Live data from Hacker News

Google Admits Handing over European User Data to US Intelligence Agencies

news.softpedia.com

61–70 of 91 posts

Re: Google Admits Handing over European User Data to US Intelligence Agencies

#61
post #9

Earlier quoted context omitted.

"European Union legislation requires companies to protect the personal information of EU citizens" It's the law. What's more, it's a good law. I am concerned that they broke it, and seem to have tried to hide this.

The Patriot Act seems to trump EU law in many cases, as security fears oft trump privacy concerns. It's a good discussion to be had for sure, am I'm sure EU parliament members will debate it in length: They don't seem to have tried to hide anything. From another report: http://www.h-online.com/security/news/item/Google-also-passe... The previous Microsoft admission that sparked this line of questioning: http://www.h-…

The Patriot Act does not trump EU law here, because the Patriot Act is not in force in the EU, it is not the law of the land in the EU, and is not legal.

Re: Google Admits Handing over European User Data to US Intelligence Agencies

#62
I think there is a misunderstanding of the intent of this provision of the PATRIOT act. It's primary purpose is to serve US based companies by providing cover from shareholder activism and negative press when they are outed for providing such information; and to streamline the process of dealing with such requests because there is little to be gained from resistance through litigation.

In other words, the PATRIOT act provides corporations with the least expensive option for providing user data and provides them with political and legal cover when they do so.

Re: Google Admits Handing over European User Data to US Intelligence Agencies

#63
post #7

One solution might be for Google to spin off its EU datacenter operations into a company incorporated outside of US jurisdiction. The Patriot Act would then no longer apply and Google would not be force to break EU law.

Two companies competing with each other are less valuable than one company, though.

Re: Google Admits Handing over European User Data to US Intelligence Agencies

#64
post #60

This is a very real problem and provides case in point as to why everyone needs to start using client-side encryption for their data and communications. In some cases this is still currently impractical to do on a day to day basis but in others such as Email, Social Networking or Instant Messaging it is not[1][2]. [1] I'm involved with a company that recently launched a free tool that provides transparent client-side…

The Chrome extension is not working for me on Mac. When I click "options" nothing happens, and there's no confirmation that it's working.

Re: Google Admits Handing over European User Data to US Intelligence Agencies

#65
post #24

Earlier quoted context omitted.

How does the "The Patriot Act seem to trump the EU law" ? In what sense? I reject the idea that a US law is more important in Europe than an European one. If that is what has happened, then it is wrong. If nothing was hidden, why is this policy only coming to light after the fact? There seems to be some degree of not wanting people to know.

From the article "but they [the companies] can be forced to keep quiet about it in order to avoid exposing active investigations and alert those targeted by the probes." There are a number of reasons why both the government and the companies would want to keep it secret: 1. Bad reputation for the company. 2. Bad reputation for the government on how much spying they actually are doing. 3. "keep quiet about it in order…

The US companies can be forced by the US government to be kept quiet about the data they revealed. However, their subsidiaries are European companies, and therefore must comply to EU law, therefore they shouldn't share the data, and if they do, that's a crime, and if they furthermore keep quiet about it, it's an even bigger crime.

I think they should be punished by law to the fullest extent available. Along with everybody that was responsible and is within the reach of EU law.

Actually, the EU should request extradition of those responsible that reside in the US, even if they didn't break the US law. Fair, isn't it?

Re: Google Admits Handing over European User Data to US Intelligence Agencies

#66
post #9

Earlier quoted context omitted.

The Patriot Act seems to trump EU law in many cases, as security fears oft trump privacy concerns. It's a good discussion to be had for sure, am I'm sure EU parliament members will debate it in length: They don't seem to have tried to hide anything. From another report: http://www.h-online.com/security/news/item/Google-also-passe... The previous Microsoft admission that sparked this line of questioning: http://www.h-…

I don't understand why you think that the Patriot Act seems to trump the EU law. The companies have separate subsidiaries in Europe. What the Patriot Act seams to be doing is Piercing the corporate veil. http://en.wikipedia.org/wiki/Piercing_the_corporate_veil . Making the EU company break EU law.

> Making the EU company break EU law.

That's a very incorrect statement. Noone can make you break the law.

In this case, the correct interpretation is, preventing US companies from having EU subsidiaries. Which means that the US offices have to be a subsidiary of some overseas corporation (i.e. make Google incorporate in Europe, or possibly some tax&law haven, like Cayman islands (I don't actually know about the laws there, but I'm sure there is a place on earth that would be ok)).

Re: Google Admits Handing over European User Data to US Intelligence Agencies

#67
post #40

The article doesn't mention the "Safe Harbor" provisions. This is a negotiated exception to EU Data Protection - roughly speaking, US companies can export the data to the US, as long as they promise to give equivalent protection. Google uses this to allow it to operate with personal data in the EU. If Google have exported the data to a US jurisdiction under Safe Harbor, then a subsequent PATRIOT Act request wouldn't…

That doesn't make one jot of sense.

By complying with the request they immediately violated the safe harbor provision.

Re: Google Admits Handing over European User Data to US Intelligence Agencies

#68
post #58
post #21

Earlier quoted context omitted.

When the government (that your business operates) is requiring you to hand over data what do you do? Is it Google's fault or the US government? I certainly don't think complying with the law is "evil". If the law is bad, fix the law.

I agree it's a very tough place to be. About fixing the law -- In that case I would expect Google to fight the government on this point. I wonder if they are/will?

http://www.google.com/publicpolicy/transparency.html

Re: Google Admits Handing over European User Data to US Intelligence Agencies

#69
post #3

Corporations based and operating in the US are subject to the PATRIOT Act, it's a shitty law but it's still the law. At least they are transparent about it. Edit: here is the article in question: http://www.wiwo.de/politik-weltwirtschaft/google-server-in-e... They asked if their EU based dataceters are also subject to US warrants and they answered that they are.

"European Union legislation requires companies to protect the personal information of EU citizens" It's the law. What's more, it's a good law. I am concerned that they broke it, and seem to have tried to hide this.

I would expect my EU government to impose sanctions on google forcing them to put a banner on all pages they serve to inside EU advertising that your information might be handed over to us intelligence services.

Re: Google Admits Handing over European User Data to US Intelligence Agencies

#70
post #40

The article doesn't mention the "Safe Harbor" provisions. This is a negotiated exception to EU Data Protection - roughly speaking, US companies can export the data to the US, as long as they promise to give equivalent protection. Google uses this to allow it to operate with personal data in the EU. If Google have exported the data to a US jurisdiction under Safe Harbor, then a subsequent PATRIOT Act request wouldn't…

That doesn't make one jot of sense. By complying with the request they immediately violated the safe harbor provision.

They certainly violated the spirit, but may not have violated any actual rules. I could imagine that there's some exclusion in the safe harbor rules for "national security".

It's not clear whether the Data Protection laws were ever designed to guard against national governments. I imagine that those who wrote them were really thinking about avoiding disclosure to private individuals or other companies.

Post reply on HN