I believe the authorities are correct here. Shopify is sending all personal data to CloudFlare, CloudFront (Amazon) and Fastly, so 3 US companies. They could sign so-called "data processing agreements" where they promise to safeguard personal data. But the Shopify FAQ explicitly states that they are unwilling to do so. As the result, Shopify is legally considered to not be processing data under the instructions of th…
As the author showed the volume of business and revenue in Germany is tiny, there may be not worth the effort for Shopify to do it. It may be the correct business decision. The differences in laws and requirements by country is one of the biggest factors to consider when providing international services of any sort.
Shopify Is Illegal in Germany
11–20 of 349 posts
Re: Shopify Is Illegal in Germany
#12All EU companies sending any PII to US-owned companies, regardless if the actual data stays in the EU or not, are in danger to be sued similarly to the author of this post. This is, among other laws, because of the US CLOUD act: > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requ…
Re: Shopify Is Illegal in Germany
#13Re: Shopify Is Illegal in Germany
#14Wait, does this imply that running a website behind CloudFlare is illegal in the EU? After all, webshop or not, IPs will be transmitted... Or are IPs only a problem in connection with getting user data like name and address? Or is it the IP+cookie combo?
IPs are sometimes PII. It seems that if you're the ISP, the IP is PII, but if you're a website, the IP alone may NOT be PII.
Re: Shopify Is Illegal in Germany
#15Re: Shopify Is Illegal in Germany
#16Earlier quoted context omitted.
As the author showed the volume of business and revenue in Germany is tiny, there may be not worth the effort for Shopify to do it. It may be the correct business decision. The differences in laws and requirements by country is one of the biggest factors to consider when providing international services of any sort.
This affects the entire EU. I try to hammer it into people's heads here in NL. Using US-based cloud services if you touch PII is a huge risk as they're all getting like crazed addicts fighting over their next high PII-high.
Re: Shopify Is Illegal in Germany
#17Sorry for the German only link, but this is from today and didn't make the rounds yet. It is not really about Shopify itself, but about the use of CDNs - which would be even more worrisome. Shopify Support couldn't help the shop owner.
GDPR is ugly. The only thing it allows you to do before you get confirmation to process PII is to show static page requesting for permissions. That's basically it. You can't do any "cloudy" stuff prior.
Re: Shopify Is Illegal in Germany
#18All EU companies sending any PII to US-owned companies, regardless if the actual data stays in the EU or not, are in danger to be sued similarly to the author of this post. This is, among other laws, because of the US CLOUD act: > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requ…
In theory, yes. In practice, the issue is that Shopify refuses to sign a data processing agreement: https://gdpr.eu/what-is-data-processing-agreement/
Re: Shopify Is Illegal in Germany
#19I believe the authorities are correct here. Shopify is sending all personal data to CloudFlare, CloudFront (Amazon) and Fastly, so 3 US companies. They could sign so-called "data processing agreements" where they promise to safeguard personal data. But the Shopify FAQ explicitly states that they are unwilling to do so. As the result, Shopify is legally considered to not be processing data under the instructions of th…
Re: Shopify Is Illegal in Germany
#20I believe the authorities are correct here. Shopify is sending all personal data to CloudFlare, CloudFront (Amazon) and Fastly, so 3 US companies. They could sign so-called "data processing agreements" where they promise to safeguard personal data. But the Shopify FAQ explicitly states that they are unwilling to do so. As the result, Shopify is legally considered to not be processing data under the instructions of th…
> The data protection authority justified this with the fact that US authorities could access personal data (probably primarily the IP address) for criminal purposes on the basis of the CLOUD Act, among other things. This occurs regardless of whether data is stored on servers in the USA or Europe.
I have to imagine the particular bureaucrats the author was dealing with are somehow wrong here? Otherwise this implies that a European business cannot use basically any American software (directly or even indirectly, like this case), even if that software fully conforms with processing and storing all data in Europe. The fact that American authorities could coerce any American company into turning data over, even if it’s stored in Europe, is enough?