If a user in Florida tries to view a post by a user in Germany, doesn't the German user's data have to leave the EU?
If a user in Florida tries to view a post by a user in Germany, doesn't the German user's data have to leave the EU?
For those downvoting me, I'd love to hear why you think it's more complicated than that. Contrary to popular belief, the people who wrote the GDPR are pretty technically sophisticated and understand that data on the internet has to move between countries from time to time.
1. Sam makes a post.
2. FB predicts Pat will comment on this post if they see it.
3. Pat sees the post, and writes a comment.
4. FB predicts Alex will reply to Pat's comment if they see it.
5. Alex sees the comment, and writes a reply.
To show why data transfer is such an issue, assume Sam, Pat, and Alex are all in jurisdictions with EU-style privacy regulations and that don't have data transfer agreements with each other.
How would you build a system that supports 1-5, a user journey that is core to Facebook's usage, in a way compliant with these regulations? For example, where is the discussion stored? Where do the models in (2) and (4) run?
As far as I can tell, the really difficult aspect here is how and where to permanently store the fact that the two users are talking to each other once the comments are actually made, since the mere fact that they are talking to each other demonstrates a relationship between them which may be considered PII in some contexts. Or at least, it would be difficult if the US also had privacy laws like the EU's, and IMO any coherent solution should be able to work if the US adopts something like GDPR. Unlike the message contents, this is quite difficult to store in a privacy-preserving way. I think the discussion would be more interesting and feel less like attacking a strawman if people were to focus on the interesting questions like this one, rather than the extremely uninteresting question of whether Facebook can serve posts to the US at all (which it obviously can).
> One option would be to serve this data directly from the European server.
What do you think happens with the data when you "serve it directly from the European server" to a user in Florida?
Exactly, it leaves the EU to go to Florida. ;-)
So the only thing the US government could get, are the public facing posts/images which the user posted but nothing more. If the profile is private, even less. No messenger data (except when send to users in the US).
Meta could be more accommodating to the wishes of the EU and place a greater focus on privacy, but that would mean changing how they do business. Meta clearly don't believe that it's possibly for their businesses to be profitable without data mining the crap out of their users. I know it's not a popular opinion, but business like Facebook and Instagram are the direct reason why the EU feel the need to step in and regulate.
It's where the data is stored and kept that is at issue.
Enlighten us?
You guys are just playing with semantics.
In terms of this context, easiest way would be to shard db infrastructure. Not even a remotely big deal for Facebook, with their size.
Hell, they should already want this, to avoid costly, and high ping time, intercontinental links.
But oh nooos, so hard to do. Absurd.
Think about internet archive, BitTorrent dumps of Facebook, etc.
Wouldn’t the true solution simply be for those who don’t want other regions to save to simply not have access, e.g firewall?
It would then been trivial for someone to crawl EU pages and rebuild the corpus of data.
The only real solution is to firewall off regions and prevent those users from accessing anything other than their own.
This is already what some countries like China do, for instance
If you're in a given geography/regulatory regime, and you read something on your smart phone, technically you were served that via some cell tower or ISP, those bits transited that infrastructure. In the US there's a massive clot of regulatory blockage working it's way slowly through the bowels of government around the term of art: "common carrier".
As with many things that devolve into nitpicking, there is a deeper issue: the EU is increasingly regretting becoming the host to, ironically, European-style colonialism on large-scale consumer Internet platforms. The PRC has its own Google, Twitter, Facebook, etc. The EU has Google, Twitter, Facebook, etc. and doesn't love that US companies and regulators are kind of driving the digital lives of the citizens.
The proximate tussle is about the durability of the storage involved. As a European regulator I might be much more comfortable with a write-through cache like TAO holding messages, or FBIDs of messages, including a German in the chat than I am with all such chats being held on a DFS in Prineville among other places, and having them ground over by a Spark or Hadoop job in Forest City among other places.
They'll kick it around and come up with some compromise that will serve end-users by accident at best. Europe won't develop a homegrown consumer Internet industry in our lifetimes. The odds are both US and EU legislators and regulators will miss a step and it'll be ByteDance everywhere by the time anyone reads this :)