Live data from Hacker News

Shopify Is Illegal in Germany

lsww.de

11–20 of 349 posts

Re: Shopify Is Illegal in Germany

#11
post #5

I believe the authorities are correct here. Shopify is sending all personal data to CloudFlare, CloudFront (Amazon) and Fastly, so 3 US companies. They could sign so-called "data processing agreements" where they promise to safeguard personal data. But the Shopify FAQ explicitly states that they are unwilling to do so. As the result, Shopify is legally considered to not be processing data under the instructions of th…

As the author showed the volume of business and revenue in Germany is tiny, there may be not worth the effort for Shopify to do it. It may be the correct business decision. The differences in laws and requirements by country is one of the biggest factors to consider when providing international services of any sort.

This affects the entire EU. I try to hammer it into people's heads here in NL. Using US-based cloud services if you touch PII is a huge risk as they're all getting like crazed addicts fighting over their next high PII-high.

Re: Shopify Is Illegal in Germany

#12
post #7

All EU companies sending any PII to US-owned companies, regardless if the actual data stays in the EU or not, are in danger to be sued similarly to the author of this post. This is, among other laws, because of the US CLOUD act: > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requ…

In theory, yes. In practice, the issue is that Shopify refuses to sign a data processing agreement: https://gdpr.eu/what-is-data-processing-agreement/

Re: Shopify Is Illegal in Germany

#14

Wait, does this imply that running a website behind CloudFlare is illegal in the EU? After all, webshop or not, IPs will be transmitted... Or are IPs only a problem in connection with getting user data like name and address? Or is it the IP+cookie combo?

https://bluecatnetworks.com/blog/is-an-ip-address-pii-the-an... may provide some insight.

IPs are sometimes PII. It seems that if you're the ISP, the IP is PII, but if you're a website, the IP alone may NOT be PII.

Re: Shopify Is Illegal in Germany

#16
post #5

Earlier quoted context omitted.

As the author showed the volume of business and revenue in Germany is tiny, there may be not worth the effort for Shopify to do it. It may be the correct business decision. The differences in laws and requirements by country is one of the biggest factors to consider when providing international services of any sort.

This affects the entire EU. I try to hammer it into people's heads here in NL. Using US-based cloud services if you touch PII is a huge risk as they're all getting like crazed addicts fighting over their next high PII-high.

It's the way the EU can protect their own tech industry.

Re: Shopify Is Illegal in Germany

#17
post #2

Sorry for the German only link, but this is from today and didn't make the rounds yet. It is not really about Shopify itself, but about the use of CDNs - which would be even more worrisome. Shopify Support couldn't help the shop owner.

GDPR core is pretty simple: You cannot do stuff (process, store, transfer to third parties) with PII unless X condition is met. An internet site, on first visit (being genuine first visit or just cookieless visit) cannot do things with PII, because there is just no way to even tell if X is met, therefore not only data storage (IP address in Apache access logs included) is illegal, but moreso transfer to third party via CDNs and what not.

GDPR is ugly. The only thing it allows you to do before you get confirmation to process PII is to show static page requesting for permissions. That's basically it. You can't do any "cloudy" stuff prior.

Re: Shopify Is Illegal in Germany

#18
post #7

All EU companies sending any PII to US-owned companies, regardless if the actual data stays in the EU or not, are in danger to be sued similarly to the author of this post. This is, among other laws, because of the US CLOUD act: > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requ…

In theory, yes. In practice, the issue is that Shopify refuses to sign a data processing agreement: https://gdpr.eu/what-is-data-processing-agreement/

I know some of the team that worked on GDPR and CCPA compliance for Shopify and let's just say it is not surprising they're cutting corners.

Re: Shopify Is Illegal in Germany

#19

I believe the authorities are correct here. Shopify is sending all personal data to CloudFlare, CloudFront (Amazon) and Fastly, so 3 US companies. They could sign so-called "data processing agreements" where they promise to safeguard personal data. But the Shopify FAQ explicitly states that they are unwilling to do so. As the result, Shopify is legally considered to not be processing data under the instructions of th…

Shopify is a Canadian company, does this change anything?

Re: Shopify Is Illegal in Germany

#20

I believe the authorities are correct here. Shopify is sending all personal data to CloudFlare, CloudFront (Amazon) and Fastly, so 3 US companies. They could sign so-called "data processing agreements" where they promise to safeguard personal data. But the Shopify FAQ explicitly states that they are unwilling to do so. As the result, Shopify is legally considered to not be processing data under the instructions of th…

I don’t think you’re right about that? What I got from the article is that customer data is processed and stored in the EU, it doesn’t go through America. However, static assets are downloaded from CDNs operated by American companies (CloudFlare/Amazon/Fastly).

> The data protection authority justified this with the fact that US authorities could access personal data (probably primarily the IP address) for criminal purposes on the basis of the CLOUD Act, among other things. This occurs regardless of whether data is stored on servers in the USA or Europe.

I have to imagine the particular bureaucrats the author was dealing with are somehow wrong here? Otherwise this implies that a European business cannot use basically any American software (directly or even indirectly, like this case), even if that software fully conforms with processing and storing all data in Europe. The fact that American authorities could coerce any American company into turning data over, even if it’s stored in Europe, is enough?

Post reply on HN