Austria's data protection authority has found that Google Analytics is illegal
tutanota.com
tutanota.com
Amazon and Cloudflare are all great service but your data is under US jurisdiction.
[1] https://blog.cloudflare.com/introducing-the-cloudflare-data-...
GDPR is written the same way.
i.e: https://gdpr.eu/article-3-requirements-of-handling-personal-...
The same way that US sanctions are applied by the US and everyone everywhere should follow them or risk fines and sanctions. No other country does this - when France sanctions Iran, only French citizens and companies are concerned.
"These laws apply outside our borders because the data is stored by our companies"
...are both examples of projection of power beyond borders, just with very slightly different rationale.
The US withrawing the CLOUD Act.
How would Excel being run locally, with its work product being emailed back and forth, be impacted by this?
The history of this strategy working, versus becoming a job/contract bank for cronies over time, is very poor in the long run. Regardless of the political system which attempts it.
Besides, EU bodies just make the rules. They don't need to provide actionable alternatives or even have to comply with those rules themselves.
Just don't upload that CSV containing all of your customers to Microsoft, that shouldn't be too hard.
Have you ever worked in a large organization?
I can't wait to see the clusterfuck of them trying to migrate away from MS.
Netcup, xTom, Hetzner, OVH, Scaleway just off the top of my head
Disclaimer: I work at Nextcloud so I'm a bit biased
Please do not email us from private mail addresses like gmail, gmx and the like. We only provide a trial to businesses > 50 employees. As a small business or private user, we recommend you simply try our demo or talk to one of our partners.
You can't even get people that need a simple word processor or spreadsheet to use LibreOffice.
The courts, not consumers, are the ultimate deciders in this situation. Companies say so under oath and a judge weighs the evidence.
When a company decides to use a product, it needs to ensure that product is legal to use in their jurisdiction(s).
If it gets to a court, it's likely that the consumer/client is the claimant and the Company who chose to use US Product X is the defendant. The company who makes US Product X is likely nowhere to be seen.
This is the proximal decider. They’re predicting the decision of the ultimate decider, which remains the courts. Providers would have to make the proximal deciders comfortable that the ultimate deciders will accept their compromise.
This means that as a business, theoretically you'd have to vet every single customer and supplier regarding their involvement with US-based companies.
Since realistically this would amount to most companies not being able to do any business at all anymore - and consequently the economy grinding to a halt - in most cases this doesn't have immediate repercussions.
However, such unpredictability caused by regulations such as GDPR is a huge problem because you can't ever be sure you won't be issued a - potentially crippling - fine simply because some local authority considered this a good idea.
Technically, the US can seize the assets of a US company that refuses to comply with these rules (or simply have their CEO arrested). That's what it comes down to: If a US company has a controlling stake in a subsidiary it's legally obligated to hand over any data that subsidiary controls.
The EU on the other hand could escalate this further and prohibit American citizens and organizations from owning a majority stake in EU-based companies because that's what this boils down to on the other hand: Running or even just doing business with a company that's controlled by a US entity technically is illegal for EU businesses and citizens right now.
This is not a pretty situation, but it's not one either where one side is clearly right and the other side is clearly wrong.
In principle, I agree with the EU point of view. Privacy is a fundamental right that should be upheld. However, de facto outlawing most economic activity and then washing one's hands of any responsibility to provide a reasonable alternative is no solution at all, but makes the problem worse: Businesses might establish legal entities outside the EU, where they're not affected by this. Others might try to host and run everything themselves, which will result in much less secure data and infrastructure because most SMBs simply aren't able to provide the same security standards as Microsoft, Amazon or Google.
It's on the EU und the US to provide a dependable legal framework for dealing with these types of situations. That's ultimately what entities like the EU are for, after all.
how is this suprising? This has been the case in Civil law since atleast napoleonic times.
Contracts do not declare laws or rights invalid, unless these exceptions are defined in said law.
So the SCC's are a perfectly fine tool, but you just need more than that.
In fact, this whole case is exactly about that. Some Austrian website tried to use Google Analytics and just added another disclaimer in their cookie banner. Now they are facing the consequences.
There should be accept all, accept necessary, reject all options.
The cookie banner anti-patters are most infuriating game of gotcha since tiny moving X button on pop-up ads.
So regarding your question, I guess the answer would be: A European website makes use only of services, which are not in danger of the US (or other countries from outside Europe) ordering the company to grant them access to the data. I guess this means, that you cannot use any services, which are offered by companies, which store data in the US and possibly even if they store it elsewhere, but fall under US law.
I'd guess a "European website" stands for a website that safeguards EU users by being compliant with GDPR.
Are the any alternatives that offer the same kind of thing as Google?
This is poor reasoning because it is missing context.
Still, it looks like the cheapest option out there. Matomo costs €19/month, Fathom - $14/month (or $140/year), Piwik Pro has a free option, but they're very enterprise oriented, not sure if they're good for small sites
Or you can rely on server logs.
Luckily for everyone but simultaneously sadly for the curious ones among us I think the referer header is broken so the thing I always wanted to know - where users came from - is a lot less useful these days.
Damn it! Looks like I'll have to set up my own web server and save the logs myself.
I'd even be happy with one that makes it in the top 10.
The reality is that we don't have the same ability of popping companies up and funding them.
Hell it could be the next Boeing-Airbus saga for all we know. The Chinese certainly don't seem particularly bothered telling the US to go fuck itself.
At least that is what I'm hoping for, however unrealistic it might be.
But seriously: Google just needs to move the problematic part of their EU business into EU and start complying.
Microsoft once had the right™ offering: Deutsche Telekom running the Azure data center, so it's the same software etc., but legally fully separated. Didn't get many customers (I don't know what kind of restrictions there were)
Google can run the same servers and stuff in Europe with European stuff in their own servers. They just disable things not allowed in EU and don't send user data to the US.
Now to be very clear! I am not against most of GDPR. But some of the interpretations of it have gone too far and it will hurt Europeans in the long run.
This is actually one of the best things that can happen to companies like google and Microsoft as they can afford to develop the infrastructure to support easy geo based cross continent data storage - and they can then sell it as part of their cloud offerings.
In theory. Reality is quite far from that, as anyone on the ground can attest.
There is zero chance, for instance, that anyone in Greece or Portugal or Ireland will be impacted, judicially, by this decision for several years. That’s better than before. But it’s far from e.g. a U.S. federal court ruling in California’s impact in New York, or a French court’s ruling in Paris in Marseille.
That's a charitable phrasing. As per Protocol 2 on the functioning of the European Union, article 8 [2]:
The Court of Justice of the European Union shall have jurisdiction in actions on grounds of infringement of the principle of subsidiarity by a legislative act, brought in accordance with the rules laid down in Article 263 of the Treaty on the Functioning of the European Union by Member States
What Poland did was declare nationally (government, and then a national court) that the EC was infringing on its sovereignty (principle of subsidiarity). But as the above text says, national governments don't have jurisdiction when it comes to matters questioning the primacy of European law.
[2] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:12...
This is the essence of a divergence of theory and practice. The text says one thing. In reality, something else plays out.
I think the text will prevail. But that delay (and uncertainty) is precisely what I’m talking about. And it happens everywhere, with active regulatory arbitrage an all-but-admitted strategy of a significant section of the SME space.
I don't think this is true. The impact will be felt immediately all over Europe, in fact it is already in the news here and people are already discussing dropping GA from websites:
https://www.nu.nl/tech/6178229/google-analytics-binnenkort-m...
In the article it points out that there are similar suits across the EU by the same organization, so it's not too unlikely that there will be similar reults in some or all of the cases.
It seems Google was sued in Austria and they have found it to violate the GDPR so yes, it applies to the whole EU.
GDPR is a set of minimum standards that are common between countries in EU, some have even more drastic laws.
So that means the current status is that's precedent a court in another EU country would strongly consider but technically could come to a different decision on and in either case the losing party has the option of appealing to the EU level.
The court has not arbitrarily declared GA illegal, it just follows what the GDPR mandates - and came to the (quite obvious) conclusion that GA is not compatible with the GDPR.
Consequently it is illegal everywhere where the GDPR applies. This doesn't mean that there are immediate consequences for those who use GA on their websites in any other country, but it is very likely that other EU countries' courts will decide the same way.
From the article:
> This is a very detailed and sound decision. The bottom line is: Companies can't use US cloud services in Europe anymore. It has now been 1.5 years since the Court of Justice confirmed this a second time, so it is more than time that the law is also enforced.
This article is addressing a specific case which follows from a previous judgement (known as Schrems II) which determined that Facebook could not transfer data from Ireland to the US under the US 'Privacy Shield' framework, as it no longer meets the GDPR's adequacy requirement due to CLOUD Act.
This finding by the Austrian court just reaffirms that the Schrems judgement also applies to Google Analytics.
As the article mentions, this is the first of 101 cases ongoing brought by Schrems, and I expect them all to end in more or less the same outcome.
https://www.europarl.europa.eu/RegData/etudes/ATAG/2020/6520...
The reason I uninstalled the hacker news app 'Materialistic' is because it regularly crashed and was probably unvoluntarily siphoning off pii data through the crashlytics module.
"Based on this data, Google was able to deduce who he or she was."
Presumably the PII didn't come from the data transmitted to GA by the site, more that GA was able to cross-reference the client ID from the cookie and determine the identity of the user.
So if one was to disable GA cookies and/or override the client ID being sent from one's own site, would that be a workaround?
If the answer to #1 is no, then any assertions that Google is not operating as a monopoly in the space are undercut. If the answer is #2 is no, then there are quite a few BI/Analytics/Strategy personnel who might find their value more difficult to justify!
China is doing this model for years. Just with a different motive I guess.
They tried this also with Telekom Germany for the Azure cloud but stopped doing it
(the data Google collects about you outside of your account activities still might, though).
I'm as concerned as anyone about privacy issues but GDPR has just gone too far in the sense that nobody really understands it (I've undergone trainings with 2x previous employers and everyone just kind of shrugs that it doesn't make sense and we'll do our best bla bla bla ...) and that now they're trying to make an actual useful piece of software illegal? And that for reasons that the very people they're trying to protect will completely fail to understand.
So many marketing departments depend on it, how can they realistically enforce this law?
I'm saying this as someone who's not a fanboy, GA can be a pain to use and overly complex, maybe Matomo is even better.
This is typical EU over reaching bs.
As a European, I welcome this wholeheartedly! It makes my daily job harder (as a programmer), but it’s needed to stop this insane industry of using private information as a currency. Most people seem to don’t care, but that is mostly because they don’t understand the consequences of this.
GDPR isn’t really that hard to understand. If you need to gather PII, you need the proper approval from the end user to do so. If you don’t have the proper approval, you can’t store it. Also, don’t gather information you don’t need. If you only need page views, don’t store IP, resolution, localisation and all these things in addition. This is common sense, not science. In fact, you should be happy to have these restrictions, because it lowers the risks in case of data breaches.
The real problem with GDPR is that we’re so used to violate peoples rights that we have completely forgotten how we should behave.
Or would that still violate GDPR as Google as an American company can still be coerced to give access to data stored on their servers outside the US? But I can't imagine that to be the case, as it would effectively mean that any business where an American company stores user data is illegal.
I work for a European company that is already being impacted by this ruling. Our first step is to replace Google Analytics, but I believe we are also looking through all cloud usage for any traces of PII.
I think this is a huge opportunity for European companies to get a foothold in the Analytics/Ads/Cloud/Office spaces. Perhaps also an opportunity for good open source alternatives, like Matomo Analytics, to get adopted.
There is the law, and then there is enforcement of the law, and the latter has not fully happened yet.
Yes, because of CLOUD Act. If GA would create a deployable agent that proceses user data on your server before sending it in aggregate/anonymously to central GA, that would make it usable
> Where the controller or a processor established in the European Union is not able to take adequate additional measures to guarantee such protection, the controller or processor or, failing that, the competent supervisory authority, are required to suspend or end the transfer of personal data to the third country concerned.
It would seem as though any EU company that can be compelled to transfer data to the US would be found not to be able to take adequate measures to guarantee the protection of the data. I'm not familiar enough with the law in the US to understand whether the US authorities can compel an EU subsidiary of a US company to transfer data out of the EU, but if so...
They can. If I remember correctly Microsoft refused FBI request for some data that was stored in Ireland so the Cloud Act was created.
GP is wondering if no US employees had access to the data directly if US law would have Microsoft US order Microsoft Ireland (which is a wholly owned subsidiary) to transfer the data to the US.
It’s an interesting question. My non-lawyer take, even if they can force Microsoft US to make the request ultimately Microsoft Ireland is an Irish company operating under Irish law. If the data transfer to Microsoft US is illegal, they mustn’t do it.
A situation where this already happens is technology transfers. If information is export controlled (mostly military related), a foreign non-EU/non-NATO owner of a German company can ask and demand as much as they want, non of their employees will ever see that information.
What about people viewing from the EU?
All very confusing.
The GDPR covers the privacy of individuals residing in the EU. That means you don't need to track which user has which nationality, you can just make decisions based on the location of your users. If you're an American company targeting American customers then you don't need to worry about Europeans passing by on their holidays. If the request comes from the EU, don't load your personal data collection code, internal or external, if you're unsure about the legality.
That said, if you don't offer any services (free or paid) to the EU and one of your customers happens to use your service on a business trip, you don't need to worry either. This mostly applies to contracts and data procession, much less to actual websites and web services reachable from anywhere, but it's an exemption that'll save a lot of data hoarding companies that track Americans, Asians, etc. through indirect means.
That is different from the headline. GA is still legal; the judgement is that it remains illegal to transfer PII from the EU to the US. That's not new; that's GDPR. This judgement is just upholding GDPR.
It's just data traders grumbling about a law they don't like in a place they don't live in.
If there is oversight from the US (i.e. it is still the owner), this is not possible.
Such a move might also be frowned upon by the American government, because you're essentially cutting them off from part of your company. I think this concept would work from an EU standpoint, but it wouldn't surprise me if the US government would prevent you from doing that, or even hold you personally accountable.
You'd also need to get a pretty good analysis of tax laws because suddenly the top owner of the company isn't foreign to the EU anymore, and that could be a problem for the tax evasion schemes big tech is such a fond of.
All in all, I doubt it's worth the hassle. As a customer of Google Analytics you'd need to have some logic to load either the European or the global analytics script, and the data cannot be combined into one overview without stripping a lot of important context (or breaking the law in the same way).
https://cdt.org/insights/microsoft-ireland-case-can-a-us-war...
https://en.wikipedia.org/wiki/Microsoft_Corp._v._United_Stat...