Live data from Hacker News

Ask HN: Do I have to host all data in the EU to comply with GDPR?

news.ycombinator.com

51–60 of 74 posts

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#51

I've been looking into this for my app. There's a lot of outdated or misinformed opinions out there (any info from before Schrems II in July 2020 should be ignored), but here's what I've concluded: At this time, it looks like it's probably not legal to routinely store European data in the US under GDPR. There are limited exceptions (see below), but I don't think you can just host everything in the US. GDPR requires y…

This is one of the best answers I've read to this question.

It's not only the Cloud act but also the FISA act and the executive order nr.12333

The EU data protection head has made it clear that Standard Contractual Clauses do not suffice, as a workaround. EU and US administrations are trying to work out a working compromise, but no progress yet (and frankly, not likely to happen soon, as there are more relevant priorities)

Courts are slow, but they are starting to affirm the EU law.

For example,

the Austrian Data Protection Authority (DSB) ruled that the use of Google Analytics and thetransfer of personal data to the US violates the GDPR.

the French data protection authority (CNIL) also confirmed that these personal data transfers to the US are a violation of the GDPR.

These are the first decisions from EU data protection authorities in response to 101 complaints filed by https://noyb.eu/en , so more to follow...

Quite obviously, the same principle applies to any service that sends data to the US. (for example, fonts can be used to track user; IMHO push notifications might be next, because, even if encrypted, provide data^Hmetadata that combined with other data reveal a lot about users behaviour...)

The Portuguese Data Protection Authority ruled re. data processing carried out by Cloudflare for the Portuguese National Statistics Institute. Cloudflare declared to use its own servers in the European Union, but CNPD noted that Cloudflare had data centers all over the world and there was no evidence that, in the event of an emergency situation or legal order, personal data could not be transferred outside the EU in jurisdictions that don't provide equivalent protections.

The CNPD had ordered the immediate suspension of data flows to the United States despite the adoption of the standard contractual clauses.

Expect more of these decisions in the coming months.

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#52
post #48

Earlier quoted context omitted.

Spending a lot of money on something you don't need to do is not 'pragamatic'. "It's unfortunate that finding the answer to such a simple question seems to require lawyers, " Yes, and it's the a problem for the EU. While there is definitely a need to have some kind of regulatory elements in place, the degree of complexity involved creates considerable constraints and overhead for ultimately very little gain. There is…

Whether I "need" it or not depends on how much of my future customer base I estimate will be EU-based. Believe me, I don't think these laws are very well structured (they're not even clear enough that you have to dig through 15 different sources and recent court rulings to figure out what to do) and I don't want to add complexity to my setup, but I am trying to grow my business: if it works out financially with enoug…

"I don't think these laws are very well structured (they're not even clear enough that you have to dig through 15 different sources and recent court rulings to figure out what to do) "

"The headache will be worth it"

Those are contradictory, which is my point.

What if it turns out you really don't need to host your data in the EU? Then it definitely 'will not have been worth it'.

Unless there is some timing risk whereby you risk actually damaging your business because you're under threat of service degradation or litigation because you're 'behind the ball' in which case there might be some rationale for doing it ahead of time.

We don't even know for sure what bits of data might need to be moved to be compliant, or that the 're-architecture' itself may not be sufficient and will require 'another rearchitecture' ...

Do something when it's clear that it needs to be done, otherwise, I don't see how there is any upside at all.

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#53
post #47
post #43

Earlier quoted context omitted.

The whole situation is confusing for me. We set up a few project with kubernetes clusters for local governments in the Netherlands. They denied DigitalOcean because even though they have servers in Amsterdam, the company is in the US, so we went with a much higher priced custom K8s cluster from a local provider. So not really sure if they were right, but according to them even just having your servers run by a US com…

Any US based company can be forced to give up the data of European customers and be silent about it (see CLOUD act) so as far as I see it any US based company that adheres to the CLOUD act can not be GDPR compliant.

Yeah that's there arguing as well. Although local govs for some reason have no problem working with Azure.

EU cloud hosting companies however are not as mature as the big US players so makes it more of a pain.

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#55

IANAL Customers don't have to be in EU for GDPR to apply, it applies everywhere as long as the data subject is an EU citizen. You're probably already not compliant unless you can 100% guarantee that none of your users in the US are EU citizens. The goal of GDPR is not to enforce a technical choice of a provider/technology but to ensure the existence of processes and the validity of data collection and usage by compan…

No, the GDPR does not apply to EU citizens wherever they might be. That would be completely unworkable. The GDPR applies to anyone located in the EU.

I partially agree.

https://gdpr-info.eu/art-3-gdpr/

3-1: if you're EU citizen in the US using only a US service then GDPR does not apply it falls under US data protection however if that US service is using an EU subprocessor then GDPR does apply

3-2: if you're a US citizen in EU you're under GDPR regardless of the service you're using

Also https://gdpr-info.eu/recitals/no-23/ if you're a US company targeting EU residents you fall under GDPR

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#56

IANAL. You don't need to host it in the EU per se, but you must host the data in a country with similar privacy protections. Practically, this means no US cloud hosts. I'd recommend replicating your cluster to a European cloud provider if you want to be sure. Hosted Elasticsearch and MySQL/Postgres are available in tons of European cloud providers, sometimes for a lower price than their American competitors. It's mor…

The definition of PII can be a bit grey, some have deemed that IP addresses of the service provider, although not identifiable to a specific customer, can also be seen as PII as they can all people to be identified within a small group of users (where the IP does not resolve to a specific user). Even companies within the EU are being told that they need to be cautious how and when they collect data, and how it needs…

It is quite easy really. If you are not able to identify a person by IP it is not PII. It MAY be PII for ISPs for example if they are able to associate the IPs to customers so they would have to treat it as such.

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#57
post #49

Earlier quoted context omitted.

Note that this is not (only) about the physical location, but also on the legal side who can access the data. Even if the US company runs the servers in Europe it doesn't matter. U.S. government can request compliance with the CLOUD Act. Larger companies try to Dona little legal firewalling, by having European customers being customers of an Irish company, not the American HQ. However there are doubts whether such a…

If this is true, then no American company can do business in EU. Because the US government can always request compliance with CLOUD act.

Yes, if a company can't follow law, it can't do business. In this case US law and RU law contradict each other. If the governments can't find a compromise (previous attempts for compromise habe been overturned by courts) or won't change legislation companies have to pick how much legal risk they are willing to take. And GDPR-enforcement slowly increases.

See for instance https://www.cnbc.com/2022/02/07/meta-threatens-to-shut-down-...

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#58
post #37
post #11

With all the "IANAL" answers here, let me give you a different one: if it's viable, I would try to host all data in the EU for all your EU customers regardless of the legal situation. Because the legal situation is likely to change further - just plain and simple, it's a risk, and if your cost in avoiding that risk is sufficiently low, that might be worth it. And you can advertise it as a benefit to your customers.

Yup. The spirit of GDPR is "do the right thing."

The spirit of the GDPR is "do what we think is right even if we don't really understand what you really are doing - we have very fancy principles but no idea how to implement those, so we'll impose a ton of crazy measures hoping to move the needle, and failing miserably".

As a European, I don't really care of the spacetime position of the magnetic moment encoding if I clicked in the big red button or not. It does not change anything to my life. What I do care is that my sensitive data are kept securely. And even my government if failing to do that, so before they impose anything to the latest SAAS I subscribed to, they have a ton of work to do in-house.

I also care about what people post about me, but GDPR has an exemption for public data, so I am not more protected today than I was yesterday.

I am sure someone, somewhere feels all warms and fuzzy about "protecting" the European citizen, but boy did he miss the mark.

Re: Ask HN: Do I have to host all data in the EU to comply with GDPR?

#60
post #58
post #37

Earlier quoted context omitted.

Yup. The spirit of GDPR is "do the right thing."

The spirit of the GDPR is "do what we think is right even if we don't really understand what you really are doing - we have very fancy principles but no idea how to implement those, so we'll impose a ton of crazy measures hoping to move the needle, and failing miserably". As a European, I don't really care of the spacetime position of the magnetic moment encoding if I clicked in the big red button or not. It does not…

>the spacetime position of the magnetic moment encoding if I clicked in the big red button or not.

That's not what it's about, it's about weather you consent to third party cookies or not.

Post reply on HN