isn't really an ethical question and doesn't really have much to do with either privacy or security either. It's just a matter of the EU and its privacy legislation considering EU prying to be acceptable but not US prying, which is a political decision.
In general, Members of the European Parliament have less understanding of business and trade than businesspeople and traders, and in my view[0] tend to follow their emotions more in those areas.
Some also have a streak of anti-Americanism, in varying degrees. As the heat increases, this sort of resolution may occur more frequently.
I'm sceptical of the notion that MEPs all voted according to their devotion to fundamental rights.
None of this means that I believe pursuing the resolution into legislation is a bad or a good idea. I'd have to see (and understand the consequences of) the proposed measure.
[0]This is an impression; I have no empirical data
This is what it comes down to, your disbelief that MEPs could have a genuine interest in their constituents' privacy.
Sure it does, but so do all the loopholes they wrote into those laws so EU member states could continue their own surveillance programmes and data seizure powers, and for that matter all the then-illegal spying programmes that were retrospectively legalised when Snowden et al brought them to light. Let's not pretend the EU and its members are whiter than white in this area, nor that the EU is above attacking the US tech sector through non-technical means.
or probably just general dissatisfaction with the U.S.
There’s certainly plausible deniability that it isn’t, I’ll give you that. Is it extra leverage that will almost certainly come into play? Yes, it’s also that.
According to the article, the only implementation on the US side was by presidential policy directive. So our faith in the US implementation of the 'privacy shield' is only as good as our faith in the integrity of said Directive.
Even starting from a low point where it's quite clear Trump is interested in tearing up anything Obama put his name to; his increasingly reckless approach to international relations lowers our faith in any presidential directive by the day. At this point 'privacy shield' either needs to make it into law proper, or we should just assume its days are numbered.
Why should the EU parliament care about that?
Plenty of EU business interests use AWS and Gmail.It's obvious why Google wouldn't be interested in a similar model for their products.
AWS recently wrote me an email, that because my billing address is in the EU, my contract has been transferred to a newly founded company AWS EU, which in turn has subsidiaries in most EU countries.
I have no significant business with AWS and have not investigated what this all means.
But I wouldn't be surprised if Amazon sees the risk that with the current US administration they don't want to rely on international business anymore. Having only national (or intra-EU) contracts with their EU customers seems just the safer option. Dealing with investments and profits inside a group of fully owned subsidiaries is probably much easier than dealing with two fundamentally different systems in every single customer contract. The EU striving for data-protection and the US insisting that foreigners have no rights and international treaties are bad unless they unilaterally favor the US.
Since AWS EU presumably shares the same infrastructure as AWS US it's probably more of an accounting trick (but keep in mind any GDPR fines would apply to the entire group, not just the individual corporation, so it's not really a financial protection).
The development is certainly positive and the GDPR is also very similar to pre-existing German privacy laws in many aspects, so I'm not complaining.
Because many thousands if not millions of smaller businesses across the EU depend on US businesses as well, and sharing some sort of personal data with them is often necessary for the provision of the relevant service.
Given the hassle and costs we've all just had with GDPR, the EU going all-in on undermining Privacy Shield would not be a welcome development for businesses.
Privacy Shield is a fig leaf more than anything. Using any US company (or non-EU company from a country without adequacy) is a major risk for compliance.
This is a bit like when people complained their companies were going bankrupt because Facebook/Apple/Twitter/Google shut down an API without warning. If you build your business on such a wobbly foundation, it's a calculated risk and you need to be aware of it.
It is entirely unconstructive to call US-based foundations wobbly when the EU-based equivalents (a) sometimes don't exist at all, and (b) where they do exist, suffer from analogous privacy concerns around government snooping.
The allegation here isn't that, to pick one relevant example, Stripe is abusing the personal data they process when they collect payments from our customers. The objections to Privacy Shield, like Safe Harbor before it, are mostly about the US government itself having rights under US law to gain access to that data, regardless of the actions or intentions of US-based businesses.
Now, I don't like the current heavy-handed approach to data hoarding by governments under the guise of national security any more than the next HN reader. But let's be clear: the EU and its member states do essentially the same thing, routinely writing special cases into privacy laws that exclude governments when they want to pry for supposedly security-related reasons. It is the height of hypocrisy for the EU authorities to allege that processing data in the US is unsafe because of the risk of US government interference, while at the same time turning a blind eye to what's going on in their own back yard.
In any case, since sadly there is little prospect of any of the governments involved on either side of the Atlantic giving up these powers any time soon, undermining otherwise reasonable privacy laws because of them serves no useful purpose. It just hurts businesses who are trying to do reasonable things, even if they are careful and considerate in how they handle personal data, and by extension it also hurts both their customers and the economies they operate within.
No, and I rarely hear that as the main concern.
The main concern with Safe Harbor et al. (where US businesses are dealing with EU businesses and – more importantly – EU people) is commercial abuse of data (Facebook!) and data breaches.
Government access isn't seen as particularly problematic in criminal and anti-terror cases, but in mass surveillance of Internet and telephone connections, as well as in the context of industrial espionage.
For the record, we have heard very different concerns then. One big concern I have seen expressed, particularly in the more recent context of the GDPR, is that the government surveillance powers constitute a legal obligation on businesses, but only EU versions of such powers are recognised as legal obligations on EU businesses. Thus EU businesses cannot avail themselves of that lawful basis for processing if they export data they control to a US business (even one covered by Safe Harbor before or Privacy Shield now) for processing and the US government then grabs the data.
The logical conclusion if all such schemes are struck down is that exporting any personal data to the US for any reason will become illegal, with obvious catastrophic consequences if the law is then enforced to the letter.
The main concern with Safe Harbor et al. (where US businesses are dealing with EU businesses and – more importantly – EU people) is commercial abuse of data (Facebook!) and data breaches.
The entire point of Privacy Shield, like Safe Harbor before it, is to give EU businesses reassurance that they are not breaking data protection law by transferring personal data to a compliant US business. Businesses that are doing things with the data that would not be permitted under the stronger EU regulatory regime aren't supposed to qualify for Safe Harbor/Privacy Shield status in the first place.
It doesn't prove a business implements privacy by design or takes any steps to ensure data protection. It just proves the business was willing to pay the registration fee and sign a bunch of legal documents that may or may not result in fines if proven to be violated.
Exactly, I didn't mean that Privacy Shield is the problem, but that it is trying to address that problem, but I can see that I expressed myself ambiguously.
> The logical conclusion if all such schemes are struck down is that exporting any personal data to the US for any reason will become illegal
But that's good! Not in the sense that we should wish for that outcome, but in the sense that the US should offer real assurances to us that allow us to enter such an agreement..
I understand the principle you're aiming for. However, as a practical matter, it is constitutionally impossible for the US to enter into the sort of binding agreements that would give you the assurances you seek, and there is no realistic prospect of literally amending the Constitution of the United States to make it more subservient to international interests so that it could give those assurances. Pursuing the strategy you advocate could only end in crippling large numbers of EU businesses, setting back the already lagging development of our tech and creative sectors by years more, and catastrophic effects on our economies.
A good general tries to fight only battles he knows he will win, but it's a crazy general who tries to fight battles he knows he can't win.