PostHog Cloud EU
posthog.com
posthog.com
There are tons of decent european-based cloud providers,… like upcloud, Scaleway, exoscale or OVH to name the ones at the top of my head.
I would love to know what motivated this choice outside of "nobody got fired buying IBM/AWS" or résumé-driven development.
To be blunt, we cannot guarantee not sharing data in the scenario that the US government forces us to transfer data to them from our EU Cloud. We have self hosting for those who want 100% certainty of GDPR compliance, as then we require no access to the instance.
The case law[0] as it stands today makes it impossible for US companies to fully comply in practice if providing cloud software like this - in order to comply with a request from a US agency to transfer data out of the EU, a US company would need to breach its obligations under GDPR today (and vice versa). However, recent changes[1] in the US may (or may not) enable legitimate transfers from the EU to US, but a ruling from the European Commission on this isn't expected until 2023. For this reason, we've launched PostHog Cloud EU on AWS in Frankfurt for now (we've had many customers asking for this) as a first step. From here, we can iterate depending on the above or by changing our legal structure if we wind up with a ton of adoption and want to improve this offering.
We'll issue a few clarifications to the page and docs to help explain the above properly, as I think we should make the above points more clearly on our website. We didn't expect this to appear on HN front page so fast!
[0] https://noyb.eu/en/project/eu-us-transfers [1] https://noyb.eu/en/new-us-executive-order-unlikely-satisfy-e...
You should definitely adjust your messaging then because your announcement makes a big deal about your EU offering being GDPR compliant which it thus can't be. There's no such thing as "almost GDPR compliant". That's like "almost not getting fined". The customers asking you for hosting your service on AWS in Frankfurt were clearly misinformed if they did so because they thought it would provide them with GDPR compliance and it seems shady that you went along with it instead of informing them that only self-hosting with a non-US (and non-subsidiary) company can make them compliant.
I'm not a legal expert but this sounds like you're almost engaging in false advertising if you claim PostHog Cloud EU to be GDPR compliant.
I know some companies fall for these lies, or decide to break the law a little bit because it’s convenient.
We went extra length to make sure we are US cloud free. With few exceptions it wasn't that difficult.
[2] https://noyb.eu/
> PostHog Cloud EU is hosted in the AWS eu-central-1 region based in Frankfurt, Germany.
So, no real benefit over using AWS?
If your argument is that AWS isn't legally bound by the EU, you're mistaken as they're operating in Ireland at the very least.
If your first thought is that this would render EU companies unable to use common cloud providers like AWS, Google Cloud or Azure, you're not wrong, although most EU companies are likely unaware of this as it's the outcome of a recent court case and not entirely settled.
As a EU resident I would advise EU companies to avoid all US service providers and their subsidiaries where possible, regardless of where their servers are located until the US legislature makes explicit guarantees protecting EU servers from being accessed by US law enforcement without going through the apropriate international channels (which would include notifying all affected EU residents of the access).
I realize this can't always be avoided but replacing Google Analytics with another US company over GDPR concerns seems a lot of effort for no effect when there are self-hosted and EU-based alternatives available.