Live data from Hacker News

Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services

infoq.com

161–170 of 186 posts

Re: Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services

#161
post #150

The website of the German federal tax office is not GDPR-compliant: https://twitter.com/jdvhouten/status/1488481039630704644 Seems premature to sanction private businesses when EU governments have not yet been able to come fully into compliance. Perhaps the changeover is more difficult than anticipated? As others allude below, it might make sense for the relevant EU-based alternatives to come online/scale up.

That’s not how the GDPR is written. It may seem premature, but someone has to be first to be ruled against in order for the interpretation to come into being, same as the Supreme Court and any other interpretive judicial systems.

That the private fine is essentially a token throwaway amount reflects that the court isn’t trying to throw the book at them; one can imagine the court will be much more upset about the government instance you highlight if it remains unaddressed.

Re: Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services

#163

Can it be explained, why “data is encrypted at rest using your own key” isn’t acceptable to regulator? Google might be compelled to hand data over, but data is encrypted and useless.

There's no mention of encryption at rest using your own key. To quote the ruling:

> If the second respondent (Google) subsequently refers to encryption technologies - such as the encryption of "data at rest" in the data centers - he must again be countered with recommendations 01/2020 of the EDSA. Namely, it states that a data importer (such as the Second Respondent) who is subject to 50 US Code § 1881a (“FISA 702”) has a direct obligation with regard to the imported data that is in his possession, custody or control to grant access to or release them. This obligation can expressly also apply to the cryptographic key without which the data cannot be read (ibid. margin no. 76).

> As long as the second respondent has the opportunity to access data in the Plain text access, the technical measures taken cannot be regarded as effective in the sense of the above considerations.

The last paragraph suggests true end-to-end encryption may be acceptable, but that's not how Google Analytics works.

Re: Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services

#164

Can it be explained, why “data is encrypted at rest using your own key” isn’t acceptable to regulator? Google might be compelled to hand data over, but data is encrypted and useless.

As long as you proxy^ all requests to Google for that data through your own servers, and do not include X-Forwarded-For: or any other identifying details in the request you transmit to Google on their behalf, and your crypto implementation is deemed sound, then that would likely be found not to be a GDPR violation. This runs counter to the tendency of websites to offload the burden of "go fetch and evaluate XYZ" to the useragent, and requires a server under your control that is not under US jurisdiction^^ to host or proxy all internet traffic of any kind necessary to deliver the service. (I am not your lawyer, this is not legal advice.)

^ some services may ban you for proxying in this manner without a contract

^^ proxy must not be hosted by or operated within AWS, GCP, Heroku, or any other US-controlled services provider

Re: Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services

#165

Earlier quoted context omitted.

That’s a weird attitude, at its core the GDPR is simply about keeping track of data, and ensuring that it’s not used for anything the users didn’t consent to. I’m having a hard time seeing how the rules could be any different. Remember that the GDPR is also result of companies looking at the cookie law and deciding “fuck it, let’s find a loop hole and not change anything”.

Oh, I don't know, maybe writing it so that it doesn't mean companies in the EU "basically have to cease all economic activity"? Or writing it so that it doesn't claim to tell me what I have to do with my website when I live in another jurisdiction. I laugh at GDPR. The EU can keep its bureaucracy to itself thank you very much. Making simple websites illegal and forcing me to hire a lawyer to figure out not what I'm a…

> basically have to cease all economic activity

I'm sorry, but that's the same bullshit argument that the Danish online retailers are making. So apparently it is absolutely impossible to do business, of any kind, without violating users privacy? Sure, some business can't function under the GDPR, that is true. The question then become, do we actually care? I don't. Those who can not deal with the GDPR are either extremely shady, or they are based in countries where the governments do not care about violating my privacy at all and will use creepy laws to force them to hand over information and shut up about it.

The GDPR is very aggressive, and rather broad in scope. Ideally I do agree that it should be a bit more forgiving, but given that business didn't even want to pretend to respect the privacy of customers, it's forced to be very restrictive.

The business that rely on user tracking, sell and reselling user data are directly to blame for the GDPR. They went WAY to fare and the GDPR is the EU reacting to an industry that failed to play nice.

Re: Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services

#166
post #163

Can it be explained, why “data is encrypted at rest using your own key” isn’t acceptable to regulator? Google might be compelled to hand data over, but data is encrypted and useless.

There's no mention of encryption at rest using your own key . To quote the ruling: > If the second respondent (Google) subsequently refers to encryption technologies - such as the encryption of "data at rest" in the data centers - he must again be countered with recommendations 01/2020 of the EDSA. Namely, it states that a data importer (such as the Second Respondent) who is subject to 50 US Code § 1881a (“FISA 702”)…

> but that's not how Google Analytics works

Yes. I made the question, given the discussion is being treated as much wider, beyond GA.

This also tells me, using own key can still be used by Google to operate as is (US company with EU owned entity and EU located DC)

Re: Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services

#167
If Google restructured into a franchise model, where each franchisee independently operates Google XY per country XY, then that would legally allow each Google XY to comply with GDPR while paying Google US a franchise fee. Technically, however, this is a nightmare to implement, since each Google XY would have a due diligence responsibility to audit all source code changes, and Google US would be required to issue a complete working set of product code to each independent franchisee, as otherwise they're just subsidiaries from a code standpoint, which when interpreted by a court would likely be found equivalent to being a full subsidiary rather than just a franchisee (as Google US would then retain the ability to collect GDPR-protected data in violation of GDPR).

Re: Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services

#168
post #4

EU based cloud services always could compete before. Now they will compete on the basis of being in the EU instead of being better.

Have you considered that being in the EU, with higher data protection standards, makes them better?

Re: Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services

#169
post #116

This could go a few ways. First, I'm sure Google will fight this and the fight will go on for some time. If they loose, Google could build EU data-centers and try to be GDPR compliant, which seems the most likely outcome. They could also pull out of the market, which seems less likely. If they pull out, I'm not sure that would be good for the EU market. People are suggesting that EU entities will spring up to fill th…

>Google could build EU data-centers and try to be GDPR compliant That doesn't matter, since US CLOUD Act allows US law enforcement to subpoena data even if they are stored in the EU. The only "way out" is to use cloud providers that have no presence in US.

Basically create a new, completely independent EU entity.

Re: Austrian DPA Ruling Against Google Paves the Way to EU-Based Cloud Services

#170
post #74

Earlier quoted context omitted.

"Google will just lock the data in the EU and keep doing business as usual." Personal data of EU citizens cannot be processed by american companies, full stop.

Wow, as an EU citizen with some data stored by US credit agencies, I would love to see those credit rating agencies restricted in how they use my data!

Send them threatening GDPR emails. I've found that helps in most cases - once had a VP emailing me to personally apologize
Post reply on HN