EU signs off on data transfers deal with US
politico.eu
politico.eu
This agreement puts products like Google Analytics back on firm legal footing. Bad luck for Meta that they were the one company singled out for a fine for doing what everyone else was doing in the period between agreements.
As I understand it, EU privacy law is fundamentally incompatible with US spying requirements, both sides know it, neither side cares.
The plan is to make one illegal agreement after another, each giving about 2 years of pseudo-protection until the slow EU legal procedures catch up. Then start anew with the next agreement.
There is too much trade at risk otherwise. There are enough macro headwinds for the global economy without adding self-inflicted injuries.
> the EU's top court struck down two previous agreements over fears of U.S. intelligence agencies' snooping.
Yeah, if only America's government agencies could keep within the confines of the law.
To use an extreme example to drive the point home, going to war with someone is (or can be made) legal too...
There's a lot of Europeans in the comments who mistakenly believe that GDPR applies outside of the EU. It does not. The US is a sovereign nation with its own laws, and it does not have any analogous legal restrictions like GDPR, nor does it have any legal restrictions against the government using it's intelligence apparatus against non-Americans.
That doesn't mean the non-EU countries will enforce it, it means that EU countries will enforce it even if the violation of the law happened outside of the EU.
Extra-territoriality of law is a fantasy, not a reality, unless it's backed by significant soft and hard power. Any country can say their law is extra-territorial all they want, but they have no jurisdictional authority to the enforce the law in an extra-territorial way. The extra-territoriality of GDPR has never been tested, but it's pretty clear to me that the EU cannot successfully enforce GDPR against a non-EU entity in the US. It may be able to use soft-power against smaller nations, but not against the US.
If the GDPR needs to extend into the US, it has to be via treaty, which has the same force as federal law, or via analogous federal law in the US. Neither of which exist right now. In fact, the exact opposite exists. The US government has made it pretty clear with the Cloud Act and other laws that the GDPR does not and will not apply to US-based companies operating on the Internet.
The EU is welcome to try to enforce it. In some ways, I would hope it would succeed (I support GDPR privacy rights/goals), however the precedent of extra-territoriality and sovereignty is not small.
Not quite. It applies to people "in the Union".
If the entity doing the processing is established in the Union then it applies to all of that entity's processing of personal data, regardless of where that processing takes place or the citizenship of the people whose data is being processed.
Same for entities not established in the Union but in a place where Member State law applies. The example they give in the corresponding recital is in a Member State's diplomatic mission or consular post.
For entities not established in the Union what it says it applies to data subjects who are in the Union in regard to activities related to offering them goods and services or monitoring their behavior as far as their behavior takes place in the Union.
Everyone in my surroundings (yes, anecdotal) is switching more and more to EU alternatives, and only uses US cloud-based software, if it can be used on-prem or inside EU datacenters.
Because cutting off a substantial amount of EU <-> US trade would be a disaster for the continent.
if "illicit transfer of PII for nefarious purposes" = "trade" then... I'm out of words.
No one elected the traitors of our rights that take such decisions in the commission...
Can someone explain to me what trade this underpins? AFAICT it's basically a one way street. Large corporations in the USA get to advertise to citizens of the EU. How does anyone in the EU benefit from this? Or even, how does any large EU corporation benefit from this?
https://www.lemonde.fr/en/les-decodeurs/article/2022/07/12/u...
Edit: Unless, of cpurse, some three letter agency front needs a non-US source to provide said data.
GDPR purports to apply to the processing of personal data of people in these cases:
1. When the company is established in the Union, regardless of whether the processing takes place in the Union or not.
2. When the company is not established in the Union but the processing is related to offering goods or service (paid or free) to people in the Union.
3. When the company is not established in the Union but but the processing is related to monitoring behavior that takes place in the Union.
I will believe this when it is challenged in court and it stands. As the article noted, this has been tried before.
https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae6...
That’s such a joke. What protections? The only protections I see are in a handful of states like California along with federal regulation for healthcare and payment data.
I wish the EU had applied more pressure to US lawmakers to come up with a national data privacy law similar to GDPR and CCPA.
All of that said, this agreement was inevitable. If data can’t be transferred between the EU and US, I don’t think it’s hyperbole to call that situation an economic disaster. The US and EU have too much commercial intermingling to have the EU actually cut off data movement to US data centers.
It hasn't been an economic disaster so far, why would it be now?
And it is not that they will seal off datacenters. It just makes US companies liable for handling EU-user data in EU-jurisdiction. If they are caught red-handed exporting data to US, fines will be on the way.
The only beneficiaries from this are FANG (lower costs) and 3-letter US agencies (they info they need at the reach of their hand).
Whiteout any proper audits or whistleblowers, how would you catch that?
For instance the DNA database of the EU ppl stored in the US (you know the "where are your ancestry from" DNA stuff from the US, which were actually used by the "services", caught right handed).
Urban legends say\ they can "find" somebody who got one of his/her relative do such DNA sampling.
The EU should just drop all Data Protection laws to make it fair, otherwise all they are doing is increasing the advantage of those agencies that play fast and loose with people's data.
Can EU startups finally use US providers?
It would be encouraging if pressure from the EU actually resulted in improved privacy protections in the US.
[0] https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae6...
The certification is based on Principles outlined in the document and are very GDPR-ey
... none of which are European, or much aligned with European interests in any way
I call BS.
A short check tells me that any current or future president can revoke an executive order at any time. So, the commissions decision in regards to FISA (which this is mainly about) hangs on Bidens word that neither he nor one of his successors will change it? Yeah ... I don't see how that's gonna fly with the EUCJ.
(The article also stated it, but I wanted to check in the original documents if that's really all they base their "all is good with FISA now" decision on)
One key issue was that European citizens should have a way to make complaints (it wasn't clear which US agency was responsible and if they'd act), another that intelligence agencies don't get a blank check looking at all data.
Either GDPR is removed as law in the EU or Non-US citizens are given full constitutional rights under US law. That's it.
But this is no surprise since the US is basically the funder of the EU, they get what they want
That's very sad
Do you think that I, as a European, want to be cut off from using ChatGPT or Google Docs?
The US is a failing economy with half of the world starting to detach from the USD
The US already starting to tinker with Copyright laws in order to boost and be leader in AI.. this is a red flag
This is another attempt for the US to save its economy
EU should do like the US and Asia, protect its industry
You mean "funder" as in financial funding? If so, how exactly?
https://en.wikipedia.org/wiki/Marshall_Plan
They funded and founded the EU, it was their idea, to merge economies and to open up borders to trade their goods push their influence further East
And it was their ideas to break big monopolies so their industry could be more competitive over there
https://en.wikipedia.org/wiki/European_Coal_and_Steel_Commun...
And now, it is their idea to allow data transfers and tinker with copyrights law so they can further help their AI industry
Thanks for sharing the link to the ECSC, it's been a while since I read about that. I wouldn't say though that the US founded the EU (https://en.wikipedia.org/wiki/European_Union), at least not in the literal sense of the word.
It's not just about the big names like Google or Meta. What about EU startups? They're left in limbo, unsure of what this means for them or the cost involved with complying with an additional set of rules. The final decision is with the court on a case by case basis, just as before!
Honestly, I doubt this will make any company at ease about EU to US data transfers - there's too much risk & cost for EU companies.
Whose law?
The US is a sovereign nation. US law explicitly allows them to snoop on foreign entities/persons/data.
GDPR doesn't have jurisdiction outside the EU.
I wish it were otherwise, but it is not. The EU isn't a world government, it's a regional government/alliance, somewhat analogous to the US. The US often manipulates other nations to agreeing to pass laws that align to their policy goals globally, but ultimately it's a decision of sovereign nations to pass laws. I don't think the EU wants to call into question the entire concept of sovereignty in a policy conflict with the US, since the US is the a hegemony and one of only two global superpowers (and arguably the only one).
In essence, as long as the Cloud Act exist and is enforced, I fail to see how US <-> EU data transfers can ever be GDPR compliant.