What matters is that the data is stored by - and accessible to - a company which submits to the US laws.
What matters is that the data is stored by - and accessible to - a company which submits to the US laws.
Ed. cleared up phrasing around new use, replaced meaning with use for .. meaning.
That is exactly how things work. Unless the government goes through the effort of passing a law to prohibit something (and getting approval of the people's elected representatives, and the courts), then the thing is legal. How else do you propose things should work?
Then there's the issue of marketing/propaganda (which the parent mentions as "hammered") whose sole purpose it's to change people's minds in an emotional way. I wish people would learn about Edward Bernays, nephew of Freud, who instituted this. In and of itself, propaganda has never been illegal, but no one likes to admit to being emotionally manipulated. (But when you begin to pay attention to your emotions, you can spot this stuff from a mile away).
Also, it's important to note that humans are actually quite bad at this sort of judgement. I'm sure if you showed everyone in Germany in 1980 a computer, and how it can instantly store and retrieve files and documents, and asked them 'is this moral?' they would be against it on the grounds that it would put hundreds of office workers out of a job.
It's the job of the judiciary to interpret the laws in these situations, and part of that is looking at the spirit of the law and create case law which may alter the powers of government.
This is very much part of the Western tradition of common law, as is a vigorous discussion over how far the judiciary should be able to go. It's fair to say popular sentiment has drifted in a libertine direction over the last 50 years, but the debate is far from settled.
(In fact we can speculate with some reliability about what the future may hold: via one mechanism or another, including the judiciary, governments usually trend more libertine in times of peace and more authoritarian in times of crisis.)
Computer programs suffer all of this as well :)
Which founding principles, exactly? Your comment seems to imply you think we should live in a world where we are only allowed to pick our actions from an enumerated list of approved actions. That world is extremely contrary to the kind of world I would like to live in, but also seems to contradict most of what I know about the history of the western world. Is that really what you mean?
I'm fairly certain that's not what OP meant, no.
What OP is getting at is that the common law tradition isn't to explicitly spell out all the nuances of when that action is actually disallowed, but rather to set out the general principles, and let case law define the precise limits of that boundary. In contrast, the civil law tradition is very much based on statutory law explicitly setting the boundaries, and case law serving only to disambiguate.
The "aggressive and putative new use" they're referring to is basically taking common law's fuzzy boundaries and pushing a civil law interpretation on top where all the grey areas are assumed to be allowed.
If you encrypt the data with your own key, they should not be able to access it.
This problem has to be solved on a political level. There is no technical fix and the legal workarounds appear to be exhausted.
[1] https://aws.amazon.com/blogs/database/securing-data-in-amazo...
It comes down to the details of the legal obligation they have under U.S law. Are there limits to what they have to do to help U.S law enforcement, and what exactly are those limits?
If GDPR makes all the cloud services provided by American companies illegal, what alternatives European companies have? Services like OVH and Hetzner are great as a low cost but they don't provide the same services at all.
How about Netsuite (Oracle), Netsuite, etc.?
My guess is that ~100% of European companies use some kind of US service and there are no realistic alternatives, are they going to rule all companies are doing something illegal?
I don't think it's a good idea to let the world (and the internet) fragment into ever smaller jurisdictions that can no longer find a way to trade with each other.
We need a legal agreement to sort this out or everyone will be worse off.
* They wouldn't actually have to compete at all if U.S services were banned.
You can process IP addresses without consent only if it is technically necessary: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... (paragraph b)
But you always (!) need consent to transfer personal data to a non GDPR compliant entity: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... (paragraph f)
"(1) Personal data shall be: (f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’)."
See also Schrems II: https://en.wikipedia.org/wiki/Max_Schrems#Schrems_II
But from a legal point of view we, as a European company, are forbidden to use any US infrastructure provider. We can't ask for consent to transfer data to an US based entity if our consent form itself is already hosted by an US based entity. And even if we did find a solution, like hosting the main infrastructure with a European company and asking for consent for some later data transfer, we are most likely forbidden to transfer data to US based entities at all.
From what my lawyer told me the ruling from https://noyb.eu/en/austrian-dsb-eu-us-data-transfers-google-... applies to all services from AWS, Google Cloud, ...
There will be many rulings that follow. Everybody is just waiting for the Irish Data Protection Commission to actually do its work, but the Irish DPC does not seem to be much in favor of data protection: https://noyb.eu/en/irish-dpc-handles-9993-gdpr-complaints-wi... & https://bigbrotherawards.de/en/2022/lifetime-achievement-iri...
This will change soon. From what I heard work is underway to let national data protection offices handle cases without the Irish DPC or force the Irish CPC to work.
The idea with the SCC is that instead of all data transfers being covered by a single adequacy decision, each company adds SCCs to it's contracts with customers promising that data of EU citizens will be handled in a way that's compliant with GDPR.
Reading this piece from CNIL, I can't see how a US company is going to be able to use SCCs to protect EU citizens from data access by the US government. Non US citizens typically don't have a lot of rights in the eyes of the US gov and they've traditionally been pretty happy to rifle through the data of those people at will.
ed: the point by another commenter about using your own encryption key is a good one. However, the view of CNIL essentially seems to be that transferring any data to the US is risky so to me it feels like you'd be swimming against the tide.
Corporations such as google have legal and financial centers all over the world and these will be structured towards providing the best circumstances for the corporation (tax, legal).
On the other hand, don't all these corporations have data centers all over, that replicate data to provide a better service? Which is to say that pretty much most data is available to all legal jurisdictions. At least as I understand it..
https://en.wikipedia.org/wiki/CLOUD_Act
No problem at all with GDPR and third countries. They simply need to have a regulatory framework making compliance possible.
https://www.imy.se/en/organisations/data-protection/this-app...
And that’s exactly what it would be like, though the house in Paris would be owned by a company that has a legal entity in the United States.