Live data from Hacker News

Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services

infoq.com

131–140 of 186 posts

Re: Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services

#131
post #91
post #3

This is already affecting websites and web apps. At least all of our customers are moving away from Google Analytics and many try to also get rid of other Google services like fonts and maps. I'm very interested to see what this changes in other european countries.

I really don't understand the problem with Google analytics. Anyone who is able to explain that in easy terms? So they are collecting data about me to show me better ads. Isn't that what I want? They compare my data to a collection ("look-a-likes") of others that match my data fingerprint. What's wrong with that? The way I understand it nobody is interested in me as a person (which is a bit sad, but that's a differen…

[deleted]

Re: Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services

#132
post #38

Earlier quoted context omitted.

https://www.hcaptcha.com/ is a drop-in replacement for recaptcha. It's not EU based, but at least it's not Google, and the service is privacy oriented...

It's run by Intuition Machines, Inc. which seems to be incorporated in California. That fact alone disqualifies it.

Actually, no. hCaptcha has always been very privacy-focused, so in this case there are technical safeguards available: enterprise customers can pre-blind all data on their end, meaning hCaptcha gets no PII at all.

(disclosure: work there)

Re: Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services

#133
post #4

EU based cloud services always could compete before. Now they will compete on the basis of being in the EU instead of being better.

Interestingly, it's not actually about being in the EU specifically, it's just about being in a jurisdiction with equivalent data protections. It's not a "must be EU" cloud requirement, it's a "must not be USA" requirement. Canada, Brazil, Japan, India, and many other non-EU countries have GDPR-like data protection regulation that would be totally acceptable I think (IANAL). The core problem is USA specific - either…

Note that the US is absolutely capable of passing a data protection law at any time. I wouldn’t hold my breath, though.

Re: Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services

#134
post #48

Earlier quoted context omitted.

Google search seemed to work fine before that stuff was tracked.

That's because way less people were trying to game it.

And because websites used to link to other websites for non-profitable reasons (blogs, directories, and webrings).

Re: Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services

#135

Earlier quoted context omitted.

I think part of it is desperation. There is absolutely nothing the EU can say that will convince the American politicians that privacy and corporations are out of control in the US. Americans might believe it's fine, but Germans are careful about how personal data is handled and who has access to it. Culturally the US and Europe is drifting further apart and from the European side it's very hard to see that the US is…

Pretty sure Google and Facebook have more trust than politicians. Maybe politicians should ban themselves?

That depend on where you live. Regardless of how extreme, I trust every single politicians in the Danish parliament a lot more than both Google and Facebook.

Re: Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services

#136

Earlier quoted context omitted.

It's run by Intuition Machines, Inc. which seems to be incorporated in California. That fact alone disqualifies it.

Actually, no. hCaptcha has always been very privacy-focused, so in this case there are technical safeguards available: enterprise customers can pre-blind all data on their end, meaning hCaptcha gets no PII at all. (disclosure: work there)

If y’all write a blog post about how your preblinding option makes you GDPR-compliant for silent embedding even though you’re a US entity, that would be front page material right now.

Re: Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services

#137
post #126

Out of couriosity: Does the CLOUD act, FISA and whatever else also cover offshore subsidiaries? E.g. would a german Google GmbH still be subject to the CLOUD act if that legal entity has no relationship with the US? On the one hand, I can't imagine US surveillance leaving open such a glaring hole, on the other hand I wonder what basis US law could apply to companies of non-US countries.

In your scenario, is the theoretical Google GmbH a subsidiary of a US corporation?

I don't know much about the legal details, but I imagine it would have to be.

After all, the purpose of the company would be to offer Google services in Germany - so I imagine, it would either be a subsidiary or a de-facto shell company.

Good point though, that sort of answers my question already.

Re: Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services

#138

Earlier quoted context omitted.

>can’t be compelled to handover to US law enforcement Even if a US company holds their data in the EU, due to FISA 702, the CLOUD act and EO 12.333, they can still be compelled to hand over that data. So being a US company is a dealbreaker, regardless of where the data is stored.

What if google uses EU based legal company? https://cloud.google.com/terms/google-entity

Google would have to redesign their corporate structure so that EU customers of Google EU are never subject to US law, with no US-owned business anywhere in the subsidiary chain. Imagine that this is the current chain:

Alphabet (US) -> Google (US) -> Google (EU)

Under such a structure, Google (EU) is not GDPR-compliant, and will need to drop all upstream inheritance of (US) to comply with this ruling.

I am not your lawyer, this is not legal advice.

Re: Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services

#139
post #123

Does this also mean that e.g. EU business are not allowed to use Stripe or PayPal, since those are owned by US companies? Or, that it's not good enough anymore to use a EU hosting for Mixpanel or AWS or DigitalOcean?

If you, a GDPR-bound business, are silently serving, embedding, or otherwise using resources served by US businesses without explicit opt-in approval, then you absolutely could be violating GDPR, specifically for example if the user’s IP becomes known to the US-operated resources. This would theoretically apply whether using AWS hosting (even in EU availability zones), Stripe or PayPal cart checkouts, or any other pl…

Thanks for explaining - that's how I also understood it, just wanted to make sure I didn't miss anything.

Re: Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services

#140

So how does this apply to Gmail? If somebody sends an email to me, and I'm using Google Workspace, could they argue I'm sharing their personal information with Google then?

Yes, they could theoretically file a GDPR complaint. It is not certain that the courts would judge it a violation, but it’s quite likely, since their data is resting in servers owned (subsidiary-to) a US business.
Post reply on HN