Amazon and Cloudflare are all great service but your data is under US jurisdiction.
Amazon and Cloudflare are all great service but your data is under US jurisdiction.
The US withrawing the CLOUD Act.
How would Excel being run locally, with its work product being emailed back and forth, be impacted by this?
The history of this strategy working, versus becoming a job/contract bank for cronies over time, is very poor in the long run. Regardless of the political system which attempts it.
Besides, EU bodies just make the rules. They don't need to provide actionable alternatives or even have to comply with those rules themselves.
Just don't upload that CSV containing all of your customers to Microsoft, that shouldn't be too hard.
Have you ever worked in a large organization?
I can't wait to see the clusterfuck of them trying to migrate away from MS.
Netcup, xTom, Hetzner, OVH, Scaleway just off the top of my head
Disclaimer: I work at Nextcloud so I'm a bit biased
Please do not email us from private mail addresses like gmail, gmx and the like. We only provide a trial to businesses > 50 employees. As a small business or private user, we recommend you simply try our demo or talk to one of our partners.
You can't even get people that need a simple word processor or spreadsheet to use LibreOffice.
The courts, not consumers, are the ultimate deciders in this situation. Companies say so under oath and a judge weighs the evidence.
When a company decides to use a product, it needs to ensure that product is legal to use in their jurisdiction(s).
If it gets to a court, it's likely that the consumer/client is the claimant and the Company who chose to use US Product X is the defendant. The company who makes US Product X is likely nowhere to be seen.
This is the proximal decider. They’re predicting the decision of the ultimate decider, which remains the courts. Providers would have to make the proximal deciders comfortable that the ultimate deciders will accept their compromise.
This means that as a business, theoretically you'd have to vet every single customer and supplier regarding their involvement with US-based companies.
Since realistically this would amount to most companies not being able to do any business at all anymore - and consequently the economy grinding to a halt - in most cases this doesn't have immediate repercussions.
However, such unpredictability caused by regulations such as GDPR is a huge problem because you can't ever be sure you won't be issued a - potentially crippling - fine simply because some local authority considered this a good idea.
Technically, the US can seize the assets of a US company that refuses to comply with these rules (or simply have their CEO arrested). That's what it comes down to: If a US company has a controlling stake in a subsidiary it's legally obligated to hand over any data that subsidiary controls.
The EU on the other hand could escalate this further and prohibit American citizens and organizations from owning a majority stake in EU-based companies because that's what this boils down to on the other hand: Running or even just doing business with a company that's controlled by a US entity technically is illegal for EU businesses and citizens right now.
This is not a pretty situation, but it's not one either where one side is clearly right and the other side is clearly wrong.
In principle, I agree with the EU point of view. Privacy is a fundamental right that should be upheld. However, de facto outlawing most economic activity and then washing one's hands of any responsibility to provide a reasonable alternative is no solution at all, but makes the problem worse: Businesses might establish legal entities outside the EU, where they're not affected by this. Others might try to host and run everything themselves, which will result in much less secure data and infrastructure because most SMBs simply aren't able to provide the same security standards as Microsoft, Amazon or Google.
It's on the EU und the US to provide a dependable legal framework for dealing with these types of situations. That's ultimately what entities like the EU are for, after all.
[1] https://blog.cloudflare.com/introducing-the-cloudflare-data-...
GDPR is written the same way.
i.e: https://gdpr.eu/article-3-requirements-of-handling-personal-...
The same way that US sanctions are applied by the US and everyone everywhere should follow them or risk fines and sanctions. No other country does this - when France sanctions Iran, only French citizens and companies are concerned.
"These laws apply outside our borders because the data is stored by our companies"
...are both examples of projection of power beyond borders, just with very slightly different rationale.