Big Tech can transfer Europeans’ data to US in win for Facebook and Google
arstechnica.com
arstechnica.com
The entire problem for me is basically what Snowden revealed. In most democratic western countries a certain level of privacy is actually enshrined into law due to it's propensity for abuse. -- the US spying on Swedens behalf means that technically Sweden is not spying on Swedes.
The US having data on me by itself isn't a huge deal; there's no fucking way I will ever want to live there and factually: nobody is going to go sniffing into my life like in the movie "Enemy of the State" (though I suppose they could). However, the US sharing that information with Sweden can affect my life, because it's intentionally bypassing a protection that I am supposed to have in order to live in a free democratic system.
Failure to respect privacy lends itself to authoritarianism as people will self-censor if they feel they are not able to express themselves. Maybe I'm overstating this but it's a real concern of mine.
I don't think you are. I live in US and its version of 'privacy' has been normalized to a horrifying degree ( click this button so that we can do whatever we want ). We are basically at a point where 'enemy of the state' movie comparison is not even apt, because in that movie the audience would be petrified by it. Most are comfortably post-privacy.
The problem is our democracy is completely broken, and the fact that 80%+ of people agree on something that would even be socially beneficial, means absolutely nothing in terms of getting it done. Politicians and corporations love hoovering data for the exact same reason - perceived power. So nothing changes. And no politicians run on topics that people care about because you don't get to the point of being able to run for the presidency unless they're a billionaire, or have become really good at greasing the bellies of those that matter. And those that matter, only want even more surveillance.
It's topics like this, and others, that lead individuals like me to think our system is due to collapse. Not the issue in and of itself, but the fact we have a democracy that seems to have little to nothing to do with the interests of the people. Instead it's just propagandized crap after propagandized crap made into the issue of the day (that incidentally tends to have absolutely 0 benefit to the lives of the average American), while what people actually care about is completely ignored.
Anyhow, rant over. Point being, no nobody is "post-privacy", let alone comfortably. It's more like we're a democracy that's become "post-democracy", and seemingly comfortably so. Plato is more a prophet than a philosopher at this point.
[1] - https://www.pewresearch.org/internet/2019/11/15/americans-an...
I am saying this as the odd sheep in the family. Everyone else has kids running with Chromebooks, Ipads, every app imaginable, self imposed house wiretap and TV that carefully tracks their choices. And I have a wife too, which does put up with some of my craziness, but is unwilling to give up facebook so I need to carve out an exception for her on my network.
You are not wrong about our democracy, but have you considered that it is partially by design?
They give up their privacy and go to work. They give up their privacy and go to school. They give up their privacy to have a laugh. It's a horrible investment of time and effort for them to live in hyperawareness of actual threats that are also almost impossible to avoid. That doesn't make them responsible for their plight any more than a antebellum slave that fails to escape the plantation.
So yeah, I am accepting my share of the blame. People in general need to accept theirs. Once that happens, we can go after the actual culprits. Things don't change until we recognize reality for what it is.
And this has always been true. People blame the victims of surveillance for not being concerned enough to stop the perpetrators, who somehow come off as innocent by comparison; i.e. if you let them get away with it, of course they'll do it - who wouldn't! You might as well say it of a murder victim (if you empathize with murderers like coders empathize with tech giants.) As Stallman says, you're compelled to sign away your rights, because they'll make you do it to send your kids to school, to have a phone, to pay your taxes, to go to court, to interview for a job, to pay your rent, etc. For the average person this entails signing dozens of EULAs with dozens of different companies.
We can pretend that we're living in a democracy, but if the current actual material reality of citizenship necessarily requires signing all of your rights away (most often your right to privacy, your right to trial, or your right to speak), you know where you're living. You don't need to be a techie to know what that is; everybody knows what that is.
- 2022: https://www.thelocal.se/20221116/swedens-parliament-votes-th...
- 2021: https://edri.org/our-work/the-terrifying-expansion-of-sweden...
- 2019: https://www.cpomagazine.com/cyber-security/swedish-police-gi...
- 2008: https://www.eff.org/deeplinks/2008/06/sweden-and-borders-sur...
That I currently have a protection in law does not mean that the sitting government enjoys that I have it, however it is politically toxic to remove such laws directly so they erode them over time; in the mean time they enter these arrangements with third-party countries. (thus, terms like FIVEYES and FOURTEENEYES exist)
I believe though that intentionally loopholing the law to avoid this political problem is much worse than repealing the laws that protect me. It shows a fragrant disregard for the rule of law.
a Rundown of the western alliances:
* Five Eyes countries: United States, United Kingdom, Canada, Australia, and New Zealand
* Nine Eyes countries: The Five Eyes plus Netherlands, Norway, Denmark, and France
* Fourteen Eyes countries: The Nine Eyes plus Italy, Germany, Belgium, Sweden, and Spain
* Partners of the 14 Eyes: Israel, Japan, South Korea, Singapore, British Overseas Territories
i love this. its the anglo nations and their friends. in order of friendship. i feel like it explains a lot about the world.
* Five Eyes countries: anglo BFFs.
* Nine Eyes countries: scandinavians, half-anglo and norman cousins.
* Fourteen Eyes countries: former Axis + neutrals. not fully trusted but still close. sweden an outlier considering what they did to assange.
* Partners of the 14 Eyes: The honorary westerners.
Likely not overstating it because this is exactly what has happened both historically and currently in some countries.
The need for privacy is proven, not because people need to hide criminal behaviour or menial things, but because we can't rely on people with power to always do the right thing.
This sounds like another way of saying that you want to hide criminal behvaiour.
* Consume certain types of food or chemicals.
* Meet with more than 2 or 3 people at a time.
* Stay out past a certain hour.
* Allow your children to be outside without supervision.
* Have an abortion (even in cases of rape!).
* ...
Now follow the law.
See, that's fucked up isn't it?
You don't need to follow the laws of every country at all times. I am sure I have broken plenty of Chineese laws, but that's okay because I don't live in China.
Is your assertion accurately represented by the following prepositions:
A) The poster you're replying to, is desirous of the purported safety of guaranteed informational asymmetry from those in power
B) the poster in being so desirous, in all likelihood, is mistaken in the perception that codified informational asymmetry is a protection to them, because the same protection covers the person in power, except arguably moreso
Or...
C) the only reason to be desirous of such asymmetry in the first place is that one harbors the possibility of criminal intent.
Which from your phrasing of your original comment, came off with an unsaid part of "which I (referring to yourself) don't have or care about).
I'd like to think C doesn't enter the equation; and I'm fairly sure others have probably reacted thinking that was where you were going with it. If that was the case, fine...
However, even C) is rebuffed by "the definition of criminal is fluid and changes over time; and there is little guarantee in the stickyness or aggreeableness of said change". Material examples resonant with said rebuff can be found in the Roe v. Wade overturn, among other things.
But if B) is more in line with your thinking, I'd be quite interested in further expanding on it. I'd also be interested in where you fall eith regards to the statement "everyone is criminal at some point, no exceptions".
I've always entertained the hunch that one of the best disinfectants for a serving public official would be the complete dissolution of any right to privacy for the term of service. Coincidentally, there'd be problems in that most potential candidates for such work would be few and far between, and there could be pathological effects/selection pressures on the candidate pool, but I've never really had anyone to rubber duck the theory off of before.
>However, even C) is rebuffed by "the definition of criminal is fluid and changes over time; and there is little guarantee in the stickyness or aggreeableness of said change"
Which is why I believe it to be important for laws to not be retroactive. If someone is living somewhere which allows retroactive laws and wanted to do something then trying to find ways to hide your potentially criminal behavior could be desirable. I believe people should just be honest that they want to have their crimes be hidden to reduce their legal liability than to pretend that they just really like privacy as a concept or because they think privacy in a human right.
I genuinely do not engage in any criminal activities (that I am aware are criminal at least) - so I dont fully understand where the criminality angle comes from.
However, consider the toilet: everyone basically knows whats going on in the toilet, some people do criminal things in the toilet, yet we give toilets doors & special stalls. This is what privacy is, a little comfort that you are not being watched while doing intimate or personal things. With the understanding that, yes, sometimes this comfort can lead to some people abusing it.
So I thought I'd start at the most basic example: Police that have used government databases to spy, stalk and harrass: ex's and attractive women they saw in public. This is barely scratching the surface in the many ways that information of totally innocent people has been misused.
USA:
N.J. cop used police databases to stalk ex-girlfriend, investigators say https://www.nj.com/monmouth/2023/01/nj-cop-used-police-datab...
Officer Fired for Allegedly Using Police Database to Stalk, Harass Women https://www.newsweek.com/officer-fired-allegedly-using-polic...
Australia:
Former policeman accused of using force database to stalk ex-wife and girlfriend https://www.theage.com.au/national/victoria/former-policeman...
Former federal police officer faces new charges over stalking of ex-girlfriend https://www.canberratimes.com.au/story/6138318/former-federa...
(Note the two above articles are not the same person)
UK:
Met police officer 'used CCTV cameras to stalk his ex-girlfriend after telling her to take up sex work to pay her bills' https://www.dailymail.co.uk/news/article-11868575/Met-police...
Creepy cop saw attractive woman on the road and 'looked up her license plate number so he could stalk her on Facebook' https://www.dailymail.co.uk/news/article-2178556/Officer-Jef...
This list is of course not exhaustive. There are simply too many examples to cite here.
There are no "good guys and bad guys", that is an infant's-level understanding of crime. Rather all systems need to be designed assuming that bad actors may access them. This means that "red tape" and oversight is needed, as well as ensuring that not too much information is pooled into a single system.
The information that Facebook/Google learns about their users far exceeds what governments have allowed in their own systems. Privacy advocates are right to be concerned about access to these systems.
To have a functional democracy we actually need enough friction in the enforcement system that people have a reasonable chance of getting away with breaking laws so enforcement becomes a conscious decision to expend resources for obvious societal gain rather than a dragnet on behaviour we may not like but questionably harms anyway beyond the individual engaging in said behaviour.
As a US citizen, I'd love European style data protections enshrined as law.
GCHQ is the preferred proxy for NSA.
As a US citizen, I'm desperate for this. Or even better laws. The GDPR, for instance, is a great thing and better than anything we have going here -- but it's still insufficient.
Snowden, if any, shown that the USA gov can and already do regularly monitor communications.
We have CTF, KYC and AML regulations, as well as any related laws, for a reason.
Europe has now to deal with Russian invasion of Ukraine, because of this anti American sentiment.
If you don't see how the two things are related, and blame the USA who's the largest security supporter of Ukraine and Europe via NATO, then this whole privacy debate is useless.
Edit: 100 years ago, Germany was in a similar position like Russia today. Large powerhouse who thought they could get their way by military force. Sure, let Germany take some poland. Because of Germany we got WW1 and WW2, and 100 years later many haven't really learned their lessons.
There is nothing more pro-American than pointing out where the US needs to do better and agitating for that to happen.
But I also have a brain, and while I'm a huge critic of those things, I'd side with them anytime against current dictatorial regimes.
Why people romanticize dictators and reject democracy, I don't know.
I don't know how anyone can say this with certainty about any country these days unless you have a terminal disease or are up there in laps around the sun.
You have Western leaders literally toying with the idea of starting WW3 this week by inviting Ukraine into NATO - and sure it's not a certaintly, but so-called world leaders with bunkers are surprisingly laissez-aller about this.
And sure, the US is part of that block of countries, but there's a ton more distance between Russia and the US, than between Russia and Sweden.
The US is unlikely to ever properly regulate its treasured "big tech".
As the footprint of digital services on our lives keeps increasing the EU must decide what sort of society and economy it really is.
The problem was with insufficient safeguards for data requests by the US government -- law enforcement and spy agencies. That's supposedly been addressed by the Biden executive order, but we'll see if the CJEU actually buys that argument.
They do know that (excepting special circumstances like insufficient justification) an EO can usually be overturned with minimal oversight by the next administration, right?
Like, the Commission are really unlikely to revoke this even if (for example) DJ Trump returns and revokes this order.
The Court almost certainly would, but that would take time.
So my layman believe is that they don't need a treaty, since it will probably be overturned anyway.
Especially because it's going to be absolutely meaningless. Administration opinion since Bush, Jr. has been that no foreigner has any rights an American is bound to respect, unless they're on American soil, which requires a handful of courtesies. They can announce this policy with all pomp and circumstance and on the same day have the Attorney General write a secret brief explaining his theory that it doesn't bind the government in any way, which becomes secret law.
Royal pronouncements and secret laws. What a democracy.
-----
edit: they literally dragged out Eric Holder the other day to complain that a court order barring intelligence agencies from backchannel communications with social networks was going to cause terrorist attacks and child molestation. The guy who coined "too big to fail" but wasn't saying it sarcastically, and who admitted that his legal opinion on due process in the case of the assassination without trial of American citizens was that whatever process they used to decide what they would do was "due process."
It already made that decision in the first half of the 20th century. If you haven't heard, it decided to be a capitalist society. Nothing surprising here.
There are many different kinds of capitalism, some mostly good and some mostly bad, so just saying "it decided to be a capitalist society" lacks sufficient specificity. Also, capitalism is an economic system, so it's leaving out the "sort of society" part.
No, there isn't. There are merely different stages and the order they come in may vary ever so slightly as they affect one another. Over time, capital always accumulates, exploitation of the working class always tends to increase, and the rate of profit always tends to decrease.
https://www.politico.eu/article/eu-commission-violation-priv...
This carries the risk of losing the entire EU market, and further, the rise of actual competitors in the EU.
Can't have that. Gotta keep the EU dependent on US tech. Better make sure America retains tech dominance over Europe, and can keep raiding their tech talent with the lure of high compensation and global impact unavailable in the EU.
In all seriousness, the trans-Atlantic tech trade seems like a vaguely mercantilist colonialist system: Raw materials (skilled labor) flow in, finished goods (tech services) flow out.
You obviously have no clue what surveilance means and where it can lead. People like you explain the shambles that is the US political and regulatory system. Allow others to be concerned about having any dependency on it and not making naive assumptions about how it might evolve.
And that's what the outcome here is: data can be transferred to US companies which legally binding commit to comply with GDPR.
What was all the back and force about was that due to various US laws suing parties argued that US companies can not comply with GDPR even if they legaly binding commit to do so. Various courts ruled that that is indeed true.
Now again regulator have found another way to argue "it's legal like intended" which required some concessions from the US.
We will see if that way, like some previously ways, will be shut down by courts.
The EU Commission is a lobbyist's playground, and the least-democratic of the EU institutions. I'm shocked that the Commission can do something like this by decree, without any review by other institutions.
I don’t actually understand what the legal status of the “adequacy decision” is—it seems that once it’s thrown out by CJEU anyone who’d trusted it is still considered to have been doing illegal things? What does the decision make possible that wasn’t before?
That said, diplomacy has always been a part of the executive, which combined with the spread of democracy has led to weird hacks such as signatures on treaties not actually meaning anything until a parliament approves of (“ratifies”) them.
I think the idea is that the Commission maintains a list of countries to which it is OK to transfer data. The list is referenced from the regulation, but maintained by the Commission. Effectively, the Commission can adjust the legislation by buereaucratic pen-stroke, by altering the list.
I don't know whether it can operate retrospectively; for example, if you were off the list for a few years, but are now OK again, does that mean that your tech companies can't be chased for what they were doing when it wasn't OK?
I'd also like to know how this affects the UK. I don't know whether the UK implements the Commission's list in our legislation.
Like I said, I haven't had a chance to dig yet.
the entire point of the EU is the transfer of power from member state elected parliaments to a continent wide appointed executive
and it's designed as a ratchet: once transferred it's impossible to get back (other than leaving the entire thing)
https://news.ycombinator.com/item?id=36677578
Edit: of course for the next 1-3 years, compliance departments in the EU can declare themselves not guilty and business will continue as usual.
Personally (and probably naively), I do hope the EU and US can find enough common ground. It'll make everyone's lives a lot easier [1].
[1] ...if the US can get out of the habit of rifling through the data of EU citizens at the drop of a hat.
I think this would pretty much only be a net loss for EU consumers and businesses. Maybe no longer having access to American tech companies' services would be beneficial long-term but only if EU entrepreneurs build domestic alternatives, which we know is pretty unlikely. I think the reality is that they'll just loosen their laws so they don't get shut out. As we're seeing them do here.
Why is it unlikely?
They won't. They have made it pretty clear that all your data are belong to us.
Maybe? I think that depends on how you're measuring "loss".
https://noyb.eu/en/european-commission-gives-eu-us-data-tran...
If we were talking about doing a fully isolated instance of Facebook for the EU that would be one thing, but messing with where records physically live is dumb showboating. As long as US users connected to US backends can interact with EU friends’ content, it’s clear that the geographical separation is providing no meaningful secrecy of EU data.
Are you trying to say they are their own master, or did you want to write "USA" instead of that second "EU"?
In my experience, small tech is even riskier because they have similar technological capabilities as big tech to aggregate data and less oversight. Google, for all its ills, has an incentive to protect user privacy: people stop sending them money if they think Google is letting rando criminals harvest userdata, and governments get really antsy if they can't provide audit records for where the data goes and how it's secured. User trust is a lot more valuable to Google than risking that data, and (while the way Google uses the data can be cringe from time to time) the data itself is extremely secure, relatively speaking. Smaller firms can be bribed by those criminals, or bought by another firm with a different idea of privacy, or they simply go under and it turns out the data was unencrypted this whole time and, oops, the physical hardware storing the data just got auctioned off without a proper scrubbing, or some mid-level engineer had a copy of the whole user database on their laptop, or etc. And governments are worse at chasing the long tail of small firms; the legal process is better tuned to plop Meta and Google's lawyers' asses in the chair of an inquiry board than the lawyers / CEOs / garage-bound owners of a thousand small firms.
Those who think "europe is good on privacy" and want others to "shut up about it" ignore the deep corruption that exists (with regional flavours) which is usually shielded in bureocracy and process to pretend it's doing things on behalf of people and not simply their corporate quid-pro-quo friends and their self preservation interests.
But hey, it's easier to pretend "things are fine and that the problem is 'the right'" or some other boogeyman that dares criticize things outside the overton window.
I know that the US and most of Europe differ wildly on their understanding of monopoly protection. Extrapolating, I wonder if different EU members differ broadly on what constitutes "privacy" and therefore one might expect somewhat inconsistent results on privacy decisions based on who's hand holds the tiller that day.
My understanding is that there's always pressure from the executive to get more rights (surveillance, weapons, confinement). Depending on the administration and responsible minister, this results in slower or faster decrease in privacy.
E.g. here in Germany the current administration stance is against mass surveillance. But the responsible minister of inner affairs calls for less limits on surveillance. Luckily the entire rest of the administration is against it...
It's corruption. People just don't want to see it. The same way people compare health systems to the US to pretend they're not royally screwed and corrupt.
> I know that the US and most of Europe differ wildly on their understanding of monopoly protection. Extrapolating, I wonder if different EU members differ broadly on what constitutes "privacy" and therefore one might expect somewhat inconsistent results on privacy decisions based on who's hand holds the tiller that day.
Not really. Every other country is trying to ban encryption, further ban speech, ban criticism of politicians to "protect children", I'm sorry, to protect "minorites" this time around.
And this is not just EU, UK and other non-EU members have the same issues. The point is, for whatever reason, these countries which are absolutely corrupt but have very status quo parliamentary systems with little political involvement, get treated as if they didn't have entrenched corrupt politicians who couldn't give less of a fuck, about privacy or the citizen in general.
You just have to be involved a little in the country's politics and you see it.
Money well spent. Now it is clear why they spend milions for "lobby".
What I do mind though is, once again, the EU Commission showing what they are: leeches fed on lobbyists money to pass laws favoring big corporations. It's insane but the EU Commission is, since it exists and relentlessly and endlessly, the bad guy. The EU Parliament, where there's at least a few hundreds elected people, tries to tone down the EU Commission but the Commission has been given so much power it pretty much writes the rules (which all the EU countries are forced to transpose into national laws).
AFAIK more money is spend in lobbying in the EU than in the US.
It's legal bribery and it's sad really.
Except that Facebook/Google/etc collects your data even if you do give them a giant middle finger and refuse to do business with them.
This is through a program called Privacy Shield. For years Privacy Shield was allowed in the EU. It requires registering with theUS Gov't and having certain standards in place. It's not as strict as GDPR but it is still something.
This does have implications for big tech as well but big tech could have always afforded to jump through hoops for Europe using loop holes and subsidiaries. This levels the fiend a bit.
I'm not sure that letting smaller companies abuse people like the big companies do is a good kind of field-levelling.
My information belongs to ME and I should be able to give it in exchange for anything I want. That is my right that was taken away by the EU and now I have it back.