If you take the article at face value, it is illegal to create any kind of TCP/IP connection with a server that is operated by a company which does not operate exclusively in the EU.
This is a strong interpretation, but it‘s really not far off from what the court did here: they declared it illegal that an IP Adress (!) was transmitted (not stored?) to a company that could potentially (?) be subject to non EU subpoenas.
If NOYB managed to make the entire internet illegal just so they have a sharp axe to go after the things they don‘t like (Google Analytics, cookie "consent" banners), congratulations. They have built a slope so slippery it should have an ICU at the bottom.
In my view there is no crime bad enough that it justifies having laws on the books that criminalize everyone just so we can selectively enforce them against the bad ones.
In my view there is no crime bad enough that it justifies having laws on the books that criminalize everyone just so we can selectively enforce them against the bad ones.
It may be worth noting that this doesn‘t involve a fine, only that they cease the activity. That is my personal silver lining as someone operating services within the EU that clearly are not lawful.
It‘s literally a scorched earth, because it will be pretty tricky to provide even gopher services to a global internet until we develop a TOR like alternative to TCP/IP.
I don't know what makes a US company eligible to be sued in a EU member court. I guess you have to be doing some kind of business with European customers, so a non profit blog may be ok?
How do you solve this? You have to create a legal entity not connected to you that can purchase a server within the EU and then somehow syndicate your content to them without establishing a strong legal connection.
I think this only impacts EU providers who sublicense to US providers, if/when they record any ephemeral data collected prior to the user consenting.
So an EU business logging the IP addresses of visitors might be not-okay until they consent, though GDPR has some flexibility around “IPs power the Internet”, so long as you don’t try to convert them into personal identifiers.
That applies whether US or EU providers are involved, but as the courts point out, any non-ephemeral data within US territory or corporate boundaries is an automatic GDPR violation for an EU company.
So, in the gopher example, as a US provider you can do whatever you want, and as long as you’re approximately complying with CCPA, you’ve got GDPR in the bag as well, especially if you just offer the same rights to all users (to not be tracked by default).
But as an EU provider, if you host your Gopher server in the US, you may well be violating GDPR as a citizen of a signatory country, since a U.S. provider can’t honor the choice to not record ephemeral data, and therefore compliance is impossible even if the provider currently honors it.
This means that AWS is probably not a legal provider for GDPR purposes, since they can be compelled to ignore GDPR, unless the US signs a new treaty. And that’s the terrifying reality of that safe harbor agreement expiring that may result in Amazon having to restructure itself to avoid losing the market; the US entity would have to become a subsidiary of a parent in a treaty-signed country.
If so, that's my point. As far as I understand what Akamai does, they where probably just the conduit for establishing a TCP/IP connection to the Cookiebot service. The court neither felt the need to establish that Akamai stored the data, nor that it left the EU. The mere fact a non-EU company was involved in the connection was enough. I'm probably wrong, and I would like to know how, to maintain my sanity.
You mean an ISP? No, Akamai isn't an ISP.
Cookiebot is unambiguously using its own trustworthiness to let Akami access their users' personal data. There's nothing fuzzy or dubious here.
The only news is that what many people expected to be perfectly legal, that is doing that with a confidentiality clause and never having the data leave the EU actually wasn't, because of a different detail.
If I serve images from Akamai (or Cloudinary, FileStack…). Do you think that‘s problematic?
Do you think apple is is deceiving me when I download a song from iTunes?
Yes, the GDPR has rules that very clearly apply to CDNs, hosting providers, and etc.
What is new is that Akamai breaks those rules. I don't know the situation of the other ones you cite.