The US definitely needs stronger laws here.
The US definitely needs stronger laws here.
Can someone clarify for me why the physical location where data is stored is a big deal? Why does the US need stronger laws here?
This is probably just my inner naive technologist speaking, but I really enjoyed the moment of time during which the internet was a global network of computers that created a virtual space where physical borders were largely irrelevant. So it's a bit jarring for me to see people take for granted the idea that borders matter on the internet after all.
Edit: 0x62 has a good explanation here: https://news.ycombinator.com/item?id=41357888
I hadn't considered the recursive nature of suppliers.
What can you do if your data is silently copied by third parties and used for other activities? What if I build a ghost profile of you and steal your identity when I have enough data? What if I relay that you have a fancy car to some people who have the means to get that from you while sleeping? What if I craft a good scam by targeting you with your own data?
It's not about data is sent to where, it's about what happens when it arrives to the physical servers, who has access to these files, and what can they do with it.
When I visited the states, I got EZ-Pass spam/scam e-mails for a year, on an e-mail I gave to nobody when I was there. So, these laws matter.
Right, but the EU can only enforce its laws on companies that have a presence in the EU. A company that doesn't do business in the EU and never will do business in the EU will not obey EU law regardless of what those laws say.
Meanwhile, a company that does business in the EU would be subject to fines by the EU and wouldn't be able to dodge them without just stopping doing business in the EU. So why do the laws not just say "here's how you have to treat data belonging to our citizens if you want to continue to do business in the EU"? Why does the physical location of the data that is being thus protected matter at all?
The company would need to have a DPA with it's cloud provider. That cloud provider technically would also need a corresponding DPA with any 3rd parties that they themselves use, except without an EU presence that is hard to enforce.
In this case where there is one hop you could argue that it's the companies responsibility to ensure that their service providers are operating in compliance. Imagine the same scenario, but with one, two or more middlemen and the whole thing becomes an unenforceable mess of jurisdictions for the company to do meaningful due diligence on their service providers.
It's much easier for the EU to say EU data has to be stored in the EU, and know that any party touching the data is likely to be in compliance, and significantly easier to investigate if they are not.
As far as I understand, the EU is fine with you sending data to other countries, as long as those countries have the same standards for data protection. In the EU's opinion, the Cloud act, as well as the whole NSA situation, mean that the US doesn't fulfill this definition.
Yes, we have a GPDR compliant law in place, and we can interoperate with EU.
Because the place where data is collected and stored may have different rules around privacy and data protection then the place it is exfiltrated to.
If I give my data to a company in one place that has strict laws on what may be done with that information, I don’t want it escaping to a low-protection jurisdiction where there are no penalties for selling it to the highest bidder for god knows what purpose.
If there was an acceptable worldwide convention on personal data privacy that would solve the problem. Until there is, it matters a lot.
The EU has a law that said you must treat data of their citizens with respect. Fine, that's great. Any business that has a presence in the EU will need to follow that law. At that point, why does it matter where the bits are actually stored? Can the EU for some reason not enforce its privacy laws on Uber if Uber keeps its data somewhere else?
Conversely, if a business has no presence in the EU, can the EU enforce its data location laws on them?
The only thing that seems to matter for enforcement is where the company is located, so I'm really unclear what data location has to do with anything.
Yes. Even assuming these laws still work if data is in another jurisdiction (prob. not), they become unenforceable. If someone sells your data in, say, Somalia, how could EU gather evidence and start a legal process?
Maybe not, especially if they are separate corporate entities. Uber EU may choose to pay for operation of data storage by Uber US. Uber US is not under the same privacy restrictions and sells the data for profit, then what? Who sues who and for what?
This is also partly about governments - the US in particular is known for compelling access to servers that are on its soil and doing large-scale spying (not that EU powers don’t do the same, but bear with me). Companies operating in the US may not be legally able to guarantee data privacy. So having the data not enter US jurisdiction in the first place is considered safer.
Global network of computers where data ultimately flowed to American mainframes. Countries realize data is a resource / liability / vunerability, and even if most struggle to profit from it, they'd still want sovereign control over it. You only really control things on your soil. Physical location / possession matters for control.
This feels like an outdated worldview that no longer really applies to data. Data can be exfiltrated from the EU in milliseconds and there's nothing that the EU can physically do about it short of setting up a great firewall a la China.
The only thing they can do about it to retain sovereignty is to tell companies they're not allowed to exfiltrate data. But if they can do that successfully, they can also just tell the companies what they're allowed to do with the data wherever it is in the world.
If that someone is a legal entity within your jurisdiction, you have lots of options.
I edited my original comment to link to someone who gave a good explanation—what I hadn't considered is how difficult tracking suppliers and subcontractors recursively and ensuring that they all have a presence in the EU would be. I think it's a bad solution to that problem, but it does make sense.
https://incountry.com/blog/data-residency-laws-by-country-ov...
These laws seem to have been written for the age of fax machines, not for today.
In the case of EU countries (I think its part of gdpr), services that handle personal data need to make sure that that data stays safe. The only way they can do that is to make sure that the data stays in a certain region.
I think that is why op is advocating for stronger laws. Due to lax privacy laws in the US, it's impossible for European companies (and other privacy concerned companies) to host their data in the US, therefore your missing a share of the market
This explanation makes sense, but assuming "certain governments" includes the US then the remedy isn't stronger laws in the US, it's weaker laws—it means that the US was the first to break the borderless internet and it needs to rewrite its laws to be border-agnostic.
Sure they would, I think? They would just have to foot the bill to travel and file in a US court. And whatever user agreements they 'agreed' to might come in to play without legislation to supersede it. But they would have standing, I'm pretty sure.
Schrems I [1] (the old CJEU judgment invalidating Safe Harbor) endorses (§90) the opinion that:
> [D]ata subjects [whose personal data was transferred to the US] had no administrative or judicial means of redress enabling, in particular, the data relating to them to be accessed and, as the case may be, rectified or erased.
In what reads like a reference to FISA, it continues (§95):
> Likewise, legislation not providing for any possibility for an individual to pursue legal remedies in order to have access to personal data relating to him, or to obtain the rectification or erasure of such data, does not respect the essence of the fundamental right to effective judicial protection, as enshrined in Article 47 of the Charter [of Fundamental Rights of the European Union].
It then stops short of calling out FISA by name, instead (IIUC) invalidating on the basis that the adequacy of the legal regime was not addressed in the Safe Harbour decision to begin with. Privacy Shield came next and did, so Schrems II [2] (the newer judgment invalidating Privacy Shield) states (§181–2):
> According to the findings in the Privacy Shield Decision, the implementation of the surveillance programmes based on Section 702 of the FISA is, indeed, subject to the requirements of PPD‑28. However, although the Commission stated, in recitals 69 and 77 of the Privacy Shield Decision, that such requirements are binding on the US intelligence authorities, the US Government has accepted, in reply to a question put by the Court, that PPD‑28 does not grant data subjects actionable rights before the courts against the US authorities. Therefore, the Privacy Shield Decision cannot ensure a level of protection essentially equivalent to that arising from the Charter [...].
> As regards the monitoring programmes based on E.O. 12333, it is clear from the file before the Court that that order does not confer rights which are enforceable against the US authorities in the courts either.
It sounds like the official legal position of the US executive is that individual foreigners do not have standing to contest FISA 702 surveillance of them. (I could not quickly find the text of that position.) This is a 2020 judgment in a case from July 2018 regarding a European Commission decision from 2016, so the implications of the CLOUD Act, signed in March 2018, do not look to be in scope.
[1] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62...
[2] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62...
But if you are subcontracting to an agency you need to list them as Subprocessors in your DPA. So subcontracted support staffing companies for example would be required to be listed and explicitly consented to.
This is all assuming you set up the base contractual protections for the data required to export the data at all, which Iber apparently didn’t do here.