Google is moving EU citizens’ data to US?
andreagrandi.it
andreagrandi.it
"We’re improving our Terms of Service and making them easier for you to understand. The changes will take effect on March 31, 2020, and they won’t impact the way you use Google services."
No mention of Google LLC. And, surprise! I'm an Italian citizen living in Italy.
Facts:
1) I don't live in UK 2) They threated me at UK resident 3) It's not possible to change the country directly from Google account, you have to go to Play Store (which I don't use it anymore) 4) It was impossible to contact them
To be clear, I'm not saying you did so maliciously. Seems like an honest mistake on your part. Well, it did until you started digging in.
What does the GDPR say google should use in preference to the last known mailing address?
But it's really a non-issue. Google will make a good effort reducing such errors, and there aren't going to be legal consequences, nor wild leaving-Europe-for-good-drama as envisioned by some in this threat.
suuuuuuure.
I take this as a strong indicator, that Google believes you are a UK citizen.
My concern is: why do they mention UK leaving EU if I'm not UK citizen? And why there is no way to appeal/complain directly with them?
Mistakes can happen from anyone, but if they don't let me contact them I have no way of fixing this.
PR most likely. Within the UK this phrasing makes it less likely to actually be read / acted upon.
However there could be more than a few grains of truth to it as well.
(happy to dig up some legal documents by Allen and Overy a well-known law firm if people want to read an analysis).
Somewhere else doesn't necessarily need to be "in different jurisdiction"
Other disaster recovery concerns also mean that having large geographical distance between datacenters is a good idea. This can lead to jurisdictional issues, which need to be addressed when building the system.
[1] https://en.wikipedia.org/wiki/Electrical_grid#Wide_area_sync...
“ We continue to offer a range of international data-transfer mechanisms and we are certified under the EU - U.S. and Swiss - U.S. Privacy Shield frameworks, which are a legal mechanism to enable the transfer of personal data from the EEA and Switzerland to the US, where certified organizations guarantee to provide a level of protection in line with EU data protection law. We also offer EU-approved Model Contract Clauses for some services.
“We will continue to monitor the evolution of international data-transfer mechanisms under the GDPR, and are committed to having a lawful basis for data transfers in compliance with applicable data protection laws.”
I find it interesting they do not specify what data is internationally transferred, and that they “monitor the evolution” of mechanisms that are compliant with the GDPR, but never say they themselves are compliant. They only position themselves in the light of a Data Processor of the GDPR, but not the actual Data Controller (eg Google Search).
It all smells very fishy.
"We have top men on it."
"Who?"
"Top. Men."
> Data protection supervision over private organisations such as companies is carried out by national data protection authorities. All EU Member States have at least one such authority.
> You can also take up your complaint with the courts in the relevant Member State.
> The EDPS is not competent for complaints against such private organisations; we can therefore only refer you to the relevant national authorities.
Instead, you can find national authorities here: https://en.wikipedia.org/wiki/National_data_protection_autho...
The authority in the country where the headquarters of the infringing company are will handle your complaint, as per GDPR article 56(1)¹. I don't know what happens if you complain to your local authority, they might just forward it themselves or maybe they'll tell you that you're in the wrong place. It shouldn't matter much since GDPR is EU-wide, so you can just send the same complaint to another address.
¹ https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
In Google's case this is Ireland, so the correct link would be: https://forms.dataprotection.ie/contact
Note that I am not saying anything about the article, whether Google/Alphabet is wronging anyone, or calling for anyone to file a complaint. If you want to file a complaint based on what others said, this would be the place.
At all.
Firstly lets establish the rules using the ICO's (the UK's Data Authority) handy FAQ [1], a site providing a copy of the GDPR [2], the EU Commissions adequacy decisions page [3], the EU's privacy shield page [4], and the dedicated site for the privacy shield's Google LLC page [5]:
In short (yes, this is my idea of short):
* We, the UK, are currently in the transition period where EU rules still apply [1 - "What happens now that the UK has a withdrawal agreement?"]. This lasts until Jan 1st 2021 [6]
* We, the UK, are currently on track to have pretty much the same rules (cynicism allowed) [1 - "Will the GDPR still apply when we leave the EU"]
* So Brexit shouldn't change the legality (more cynicism allowed)
So are Google breaking the law?
* The GDPR has a provision allowing third countries and international organisations to process data presuming. It is Article 45 [2]
* The USA has been approved for this [3]. Years ago [4].
* Google LLC is approved under Privacy Shield [5]
So, there is no indication of anything illegal going on. Yes they are segmenting the data incorrectly and messaging an italian as though they are a brit. However the change would be perfectly legal was it to be done to the whole of the EU.
I don't like it, but it is legal.
[1] https://ico.org.uk/for-organisations/data-protection-and-bre...
[2] https://gdpr.eu/article-45-adequacy-decision-personal-data-t...
[3] https://ec.europa.eu/info/law/law-topic/data-protection/inte...
[4] https://ec.europa.eu/info/law/law-topic/data-protection/inte...
[5] https://www.privacyshield.gov/participant?id=a2zt000000001L5...
AFAIK, it's not illegal (per GDPR) to process EU citizen data in data controllers if the individual is no longer in the EU.
_Edit_: Yes, I read the article. It looks like this person got this email notification because they had activity in London (per their resume on their website). That doesn't make the email illegal nor does it mean their activity in Italy is going to be on a non-EU controller.
The email implicitly states that it's for the UK only.
It says on your website that you worked in London.
This email is likely a courtesy notification because you had activity in the UK, a UK billing address, or something that put you there, meaning if you have activity there again, the controller will be different.
What this email does not mean is that your Italy based activity is going to a different controller, so how exactly is this illegal?
* Read literally, the email only talks about the UK, not Italy.
* If you go to the UK again, then your activity in the UK will be on a nom-GDPR handler.
There is nothing illegal here, and just because you're sitting in Italy at this moment doesn't mean Google is moving Italian activity handlers. The email is a notification about Uk only.
However, the article still kinda vague to me, cause I got the same email, and I'm mos def in the US.
I'm so deeply inside the US that I have no idea how to check where google stores my data, and I don't really care cause the US has some bigger orange fish to fry. And pie to bake. Ajit Pie!!
However, I still don't think there's nothing illegal here. AFAIK & IANAL, It's not illegal to process EU resident data in data controllers outside of the EU (in the US).
Most people are taking the position that if either end of the request is in the EU or owned by an EU entity its covered.
What do you do when laws from different countries conflict with each other?
From my understanding, yes. Also if you are an EU citizen living in America, it also applies to you.
The simpler suggestion is that Google stop collecting and warehousing people's personal information.
I don't think the latter part is true. AFAIK GDPR does not give you the right do have your data owned or processed by an EU entity. GDPR does not say that.
It doesn't matter where your data is stored or processed, Google must still follow GDPR rules for data about EU residents. The first part of the comment is correct.
I'm not actually completely sure why some companies do this whole EU data controller seperate company thing. I guess for organisational or legal simplicity?
(Edit: I reworded to hopefully remove ambiguity)
https://gdpr.eu/companies-outside-of-europe/
It applies even to non EU citizens resident in the EU.
Google, however, does have entities within the EU, so they can enforce penalties or what not.
No. And your link doesn't support this assertion.
> It applies even to non EU citizens resident in the EU.
Yes.
According to their email, they think I'm a UK user:
"because the United Kingdom (UK) is leaving the European Union (EU), Google LLC will now be the service provider and the data controller responsible for your information and for complying with applicable privacy laws for UK consumer users"
But I'm not.
I can't say they are doing this intentionally, but it's surely a mistake and there is no way to reach them for a complain.
My understanding is that you always have the same rights. Whether Google follows them is another question.
It doesn't matter where the company stores and processes your data, as an EU resident, they still must follow GDPR rules.
EDIT: also if they believe you are a UK citizen they won't act GDPR compliant.
Companies need to be up front with you about what data they keep, and why, and they have to comply with the regs - but nowhere does it say your data has to be kept in the EU.
I'm curious as to where you have got the belief that your data must be stored in the EU. Perhaps you could point towards where in the GDPR you got this from?
Example: some_command -> where your data is stored at. I don't know how to verify that information.
Please elaborate. What is difficult? And why is it difficult?
Are you saying they're doing it by accident? Even if so, that means they're negligently handling the data. And if not, they're purposefully disobeying the law.
If they procrastinate, or do it sloppily, because they decide to do other things with their time than prioritize keeping their books properly, they are deliberately not doing their bookeeping.
It's the same thing with accessibility. People will say, "Our app isn't accessible, but that wasn't our deliberate choice, we just haven't tried to make our app accessible."
Nope. When you chose to spend time growth hacking instead of accessibility hacking, you deliberately chose money over accessibility.
Google does not get a pass because they didn't deliberately set out to do the wrong thing. By not choosing to do the right thing, the right way, they deliberately chose to do the wrong thing.