Earlier quoted context omitted.
I mean, we can be doing this back and forth for a while, but again, to quote from the article: "Judge Christopher Parker did not accept Nicholson's "wholly inadequate" excuse that providing his password would expose information relating to cannabis." So basically he said "I know the password, but I'm not going to tell you". That's obstructing justice. My point is if you say you don't remember and maintain saying you…
https://www.legislation.gov.uk/ukpga/2000/23/part/III The police think Bob has material that they need to see. They think that: The key, password, code is in the possession of the person given notice. Disclosure is necessary in preventing or detecting crime. Disclosure is proportionate. The protected material cannot be obtained by other reasonable means. They serve a section 49 notice. Bob can ignore this. But that m…
How the UK's online safety bill threatens Matrix
151–160 of 165 posts
Re: How the UK's online safety bill threatens Matrix
#152Earlier quoted context omitted.
A US company can be compliant. They just have to host EU user data in the EU.
Wait, is that really the standard? Wouldn't that imply that virtually any service doing business with EU customers would need to be either a multinational business or based in the EU? And just buying server hosting in the EU won't actually change that much about data access; if I'm a purely American business and I buy hosting in the EU, I think I'm still subject to US data requests. None of that goes away as far as I…
If you're an US company you would at least need to setup a independent EU subsidiary that you do not directly operationally control (perhaps owning shares works).
Re: How the UK's online safety bill threatens Matrix
#153Earlier quoted context omitted.
> GDPR really isn’t that complicated for most purposes You're coming at it from a position of knowledge and confidence. The guide produced by the Information Commissioner's Office for organisations has 48 sections/pages [1] and features a toolkit with 7 different self assessment quizes [2], plus an extra one to help small businesses [3]. Even the "What is personal data?" section of the site alone contains dozens of p…
Okay, fair enough - I agree that GDPR is certainly scary and daunting. But once you get past that, it is still something that can practically be implemented by small businesses, and generally improves things for users. My whole point here is that the Online Safety Bill cannot be practically implemented by anyone other than massive businesses, and even then it implicitly requires massive privacy violations. Which puts…
If you do this an executive and not try to circumvent or game this (like with taxes), there should be no jail time for you.
[1] not that I do like giving that power to content-auditing-companies.
Re: How the UK's online safety bill threatens Matrix
#154Earlier quoted context omitted.
https://www.legislation.gov.uk/ukpga/2000/23/part/III The police think Bob has material that they need to see. They think that: The key, password, code is in the possession of the person given notice. Disclosure is necessary in preventing or detecting crime. Disclosure is proportionate. The protected material cannot be obtained by other reasonable means. They serve a section 49 notice. Bob can ignore this. But that m…
Absolutely, but that loops back all the way back to my original question - has anyone ever been successfully been prosecuted for actually forgetting their password. Or at least saying "look, my passwords are auto generated and 32 characters long, I think the 5th and 8th characters were a # but I'm not sure". What then? You're not refusing to provide the password, you are just not exactly sure what it was, and if you…
If you're providing part of your password you run the risk that
i) you'll be convicted of the S53 RIPA offence (potentially 2 years for most stuff, potentially 5 years for child sexual exploitation or terrorism)
and
ii) they'll decrypt it somehow and you'll also be convicted of the original offences.
Criminals are well aware of the trade-offs of the English courts. Do you plead guilty at the earliest opportunity (and get a reduction in sentence as a result) or do you wait until the day of the trial (because many trials collapse before they get to court).
Re: How the UK's online safety bill threatens Matrix
#155Earlier quoted context omitted.
Wait, is that really the standard? Wouldn't that imply that virtually any service doing business with EU customers would need to be either a multinational business or based in the EU? And just buying server hosting in the EU won't actually change that much about data access; if I'm a purely American business and I buy hosting in the EU, I think I'm still subject to US data requests. None of that goes away as far as I…
It's most specific to the US because of CLOUD ACT and FISA courts. It would be the same for countries that have a similar structure in place. If you're an US company you would at least need to setup a independent EU subsidiary that you do not directly operationally control (perhaps owning shares works).
Sublime Text 4 just came out. That's based in Australia, where courts have similar data access, including the ability to require companies to circumvent encryption. Part of the purchasing process requires providing an email and other billing information.
Is it legal to sell Sublime Text 4 to a European? If Sublime Text was based in the US, would it be legal to sell it to a European citizen? What you're implying is that the EU can't legally have access to the majority of US-based Internet services, and that just seems so extreme that I feel like I wouldn't be hearing about it on Hackernews if that was the case.
But I don't know, I can't really confidently say you're wrong. Maybe it's just been under-covered, or I'm just not paying attention to the right news sources. At the very least, this can't apply to business-necessary information, right? Otherwise, it seems like you're saying that EU data in general can't be legally exported from the EU to most of the world, which seems like it would be a massive problem for the majority of the software industry.
There are a lot of software services based in countries with intrusive government data access: Fastmail (Australia), DuckDuckGo (US), Github (US), Itch.io (US). You're claiming EU residents don't legally have access to them? Again, I don't have any basis to argue that you're wrong, it's just... why wouldn't that be covered on basically every single tech blog if that was the case?
Re: How the UK's online safety bill threatens Matrix
#156Earlier quoted context omitted.
It's most specific to the US because of CLOUD ACT and FISA courts. It would be the same for countries that have a similar structure in place. If you're an US company you would at least need to setup a independent EU subsidiary that you do not directly operationally control (perhaps owning shares works).
So what are the full implications of that? I hate FISA too, but most non-EU countries have FISA-like structures in place as far as I know. Sublime Text 4 just came out. That's based in Australia, where courts have similar data access, including the ability to require companies to circumvent encryption. Part of the purchasing process requires providing an email and other billing information. Is it legal to sell Sublim…
If the EU customer is a company and not a private citizen and if it does involve storing personal information of the EU customer customers.
"What you're implying is that the EU can't legally have access to the majority of US-based Internet services"
No. You as an EU company can't transfer customer data to or redirect customers to US companies in a legal way.
"Otherwise, it seems like you're saying that EU data in general can't be legally exported from the EU to most of the world"
It depends on who does the "exporting" and what the "exporting" includes. But in general yes, it can't if the citizen whos data is exported can't be guaranteed to have the same rights as with the data in the EU. That is the core of it, Facebook can't offer a website in the US that is open to the EU and take information on the website "exporting" the data by POST HTTP requests to it's servers in the US (which they don't because Ireland, but in general yes).
There is much more to it, like "Can I store customer data in Google for Business spreadsheets?"
You're probably fine with Gmail because people know that this is an US company and sending an email to an US company is something a EU citizen might want to do. It's not as clear with Fastmail. It's not clear at all if you use custom domains with both. If you use a custom domain, where the customer can't see that it's outside the EU, do you export email addresses outside of the EU e.g. to Australia? But data protection agencies in the EU will take some more time to arrive at all these finer nuances. For now they are focused on Facebook and Google, and in 2021 went one level deeper with acknowledging that it's illegal to use Mailchimp in the EU (currently, I assume Mailchimp will create an EU legal entity and host EU data in the EU in the future when pressure rises).
For large enterprise that have subsidiaries in the EU it's already illegal to transfer EU employee data to the US for processing.
"You're claiming EU residents don't legally have access to them?"
As an EU citizen you can do whatever you want with your data, so "EU residents don't legally have access to them?" is misleading, because it would not be illegal for the citizen but - if - for the company. The company has a problem if it can't prevent three letter agencies from accessing the data. If you have no assets in the EU and do not plan on visiting the EU there is not much to fear though probably. I think it might be legal - not sure I've read something about it - to process data e.g. as a hotel for EU tourists, if you delete the data afterwards. Yes the GDPR is broad.
"But if I sell software in multiple countries, and part of my account process is collecting an email address or other PII, is that not GDPR compliant unless I set up offices in the EU?"
If you sell drugs to the US you're in trouble, even if it is legal to sell drugs in the country you live in.
You as a US company probably can sell to EU citizens but IANAL. The bigger problem for the EU if you sell to EU citizens from the US is VAT. If you send physical goods then your customer needs to pay VAT at customs - as many people in the EU found out after Brexit, if you send digital goods then the customer usually doesn't pay VAT. This is what agonizes the EU more than the GDPR and is the base for France to charge digital taxes to US companies.
"I wouldn't be hearing about it on Hackernews if that was the case."
Well I've lost 100+ karma for pointing out in the last years that it is illegal for EU companies to use Mailchimp. Today is the first discussion where people agree - still I lost 10 karma.
Re: How the UK's online safety bill threatens Matrix
#157Earlier quoted context omitted.
As a private citizen I like GDPR - even if Facebook will find ways around it (but I do not really care, I've left Facebook many years ago because of privacy concerns). As someone who implemented it in several companies, I don't like it because it hits smaller companies much harder than bigger ones, and because it tries to be technology agnostic it is quite fuzzy, compate to something like SOX or PCIDSS (which I also…
As both a private citizen, and one who implements it, I hate it. It’s increased regulation around a subject that I was not doing in the first place (I don’t care what you’re doing online, never tracked, etc) that only increased the cost of business. We need more competition, not less.
Maybe you were handling personal data correctly. Very many were not (witness numerous data breaches and private data exploited that was held for no reason). Therefore regulation was needed.
> We need more competition
Competition is good. A race to the bottom is not.
Re: How the UK's online safety bill threatens Matrix
#158Earlier quoted context omitted.
GDPR is pretty harmless and relatively easy to implement I think
What was particullary easy implementing GDPR for you? I found some areas particullary hard. Legitimate interest is a minefild and mostly can't be used, except e.g. delivery addresses. Finding GDPR compliant companies - with the US out of question - was also hard. Tracking and deleting data on request when storing in dozens of systems was hard - even returning all the data stored in dozens of external SaaS companies w…
Deleting people's private data upon request, namely when they click a button -- in my case (unlike yours) there's not many places to delete the data from.
The most challenging thing is instead writing a DPA, and wondering what to write about inspections and auditing, in a remote only company with servers in the cloud (any thoughts about that?)
Re: How the UK's online safety bill threatens Matrix
#159Earlier quoted context omitted.
So what are the full implications of that? I hate FISA too, but most non-EU countries have FISA-like structures in place as far as I know. Sublime Text 4 just came out. That's based in Australia, where courts have similar data access, including the ability to require companies to circumvent encryption. Part of the purchasing process requires providing an email and other billing information. Is it legal to sell Sublim…
"service doing business with EU customers " If the EU customer is a company and not a private citizen and if it does involve storing personal information of the EU customer customers. "What you're implying is that the EU can't legally have access to the majority of US-based Internet services" No. You as an EU company can't transfer customer data to or redirect customers to US companies in a legal way. "Otherwise, it…
VAT might be annoying in the sense that it forces me to ask for an address if I'm selling software to someone who lives in the EU, but that's basically fine. I can do that as a US company, and I can pay higher taxes, that's not a problem.
But if I'm building a software company, I don't have the resources to set up a foreign company to handle everyone in the EU who wants to buy a copy of my software. In practice, that requirement would mean that most single-person software teams outside of a few allowed countries can't sell to the EU.
Eventually you just get a lawyer to answer questions like these, but it does kind of sound like if I'm understanding you correctly, I should just be excluding any EU residents from buying anything I make regardless of the privacy policy, unless I have a zero-knowledge product. Which... being zero-knowledge is tricky because VAT exists, and I don't think I can not collect EU resident billing addresses and still pay taxes in an auditable form.
Maybe that's fine though, maybe that just means in practice you have to contract billing to a company that has an EU office, and then the problem is gone.
I should have phrased this differently, I know that GDPR doesn't constrain what EU residents do. But in practice it doesn't really matter to me if it's legal for them, it matters to me if it's legal for me. I don't know, apparently I need to do more research on this.
Interesting though, I appreciate you taking the time to elaborate.
Re: How the UK's online safety bill threatens Matrix
#160Says it all.