Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services
infoq.com
infoq.com
It would be nice if the same logic applied to manufacturing and environmental legislation - it stops the race to the bottom.
"BND helped NSA to spy on Austria, EU partners: report" https://www.aa.com.tr/en/world/bnd-helped-nsa-to-spy-on-aust...
"Alleged NSA post in Austria becomes state affair" https://apnews.com/a3537677459e41b9ba4d21d8208dd28a
"UK, Dutch spy agencies curb intel flow to Austria over Russia ties: MP" https://www.reuters.com/article/us-austria-security-idUSKCN1...
"Vienna Is the New Havana Syndrome Hot Spot" https://www.newyorker.com/news/news-desk/vienna-is-the-new-h...
But I think this more then anything shows why the US should not be regarded a country with adequate level of data protection. I would honestly just assume that they force Google to record every single meeting between heads of states or meetings with companies that work in telecom or weapon systems. Even the most boring meeting with officials in some small municipality can probably be valuable information about infrastructure and how it's going to be protected and these are maybe the most unsuspecting because they think "why would anybody care about the water distribution in our small city".
California helps Germany to spy on Texas.....what a shame that Union is.
I am not affiliated, but I am a massive supporter of them and is one of the donations I am happier to give
Am a supporter too, as a matter of fact it's the only recurring donation payment i have...
Alternatively they could mirror an approach that Microsoft had with ther Office Online for a while, that is find a European company acting as "trustee" for the data, so that even if the NSA came knocking the US based company would not have any data on any of their infrastructure it could give them.
But, at the heart of it, it makes sense. If foreigners can use services in your jurisdiction, you want to see what they do for security purposes.
Nonetheless, it's against the belief of "innocent until proven guilty."
If legal protection from the state is enforced (even for other states) this means there need to be wholly separate services in each jurisdiction.
This seems very undesirable, especially for the US with it's multinational web companies.
which is the correct conclusion? As the state can only offer legal protection under its own jurisdiction.
Sure, real life complicates things a bit. (mainly, the jurisdiction of the EU as an institution in and of itself compared to its member states is a messy affair) but it is still a totally valid argument none the less.
Not sure I follow, US gov can't legally protect non US citizens from itself abusing them? It should be as hard for the spying to happen for an US or non US citizen or company.
As a "foreigner" in a friendly country I'm understandably not too happy about this. And the logical outcome is that the US will lose business anywhere this is unacceptable.
There are a LOT of things that law enforcement agencies want that they should not get. The fact that they want it or that it would be useful to them is not enough of an argument to give it to them. It has to be balanced against other factors, to decide what is best for society as a whole.
Given that the big 3 cloud providers already have some trouble providing stable operations, I suspect it won't be the pinnacle of reliability, but have no first-hand experience with them.
Pricing for services in the EU GDPR "Sovereign" safe-zones (e.g. "Germany Central (Sovereign)") is largely the same as for services in other zones:
Azure App Service in Germany Sovereign: $62/mo
Azure App Service in West US: $54/mo
1TB Azure Storage in Germany Sovereign: $21.00
1TB Azure Storage in West US: $20.80/mo
---------------
As for reliability, I haven't noticed any difference in availability and downtime between my Azure resources in any of the zones I've got services in. YMMV. Lately Azure's actually looking pretty good compared to AWS's spate of outages over the past 6 months.
Impossible, the mother company is still american.
Canada, Brazil, Japan, India, and many other non-EU countries have GDPR-like data protection regulation that would be totally acceptable I think (IANAL).
The core problem is USA specific - either the USA needs to implement serious data protection laws where they can't blanket surveil foreign user's data, or EU businesses will have to move elsewhere.
I wouldn't be surprised if in future, similar local rulings appear in Canada/Brazil/Japan/Indian/the rest of the world for businesses based there too. It might be a difficult few years for US-based cloud providers.
This kind of soft power even has a name, the brussels effect[0]
There needs to be an official adequacy decision, it's not automatic
https://ec.europa.eu/info/law/law-topic/data-protection/inte...
Canada is indeed covered by one such decision
- Andorra
- Argentina
- Canada (commercial organisations)
- Faroe Islands
- Guernsey
- Israel
- Isle of Man
- Japan
- Jersey
- New Zealand
- Republic of Korea
- Switzerland
- the UK
- Uruguay
2022 is a great year to be a cloud provider based in any of those.
This adds an advantage. It doesn't mean they can be, and need to be competitive in other ways too. And there is not one, but several EU based services that compete with each other.
At least all of our customers are moving away from Google Analytics and many try to also get rid of other Google services like fonts and maps.
I'm very interested to see what this changes in other european countries.
As it's a direct result of an CJEU ruling (Schrems II), all other (EU) countries will have to do the same.
It's not EU based, but at least it's not Google, and the service is privacy oriented...
(disclosure: work there)
I spend 5 minutes on american recipe websites to scroll through the SEO bullshit before finding the actual recipe, but that doesn't mean it's useful.
So, no, it's just Google telling you to let them collect analytics on every aspect of your life for "search improvement purposes".
This was one of the ways the NSA programs worked... just tap the google lines which were unencrypted and slurp the data as it moved from datacenter to datacenter.
That doesn't matter anymore. According to the relatively recent ECJ ruling mentioned in the article you're not allowed to transfer any PII to companies that are in any way affiliated with a US-based entity (e.g., by virtue of having a US-based parent company), which clearly is the case for Amazon and AWS.
It doesn't stop there. According to some privacy experts, even a third party just having a US-based supplier might be construed as a customer of that third party being in violation of GDPR, at which point we'd basically have to cease all economic activity.
I like the goal of privacy, but I won't be sad to see the ridiculous GDPR law implode.
I’m having a hard time seeing how the rules could be any different. Remember that the GDPR is also result of companies looking at the cookie law and deciding “fuck it, let’s find a loop hole and not change anything”.
Or writing it so that it doesn't claim to tell me what I have to do with my website when I live in another jurisdiction. I laugh at GDPR. The EU can keep its bureaucracy to itself thank you very much. Making simple websites illegal and forcing me to hire a lawyer to figure out not what I'm allowed to do, but how I must do it just so is just the sort of nonsense I've come to expect from them.
And yes, I agree that it is a continuation of the stupid cookie law that has made the web measurably worse in every regard. As I wrote here recently,
> What an utterly useless law. We have a convenient way for people to request universally that sites not track them. So let’s make a law that makes them have to ask “the right way” every. Single. Stinking. Site. On. The. Internet. Every. Single. Time. They. Visit. Every. Single. Site. > > One might be forgiven for assuming that the law was actually intending to accomplish the reverse of the stated goal. It gives site owners tons of explicit opt-ins that nobody can complain about, even though they were coerced.
Those abusing personal information without consent deserve all the fines that can be thrown at them. I'd rather there were personal liability in the same manner as Title IX of Sarbanes-Oxley, but in the meantime, this is the best there is.
> According to some privacy experts, even a third party just having a US-based supplier might be construed as a customer of that third party being in violation of GDPR, at which point we'd basically have to cease all economic activity.
That's the only thing I was really replying to here at the start.
As of now, as a business you essentially have three alternatives:
1. Run the entire infrastructure you need yourself or have it run by EU-based companies guaranteed to have no relations with US-based entities whatsoever (Good luck with finding those ...). This, for example, includes payment systems and banking infrastructure, because guess where many EU-based banks host their infrastructure? That's right, AWS.
2. Go out of business.
3. Ignore this aspect of GDPR for now, document everything, continue to do your own due diligence, and hope for the best.
I'm sorry, but that's the same bullshit argument that the Danish online retailers are making. So apparently it is absolutely impossible to do business, of any kind, without violating users privacy? Sure, some business can't function under the GDPR, that is true. The question then become, do we actually care? I don't. Those who can not deal with the GDPR are either extremely shady, or they are based in countries where the governments do not care about violating my privacy at all and will use creepy laws to force them to hand over information and shut up about it.
The GDPR is very aggressive, and rather broad in scope. Ideally I do agree that it should be a bit more forgiving, but given that business didn't even want to pretend to respect the privacy of customers, it's forced to be very restrictive.
The business that rely on user tracking, sell and reselling user data are directly to blame for the GDPR. They went WAY to fare and the GDPR is the EU reacting to an industry that failed to play nice.
So they are collecting data about me to show me better ads. Isn't that what I want? They compare my data to a collection ("look-a-likes") of others that match my data fingerprint. What's wrong with that?
The way I understand it nobody is interested in me as a person (which is a bit sad, but that's a different story...).
EU based companies will not be allowed to mine US customers the same way.
Sure, except they don't find an advantage in the restriction.
They are not cloudy. A dark kitchen OTOH ...
very, very little.
see https://medium.com/the-global-millennial/why-walmart-failed-...
Anyone apart from Gcore labs?
European ISPs with Tier-1 capabilities: Sweden's Arelion (prev. Telia Carrier), Telecom Italia's Sparkle, T-Systems (part of Deustche Telekom), France's Orange, and the business and carrier division of Telefonica.
Webhosting with demonstrated capabilities are another one: I can only name OVH to be frank. Iliad (dba Scaleway) has good European connections but not global, and Hetzner while a capable hoster is not that invested outside of Germany.
Hetzner has only a handful of locations - they'd have to massively scale up to be a viable CDN and add all the needed tech.
This makes it worse, since they fall under US CLOUD Act now.
In July 2020, the CJEU has issued its groundbreaking "Schrems II" ruling,
holding that a transfer to US providers that fall under FISA 702 and EO
12.333 violate the rules on international data transfers in the GDPR. The
CJEU consequently annulled the transfer deal "Privacy Shield", after
annulling the previous deal "Safe Harbor" in 2015. While this sent shock
waves through the tech industry, US providers and EU data exporters have
largely ignored the case. Just like Microsoft, Facebook or Amazon, Google has
relied on so-called "Standard Contract Clauses" to continue data transfers
and calm its European business partners.
Max Schrems, honorary chair of noyb.eu: "Instead of actually adapting
services to be GDPR compliant, US companies have tried to simply add some
text to their privacy policies and ignore the Court of Justice. Many EU
companies have followed the lead instead of switching to legal options."
https://noyb.eu/en/austrian-dsb-eu-us-data-transfers-google-...https://noyb.eu/en/101-complaints-eu-us-transfers-filed https://noyb.eu/en/update-noybs-101-complaints-eu-us-data-tr...
But on closer read, it seems to partially apply to SaaS/PaaS cloud services, which hold data outside EU.
Google also provides IaaS/PaaS cloud offering based within EU as well [0].
I am curious as to what argument can find it acceptable to block US company, also when they place data within EU and can’t be compelled to handover to US law enforcement.
Even if a US company holds their data in the EU, due to FISA 702, the CLOUD act and EO 12.333, they can still be compelled to hand over that data. So being a US company is a dealbreaker, regardless of where the data is stored.
Alphabet (US) -> Google (US) -> Google (EU)
Under such a structure, Google (EU) is not GDPR-compliant, and will need to drop all upstream inheritance of (US) to comply with this ruling.
I am not your lawyer, this is not legal advice.
On the one hand, I can't imagine US surveillance leaving open such a glaring hole, on the other hand I wonder what basis US law could apply to companies of non-US countries.
After all, the purpose of the company would be to offer Google services in Germany - so I imagine, it would either be a subsidiary or a de-facto shell company.
Good point though, that sort of answers my question already.
https://twitter.com/jdvhouten/status/1488481039630704644
Seems premature to sanction private businesses when EU governments have not yet been able to come fully into compliance. Perhaps the changeover is more difficult than anticipated? As others allude below, it might make sense for the relevant EU-based alternatives to come online/scale up.
The German government is, in general, a joke when it comes to websites and doing things online instead of fax/mail/paper.
That the private fine is essentially a token throwaway amount reflects that the court isn’t trying to throw the book at them; one can imagine the court will be much more upset about the government instance you highlight if it remains unaddressed.
Microsoft tried to get around that by not hosting in the EU but having a european trustee do it for them.
That got us the CLOUD act
This would theoretically apply whether using AWS hosting (even in EU availability zones), Stripe or PayPal cart checkouts, or any other platform owned and/or operated by a US business or its subsidiaries. It isn’t relevant where those US-owned data or servers are hosted.
This unfortunate situation could be corrected by the US signing a new treaty or other law that ensures that the US governments, law enforcement, and courts cannot compel US business to violate GDPR.
(I am not your lawyer, this is not legal advice.)
> If the second respondent (Google) subsequently refers to encryption technologies - such as the encryption of "data at rest" in the data centers - he must again be countered with recommendations 01/2020 of the EDSA. Namely, it states that a data importer (such as the Second Respondent) who is subject to 50 US Code § 1881a (“FISA 702”) has a direct obligation with regard to the imported data that is in his possession, custody or control to grant access to or release them. This obligation can expressly also apply to the cryptographic key without which the data cannot be read (ibid. margin no. 76).
> As long as the second respondent has the opportunity to access data in the Plain text access, the technical measures taken cannot be regarded as effective in the sense of the above considerations.
The last paragraph suggests true end-to-end encryption may be acceptable, but that's not how Google Analytics works.
Yes. I made the question, given the discussion is being treated as much wider, beyond GA.
This also tells me, using own key can still be used by Google to operate as is (US company with EU owned entity and EU located DC)
^ some services may ban you for proxying in this manner without a contract
^^ proxy must not be hosted by or operated within AWS, GCP, Heroku, or any other US-controlled services provider
You can definitely still use GA if you really wanted to, just not in any way that uses PII (the default).
In what way is it similar, I'm not seeing it? When did China introduce something like GDPR and how did it help foster an ecosystem of their own services?
Now they have pushed something very similar to the GDPR. More info about these two things here:
https://en.wikipedia.org/wiki/Internet_censorship_in_China#L...
[citation needed]
The EDPB Guidelines from November 2020 says:
"where unencrypted personal data is technically necessary for the provision of the service by the processor, transport encryption and data-at-rest encryption even taken together, do not constitute a supplementary measure that ensures an essentially equivalent level of protection if the data importer is in possession of the cryptographic keys"
https://edpb.europa.eu/sites/default/files/consultation/edpb...
"Encryption at rest" is part of any sensible GDPR compliance concept; the threat that is being defended against is theft or seizure of servers and in the case of portables like laptops and USB sticks also loss of them - without the keys or password, the data is useless.
Well, other than the usual Fathom and Plausible, that is. It might come as a surprise to some, but the web and software in general isn't just comprised of analytics.
Just to try and prove myself wrong I searched for a GDPR-compliant EU-based video conferencing tool on that "developed in Europe" site linked to in the article. The only result I got was "api.video - Video APIs for building, scaling and operating on-demand and live streaming videos".
So, because of GDPR I'm now supposed to code and run my own video conferencing service?
Wonder.me - Berlin
whereby.com - Oslo (technically not EU, but close enough)
That site is just lacking.
Secondly, hosting videos is not my core business. The shop around the corner doesn't run its own payment system either, after all.
Finally, I don't need to host videos, I need a video conferencing software, which is something entirely different.
That doesn't matter, since US CLOUD Act allows US law enforcement to subpoena data even if they are stored in the EU.
The only "way out" is to use cloud providers that have no presence in US.
As a side effect: Google.EU will be able to use the "full" power allowed by GDPR (european data & world data) as Google.WORLD will "only" be able to use world data excluding EU. But maybe Google.EU will be able to export "consolidated" (so anonymized) datas back to the US ?
Same would be applicable for Apple, Amazon, MS & Co...