A new trend I see is that some customers even rule out using EU located servers that are owned/run by US companies (such as the AWS Dublin or Franfurt locations).
A new trend I see is that some customers even rule out using EU located servers that are owned/run by US companies (such as the AWS Dublin or Franfurt locations).
A US company has to give access to the data on their servers to the authorities no matter where the servers are located.
They can go to court to prevent it but aren’t allowed to inform their customer.
That violates EU law on multiple levels.
Here's the situation it was designed to deal with. You've got a US company that has some documents. Law enforcement gets a subpoena requiring the company to turn over copies of those documents.
If the company has used some third party cloud storage provider to store those documents it has to retrieve them. It does this using the exact same procedure it would use if it was retrieving the documents for its own use. To the cloud storage provider this is just a routine data retrieval of a customer's data by the customer.
As far as I know if someone outside the EU buys cloud storage from an EU cloud storage provider, stores some files there, and later retrieves those files the EU provider will not get in trouble if that customer later did something with the files that would not be legal in the EU.
I'd be surprised if most countries don't have something equivalent. For example when German prosecutors were investigating VW after VW's emissions test cheating came to light if they had used whatever the German equivalent of a subpoena is to ask for copies of the emission system source code, would VW have been able to say "Sorry, we've got those in a private Github repository which happens to be hosted outside of the EU, so we can't get them for you"?
I suspect that the only reason the US actually had to have something like the Cloud Act and others don't is because only in the US could you have actually had a chance to succeed in saying that you cannot be compelled to turn over a document that you control and can legally retrieve at any time just because you happen to have it currently stored somewhere that the compelling government does not have jurisdiction over.
applies explicitly to daughter companies of US parents no matter which country they are based in
(More likely, there's another round of negotiation, and some new bandaid solution is produced; not like it's the first time. No-one, or almost no-one, really _wants_ this to break down entirely; the fallout would be widespread.)
It does seem reasonable to expect that the rate of companies moving stuff out of US-based infrastructure providers will increase, though; the whole thing is very fragile.
If there were to be a major migration from AWS and Azure to the likes of Hetzner, OVH and friends, also, that would likely be _permanently_ lost business for US megacorps; no-one does that sort of migration unless they really have to, so it's improbable that anyone would move back if and when the situation was resolved.
Bezos turning up at the inauguration and directing the WaPo to not endorse Harris are strong hints that Amazon is probably going to be fine, but I would say that nothing is certain when dealing with someone who's deliberately unpredictable and willing to threaten allies.
Those were completely inevitable, though; the game theory behind all this stuff essentially requires them.
> plus some symbolic concession
A really utterly meaningless one, though. I'm fairly convinced that pissed-off markets were the major factor.
> I thought he only backed off the Canadian tariffs, and only because there were retaliatory tariffs plus some symbolic concession? The China ones and the de minimis change are still in place.
Also Mexico. I'd suspect most of the Chinese ones aren't long for this world, either.
As for Github, self-hosted or vendor-hosted GitLab would be the obvious solution (self-hosted Github _is_ a thing, but only for large enterprises IIRC); other GitHub-like things are available.
I also suspect that Github in particular, and maybe MS, could, if desired, rework their services such that they didn't actually touch personal data in a form that they could disclose to the US government (which is the core issue here). This could be managed via using a third-party auth service (which typically these sort of services already support for enterprise integrations) and, for the Office-y apps, end-to-end encryption.
Replacing AWS and Azure and friends would in many ways be the big problem, especially if all this were to happen quickly (in practice, there'd almost inevitably be a significant grace period if things broke down). There's a big capacity problem there; all of these sorts of services operate basically at capacity, because economically it makes no sense to do anything else. That said, in the doomsday scenario, Amazon et al would presumably end up selling off a lot of data centres in Europe (restricted to only non-personal-data applications, they'd need fewer).
Doing without would be extremely painful in the short/medium term.
Of course if you could instead force AWS to sell the EU arm of their business, that would be a different matter...
[1] https://www.fierce-network.com/cloud/european-cloud-players-...
For a lot of stuff this is process that takes 10+ years. A fairly large step is the time between a EU regulation being created and when the same law is ratified by each country, and the span between those two events where the government seeks input from the industry on how to implement the regulation.