Live data from Hacker News

Ask HN: Do I have to host all data in the EU to comply with GDPR?

news.ycombinator.com

31–40 of 74 posts

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#31
post #11

With all the "IANAL" answers here, let me give you a different one: if it's viable, I would try to host all data in the EU for all your EU customers regardless of the legal situation. Because the legal situation is likely to change further - just plain and simple, it's a risk, and if your cost in avoiding that risk is sufficiently low, that might be worth it. And you can advertise it as a benefit to your customers.

This is a bit fantastical.

Splitting up operations from a single data centre (vast majority of situations) is quite costly and adds a lot of complexity.

'You can advertise to your customers' - except that nobody really cares that much, or at least care enough to the point it makes a difference in terms of purchasing behaviour. I mean - everyone would 'like to know that their data is local' but that does not translate into purchasing behaviour or pricing intent in most cases.

Aside from 'real costs' of doing such a thing, opportunity costs are always high. There are always '10 critical things' to work on right now, who has an extra team of Engineers to work on 'maybe it will be useful someday features?'.

Finally - it's not a hugely helpful exercise in the end: it doesn't mater that-that much 'where' the data is.

People want to know that their data is protected and that's that. So just do that, which everyone should do.

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#32

If you are on the big cloud providers, can't you consider flipping the problem and move ALL your data to the EU and apply all the requirements to all users as if they are ALL protected by European law? You will have a one-time cost to migrate things, and depend on how many customers you have it may require you to add some automation to your systems (e.g, for the cases where a customer requests to get a copy of all th…

Interesting suggestion but most of my customers are US-based so I feel like the impact on speed might outweigh the reduction in complexity?

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#34
post #11

With all the "IANAL" answers here, let me give you a different one: if it's viable, I would try to host all data in the EU for all your EU customers regardless of the legal situation. Because the legal situation is likely to change further - just plain and simple, it's a risk, and if your cost in avoiding that risk is sufficiently low, that might be worth it. And you can advertise it as a benefit to your customers.

I agree. It makes for good marketing, and it means lower-latency access for European customers.

I interpret the law as requiring it anyway, but I view this as carrot-and-stick.

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#35

If you are on the big cloud providers, can't you consider flipping the problem and move ALL your data to the EU and apply all the requirements to all users as if they are ALL protected by European law? You will have a one-time cost to migrate things, and depend on how many customers you have it may require you to add some automation to your systems (e.g, for the cases where a customer requests to get a copy of all th…

Until you run into data locality laws in India.

I think if you are trying to future proof your application for data locality regimes you are just going to have to think about region shards. It makes application architecture more difficult but it seems like the days of treating the internet as non-region specific is over.

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#36
post #22
post #11

With all the "IANAL" answers here, let me give you a different one: if it's viable, I would try to host all data in the EU for all your EU customers regardless of the legal situation. Because the legal situation is likely to change further - just plain and simple, it's a risk, and if your cost in avoiding that risk is sufficiently low, that might be worth it. And you can advertise it as a benefit to your customers.

Yeah, this is probably the most pragmatic answer. It's a pain to implement and only adds more complexity to my setup for a tiny percentage of customers; but on the other hand the more I dig into the answers, the more unclear things get with recent rulings overturning common practices. It's unfortunate that finding the answer to such a simple question seems to require lawyers, especially for a small business like mine…

Spending a lot of money on something you don't need to do is not 'pragamatic'.

"It's unfortunate that finding the answer to such a simple question seems to require lawyers, "

Yes, and it's the a problem for the EU. While there is definitely a need to have some kind of regulatory elements in place, the degree of complexity involved creates considerable constraints and overhead for ultimately very little gain.

There is probably a version of this legislation, or even better, some kind of 'data treaty' between WTO or OECD nations that makes this work out with a lot less overhead.

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#37
post #11

With all the "IANAL" answers here, let me give you a different one: if it's viable, I would try to host all data in the EU for all your EU customers regardless of the legal situation. Because the legal situation is likely to change further - just plain and simple, it's a risk, and if your cost in avoiding that risk is sufficiently low, that might be worth it. And you can advertise it as a benefit to your customers.

Yup. The spirit of GDPR is "do the right thing."

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#38
post #11

With all the "IANAL" answers here, let me give you a different one: if it's viable, I would try to host all data in the EU for all your EU customers regardless of the legal situation. Because the legal situation is likely to change further - just plain and simple, it's a risk, and if your cost in avoiding that risk is sufficiently low, that might be worth it. And you can advertise it as a benefit to your customers.

This is a bit fantastical. Splitting up operations from a single data centre (vast majority of situations) is quite costly and adds a lot of complexity. 'You can advertise to your customers' - except that nobody really cares that much, or at least care enough to the point it makes a difference in terms of purchasing behaviour. I mean - everyone would 'like to know that their data is local' but that does not translate…

How do you protect customer data from US government if you process it (not just store) in AWS/GCP/Azure?

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#39
I had to do a deep dive on all of this and I found the actual letter of the law to be readable and in some cases surprisingly well written. You're surely looking for a quick one way or another answer and there's lots of comments with their own takes so I won't rehash any of that.

Just a plug for reading the actual law like you would read the source code. There are entire sections you can skip about requirements the regulators are under and you can focus on the burdens on data processors and controllers which is effectively what you would be classified as.

Have fun, it's really not so bad.

https://gdpr-info.eu/

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#40

IANAL Customers don't have to be in EU for GDPR to apply, it applies everywhere as long as the data subject is an EU citizen. You're probably already not compliant unless you can 100% guarantee that none of your users in the US are EU citizens. The goal of GDPR is not to enforce a technical choice of a provider/technology but to ensure the existence of processes and the validity of data collection and usage by compan…

Hello,

DPO for a small UK charity here. The UK GDPR, which is now a separate article of legislation to the EU GDPR by the way, specifies in Article 3 that it applies; "to the [(F2) relevant] processing of personal data of data subjects who are in [(F3) the United Kingdom] by a controller or processor not established in [(F3) the United Kingdom]..." Link to source; https://www.legislation.gov.uk/eur/2016/679/article/3

This to me suggests that even a US citizen, who happens to be in a UK airport at the time, who has data collected, falls under the UK GDPR. But it's more likely that it applies to people resident in the country, rather than just transiting.

However, the law is irrespective of nationality, opting instead to apply depending on where the data-subject is. I believe the only changes to the UK GDPR from the EU GDPR, is the territory to which it applies. So if your data-subject are in the EU, their data is subject to the EU GDPR, or if they're in the UK, the UK GDPR.

Note also, that the UK GDPR does not make the UK Data Protection Act (DPA) redundant, but just adds a layer on top of it. So you may want to look at the UK DPA if you're going to be handling UK data-subjects data. Also, the UK legislation can be found at; GDPR: https://www.legislation.gov.uk/eur/2016/679/contents UK DPA: https://www.legislation.gov.uk/ukpga/2018/12/contents

Post reply on HN