Live data from Hacker News

Ask HN: Do I have to host all data in the EU to comply with GDPR?

news.ycombinator.com

11–20 of 74 posts

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#11
With all the "IANAL" answers here, let me give you a different one:

if it's viable, I would try to host all data in the EU for all your EU customers regardless of the legal situation. Because the legal situation is likely to change further - just plain and simple, it's a risk, and if your cost in avoiding that risk is sufficiently low, that might be worth it. And you can advertise it as a benefit to your customers.

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#13

IANAL. It is not an absolute requirement. It is often preferred from EU-based customers to store their data in EU-based data centers because then that data is subject to EU law, which can make things easier for your customers with their own legal compliance. edit because I was incorrect It is a requirement for EU users for their data to be subject to GDPR. It is not a requirement to store that data in the EU to be co…

Just to clarify, it is not just a preference, it is a legal requirement to store data of all EU citizens according to the GDPR.

https://gdpr.eu/what-is-gdpr/#:~:text=The%20regulation%20was....

https://www.cnbc.com/2022/01/18/fines-for-breaches-of-eu-gdp...

https://www.enforcementtracker.com/

It has also been ruled recently that pop-ups asking EU users to opt-in or opt-out of data sharing, where cookies etc can pass their data to the U.S., are also outside the GDPR.

https://www.forbes.com/sites/martyswant/2022/02/02/europes-n...

https://www.brookings.edu/research/the-court-of-justice-of-t...

There were updates by Meta, Google etc based on recent ruling to update their terms and to change where & how they were storing data. The recent rulings could have major impact on Google Analyitics etc

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#14

If your customer is in the public sector that is probably the case. Mandatory reading is some info on Schrems II. Starting point: https://en.wikipedia.org/wiki/Max_Schrems#Schrems_II

Also can be useful for keeping track of these rulings

https://noyb.eu/en/statement-max-schrems-schrems-ii-annivers...

Nyob is one of the roups raising these issues with the EU data protections groups

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#15
IANAL. You don't need to host it in the EU per se, but you must host the data in a country with similar privacy protections.

Practically, this means no US cloud hosts. I'd recommend replicating your cluster to a European cloud provider if you want to be sure. Hosted Elasticsearch and MySQL/Postgres are available in tons of European cloud providers, sometimes for a lower price than their American competitors. It's more overhead for sure, but nothing business-ending.

However, the GDPR only protects personally identifiable data. A lot of data is PII, but not all data is PII. You might not need to bother if you don't collect anything that's unique to a person (though user accounts might pose a problem even if you don't process any other PII).

Depending on the size and turnover of your business, you may also need to comply with some other GDPR requirements (privacy officer etc.) but that's usually nothing more than appointing someone within your company to deal with+take into consideration privacy concerns (something your company should be doing anyway if it's ethically managed). Your data storage will probably be a bigger problem for your business.

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#16

You'd might want to check out how AWS handles it via Standard Contractual Clauses: https://aws.amazon.com/compliance/eu-us-privacy-shield-faq/

It should be noted that American companies that fall under laws like the CLOUD act can't fix their noncompliance with contracts. American law always overrules contracts for American businesses. Storing data on AWS is risky, and it's only a matter of time before some judge will rule it completely illegal.

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#17

IANAL. You don't need to host it in the EU per se, but you must host the data in a country with similar privacy protections. Practically, this means no US cloud hosts. I'd recommend replicating your cluster to a European cloud provider if you want to be sure. Hosted Elasticsearch and MySQL/Postgres are available in tons of European cloud providers, sometimes for a lower price than their American competitors. It's mor…

The definition of PII can be a bit grey, some have deemed that IP addresses of the service provider, although not identifiable to a specific customer, can also be seen as PII as they can all people to be identified within a small group of users (where the IP does not resolve to a specific user). Even companies within the EU are being told that they need to be cautious how and when they collect data, and how it needs to be stored in a secure way.

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#18

IANAL - but no, you definitely don't. What you do need to have in place is safeguards that any data on EU customers not hosted in the EU/EEA is subject to the same safeguards/level of protection outside the EU that it would be inside the EU. There are "standard contractual clauses" (SCCs) provided by the EU which are the easiest thing to adopt as part of (or an appendix to) your terms of service. However there is dou…

In my opinion even hosting a server in Europe is not sufficient thanks to the PATRIOT act and GDPR. However it seems to me that this is the current generally acknowledged practice until it is sorted out by governments and courts.

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#19

If your customer is in the public sector that is probably the case. Mandatory reading is some info on Schrems II. Starting point: https://en.wikipedia.org/wiki/Max_Schrems#Schrems_II

Also can be useful for keeping track of these rulings https://noyb.eu/en/statement-max-schrems-schrems-ii-annivers... Nyob is one of the roups raising these issues with the EU data protections groups

Great! Rulings are one thing. I can however add that despite rulings, there's extensive work being done at Sweden's governmental agencies and municipalities to replace USA hosted services. The city of Stockholm (40 000 workers and countless students) just recently said no to Office 365 partly because of Schrems II.

Similar things are happening in other countries:

https://techcrunch.com/2021/08/17/stop-using-zoom-hamburgs-d...

https://edri.org/our-work/microsoft-office-365-banned-from-g...

If you want to stay ahead and will have customers in the public sector in the EU, you should probably consider hosting within the EU.

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#20
IANAL

Customers don't have to be in EU for GDPR to apply, it applies everywhere as long as the data subject is an EU citizen. You're probably already not compliant unless you can 100% guarantee that none of your users in the US are EU citizens.

The goal of GDPR is not to enforce a technical choice of a provider/technology but to ensure the existence of processes and the validity of data collection and usage by companies on EU citizens. In essence, no it is not required to host your data in Europe but that is a possible interpretation.

First lawyer up, identify which data items are PII and what is not, make sure you have a process for article 17 (right to data erasure), appoint a DPO, make a real privacy policy stating the full extend and intent of data collection. Depending on the type of data you process different regulations will apply in addition to GDPR (PDSG, HDS for health data BaFin/AMF for finance in Germany/France) they vary based on industry and country, that will impact your overall technical design so this is prep work for everything else.

Technically I would definitely suggest having a separate database in EU and be prepared to potentially split your data among different countries as well. The processing of that data also might need to be split between US/EU and EU countries.

If you deal with data aggregation between EU/US you might not be allowed to run some analytics that contain personal data and will need to anonymize it and justify of that process to your DPO.

Post reply on HN