Live data from Hacker News

Danish Data Protection Agency bans Google Workspace for Municipalities

blog.simpleanalytics.com

11–20 of 31 posts

Re: Danish Data Protection Agency bans Google Workspace for Municipalities

#11
post #7

Earlier quoted context omitted.

Why do you think this is a good thing?

Not OP but but I try to explain it from my subjective perspective: It's good because that's not your small nodejs startup but rather Municipalities. They process sensitive data about their citizens and I'm sure Denmark has strict privacy laws for that. Giving that data to Google means it's now in the US and can be used by NSA or other organisations for spying. Does that happen? I don't know. But why take the risk. Se…

> Might all sound a little hyperbolic and theoretic but it can't be excluded

> the Central Intelligence Agency (CIA), the Bureau of Intelligence and Research (INR) and the United States European Command (USEUCOM) already spied on France in their 2012 elections. Targets have been all parties and their leaders. [..] All targets were infiltrated both by human (”HUMINT”) and electronic (”SIGINT”) CIA spies. Specific tasks have been selected for all targets individually. [1,2]

Associated Press, on the other hand, did everything they could to downplay the degree of espionage and infiltration:

> American spies wanted an insider’s take on the race, including details of party funding, internal rivalries and future attitudes toward the United States. Although WikiLeaks’ publication of a purportedly secret CIA document was striking, the orders seemed to represent standard intelligence-gathering. [3]

I wonder if they would have described Russian infiltration of US parties as "standard", and not striking.

[1] https://www.huffpost.com/entry/cia-spied-french-elections_b_...

[2] https://wikileaks.org/cia-france-elections-2012/

[3] https://apnews.com/article/8e5094a33ad84837a7faa31c426ca909

Re: Danish Data Protection Agency bans Google Workspace for Municipalities

#12
post #7

Earlier quoted context omitted.

Not OP but but I try to explain it from my subjective perspective: It's good because that's not your small nodejs startup but rather Municipalities. They process sensitive data about their citizens and I'm sure Denmark has strict privacy laws for that. Giving that data to Google means it's now in the US and can be used by NSA or other organisations for spying. Does that happen? I don't know. But why take the risk. Se…

Counterpoint: The data that municipalities store is not super sensitive, at worst it contains information about the number of sick days and salary. If the NSA cares about this data at all, it will probably have other means to obtain it. On the other hand, the municipalities might now have to spend a lot more taxpayer money to support a worse system that might reduce their efficiency, increasing wait times and frustra…

That sounds very much like an "if you have nothing to hide, why are you worried about privacy?" argument. Which is deeply suspect and entirely serves the interest of the massive surveillance apparatus.

Re: Danish Data Protection Agency bans Google Workspace for Municipalities

#13
post #8
post #6

Earlier quoted context omitted.

Since the entire Privacy Shield has been ruled invalid it seems all EU-US transfers/multinational corporations which process personal data are in a tough spot. I think Max Schrems (who took Facebook, among others, to court on GDPR) has a good explanation: https://noyb.eu/en/project/eu-us-transfers > At its core, this case is about a conflict of law between US surveillance laws which demand surveillance and EU data pr…

Quoted post unavailable.

Please, don't hold out, enlighten us with your unique insight.

Re: Danish Data Protection Agency bans Google Workspace for Municipalities

#14
post #12

Earlier quoted context omitted.

Counterpoint: The data that municipalities store is not super sensitive, at worst it contains information about the number of sick days and salary. If the NSA cares about this data at all, it will probably have other means to obtain it. On the other hand, the municipalities might now have to spend a lot more taxpayer money to support a worse system that might reduce their efficiency, increasing wait times and frustra…

That sounds very much like an "if you have nothing to hide, why are you worried about privacy?" argument. Which is deeply suspect and entirely serves the interest of the massive surveillance apparatus.

On the contrary, since the state ostensibly exists to serve its citizens, there is no legitimate reason to withhold any data whatsoever from them.

The idea that all but the most dangerous military information should not be public in real time flies in the face of the concept of an informed citizenry, and is far more dangerous and pernicious than its access by hostile powers.

If some information should not be public, it simply should not be accessible by the state.

Re: Danish Data Protection Agency bans Google Workspace for Municipalities

#16
post #14
post #12

Earlier quoted context omitted.

That sounds very much like an "if you have nothing to hide, why are you worried about privacy?" argument. Which is deeply suspect and entirely serves the interest of the massive surveillance apparatus.

On the contrary, since the state ostensibly exists to serve its citizens, there is no legitimate reason to withhold any data whatsoever from them. The idea that all but the most dangerous military information should not be public in real time flies in the face of the concept of an informed citizenry, and is far more dangerous and pernicious than its access by hostile powers. If some information should not be public,…

But here we're talking about giving data about the citizens to private entities in a completely different country.

I can see there being some argument for eliminating the whole idea of "classified information", but that is absolutely not what is being discussed here. This is about the private data of the people of Denmark, and keeping it private.

Re: Danish Data Protection Agency bans Google Workspace for Municipalities

#17
post #6

I’m trying to understand the current position of the EU commission on data transfers to the US. Based on this plus the recent google analytics decisions, it seems to me that data transfers to the US are going to be prohibited by default under the recent interpretations of chapter V. Am I understanding this correctly?

Since the entire Privacy Shield has been ruled invalid it seems all EU-US transfers/multinational corporations which process personal data are in a tough spot. I think Max Schrems (who took Facebook, among others, to court on GDPR) has a good explanation: https://noyb.eu/en/project/eu-us-transfers > At its core, this case is about a conflict of law between US surveillance laws which demand surveillance and EU data pr…

I really hope that in the (near) future we figure out a system of governance to better resolve inter-national conflict. I assume these conflicts will only increase as we increasingly interact across national borders.

Re: Danish Data Protection Agency bans Google Workspace for Municipalities

#18
post #8
post #6

Earlier quoted context omitted.

Since the entire Privacy Shield has been ruled invalid it seems all EU-US transfers/multinational corporations which process personal data are in a tough spot. I think Max Schrems (who took Facebook, among others, to court on GDPR) has a good explanation: https://noyb.eu/en/project/eu-us-transfers > At its core, this case is about a conflict of law between US surveillance laws which demand surveillance and EU data pr…

Quoted post unavailable.

[deleted]

Re: Danish Data Protection Agency bans Google Workspace for Municipalities

#19
post #7

Earlier quoted context omitted.

Why do you think this is a good thing?

Not OP but but I try to explain it from my subjective perspective: It's good because that's not your small nodejs startup but rather Municipalities. They process sensitive data about their citizens and I'm sure Denmark has strict privacy laws for that. Giving that data to Google means it's now in the US and can be used by NSA or other organisations for spying. Does that happen? I don't know. But why take the risk. Se…

Impacts of such rulings also mean that the small startups and everyone in between is impacted.

There are no EU only alternatives to GCP, Azure or AWS, I mean there’s always Alicloud but well…

Alternatives will not be developed in time for these rulings to have a devastating impact on EU companies and in fact any company that works in the EU that processes data covered by GDPR even if they host purely within the EU simply because the parent company is in the US.

And even if my some miracle a real European cloud competitor would arise they wouldn’t limit their market to the EU, and the moment they have a substantial US presence and a US legal entity they can fall under similar circumstances as US originated companies.

This also means that potentially using solutions such as customer supplied or managed keys to encrypt data outside of the direct control of cloud providers is no longer sufficient to protect yourself from data transfer risk.

Re: Danish Data Protection Agency bans Google Workspace for Municipalities

#20
post #8
post #6

Earlier quoted context omitted.

Since the entire Privacy Shield has been ruled invalid it seems all EU-US transfers/multinational corporations which process personal data are in a tough spot. I think Max Schrems (who took Facebook, among others, to court on GDPR) has a good explanation: https://noyb.eu/en/project/eu-us-transfers > At its core, this case is about a conflict of law between US surveillance laws which demand surveillance and EU data pr…

Quoted post unavailable.

Why do you think privacy is not involved? Currently if a US company stores data on EU citizens then the US government can compel them to produce that data in a way that's not compliant with GDPR. That seems to be a pretty unambiguous privacy issue (not arguing that there are probably some other politics going on of course).
Post reply on HN