With what company? All good if it's a EU company like Hertzner, but it can still give GDPR headaches if you are hosting on e.g. AWS in Frankfurt because Amazon is still a US company.
With what company? All good if it's a EU company like Hertzner, but it can still give GDPR headaches if you are hosting on e.g. AWS in Frankfurt because Amazon is still a US company.
I’ve made software for the childcare industry, where the data concerns are greater than most other industries.
Nobody had any problem with AWS, or really any non-EU vendor, as long as they lived up to the GRPR agreements and could provide the usual agreements.
Only in Germany would you run into requirements to either host in Germany (at worst) or at least within EU (at best). Additionally, there’s a lot of German specific laws on top, that simply aren’t in the other EU countries, and the general population is also much more concerned about data privacy and residency than any other EU country.
It was a world of difference, and honestly enough for me that I would not enter the German market again if it meant needing to comply with any additional effort than the rest of the EU market.
A bit more of a rant: The hosting solutions in Germany are also quite atrocious once you get to a certain scale. Lack of proper managed services, tons of instability, insane maintenance policies, poor security support (eg no 2FA for many). Once you’ve gotten used to how AWS/GCP/Azure handles things, it’s hard to go back to that world.
Edit: Almost as response to my last point, AWS is setting up a unique EU sovereign cloud https://aws.amazon.com/blogs/aws/in-the-works-aws-european-s...
The only way out is to not be a US company.
Well, Germany isn't the country that made Google Analytics illegal. Other countries do care.
> Nobody had any problem with AWS, or really any non-EU vendor, as long as they lived up to the GRPR agreements and could provide the usual agreements.
I was in charge of the tech for a massive man in the middle company in Germany where we integrated with lots of companies to provide data for other companies. Noone had an issue with AWS because they were all using it. It's consumers who care and consumers who will make reports and it's companies that will pay the fine.
> With what company? All good if it's a EU company like Hertzner, but it can still give GDPR headaches if you are hosting on e.g. AWS in Frankfurt because Amazon is still a US company.
Says Hetzner (with only one r) in the first FAQ, "Is BillaBear GDPR Compliant?", on the homepage.
[ETA:] Could of course have been added after you asked here; I only checked it out just now. [/ETA]
Yea, the EU really needs to fix the EU-US GDPR issues. It's not like the US will.
And how would the EU "fix" the issues posed by the US's disregard for privacy? They tried several times but Schrems keeps tearing it down by pointing out the basic fact that you don't get a pass for violating civil rights by being the US.
But the implication was that the EU could do something to make such a treaty work and other than repeal and replace GDPR I don't see any way as long as the US insists on playing secret police when it comes to foreign data subjects.