"No."
So right now it is practically impossible to use Google Analytics in a legal way in France.
"No."
So right now it is practically impossible to use Google Analytics in a legal way in France.
What matters is that the data is stored by - and accessible to - a company which submits to the US laws.
https://en.wikipedia.org/wiki/CLOUD_Act
No problem at all with GDPR and third countries. They simply need to have a regulatory framework making compliance possible.
https://www.imy.se/en/organisations/data-protection/this-app...
And that’s exactly what it would be like, though the house in Paris would be owned by a company that has a legal entity in the United States.
Ed. cleared up phrasing around new use, replaced meaning with use for .. meaning.
That is exactly how things work. Unless the government goes through the effort of passing a law to prohibit something (and getting approval of the people's elected representatives, and the courts), then the thing is legal. How else do you propose things should work?
Then there's the issue of marketing/propaganda (which the parent mentions as "hammered") whose sole purpose it's to change people's minds in an emotional way. I wish people would learn about Edward Bernays, nephew of Freud, who instituted this. In and of itself, propaganda has never been illegal, but no one likes to admit to being emotionally manipulated. (But when you begin to pay attention to your emotions, you can spot this stuff from a mile away).
Also, it's important to note that humans are actually quite bad at this sort of judgement. I'm sure if you showed everyone in Germany in 1980 a computer, and how it can instantly store and retrieve files and documents, and asked them 'is this moral?' they would be against it on the grounds that it would put hundreds of office workers out of a job.
It's the job of the judiciary to interpret the laws in these situations, and part of that is looking at the spirit of the law and create case law which may alter the powers of government.
This is very much part of the Western tradition of common law, as is a vigorous discussion over how far the judiciary should be able to go. It's fair to say popular sentiment has drifted in a libertine direction over the last 50 years, but the debate is far from settled.
(In fact we can speculate with some reliability about what the future may hold: via one mechanism or another, including the judiciary, governments usually trend more libertine in times of peace and more authoritarian in times of crisis.)
Computer programs suffer all of this as well :)
Which founding principles, exactly? Your comment seems to imply you think we should live in a world where we are only allowed to pick our actions from an enumerated list of approved actions. That world is extremely contrary to the kind of world I would like to live in, but also seems to contradict most of what I know about the history of the western world. Is that really what you mean?
I'm fairly certain that's not what OP meant, no.
What OP is getting at is that the common law tradition isn't to explicitly spell out all the nuances of when that action is actually disallowed, but rather to set out the general principles, and let case law define the precise limits of that boundary. In contrast, the civil law tradition is very much based on statutory law explicitly setting the boundaries, and case law serving only to disambiguate.
The "aggressive and putative new use" they're referring to is basically taking common law's fuzzy boundaries and pushing a civil law interpretation on top where all the grey areas are assumed to be allowed.
If you encrypt the data with your own key, they should not be able to access it.
This problem has to be solved on a political level. There is no technical fix and the legal workarounds appear to be exhausted.
[1] https://aws.amazon.com/blogs/database/securing-data-in-amazo...
It comes down to the details of the legal obligation they have under U.S law. Are there limits to what they have to do to help U.S law enforcement, and what exactly are those limits?
If GDPR makes all the cloud services provided by American companies illegal, what alternatives European companies have? Services like OVH and Hetzner are great as a low cost but they don't provide the same services at all.
How about Netsuite (Oracle), Netsuite, etc.?
My guess is that ~100% of European companies use some kind of US service and there are no realistic alternatives, are they going to rule all companies are doing something illegal?
I don't think it's a good idea to let the world (and the internet) fragment into ever smaller jurisdictions that can no longer find a way to trade with each other.
We need a legal agreement to sort this out or everyone will be worse off.
* They wouldn't actually have to compete at all if U.S services were banned.
You can process IP addresses without consent only if it is technically necessary: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... (paragraph b)
But you always (!) need consent to transfer personal data to a non GDPR compliant entity: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... (paragraph f)
"(1) Personal data shall be: (f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’)."
See also Schrems II: https://en.wikipedia.org/wiki/Max_Schrems#Schrems_II
But from a legal point of view we, as a European company, are forbidden to use any US infrastructure provider. We can't ask for consent to transfer data to an US based entity if our consent form itself is already hosted by an US based entity. And even if we did find a solution, like hosting the main infrastructure with a European company and asking for consent for some later data transfer, we are most likely forbidden to transfer data to US based entities at all.
From what my lawyer told me the ruling from https://noyb.eu/en/austrian-dsb-eu-us-data-transfers-google-... applies to all services from AWS, Google Cloud, ...
There will be many rulings that follow. Everybody is just waiting for the Irish Data Protection Commission to actually do its work, but the Irish DPC does not seem to be much in favor of data protection: https://noyb.eu/en/irish-dpc-handles-9993-gdpr-complaints-wi... & https://bigbrotherawards.de/en/2022/lifetime-achievement-iri...
This will change soon. From what I heard work is underway to let national data protection offices handle cases without the Irish DPC or force the Irish CPC to work.
The idea with the SCC is that instead of all data transfers being covered by a single adequacy decision, each company adds SCCs to it's contracts with customers promising that data of EU citizens will be handled in a way that's compliant with GDPR.
Reading this piece from CNIL, I can't see how a US company is going to be able to use SCCs to protect EU citizens from data access by the US government. Non US citizens typically don't have a lot of rights in the eyes of the US gov and they've traditionally been pretty happy to rifle through the data of those people at will.
ed: the point by another commenter about using your own encryption key is a good one. However, the view of CNIL essentially seems to be that transferring any data to the US is risky so to me it feels like you'd be swimming against the tide.
Corporations such as google have legal and financial centers all over the world and these will be structured towards providing the best circumstances for the corporation (tax, legal).
On the other hand, don't all these corporations have data centers all over, that replicate data to provide a better service? Which is to say that pretty much most data is available to all legal jurisdictions. At least as I understand it..
Is there an issue with this technique? I've not managed to poke holes in it yet but have at it.
Keep in mind that the mere transfer of the IP address (which is inherent in a TCP connection and cannot be avoided in the default setup without proxying it yourself) is enough, regardless of whether Google will actually store said IP or anonymize it (not that you should trust them in any case).
My IP address hasn't changed in some time, so if someone was to connect various sources of information, he would be able to identify me personally
Connect my login into my personal Google account with the same IP address over and over to all the script calls on other Google services.
It's pretty easy to connect the dots once you have a far enough reach.
That something could potentially be correlated across time and space to link different facts about you, does not or should not make those things personally identifying. Otherwise there's a lot of obvious problems e.g. if you were in the habit of wearing unusually distinctive clothing, or had an interesting bumper sticker on your car, etc, then all those things would become "personally identifying" even if nobody who saw them had any idea who you are. There are also deep moral limits to how blind you can insist other people become.
lol
I think the rules are usually though, that when those correlating things are put together, into one system, then the combination of those things are in sum personally identifying. That can actually happen very quickly and in non-obvious ways. You might add something inconspicuous and suddenly that makes users unique and allows to map in any theoretical way to real identities.
I think one also has to consider publicly available information sources. Just to make a silly example:
If there was some public register of favorite foods of people, and you asked your users about favorite foods, which you store in your database. Ooops, it is personally identifying, because anyone with that data in hand could map it to identities using publicly available data.
However, I am not so sure, that the publicly available data is considered for judging whether something is personally identifying information.
An IP address limits the location of a person significantly, unless they use VPN or so, which most people do not, so it cannot be assumed, but rather one must assume, that they do not use VPN.
Add one more attribute and through correlation you might already be able to map to an actual identity. It can happen very easily and you don't want to be an organization, which suddenly realizes, that some of their data has accidentally become personally identifying, when the next data protection audit happens.
Data also does not stay in one place only. It travels from department to department, often from organization to organization even. It has these tendencies, unfortunately. Each actor might have some data as non personally identifying, but when they sell and combine, suddenly it becomes personally identifying data.
An IP address is a very critical part in the data about users and ISPs are not to be trusted to never give their data to another actor. Many ISPs are shady businesses.
> Connect my login into my personal Google account with the same IP address over and over to all the script calls on other Google services.
That's it. That IP address is _pretty sure_ me and not somebody else and therefore a personal information.