US Cloud soon illegal in EU? US punches first hole in EU-US Data Deal
noyb.eu
noyb.eu
It's important to learn from the best. Considering the election meddling efforts from agents directly from within the US government who are also owner of large media and AI companies the only reasonable outcome would be either sell those companies to EU owners or guarantee exclusion from EU markets for national security reasons.
"AWS plans to invest €7.8 billion into the AWS European Sovereign Cloud " - https://www.aboutamazon.eu/news/aws/aws-plans-to-invest-7-8-...
"...The AWS European Sovereign Cloud will provide customers the capability to meet stringent operational autonomy and data residency requirements within the European Union (EU), with infrastructure wholly located within the EU and operated independently from existing Regions. The AWS European Sovereign Cloud will allow customers to keep all customer data and the metadata they create (such as the roles, permissions, resource labels, and configurations they use to run AWS) in the EU..."
This might be bad for the citizens as it is limiting and breaking the global humanity ideal and I hate it that this is happening but EU must be really stupid to have the only open market then get ridiculed for not having "global" tech companies.
As it appears, the world going forward would be like the Chinese "tech" will be for 1.4B people, the US "tech" will be to 330M people and the EU "tech" will be for 450M people.
At this time, because you can access the EU market form US you can just form your business in US and hire people from EU to do the work. If EU imposes limits, suddenly it makes sense to invest in EU.
If you think about it, EU+UK+Asia taxpayers educate most of the "US talent". Very few of the people who invented the tech are US educated, the US educated ones tend to be the money guy or the entrepreneur free riding on foreign tax money.
Time to end the EU subsidies to US companies or maybe impose tariffs to make up for it. US is being very bad for EU, doing very nasty stuff.
I don't know about countries like Brazil etc. but I am sure that they will notice the benefits of having local companies too.
I'm not sure how these are related. The EU has far less money than the US for speculative, big payoff investments, to my knowledge. That's why there's less chance of creating new companies (and new markets) compared to the US.
Moreover, EU actually has plenty of capital as savings per capita are significantly higher than US. They lack a nice fluid market for it as Europe is much more fragmented than the USA. Recently they announced the creation of a new regime to address that(something like a virtual country with simplified regulations).
The problem is specifically that US law and policy will make both of those options unviable to guarantee the rights GDPR requires with respect to transfers to the US, once noyb gets the EU courts to state this clearly enough and invalidate the Commission’s adequacy decision for businesses which participate in the EU-US Data Privacy Framework. (In the meantime, EU companies are allowed to rely on that decision.)
There are several non-EU countries with adequacy decisions whose validity nobody is questioning, including Canada, New Zealand, and the UK. Many more countries can adequately be handled through Standard Contractual Clauses. The problem is very US-specific.
The current open markets model is not working, time to copy from the success stories: Ban foreign ones or force them to become local.
The current politicians are still in denial but as things deteriorate things will have to happen. Unlike US, European politics are not just two parties having about the same support.
Things can get very spicy very quickly. You think the anti-establishment ones are pro-American? The most pro-American politicians are those in power or those who recently lost power to the anti-establishment.
Pretty much non of the anti-establishent are pro-American(with the exception of UK with Farage) and with Musk targeting Farage I'm sure they took a note on how transactional their relationship with the US anti-establishment is.
I hope they won't be crazy enough to just bludgeon through that anyway, as past that, hic sunt dracones.
AFAIK there are no simulations in which nuclear war works. I am not convinced nukes would have helped Ukraine.
Also, as it was revealed with the war in Ukraine, the Americans spend crazy money on their military but they don't get the best value for it. They failed to provide the Ukraine the necessary ammunition and apparently the costs were multiple times higher with no better outcome compared to the Russian ones.
In addition to that, the warfare changed significantly with the drones and its the Europeans(Ukraine + Turkey) who have the most experience with those - both in use and production.
Mentioning Turkey, it's actually one of the most formidable militaries with very capable military industry complex. Although it has it's differences with EU, it is an EU candidate country and its economy is fully integrated with EU.
Later on when things calm down with Russia, EU-Russia is actually a very fruitful relationship because Russia and EU are perfect match(one has the resources, the other has the technology) and that's why Europeans didn't want to believe that the war is possible.
There are many more reasons not to be pessimistic about Europe too.
What is "fully integrated"? It's not on the Euro, for example.
Turkey and EU have a longstanding relationships with Turkey taking part in many of the EU institutions, like the customs union for example. In many ways Turkey acts as an industrial base for EU, many many EU companies have facilities in Turkey that serve EU.
Turkey is also in the Council of Europe, is in the jurisdiction of European Court of Human Rights(pays a lots of fines, unfortunately), European Border and Coast Guard Agency.
Turkey implemented GDPR compatible privacy laws, it has its infrastructure compatible and integrated with EU etc. Roads, electricity, gas, trains - everything is by the EU standards and integrated within the EU. Environment protection and worker rights are also not that far off. Turkey and EU fell apart only on political level and things like the upholding of the rule of law. In fact, Turkey is one secular government away from being full EU member.
For comparison with US, Turkey exports about $140B to EU and only about $14B to US. No matter the politics, it's EU what matters to Turkey and US is a distant 3rd with being only about %8 of the Turkish exports(Europe is %58).
Well, 6 aren't. But then I wouldn't say their economies were "fully integrated".
That's a few decades away, at best; have to wait through Putin's death, the collapse, the post-collapse warlord era, and the reconstruction.
Why? Germany already pushes for reconciliation, as they were hit the most.
For other countries in Central and Eastern Europe it doesn't matter who rules in Russia, as Russia interests are shaped by much grander forces, and those interests are opposite to those of Finland or Poland.
Let's stop looking at world through Marvel-like glasses. There are countries and nations, each with different interest shaped by the world and geography around them.
And this shows limitations of any political analysis that operates on the concept of EU.
Poland, Finland and Baltics are all in EU, and their relationship with Russia cannot be changed - core interests are completely opposite. The fact that these countries may buy russian gas if they need it doesn't change that.
Bolloré owns some major influential right-wing media in France, Axel Springer does the same in Germany (and even in the US - Politico), and so on. Axel Springer is also quite pro-American as well as being right-wing, and Bolloré is quite aligned with the North American right wing, both the anglophone and (in Quebec) francophone varieties. Plus the US Republican Party and the Conservative Party of Canada have major ties to EU member state Hungary and the current Orbán regime, which controls much of the media in that country.
All of these entities feed and profit off of rage, despite being EU-owned.
https://cloud.google.com/t-systems-sovereign-cloud?hl=en
Hardware, personnel and all access is EU company. Google can provide updates they have to manually review and install, and provides support.
It's pretty niche now but if demand grows more providers will spin up the same thing.
It would be fine if ends up like this: https://a.dropoverapp.com/cloud/download/b053fcd7-4635-4508-...
Well "liberty" will appear on our doorstep rather quickly, to free those clouds from the oppressive EU regime of course.
The results so far has been that most large companies has local legal presence within Europe, EU data centers, EU specific contracts with customers, and recently EU specific features in applications. It basically salami-tactics. Part of this strategy is also to use the court system to enforce specific aspects, like how part of GDPR is just now getting enforced after a case in March in 2024 by EDPS. The case initiated in 2021, GDPR was written 2016, so it also illustrate the pace. In the time between 2016 and now there are multiple new regulations, and those will also take time before they are fully enforced.
>here is no country called Europe, so what would it even mean?
Soon there will be, they are creating the 28th regime which is essentially a virtual country with a jurisdiction designed for speedy bureaucracy. I hope they do a good job with the implementation of the idea.
The fundamental problem is that EU and US law are incompatible. FISA allows the US to access any data from any US company no matter where it is located. It doesn't matter that the data is located in the EU, on a European server, manager by the European division of a company. As long as there exists a US parent company, FISA can compel the data. And that is fundamentally against the GDPR.
A new trend I see is that some customers even rule out using EU located servers that are owned/run by US companies (such as the AWS Dublin or Franfurt locations).
A US company has to give access to the data on their servers to the authorities no matter where the servers are located.
They can go to court to prevent it but aren’t allowed to inform their customer.
That violates EU law on multiple levels.
Here's the situation it was designed to deal with. You've got a US company that has some documents. Law enforcement gets a subpoena requiring the company to turn over copies of those documents.
If the company has used some third party cloud storage provider to store those documents it has to retrieve them. It does this using the exact same procedure it would use if it was retrieving the documents for its own use. To the cloud storage provider this is just a routine data retrieval of a customer's data by the customer.
As far as I know if someone outside the EU buys cloud storage from an EU cloud storage provider, stores some files there, and later retrieves those files the EU provider will not get in trouble if that customer later did something with the files that would not be legal in the EU.
I'd be surprised if most countries don't have something equivalent. For example when German prosecutors were investigating VW after VW's emissions test cheating came to light if they had used whatever the German equivalent of a subpoena is to ask for copies of the emission system source code, would VW have been able to say "Sorry, we've got those in a private Github repository which happens to be hosted outside of the EU, so we can't get them for you"?
I suspect that the only reason the US actually had to have something like the Cloud Act and others don't is because only in the US could you have actually had a chance to succeed in saying that you cannot be compelled to turn over a document that you control and can legally retrieve at any time just because you happen to have it currently stored somewhere that the compelling government does not have jurisdiction over.
applies explicitly to daughter companies of US parents no matter which country they are based in
(More likely, there's another round of negotiation, and some new bandaid solution is produced; not like it's the first time. No-one, or almost no-one, really _wants_ this to break down entirely; the fallout would be widespread.)
It does seem reasonable to expect that the rate of companies moving stuff out of US-based infrastructure providers will increase, though; the whole thing is very fragile.
If there were to be a major migration from AWS and Azure to the likes of Hetzner, OVH and friends, also, that would likely be _permanently_ lost business for US megacorps; no-one does that sort of migration unless they really have to, so it's improbable that anyone would move back if and when the situation was resolved.
Bezos turning up at the inauguration and directing the WaPo to not endorse Harris are strong hints that Amazon is probably going to be fine, but I would say that nothing is certain when dealing with someone who's deliberately unpredictable and willing to threaten allies.
Those were completely inevitable, though; the game theory behind all this stuff essentially requires them.
> plus some symbolic concession
A really utterly meaningless one, though. I'm fairly convinced that pissed-off markets were the major factor.
> I thought he only backed off the Canadian tariffs, and only because there were retaliatory tariffs plus some symbolic concession? The China ones and the de minimis change are still in place.
Also Mexico. I'd suspect most of the Chinese ones aren't long for this world, either.
As for Github, self-hosted or vendor-hosted GitLab would be the obvious solution (self-hosted Github _is_ a thing, but only for large enterprises IIRC); other GitHub-like things are available.
I also suspect that Github in particular, and maybe MS, could, if desired, rework their services such that they didn't actually touch personal data in a form that they could disclose to the US government (which is the core issue here). This could be managed via using a third-party auth service (which typically these sort of services already support for enterprise integrations) and, for the Office-y apps, end-to-end encryption.
Replacing AWS and Azure and friends would in many ways be the big problem, especially if all this were to happen quickly (in practice, there'd almost inevitably be a significant grace period if things broke down). There's a big capacity problem there; all of these sorts of services operate basically at capacity, because economically it makes no sense to do anything else. That said, in the doomsday scenario, Amazon et al would presumably end up selling off a lot of data centres in Europe (restricted to only non-personal-data applications, they'd need fewer).
Doing without would be extremely painful in the short/medium term.
Of course if you could instead force AWS to sell the EU arm of their business, that would be a different matter...
[1] https://www.fierce-network.com/cloud/european-cloud-players-...
For a lot of stuff this is process that takes 10+ years. A fairly large step is the time between a EU regulation being created and when the same law is ratified by each country, and the span between those two events where the government seeks input from the industry on how to implement the regulation.
Why would you need a regional linux distribution? The base is all open source, and I'm guessing the merges originate from everywhere in the world.
That is exactly the issue, when globalisation comes to an end as we are seeing it.
Why do you think many nations are already having their distro?
Naturally they aren't the kind of countries we would like to live on, but apparently we should not source all key infrastructure components from a country that is turning into 1984 as well.
1. My national government, by court order or sketchy secret court order.
2. Google, who are in the business of tracking and profiling.
3. The US government, by court order or sketchy secret court order.
A person might hope cloud storage provided by a national government would reduce the snooping by two thirds.
Of course, that analysis ignores risks like the service getting hacked, my account getting hacked, and suchlike - which some would say are much bigger risks.
I can understand, though, that most of the population doesn't want such complexity, and prefers to be able to reset forgotten passwords without losing their data.
Imagine this: You are a US citizen, and during COVID your kid gets a rash on their ass. You take a photo and send it to the doctor via some google service. Then google flags it, reports you to the police, and now you're in "the game", even though you did nothing wrong and were a responsible parent.
Same thing but if you had used a chinese service like Tencent (i do not know what they have as apps), nobody would care what medical images you're sending. So, who’s actually the bigger risk to your privacy and security?
And this is only the basic use case. Now imagine you're a drug dealer and you want to host your blog post explaining what experiments you did in your basement with different compounds. I guess north korean hosting companies will be your best bet.
And also I am pretty sure the opposite direction works as well, if you want to say that your president looks like a certain animated character, better use some US or EU company that have no business interests in your country.
If you're concerned about that, you use your own E2EE anyway.
(But it also wouldn't be a ban on personal use of such services, as long as the user consents. It'd "just" be very hard to use those services in business or government.)
Finally it is going to be the year of SuSE Linux Desktop, and Jolla.
Maybe we could have a second coming of Nokia N900 as well.
Oh well.
Some organizations that are deeply invested in a given tech provider do it anyway, but this is gradually going away.
Belgium has its own government cloud but its office infrastructure is on M365.
The Netherlands have nothing of their own.
EU institutions are migrating full-speed on AWS and M365.
In other words, if a US authority has any say on what's running/hosted in data centers in EU, it's a no go for more and more businesses and administrations.
US daughter companies have not means at all to direct their parent company to breach EU law, the other way around is more complicated
https://english.ncsc.nl/publications/publications/2022/augus...
But then came the CloudAct and the location doesn’t matter anymore.
You do business in the US, you have to provide the data.
But US law like cloud act is a broad overreach of US law into other countries.
Which puts them into a tough spot where there parent company has to comply with US law and give US access to their EU daughter company but their daughter company must not allow them such access at all and if they would use technical means to get it anyway it would be legally no different then a cyberattack....
For US companies to be in the clear, they would have to split their EU subsidiaries in such a way that the US branch could not access their EU operations or ship new patches, and would not have operational oversight.
Meanwhile, Germans pay with cash and credit cards are very unpopular because the German government sniffs every single transaction.
Europeans think they are pro freedom, but their idea of freedom begins by getting the government over them 24/7.
Evroc[1] is their name and I’ve been following them for a few years now. They raised a large amount in 2023 [2] and looks like they’ve just broken ground on land to build a data center just last week [3]
Very curious on how this will work for them and I plan on following their journey very closely. Any EU-based cloud engineers should apply to join!
[2] https://sifted.eu/articles/evroc-plans-e600m-investment
[3] https://www.datacenterdynamics.com/en/news/swedens-evroc-acq...
Oh come on! There are so many options in the EU to choose from, already. That none of them has the complexity of AWS is a feature, not a bug.
What they're implying is that it is illegal for US companies to comply with EU law.
This is significantly different than the EU enforcing the GDPR extraterritorially since that's basically just an increased cost of doing business in Europe and is apparently worth it.
But if the US companies have to choose between complying with US extraterritorial law or EU extraterritorial law they're going to have to choose the US, for obvious reasons.
It doesn't seem to me that convenient legal subsidiary structures or data physicality setups are gonna work here.
The effect of US companies withdrawing cloud services would be devastating to the EU. Imagine if you could no longer access your gmail or outlook account, your apple or google photos disappear , whatsapp shuts down, all you companies documents are no longer accessible on Office365 or G drive.
The results would be indistinguishable from a massive cyber attack and would take decades to recover from.
There's just no way the EU would inflict a wound of this magnitude on itself.
It would be painful, yes, but it wouldn't "take decades to recover from", not even years. These services, technically, aren't so difficult to recreate, if you have a big enough market.
That's not even considering the political backlash. How do you explain to your population that their digital lives have been permanently deleted because of a trans-national legal spat they don't care about?
I have looked into these 3 so far and was not too impressed. Would like to look at more, if there are some.
But it's great to have competition )
They aren't publicly traded either AFAIK despite being worth over 100Bln.
Outing myself as European here, but we've had a lot better results with privately owned businesses that are not 100% beholden to grow for their shareholders.
No unicorns, but sustainable growth.
They will most certainly be able to make the US subsidiary of Hetzner turn out any kind of data it technically has access to. But if Hetzner is not entirely stupid (and they are usually pretty smart) they set up their internal networks such that the US admins cannot access data located in the EU.
The problem with EU subsidiaries of Amazon and Microsoft is that the principal corporation is located in the US and subject to US jurisdiction, and that eventually, the owning company is always able to make a subsidiary comply with its demands, so it's virtually impossible to set up an impenetrable barrier between them. It's the other way round with Hetzner. A subsidiary can't command the owning company around, not even if the US government wants it to.
politicians like von der Leyen will make sure it's not gonna happen.
Some companies have gone further and not only are assuming data transfer to the EU will become illegal but also that European daughter companies (e.g. MS) might become illegal for some use-cases (e.g. lawyer documents).
Please God let this happen
The US exports hot air and gets real goods in return.
I just hope that if it happens, it's a very gradual rollout and not a hard one
I’m somewhat surprised about this kind of gleeful condescension in this particular forum, of all places.
But you are right, we might have to use SAP instead of siebel and peoplesoft
I think this is currently in vogue globally (both sides of the political spectrum), but its important to remember that we had good reaons to stop doing this in the past (or at least scale it down to absolutely vital sectors like agriculture).
I am all for it.
As someone working for the public administration I've long been worried about the decline of skills of IT workers here in Europe. It is especially flagrant in email infrastructure.
Since we are offshoring email to Microsoft for a long time already, we totally forgot how to manage email internally for the few cases when we still need it.
I work at a billion-dollar EU company that’s balls deep in Azure after a very, very long migration away from on-prem datacenters.
Cutting off US-based cloud providers would be chaos of biblical proportions.
The threat model is that the US government can either a) force the US-based employees of a US company to copy the data from EU to US and hand it to the US authorities, b) if not possible, force the US-based employees to order the EU-based employees in their reporting chain to copy the data from EU to US, or c) if not possible, order the company to circumvent any technical measures they have in place to make such copying of data impossible.
There _are_ working alternatives locally for businesses and administrations, only small because so far, most preferred to procure from the USA.
Now that there is a significant incentive not to do so anymore, maybe europeans providers will get a chance to grow and improve.