Google Admits Handing over European User Data to US Intelligence Agencies
news.softpedia.com
news.softpedia.com
Google had two choices:
1. Don't hand over the data => they break the US law
2. Hand over the data => they break EU law plus hand over personal data of users who might not want that
To me choice number one would be the lesser "evil" thing to do.The solution is to have completely separate entities of the company in the local jurisdictions. Those follow local law and only share data with their foreign sister companies in a lawful manner and otherwise can ignore foreign law. Of course this creates some complexities but it's the right way to do, everything else gets you into trouble and even huge companies as Google can't get around colliding laws from different jurisdictions.
Handing over data to intelligence agencies is just one example of mutually exclusive laws. There are actually many more like data retention laws. The internet is probably the biggest challenge to international laws and treaties ever.
If Google have exported the data to a US jurisdiction under Safe Harbor, then a subsequent PATRIOT Act request wouldn't need to involve any EU-stored data or EU companies.
This seems like a much more general issue with exceptions like Safe Harbor, and something that people/companies should bear in mind. Promises like "equivalent" protection don't help with new local laws which can always trump anything.
By complying with the request they immediately violated the safe harbor provision.
It's not clear whether the Data Protection laws were ever designed to guard against national governments. I imagine that those who wrote them were really thinking about avoiding disclosure to private individuals or other companies.
This isn't true; the WirtschaftsWoche article doesn't claim this. It says this could happen, but the claim that this article says it already did happen is a lie.
Not that this means it hasn't happened or is unlikely.
Die US-Regierung könne "auf außerhalb der USA gespeicherte Daten zugreifen". Der Konzern habe schon viele solche Abfragen erhalten, schreibt ein Sprecher des Unternehmens.
-- Rough, sorry: --
The US government is able to to access 'data stored outside the USA'. The company already got a large number of these requests, comments a spokesperson of the corporation.
--
Put like this, next to each other, is a strong indicator (yeah, it's still on the edge) that they did, in fact, already comply in the past.
First part is 'would/could/in theory' style, but the following sentence says they got these requests in the past and 'diese' (these) builds a rather strong link to the sentence before.
So - I'm not 100% sure, but let's error on the side of caution: They did it in the past.
I assume that WW would have used a much stronger phrasing, had the "Google spokesperson" actually said that. And a Google spokesperson is obviously careful when talking to the press.
Yes, it's not unlikely that they did -- but Softpedia is blatantly misquoting here. They base their writing solely on the WW article, and that one doesn't include anything to back up the claim.
In some cases this is still currently impractical to do on a day to day basis but in others such as Email, Social Networking or Instant Messaging it is not[1][2].
[1] I'm involved with a company that recently launched a free tool that provides transparent client-side AES256 encryption for Facebook, Google+, Major Email apps among others.
Google EU has a mission to "provide Google US with data hosting, and send profits back to the mothership". They have a contract, in which Google US grants free use of any code data that Google EU needs.
Google EU has a strict constitution, which prevents them from disclosing data, even if Google US wants them to. This clause in their constitution states that it cannot be changed.
If that's too extreme, they could allow the information to be released, but only if cleared by some specific third party.
That's just a rough idea. I'm sure Google's lawyers could come up with something much better.
While it would be technically possible, I think Google are probably happier just not dealing with the more paranoid businesses that are worried about this. That's the impression I got when discussing similar issues with their sales staff.
http://en.wikipedia.org/wiki/The_Shadow_Factory
http://en.wikipedia.org/wiki/NSA_warrantless_surveillance_co...
> Gordon Frazer, Microsoft UK's managing director, made news headlines some weeks ago when he admitted that Microsoft can be compelled to share data with the US government regardless of where it is hosted in the world.
He was pitching Singapore data centres and made the joke that US could just tap into any of the data centres with a warrant just like that. Then his laugh died in dry painful way leading more or less everyone in the audience to assume that the warrants had already been issued.
In other words, the PATRIOT act provides corporations with the least expensive option for providing user data and provides them with political and legal cover when they do so.
About fixing the law -- In that case I would expect Google to fight the government on this point. I wonder if they are/will?
Most people would understand the real culprit is the government. Microsoft and Amazon space there data centres geo graphically for a few reasons, and this is one of them.
The law's evil as well, agreed. The government did evil things passing it, in my world. But that doesn't seem to be the reason for the 'Google did evil' claim here.
Okay, not about this issue exactly, but the amount of data that Google collects on individuals is Law Enforcement's dream.
Edit: here is the article in question: http://www.wiwo.de/politik-weltwirtschaft/google-server-in-e...
They asked if their EU based dataceters are also subject to US warrants and they answered that they are.
It's the law. What's more, it's a good law. I am concerned that they broke it, and seem to have tried to hide this.
They don't seem to have tried to hide anything. From another report: http://www.h-online.com/security/news/item/Google-also-passe...
The previous Microsoft admission that sparked this line of questioning: http://www.h-online.com/news/item/US-authorities-have-access...
Relevant: the Google Transparency Report: http://www.google.com/transparencyreport/
I reject the idea that a US law is more important in Europe than an European one. If that is what has happened, then it is wrong.
If nothing was hidden, why is this policy only coming to light after the fact? There seems to be some degree of not wanting people to know.
There are a number of reasons why both the government and the companies would want to keep it secret:
1. Bad reputation for the company.
2. Bad reputation for the government on how much spying they actually are doing.
3. "keep quiet about it in order to avoid exposing active investigations" (this point I would think to be irrelevant in this case however)
Which are much the same reasons why someone who has stolen a TV would want to keep that secret. It doesn't make it an idea worth encouraging.
I think they should be punished by law to the fullest extent available. Along with everybody that was responsible and is within the reach of EU law.
Actually, the EU should request extradition of those responsible that reside in the US, even if they didn't break the US law. Fair, isn't it?
For the parts of Google in the US - yes. For the parts of Google in the EU - no.
That's a very incorrect statement. Noone can make you break the law.
In this case, the correct interpretation is, preventing US companies from having EU subsidiaries. Which means that the US offices have to be a subsidiary of some overseas corporation (i.e. make Google incorporate in Europe, or possibly some tax&law haven, like Cayman islands (I don't actually know about the laws there, but I'm sure there is a place on earth that would be ok)).
By, uh, mentioning it to journalists? There's a difference between hiding something and simply not announcing it loudly to the world.
But not a huge difference. It's something that would definitely be of interest.
I won't comment on the law in general for the discussion's sake, but not being allowed (or: required) to be transparent about the disclosure of data is just evil in my world.
My opinion is that they need to comply with the laws, which might require not having overseas companies in this case. Could they operate without them? Do they only exist for dodging huge amounts of taxes? (If yes, then this means that Google decided to "do evil" in return for a 20% boost in earnings)
And going to europe isn't really feasible when most of the developers they hire come from the US. They could come to Canada if they want (they already have offices but they could just move the head office.) :)
Basically this is another law that fails to face the reality of globalization and is a strong overreach of the US Gov. It's potentially also destroying jobs if companies as you say must choose a place to be in.
The law has been taking much less of a backseat in Europe when it comes to security and anti-terror. Also I find it hard to believe that the EU would just give up its data protection laws just to please Americans and allow the enforcement of an American law.
Which is possibly preferable for every US-company which thus do not have to challenge your agencies.
Public sentiment does sway sharply in the aftermath of events like 9/11 (or, in our cases, 7/7 in London and the like). We sometimes tolerate nanny state behaviour and suspending basic rights and freedoms more than I personally would like following such extreme, high-profile events.
However, even then, public sentiment seems to sway back again much faster here. Just look at the level of public concern over a tiny number of high profile deaths in the UK in recent years where police were involved, or look at how sharply Google have been slapped down over privacy in places like Germany. I think this is probably down to having a lot of very different cultures who have come together in their common interest but never merged to the extent that the US is a federation of relatively similar states. Consequently we have a much broader spectrum of political opinions permanently in play here and it's much harder to permanently overrule many years of history and precedent without someone objecting loudly enough to slow things down and force more debate.
There seems to be an inherent tension between recognising that the US is often a useful partner in economic and military matters, and recognising that we must not act as some sort of junior partner to a country that frequently gets big issues spectacularly wrong and that has a demonstrated history of screwing its partners whenever its own interests dictate.
My sense is that the US has been cut a lot of slack in recent years because of its economic strength and 9/11, particularly when we had Blair running the show here in the UK, but that public patience with the one-sided deals and all the silliness we have to put up with as a result is now rapidly running out as we have our own problems to deal with and the US are getting in the way or indeed causing some of them.
I'm less concerned by the fact that Google handled the data over US agencies than by the fact that the EU doesn't seem to have made any objections.
Whether it's because the EU doesn't care, or because they was nothing they could possibly do, I don't know. But either way, it doesn't sound right to me.
Read that statement. Again. Are you worried yet?
Are you saying that Europe is not governed by law, and citizens protections are optional there, or just that this is what happens in the USA?
If the former, I hope Europe can fix that. If the latter, why is Europe's problem?
The EU must enact sanctions against google for this, if they don't they are essentially letting all multinationals know that EU laws are less important than American laws.
That will, in this particular case, probably result in a significant dent in both the US and EU economies in the immediate future, followed by a phenomenal boost to the European economy at the expense of the US in the longer term. That will continue until the US understands that it can't just impose its will on other countries around the world any time it feels like it, and more specifically that while the US government and big business don't care much about privacy, it is a fundamental societal value in several EU countries.
I think we do much better with our current model, where each jurisdiction has its own legal and ethical norms, jurisdictions may reach multilateral agreements on areas of common interest, and anyone wanting to operate across jurisdictions needs to do so in a way that is compatible with everywhere they operate and any common agreements between those places. In this case, economic incentives for major multinationals to be able to operate across borders is, or at least should be, a compelling reason for national governments to accept their limitations and not try to exert influence beyond their borders in unsustainable ways.
That's what the European Union is about.
That's what some people would like the EU to be about. Fortunately, there is a healthy diversity in people's views on that issue just as with many other issues. Thus, in practice, we have always had European integration on several different levels depending on the individual needs of the nations involved and their collective benefit from co-operation.
Today, being in the EU is not the same as using the Euro. Though the Lisbon Treaty blurred a lot of lines, we historically had the European Courts of Justice rather separate from the European Union as well. There is a lot more historical detail on Wikipedia's page on the EU if you're interested.
If anyone thinks Europe will still look the same in five years, I think they are probably missing something, given the obvious differences in financial power between say Germany and Greece today and the obvious negative effects it is having on the better off nations. Who knows the consequences at this stage? Maybe the result will be closer integration where the financial policies of the weaker nations are restricted by the stronger nations who support them. Maybe Europe will fracture as an economic community but perhaps continue as a legal, diplomatic, free trade, and/or military one. It is clear that on matters like the privacy issue at hand, there is a lot of common ground on the basic principles regardless of economics, so I suspect that side of things will be maintained.
"As a law abiding company, we comply with valid legal process, and that - as for any US based company - means the data stored outside of the U.S. may be subject to lawful access by the U.S. government. That said, we are committed to protecting user privacy when faced with law enforcement requests. We have a long track record of advocating on behalf of user privacy in the face of such requests and we scrutinize requests carefully to ensure that they adhere to both the letter and the spirit of the law before complying."
From that, it sounds like the data is subject to subpoena, but it would be nice to not have speculation three layers thick on this point and just get a straight answer.
The old adage that 'if you have nothing to hide, you have nothing to fear' has been thoroughly incorporated into modern state doctrine.
So downvote at will, but it would be nice to do so with some counter-arguments.