An unwanted update to your Google Account
roboleary.net
roboleary.net
> What I find curious is that it says the services are essentially the same between different countries. So, there is no advantage to me as a consumer for anything to change.
The advantage to the consumer is that they have access to the services at all. Countries have the ability to completely cut off their citizens to a service if they don't follow their laws.
> As someone who travels a lot (not recently!)
But yes, those kinds of thresholds are common when it comes to residency as an official concept for e.g. taxation. Usually the threshold is around 183 days, but there is no reason why it'd be obviously less arbitrary than other choices.
But most importantly, it's the number that the US government uses on form 8840, the Closer Connection Exception Statement for Aliens: https://www.irs.gov/pub/irs-pdf/f8840.pdf
And know I know why, it's because US goverments uses this number as a cut-off for some legal consequences. Thank you!
For the UK it's 31 days of more than 3 hours of work. I think it's the same for the US.
The Automatic Overseas Test
You would normally be considered a non-UK resident if you meet any one of the following elements of the Automatic Overseas Test:
You were considered as a UK resident in one or more of the previous three tax years, but you spend fewer than 16 days in the UK in the current tax year
You spend fewer than 46 days in the UK in the tax year AND you were non-UK resident in the preceding three tax years
You work full time outside the UK and spend fewer than 91 days in the UK and you work fewer than 31 days in the UK for three hours or less in any given day.Suppose a law in Mexico requires Google to store search queries and make them available to the government for 1 year, or it requires the collection of certain types of personal information, and a law in Germany bans Google from storing search queries or collecting the information. Now a German citizen travels to Mexico, and does a web query in Mexico, do you think Google should apply Germany's Laws or Mexico's laws? It will apply Mexico's laws because that is the jurisdiction in which the query is made. Similarly if a Mexican travels to Germany and makes a query, then Google will not store the results.
Btw, this is the whole point of international VPNs. People want an internet presence in different countries in order to access content that is not available in their own country or to be treated differently than if they were in their own countries. So if you, as the German traveller, don't want your query stored, you'd VPN to a server in Germany and run your queries through that VPN. If you ran your query through the Mexican ISP, you can be sure that the information would be collected.
Thus as much as European governments may want the GDPR to be a type of shield that you can carry with you when you cross over to other jurisdictions, the reality of that portability is limited to the ability of European nations to convince other nations to go along and treat Europeans differently in their own legal system. It may work, it may not, but whether it works is not a question of the GDPR but of the ability of Europe to project power and override laws in other jurisdictions.
A implies B does not mean B implies A
A. How long this person was in Malaysia
B. What local laws they may have been in breach of or in jeopardy of breaching(or Google)
C. What specific local rules/laws Google was attempting to comply with in good faith(if any)
B & C. I'm not a lawyer, but unless you're suggesting the law in Germany and Malaysia has literally no difference to the services Google provides, I'm not sure what your point is.
"The ticket retailer Proticket, for example, filed a lawsuit against the blocking of its account after offering tickets for the musical "Soy de Cuba" and the concert of a Cuban artist. Although Proticket won its case at the Dortmund Regional Court in spring 2016, Paypal still did not change its approach."
> All US persons, including US-incorporated entities, their foreign branches (including non-US entities owned or controlled by a US person that are also subject to US sanctions with respect to certain sanctions programs, such as the US's Iran, Cuba, and North Korea sanctions programs) and employees, are prohibited from transacting with sanctioned parties.
- https://insightplus.bakermckenzie.com/bm/compliance-investig...
I am pretty sure the EU and US have treaties requiring them to respect one another's sanctions.
So PayPal "EU" is actually just the Luxembourg Bank PayPal LU which is a subsidiary of the US Holdings.
I'm not a lawyer but it seems PayPal LU just facilitates transfer of funds from EU accounts to PayPal Holdings US. Once the funds are in the US, they are subject to US law.
The blocking statue protects EU Operators from having to comply with 3rd party regulations. But since PayPal LU is simply facilitating transfer of money from the EU to your PayPal account which is in the US, PayPal isn't a 3rd party to the transaction and thus has to comply with US sanctions.
Pretty sure PayPal EU wants to be able to send money to people in the US.
I created another mailbox and am slowly migrating to it. Fuck you Google.
Why shouldn't its users seek similar geographic arbitrage?
Of course as an Internet service you don't have to comply with every single national law there is. Would that even be possible? Of course, if a nation State believes you don't respect their laws, they are "free" to try and censor your website, as many do with The Pirate Bay, Sci Hub, etc.
Which for Google and other companies means basically most countries, right? For example they have an office in Malaysia (https://www.google.com/amp/s/www.businessinsider.com/googles...).
If you have an office, the state will be able to seize your assets, or potentially jail your executives. This is not like Pirate Bay or Sci Hub.
I suspect Google would be more aggreived concerning actions taken against 1600 Ampetheater Parkway, or one of it major datacentres, than against a one-person sales front operating from a bedroom in a remote location. It might well seek to safely extract its personnel, but would have little concern with the facilities or operations it represents themselves.
The quote from the article makes this even more clear:
>> I got the same Mail. They want to move my account from Germany to Thailand. I’ve not been to Thailand (or anywhere else) since 2 years…
They are in a very real sense a multi-national - and not just for tax purposes.
And there is no legal path, to be clear, your only option is not buying ebooks, but the physical one require me to travel to Italy, which is insane.
If you don't want to be subject to the laws of the country you're in[1] you have to move. Google can't help you.
[1] Edit: I guess in this circumstance better phrased as "If you want legal protections offered by a country you're not in..."
It seems rather clear that the author is physically in Malaysia.
> I mean, that matters.
Kinda but kinda not? If you're an american citizen and for some reason go spend 6 months or a year in Malaysia, you probably don't want your accounts to be switched over to Malaysia, and possibly Malaysian, a language you probably do not speak.
The author was concerned about losing privacy protection offered by Google to people in Germany as required by German law. Which is nonsensical, because German law does nothing to protect you in Maylasia.
I remember Google forums there were angry servicemen that got Google in Arabic when they flew to Kuwait...
You could move, apply for and gain citizenship in another country, or do other things to make these choices. But contracts are even easier: Just pick a place. That's what a choice of laws provision[0] is for.
You don't lose privacy protection by virtue of Google changing your location. You lose privacy protection by not being a resident of the jurisdiction with those laws.
Apparently there were enough signs in this case to conclude he had been in Malaysia long enough to trigger the rule.
Not really. If you take Google to court, and Google tells the judge "yo, he was connecting from a Malaysian ISP for like 2 years straight", the judge is probably gonna say "okay, yeah, I can see why you thought he was a resident of Malaysia".
The way I remember this working is that it is entirely dependent on the methods of payment (MOP) associated with your account. If you remove MOPs from country A, and then 30 days later you add a MOP from country B, your underlying gaia account will have the home country migrated (affects play store, etc).
The workaround is to use different accounts, each with MOP from different countries. Pretty sure IP doesn't matter.
Regarding which legal jurisdictions apply between you and a company like Google? Well, the courts are probably not going to consider what it says in your account profile.
> The workaround is to use different accounts, each with MOP from different countries. Pretty sure IP doesn't matter.
Maybe it has changed, because this was not my experience: my methods of payments have all remained the same. It appears to be based on IP, because my transition was delayed compared to family members who moved with me because I had VPNed back to the country I had left. I’m pretty sure it was IP based, because the relative delay approximately correlated with how many days I’d used the VPN for.
And as far as Google Play Store is concerned, I’m American for some completely unknown reason, and they refuse to be convinced otherwise unless I give them credit card details; so any apps region-locked to Australia are out of my reach.
Local TV providers still use region-locked apps for streaming services.
As shown in Google’s Terms of Service, your account is associated with the following country: .
It seems there are things Google don't know about me, even though I'm not making this information secret.
I could find a way to change it and have the local store when I moved to Japan, but honestly I don't remember exactly how.
I only remember that it was a major pain in the ass to understand how to do it. I had to navigate between different applications (notably Google pay) and web interfaces to finally be able to change this setting. Worst UX ever.
Granted, I wish Google's approach to privacy was better all around, but given that they want to gobble up as much data as possible, and we all know about that by now, I am not as confused by their approach here as I am by the author's reaction.
why not ?
If I sign up with a small company based in, say, Chile, all of my information is likely to be stored there or at least governed by Chile's laws no matter where I am in the world.
The author of this article appears to have engaged with Google on the terms presented in Germany but is accessing Google services from Malaysia. The difference is that Google has a more-substantial presence in Malaysia and is hence more-beholden to Malaysia's laws. Our hero's ability to choose to interact with a first-class service while being treated as a German while abroad has been substantially degraded.
Maybe not but some of my accounts have been associated with European Google entities so it works both ways. It seems that they're simply sorting by IP from which you most often access it since consistent use of proxies resulted in predictable country association.
Recently they made YouTube Premium available in this market. And with the YouTube Music change, this also came included. However, I don't know if they fixed completely fixed the issue of viewing USA only videos from here.
I have the impression he mistakenly thinks it stayed with Germany?
Though note that the dates may be confused: the article was posted on May 1st but the edit is marked April 4th, for an update to an article which would have been posted a month later.
Most likely the date for the update is wrong and should be something like June 4th, and in
> Which will happen first? The automatic switching of the country association, or Google responding to my inquiry? It’s going to be a race!
the automatic switching won.
I don't get that impression. I think the reason it's in bold with is to show that even after the manual attempt to change it, Google responded with "sorry, still Malaysia".
Firefox has it under "Choose your preferred language for displaying pages" which seems appropriate to me.
The other one is: pick to one language and stick to it. If the page I'm reading is in some European language, please show the GDPR messages in that European language not some other language. If it's a French blogspot blog being visited by a user in Germany, show the messages in French! This is almost guaranteed to be 100% reliable. It's not like Google is ignorant of the language of the page. (I can understand not having GDPR messages translated into say Indonesian. But if you do, then again - match the language of the page.)
See also: client side certificates
I haven't seen anybody install software on the wrong language by mistake for a long time.
Not saying that I think it's OK to just ignore what is the STANDARD WAY of specifying my desired language, just saying this type of crap is what they're going to argue when trying to justify it.
I'm curious to a few things that are absent from the post but a lot of people in here are talking like they know the answers to:
A. How long this person was in Malaysia
B. What local laws they may have been in breach of or in jeopardy of breaching(or Google)
C. What specific local rules/laws Google was attempting to comply with in good faith(if any)
It's amazing how many people are jumping all over the OPs case like they have this information. If this were a bank account and/or China I don't think everybody would be giving the company the benefit of the doubt and casting shade on the OP for raising concerns...
Not as onerous as transferring a bank account to another entity, but the oversight is pretty extensive nonetheless.
There are many other services that provide much better privacy protections, eg ProtonMail.
We don't see this at all.
That tells me these services are compromised on some level.
A little while ago I noticed plenty of different VPN providers. Many of the smaller ones were bought and private labelled or had smear campaigns against them. Companies compete so some of that is understood.. but the extent of the attacks tells me players with powerful networks (governmental,business or rogue) shut down many legitimate smaller VPNs whike help promote others.
I would be wary of using any VPN if I expected privacy.
Rolling your own is easy enough but be careful where you setup shop.
I believe that there are still honorable companies out there (and I don't even use ProtonMail in particular)
I wouldn't trust any other email provider than one of those three, if I would need to have truly secure emailing via a 3rd party. But none are in a different position that Google, maybe with exception of ProtonMail.
Which ones would you list?
[1] https://en.wikipedia.org/wiki/Gesetz_zur_Beschr%C3%A4nkung_d...
Email is a small part of things I care about. Moreover, there's snowflake's chance in hell I succeed at convincing every correspondent to switch to e2e encryption and off services no more trustworthy than Google or Microsoft. So, the technical premise of ProtonMail doesn't help.
When it comes to Swiss privacy law... I'm already protected by GDPR. Google is a juicy and politically convenient target for most countries, so I'm not worried about its compliance. And I'd rather stick to a company with a legal team equipped to wrestle with government overreach.
Finally, I feel perfectly fine trusting Google to keep my private things private. I keep copies of important documents in Drive. Realistically, the highest risk vector for them leaking is someone pwning my machine.
Being "private" doesn't magically make GDPR affect non-EU residents.
- Geographical location of data (Data regions) for Google Workspace
- Culpable deniability about a user's location when anonymously accessing Google Maps
- Compliance with local laws where the user is physically located when accessing a service
- Region locked applications
- Financial/banking restrictions
I'm sure there are more. Google is justifiably concerned about compliance and liability. That's the incentive for these changes, not improving the user experience.
It's not just Google, this is the modern web. If you use a web based service I think it's better to assume everything you give them is theirs, otherwise it's an impossible battle of constantly reviewing massive ToS changes and a mutating product/features. I guess this view probably sounds a little out of touch but it's easier if you don't use a smart phone.
One of my favorite stickers: "There is no cloud, just someone else's computer"
Techies hate it when you point crap like that out - because it re-enforces that trust, reputation, creditability, character - all those things matter. And most tech companies have damn little of any of those :p
Why do I want to change?
When I signed up, the currency was USD and perhaps the country stayed USA too! There was no Indian pricing at that time (I think over a decade ago). For the US pricing, I pay $30 monthly for a 5-member plan. I want to leverage the Indian pricing of ₹125 (~$1.6) per account per month.
As a user, I might have Germany as my country in Google while living in Malaysia: maybe I like its privacy law better, or I'm a German ambassador on a diplomatic mission, or a German citizen on an exchange program, or a Malaysian citizen who signed up for Google while on vacation in Germany and is now confused about some parts of their account.
The point is, only the last scenario needs some fixing, while in all other cases, the user will understandably prefer to keep the country unchanged. Yet Google forcibly and preemptively switches country in all these scenarios, with no real benefits to the user.
But if there is no real benefit to the end user, and not everyone wants this, why force this change in the first place? Something technical that has to do with local laws.
And that's where it's really bad: - It's bad as a principle, because if a person signs a contract with an entity under a specific jurisdiction, that person doesn't expect the jurisdiction to change unilaterally. - It's bad in practice, because instead of knowing with certainty that my data is under a specific jurisdiction, I'm now subject to some automated process that could unilaterally move my data to a random country, resulting in unintended exposure to its laws
It is a coincidence, I recently had my account changed from Australia to Germany. Seems to simply depend on your IP, as I don't have any payment methods associated as speculated in another comment.
If they switch the country, did you get the prices of the new country or do you have to pay the prices of the original country association?
Isn't it a violation of privacy to track the user in that way?
Would it not be the correct way to ask for prove, that he resides in Germany and not simply switch the country?
This gave me the TOS matched to the country that Google thinks I'm in. (They're correct, in my case)
If I sign in, the "Country version" line is gone, though I'm still (correctly) shown the EU terms.
Why now? And why the wrong country? I have no links to country X and I haven’t been there in months.
So it doesn't matter where you live if the service is out of reach of this law.
That's only correct with regards to the processing of data subjects who are in the European Union. See Art. 3.2 of the GDPR.
"451: Unavailable due to legal reasons
We recognize you are attempting to access this website from a country belonging to the European Economic Area (EEA) including the EU which enforces the General Data Protection Regulation (GDPR) and therefore access cannot be granted at this time. For any issues, contact ..."
https://ec.europa.eu/info/law/law-topic/data-protection/refo...
Is Google required to comply with GDPR data and deletion requests made by EU citizens that Google has deemed to be be residing in Malaysia?
Since you’re familiar with GDPR, I would appreciate your opinion on it.
That switch made im a EU citizens living abroad using non-EU services, so no GDPR protection.
Coincidence?
Technically, it doesn't even apply to citizens, but to countries that the company markets to. The link explains all this.
Here it is the same, if he uses EU Google he is protected, because of the switch to Google Malaysia he isn't anymore.
Google probably does not as they surely don't do processing of non-EU user's data within their EU subsidiaries.
But what's a "resident"? That means where you live, not where you're temporarily staying.
> A German citizen in the US isn't protected by the GDPR.
If he's just visiting the US he's still a resident of Germany, AFAICS.
https://www.compliancejunction.com/does-gdpr-apply-to-eu-cit...
> When an individual leaves an EU country and goes to a non-EU country, they are no longer safeguarded by GDPR.