Sounds like they're going to get condemned again in the future, seeing how these things get knocked down again and again. The EU commission is really dropping the ball there.
Sounds like they're going to get condemned again in the future, seeing how these things get knocked down again and again. The EU commission is really dropping the ball there.
So maybe the DPAs will defer to the EC's interpretation of adequacy under the GDPR for this new Framework?
Lots of unknowns though, since Schrems has already announced a challenge to the Framework. The only "safe" option without any uncertainty seems to be architect every system so that data never transits to the US and is also never in the custody of a subsidiary of a US-domiciled corporate parent.
To bad the EC isn't the body that can judge whether that deal is legal, and has been caught repeatedly lying about past deals [1].
> So maybe the DPAs will defer to the EC's interpretation of adequacy under the GDPR for this new Framework?
As before, cases will go to the actual authority on the matter: the CJUE. I personally don't have high hopes for this deal to last.
[1]: https://noyb.eu/en/european-commission-gives-eu-us-data-tran...
Oh I agree with that. EC's behaviour in that case is appalling.
> Corporations can't necessarily trust the EC's own interpretations of their own laws
There is a way to be safe with regards to EU law, and it's to engineer systems where European data stays in Europe. Of course, the issue is that corporations would then be liable under US' FISA 702.
That's the big issue: the United States made a law that basically states that no US company should follow EU law, and the US admin manages to beat EC officials into submission every few years with another flawed agreement to keep the ball rolling.
It's easy to say that the US should just scrap s.702, but unless it's reciprocal with Europe scrapping their interception powers as well, that's a pretty unrealistic ask.
That is common indeed. What's peculiar with US law is that it can mandate companies to move data about people outside of US jurisdiction that is stored outside of US jurisdiction and turn it over to US authorities, even when it violates local law.
The goalposts on this move every 6 months, so the fines are easy money for the EU.
The companies are just collateral damage. For some reason HN is full of people who don’t actually understand this issue but feel very emotionally passionate that all US tech companies are evil and doing this on purpose.
“Just follow the law, you evil companies!”
Lol. They would if there was a clear law/process to follow that didn’t get shot down every few months.
As it stands, you cannot operate in the EU as a US company if you want to be totally immune from fines.
I urge you to talk to your government representatives (on both sides of the pond) if you care about this issue. This benefits nobody except for EU government coffers.
Oh no, it's the US government that claims authority to use these companies to surveil EU citizens that is the problem here. One that, unfortunately, does affect all US companies.
There isn't a process because US law makes it clear that US companies should be auxiliary to illegal acts abroad. And we find out every few months, that even when they aren't forced to, they disregard the law.
Sure, maybe they're not "evil", but they apparently can't find a way to be law-abiding entities.
If i'm not mistaken, because of this (via[0])
> The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requested data stored on servers regardless of whether the data are stored in the U.S. or on foreign soil.
It sounds like compliance is only possible* if "the US company doesn't have any influence on the EU data-holding company" which is insane. This might be satisfied if the US company simply licenses their software product (e.g. the Uber backend) to an EU company. But this might not be adequate since chances are updates would be somewhat automated, and thus the US-based Uber might be compelled by the government to ship malware with their update to catch some US criminal (or otherwise enact some US spying).
* edit: only possible in lieu of a data agreement like Privacy Shield or its successor as mentioned above
0: top comment on https://news.ycombinator.com/item?id=33561222
It's completely sane from the EU's point of view. Why would they submit their citizens to forceful government eavesdrop?
I do agree it's insane. But the insanity is not on the GDPR.
I doubt this will change any time soon. The GDPR isn't going away, and the USA isn't known for loosening their data collection laws. Maybe in a few years the EU can find a legal ground to allow the USA to spy on EU citizens without acceptable legal defences, maybe the USA will give up their capability to use American businesses as a tool to spy on the EU, but for now surveillance law is a major roadblock for American companies expanding to Europe.
>> The CLOUD Act primarily...
As far as I understand (IANAL) the CLOUD Act has not been used as basis of decision at least for Schrems II. The primary issues court found were regarding surveillance programs authorized under Section 702 of the FISA & executive order 12333.
Full Schrems II judgement is available at https://curia.europa.eu/juris/document/document.jsf?text=&do...