Live data from Hacker News

Ask HN: Do I have to host all data in the EU to comply with GDPR?

news.ycombinator.com

21–30 of 74 posts

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#21
IANAL. I do have a certification data privacy, although it is for US and not Europe.

tl;dr EU-located servers are neither necessary, nor sufficient.

Recent decisions by courts and regulators (many in the past month or so) have clarified how and which data transfers from the EU to the US are in violation of GDPR. The current landscape this is: a transfer of personal data to a Controller subject to the US CLOUD Act is in violation of GDPR.

Let me go through several important things you should know:

* EU-located servers are insufficient. A fine was issued to Cookiebot (Danish) for using Akamai CDN, even though the court acknowledged the servers were located in the EU and the contract was with Akamai's EU subsidiary. A server owned by a US company is subject to US warrants, which is what violates GDPR.

* Every rulings I've read mentions the CLOUD Act explicitly. As far as I'm aware, US companies not subject to the CLOUD Act might be GDPR-compliant. Maybe. At the least, it hasn't been found illegal yet. The CLOUD Act applies to 'telecom' companies, a definition which includes Google and Amazon.

* BREXIT: The EU has an adequacy decision with the UK, meaning no special protections are needed. The UK still has an adequacy decision with the US. So if you're in the UK and only dealing with data subjects in the UK, this is not necessary for UK-GDPR compliance. In the EU, a UK-based hosting provider is totally fine, assuming they're not subject to CLOUD Act.

* The GDPR definition of "Personal Data" is nowhere in the same league as "PII, " and thinking they're similar is generally a mistake. To a first approximation, PII only refers to plaintext data that can be used to commit identity theft. Personal Data is any data point that can be connected to an individual. Examples of things the courts have ruled are personal data included IP addresses, and the randomly-generated first-party cookie that Google Analytics uses to tell that two hits came from the same user (and nothing else). GDPR explicitly contrasts anonymous data with pseudonymous data, and the latter is (usually) personal data.

* There are a handful of other countries which do have an adequacy decision in place, including Isreal, Japan, Canada, and New Zealand. Using companies based in those countries is easy to do from a GDPR perspective.

If you want to find more about the current legal state of data transfers to the US (which is in a period of serious flux right now), the place to start searching is Schrems II, which is the lawsuit that forced legal recognition by the EU of the state of data privacy in the US. The recent wave of rulings (which is still ongoing) were part of 101 lawsuits filed by noyb, the non-profit started by Max Schrems to press this issue.

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#22
post #11

With all the "IANAL" answers here, let me give you a different one: if it's viable, I would try to host all data in the EU for all your EU customers regardless of the legal situation. Because the legal situation is likely to change further - just plain and simple, it's a risk, and if your cost in avoiding that risk is sufficiently low, that might be worth it. And you can advertise it as a benefit to your customers.

Yeah, this is probably the most pragmatic answer.

It's a pain to implement and only adds more complexity to my setup for a tiny percentage of customers; but on the other hand the more I dig into the answers, the more unclear things get with recent rulings overturning common practices.

It's unfortunate that finding the answer to such a simple question seems to require lawyers, especially for a small business like mine. I wish we could protect data and privacy without opening Pandora's box.

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#23

You'd might want to check out how AWS handles it via Standard Contractual Clauses: https://aws.amazon.com/compliance/eu-us-privacy-shield-faq/

It should be noted that American companies that fall under laws like the CLOUD act can't fix their noncompliance with contracts. American law always overrules contracts for American businesses. Storing data on AWS is risky, and it's only a matter of time before some judge will rule it completely illegal.

Tons of companies and government agencies in the EU depend on Microsoft, Google and Amazon, and undoubtedly these companies also make a lot of money this way. The scenario you sketch is a possibility, but I think both the EU and US will do everything in their power to avoid this.

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#25

IANAL Customers don't have to be in EU for GDPR to apply, it applies everywhere as long as the data subject is an EU citizen. You're probably already not compliant unless you can 100% guarantee that none of your users in the US are EU citizens. The goal of GDPR is not to enforce a technical choice of a provider/technology but to ensure the existence of processes and the validity of data collection and usage by compan…

No, the GDPR does not apply to EU citizens wherever they might be. That would be completely unworkable.

The GDPR applies to anyone located in the EU.

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#26

IANAL. It is not an absolute requirement. It is often preferred from EU-based customers to store their data in EU-based data centers because then that data is subject to EU law, which can make things easier for your customers with their own legal compliance. edit because I was incorrect It is a requirement for EU users for their data to be subject to GDPR. It is not a requirement to store that data in the EU to be co…

Just to clarify, it is not just a preference, it is a legal requirement to store data of all EU citizens according to the GDPR. https://gdpr.eu/what-is-gdpr/#:~:text=The%20regulation%20was... . https://www.cnbc.com/2022/01/18/fines-for-breaches-of-eu-gdp... https://www.enforcementtracker.com/ It has also been ruled recently that pop-ups asking EU users to opt-in or opt-out of data sharing, where cookies etc can pass…

It's not a legal requirement to store all that data in the EU.

Although it might be pragmatic to do so given the last few agreements with the US on this were shot down in court.

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#27

IANAL Customers don't have to be in EU for GDPR to apply, it applies everywhere as long as the data subject is an EU citizen. You're probably already not compliant unless you can 100% guarantee that none of your users in the US are EU citizens. The goal of GDPR is not to enforce a technical choice of a provider/technology but to ensure the existence of processes and the validity of data collection and usage by compan…

> Customers don't have to be in EU for GDPR to apply, it applies everywhere as long as the data subject is an EU citizen.

I’ve only read articles that said that the GDPR applies to EU residents (not necessarily citizens).

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#28
I've been looking into this for my app. There's a lot of outdated or misinformed opinions out there (any info from before Schrems II in July 2020 should be ignored), but here's what I've concluded:

At this time, it looks like it's probably not legal to routinely store European data in the US under GDPR. There are limited exceptions (see below), but I don't think you can just host everything in the US.

GDPR requires you to only transfer (i.e., hosting, also viewing) European data to places with GDPR-equivalent data rights. Initially, the US qualified under Safe Harbor, but that was invalidated with the Schrems I ruling. Then the US qualified under Privacy Shield, but that was invalidated in Schrems II.

The guidance from the European Data Protection Board following Schrems II is more or less this:

- You may transfer data to the a country not officially recognized as GDPR-compliant (a "third country") if the transfer is necessary to do what your customers asked you to do. But only if the transfer is occasional, and objectively necessary.

- You can transfer if the user gives you consent, but consent can only be granted for specific transfers. You can't ask for perpetual consent to host everything in the US. Consent must also be explicit (an obvious, opt-in checkbox, not a EULA), and the user must be informed about the risks of sending data to America.

- Transfers under SCCs & BCRs are still valid in principle, but only if you confirm the destination country has GDPR-equivalent data rights. If they don't (which America doesn't right now), you can transfer only if you take measures to counter the risk of government interference, and only if the government can't subvert those measures (including by court order). Schrems II is also widely interpreted as forbidding "sign & forget" - you can't delegate your responsibility to certify the safety customer data to your cloud vendors.

EDPB FAQ on Schrems II: https://edpb.europa.eu/sites/default/files/files/file1/20200...

Article describing the impact of Schrems II: https://www.lexology.com/library/detail.aspx?g=86e3448e-2f32...

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#29
If you are on the big cloud providers, can't you consider flipping the problem and move ALL your data to the EU and apply all the requirements to all users as if they are ALL protected by European law?

You will have a one-time cost to migrate things, and depend on how many customers you have it may require you to add some automation to your systems (e.g, for the cases where a customer requests to get a copy of all their data, or to delete all the stored PII), but speaking as someone who had to deal with this in two different projects, I still think that taking this route was easier than trying to special-case everything based on user-specific citizenship.

Post reply on HN