Live data from Hacker News

Shopify Is Illegal in Germany

lsww.de

101–110 of 349 posts

Re: Shopify Is Illegal in Germany

#101
post #78
post #30

Earlier quoted context omitted.

I don't think that matters - what matters is where the processing servers are. And if they are using CloudFront etc, they are sending data to the US.

But those 3 US companies all signed the safe heaven agreement, AFAIK.

The Safe Harbor Agreement was invalidated by the Schrems I case in 2015. The Schrems II case from 2020 invalidated the EU-US Privacy Shield Agreement.

In addition, the physical location of the servers do not change anything when the company operating those servers is American. They still need to comply with the CLOUD Act, even to the point of pulling data and encryption keys from servers based in the EU.

Re: Shopify Is Illegal in Germany

#102
post #16

Earlier quoted context omitted.

This affects the entire EU. I try to hammer it into people's heads here in NL. Using US-based cloud services if you touch PII is a huge risk as they're all getting like crazed addicts fighting over their next high PII-high.

It's the way the EU can protect their own tech industry.

Yeah, not letting startups use any kind of US companies is a great way to protect your tech industry. Right now, there's a trend towards hosting on the edge—cloudflare workers, deno deploy, fly.io–european companies can't use any of this. And as far as I know, there are no european alternatives.

Re: Shopify Is Illegal in Germany

#103
post #71

It is ridiculous that data protection officials focus on CDNs, third party resources and cookies. And at the same time it is totally legal for Google to collect advertizing data from some random websites so they can create a profile that follows you around. All that sites have to do is to put up obnoxious cookie banners that nobody reads. If they were really concerned about my privacy, they would ban creating cross-p…

It's not legal for EU companies to use Google Analytics, because of the same legal reasons.

This either isn't true or nobody has noticed yet. It's on all sorts of EU sites.

Re: Shopify Is Illegal in Germany

#104
post #59

Earlier quoted context omitted.

While this is true, it is too easy. The privacy angle lives in the minds of Europeans, while US people seem to care a lot less.

> The privacy angle lives in the minds of Europeans without data, it’s hard to make this argument. what we know for sure is that bureaucrats fully support the privacy angle. but from my anecdotal real life experience almost no one cares (another argument that without data cannot be generalised).

The "bureaucrats" are elected officials so if people weren't in favour of it, they would stop electing MEPs that vote in favour of it.

Re: Shopify Is Illegal in Germany

#105
post #51

The EU is try to copying China's playbook of propping up local service providers by imposing impossible-to-follow rules on foreign tech companies. In both cases, the rest of the world should retaliate by limiting access to advanced technology until laws change.

>In both cases, the rest of the world should retaliate by limiting access to advanced technology until laws change.

That part is ok,but the problem isn't the GDPR but the CloudAct.

The US made it impossible to use any service of an US company by demanding access to all their data no matter where it's stored.

Imagine the US government could enter any house just because the lock is manufacturered by an US company.

And the US has a proven history of using wiretap data for economic benefits. See Echolon and Airbus vs Boing

Re: Shopify Is Illegal in Germany

#107

When this google-font stuff came up here in Germany, I was wondering if using CDNs also need permission first. I did some googeling for my ghost blog with no clear solution (ths standard gost blog uses jsdelivr). After reading the text: you need permission to load scrips etc. through CDNS. This is bad, since most of the software does not offer to locally host the required scripts.

Yeah, a lot of (paid) themes for Wordpress and similar "DIY" CMSes are in violation by default, often without a way to change anything without editing the theme's code. On the other hand, using X different CDNs will increase load times for most sites and has no caching benefits anyway (browsers segregate caches by requesting origin to avoid the cross-origin signal that not doing so would provide). It's probably quite difficult to perform better than subsetting your fonts yourself and just shipping them as a single zopfli'd CSS file from your static domain.

Re: Shopify Is Illegal in Germany

#108

two issues are mentioned in the post. One is a rather boring cookie consent issue which the user was able to solve, the thornier one is that Shopify's use of American CDNs runs into privacy issues. A user in the comments points out that the Trans-Atlantic Data Privacy Framework, which is basically the next iteration of Privacy Shield (which was canned in 2020) will probably alleviate these issues. Personally I think…

As long as the CloudAct exists all laws, frameworks, contracts are useless and just deception

Re: Shopify Is Illegal in Germany

#109
post #51

The EU is try to copying China's playbook of propping up local service providers by imposing impossible-to-follow rules on foreign tech companies. In both cases, the rest of the world should retaliate by limiting access to advanced technology until laws change.

It is neither impossible to follow or very hard. It just happens to be incompatible with US laws that grant local law enforcement access to stuff that is stored outside their jurisdiction, for customers also outside any jurisdiction.

Re: Shopify Is Illegal in Germany

#110
post #36

Earlier quoted context omitted.

In the UK it's illegal to pay a bribe to allow your company to operate, despite it being normal behaviour in many areas [0], I assume other countries have similar laws. In the same way, just because normal behaviour in some countries is to misuse customer data, it doesn't mean it should be legal for an EU company to operate in that way. [0] https://www.bbc.co.uk/news/business-13977221

When you make common practice illegal, you invite corruption into your system because selective enforcement of the rules becomes the new normal. Laws need to understand the environment that they are made in or will never be effective and oftentimes counter productive. As is the case here. GDPR goes even further than would be reasonable for any small business that handles email addresses. Requiring a salaried data pro…

> Requiring a salaried data protection officer is not feasible

Requiring a salaried health and safety officer is not feasible. Except it is. It doesn't need to be a dedicated officer, it needs to be someone (Company Secretary, the owner, whatever) who is accountable for it.

Post reply on HN