At least all of our customers are moving away from Google Analytics and many try to also get rid of other Google services like fonts and maps.
I'm very interested to see what this changes in other european countries.
At least all of our customers are moving away from Google Analytics and many try to also get rid of other Google services like fonts and maps.
I'm very interested to see what this changes in other european countries.
As it's a direct result of an CJEU ruling (Schrems II), all other (EU) countries will have to do the same.
This was one of the ways the NSA programs worked... just tap the google lines which were unencrypted and slurp the data as it moved from datacenter to datacenter.
That doesn't matter anymore. According to the relatively recent ECJ ruling mentioned in the article you're not allowed to transfer any PII to companies that are in any way affiliated with a US-based entity (e.g., by virtue of having a US-based parent company), which clearly is the case for Amazon and AWS.
It doesn't stop there. According to some privacy experts, even a third party just having a US-based supplier might be construed as a customer of that third party being in violation of GDPR, at which point we'd basically have to cease all economic activity.
I like the goal of privacy, but I won't be sad to see the ridiculous GDPR law implode.
I’m having a hard time seeing how the rules could be any different. Remember that the GDPR is also result of companies looking at the cookie law and deciding “fuck it, let’s find a loop hole and not change anything”.
Or writing it so that it doesn't claim to tell me what I have to do with my website when I live in another jurisdiction. I laugh at GDPR. The EU can keep its bureaucracy to itself thank you very much. Making simple websites illegal and forcing me to hire a lawyer to figure out not what I'm allowed to do, but how I must do it just so is just the sort of nonsense I've come to expect from them.
And yes, I agree that it is a continuation of the stupid cookie law that has made the web measurably worse in every regard. As I wrote here recently,
> What an utterly useless law. We have a convenient way for people to request universally that sites not track them. So let’s make a law that makes them have to ask “the right way” every. Single. Stinking. Site. On. The. Internet. Every. Single. Time. They. Visit. Every. Single. Site. > > One might be forgiven for assuming that the law was actually intending to accomplish the reverse of the stated goal. It gives site owners tons of explicit opt-ins that nobody can complain about, even though they were coerced.
Those abusing personal information without consent deserve all the fines that can be thrown at them. I'd rather there were personal liability in the same manner as Title IX of Sarbanes-Oxley, but in the meantime, this is the best there is.
> According to some privacy experts, even a third party just having a US-based supplier might be construed as a customer of that third party being in violation of GDPR, at which point we'd basically have to cease all economic activity.
That's the only thing I was really replying to here at the start.
As of now, as a business you essentially have three alternatives:
1. Run the entire infrastructure you need yourself or have it run by EU-based companies guaranteed to have no relations with US-based entities whatsoever (Good luck with finding those ...). This, for example, includes payment systems and banking infrastructure, because guess where many EU-based banks host their infrastructure? That's right, AWS.
2. Go out of business.
3. Ignore this aspect of GDPR for now, document everything, continue to do your own due diligence, and hope for the best.
I'm sorry, but that's the same bullshit argument that the Danish online retailers are making. So apparently it is absolutely impossible to do business, of any kind, without violating users privacy? Sure, some business can't function under the GDPR, that is true. The question then become, do we actually care? I don't. Those who can not deal with the GDPR are either extremely shady, or they are based in countries where the governments do not care about violating my privacy at all and will use creepy laws to force them to hand over information and shut up about it.
The GDPR is very aggressive, and rather broad in scope. Ideally I do agree that it should be a bit more forgiving, but given that business didn't even want to pretend to respect the privacy of customers, it's forced to be very restrictive.
The business that rely on user tracking, sell and reselling user data are directly to blame for the GDPR. They went WAY to fare and the GDPR is the EU reacting to an industry that failed to play nice.
As a business, technically you're simply not allowed to have dealings with US-based companies anymore if you want to be GDPR-compliant.
It doesn't matter if that relation is direct or transitive. If you buy a product or service from an EU-based company, even if data on their servers is guaranteed to never physically leave the EU you're still in violation of GDPR in case that company is owned by a US-based parent company.
The reason for this is that with FISA US law enforcement can force US-based companies to hand over any data, even if that data is stored with an international subsidiary under a completely different jurisdiction.
Now, you might say: "See? This is GDPR working as intended." While that's technically true that doesn't take economic reality into account. It's simply not possible to have an exclusively EU-based economy. Otherwise, why would the EU even need to negotiate trade agreements with other countries (which during the Brexit debate has often been cited as one of the main benefits that comes with being an EU member)?
Why do businesses even have to deal with this? This is a problem at the national and international level and it needs to be solved at that level. Why is it impossible for the EU to demand a FISA exemption for EU-based companies - US-owned or not? That's not an unreasonable demand, after all, given that FISA interferes with other jurisdictions.
The reason is the EU is weak. It's far easier to bully local companies into submission than to do the right thing and stand up to the US.
I spend 5 minutes on american recipe websites to scroll through the SEO bullshit before finding the actual recipe, but that doesn't mean it's useful.
So, no, it's just Google telling you to let them collect analytics on every aspect of your life for "search improvement purposes".
It's not EU based, but at least it's not Google, and the service is privacy oriented...
(disclosure: work there)
So they are collecting data about me to show me better ads. Isn't that what I want? They compare my data to a collection ("look-a-likes") of others that match my data fingerprint. What's wrong with that?
The way I understand it nobody is interested in me as a person (which is a bit sad, but that's a different story...).