On the positive side this might give startups based in the EU a small edge over US competitors (I know, protectionism is evil, free market rules, Europe tech startups are not competitive...).
US companies can still do business in the EU btw, they will just need to structure their services so that data from EU citizens stays within the EU. For the larger players this shouldn't be an issue really, I think, smaller startups with limited resources might forgo the expansion into the EU though.
Most of these regulations are just anti-US protectionism in disguise. Regardless of the underlying merits of any such regulation, they’re used as trade barriers to give EU companies an edge over US ones, without doing anything as controversial as tariffs. I mean is there any material difference for a German citizen if their surveilled French intelligence over US intelligence? Sure, they have the EU courts to rely on, but if you’re caught up in a foreign (or even domestic) surveillance dragnet the outcome is going to be exactly the same, and there’s nothing you can do about it. All these agencies share huge amounts of data anyway, so the difference becomes quite academic.
> US companies can still do business in the EU btw, they will just need to structure their services so that data from EU citizens stays within the EU
I’d suggest people look at all of the privacy enforcement action in the EU, and ask themselves whether they think the actual outcome is protecting the privacy interest of EU citizens, or just the economic interests of member states.
BTW, I have to guess that your logic doesn't apply when the US refuse its data to go to China. Are you also saying that this is also pure US protectionism in disguise?
> BTW, I have to guess that your logic doesn't apply when the US refuse its data to go to China.
This is the more hilarious aspect of this. EU and US intelligence agencies share huge amounts of information. If an EU citizen is spied on by say, France. Not only are they not going to know it’s happening, not only is there essentially nothing they can do about it, but the French government are more than happy to share anything they find with the NSA [0]. If the EU actually had a legitimate concern about US intelligence gaining access to EU citizen data, then these intelligence sharing arrangements would be illegal.
This ruling doesn’t prevent US agencies from spying on EU citizens. The only thing it achieves is forcing US companies to do more business in the EU.
[0]: https://theintercept.com/2018/03/01/nsa-global-surveillance-...
If not, it's not super clear to me what the work-around is other than completely isolating the continents.
How can you see a private profile if it is private?
The trouble is that as a small business we can't afford to have two separate operations teams for the US instance vs. the EU instance. We're all based in North America too and it is not practical for us to hire a whole separate devops team for Europe.
Our US based engineers could in theory be compelled to hand over the data stored at rest in the EU. They could also in theory see PII like names or email addresses in the course of administering the application on their laptops in the US which counts as data export, so would still need Privacy Shield or now SCC to allow engineers to do their everyday work keeping the product up and working.
> In those circumstances, the Court specifies that the assessment of that level of protection must take into consideration both the contractual clauses agreed between the data exporter established in the EU and the recipient of the transfer established in the third country concerned and, as regards any access by the public authorities of that third country to the data transferred, the relevant aspects of the legal system of that third country.
> [...] that decision imposes an obligation on a data exporter and the recipient of the data to verify, prior to any transfer, whether that level of protection is respected in the third country concerned and that the decision requires the recipient to inform the data exporter of any inability to comply with the standard data protection clauses, the latter then being, in turn, obliged to suspend the transfer of data and/or to terminate the contract with the former.
This ruling was in no way surprising, though. Anyone doing due diligence should have easily seen that Privacy Shield was going to be struck down by the CJEU eventually.