Live data from Hacker News

Shopify Is Illegal in Germany

lsww.de

121–130 of 349 posts

Re: Shopify Is Illegal in Germany

#121
post #51

The EU is try to copying China's playbook of propping up local service providers by imposing impossible-to-follow rules on foreign tech companies. In both cases, the rest of the world should retaliate by limiting access to advanced technology until laws change.

It is neither impossible to follow or very hard. It just happens to be incompatible with US laws that grant local law enforcement access to stuff that is stored outside their jurisdiction, for customers also outside any jurisdiction.

Neither it discriminates foreign companies. Domestic companies have to follow the same rules.

Re: Shopify Is Illegal in Germany

#122
post #43

Earlier quoted context omitted.

Does any one know if the Privacy Shield V2 will address this?

No one knows yet, because the successor to Privacy Shield is still currently more of an "agreement to do something" rather than an actual law. There is at least some movement in the right direction, which is to say the US is paying lip service to the notion updating domestic law to curtail law enforcement's access to data. But that hasn't actually happened yet.

The problem is that the US wants an agreement (saying data can be stored in the US as long as the US can't access it and EU privacy laws are applied to it), but the US also doesn't actually want to lose the right to warrant the data from US companies without respecting EU laws.

The history of the situation is like this:

- Privacy shield exists

- EU users data are stored and owned by Microsoft Ireland

- US goes against Microsoft with a warrant to acquire data stored by Microsoft Ireland

- Microsoft US refuses, stating it's not Microsoft US data nor US citizens data but data from an entirely different company that's in Ireland, even though Microsoft US owns it, so US needs to go against Microsoft Ireland

- Case goes all the way to the supreme court ( United States v. Microsoft Corp., 584 U.S. ___, 138 S. Ct. 1186 (2018) [1] )

- The US government really wants the access, but a lot of noise is being made from EU customers and government about it being in violation of the privacy shield, and that Microsoft losing this case would mean no more privacy shield since it would mean said shield isn't working, so US business are making noises too

- After the hearing, but before the Supreme Court gives its answer, the CLOUD Act is passed almost hidden as part of budget bill, which says US can go against a US company to request data from foreign companies they own and they have to comply as if it was their data

- The Supreme Court dismiss the case, the US government dismiss the original warrant, press releases are made saying they're not asking the data anymore and the SC dismissed the case so the privacy shield is working, and then the US government issue the exact same warrant but now under the CLOUD Act, which this time Microsoft US doesn't contest since the CLOUD Act says they have to provide the data from Microsoft Ireland

- Microsoft Ireland data is provided to Microsoft US, which provide it to the US government, bypassing EU courts

- EU is not fooled at all and ends the privacy shield -- EDIT see comments: after a court case forced them to admit it

- The CLOUD Act allows provisions to negotiate on a country to country basis, probably so they can negotiate with each country behind doors until they each get their own "ok I cave" moment to avoid being excluded from US tech service.

- GDPR enters the scene, making those privacy provision front and center and pushing them all the way to the EU. The whole negotiate with each country on its own goes away, you need a deal with the entire EU where each country doesn't risk being isolated if they say no, a EU country cannot say yes on its own as that would violate EU law.

- Side note: the UK after leaving the EU has now already made such an agreement, meaning UK data handled by US companies are no longer protected by UK courts no matter where they're stored (sovereignty much ?)

- US wants a privacy shield 2 with the EU, which I don't see how it can happen as long as the CLOUD Act exists unless EU companies are excluded from it, but the whole reason for the CLOUD Act to exists are EU companies, they could literally have named it "Bypass EU Law Act", because other jurisdiction don't care that much about their users data for some reason

The issue the US has is that all the US tech companies providing tech services could become persona non grata from the EU market court case after court case like this one, since the US has decided neither storing the data in the EU nor setting up as a completely separate sub company puts the data out of its reach.

Please note that the US never even tried to request Microsoft Ireland the data under the EU courts, like eg France did when asking Swiss court for swiss data from Proton Mail, their issue is really about them having all access on their own without having to ask anyone else, which is precisely what the EU refuses. The EU is fine with the US asking EU court for EU companies / users data and the court deciding on a case by case.

[1] https://en.wikipedia.org/wiki/Microsoft_Corp._v._United_Stat...

Re: Shopify Is Illegal in Germany

#123
post #33

Mini Ask HN: How would a small company, say a code forge, that is based in the US ensure that it is operating such that it is legal to have EU customers? All operations will be in the US (interaction only through a website). The forge will be designed to allow all of a user's data to be downloaded by that user (easy access to all data). It will also allow wiping away any reference to a user in commits (right to be fo…

In terms of the GDPR, your company would need to satisfy compliance of the GDPR. For small companies this is pretty straight forward, and it definitely helps to think about this early. https://gdpr.eu/compliance-checklist-us-companies/

Designate a representative in the EU? That doesn't seem straightforward to me, especially for a small company.

Re: Shopify Is Illegal in Germany

#124
post #116
post #7

All EU companies sending any PII to US-owned companies, regardless if the actual data stays in the EU or not, are in danger to be sued similarly to the author of this post. This is, among other laws, because of the US CLOUD act: > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requ…

Also, since the EU considers an IP address to be PII, anyone in the EU is not even allowed to connect to any website owned by a US company, as the IP address is a necessary piece of data to make the most basic TCP/IP connection work. Basically, the EU has put up a legal firewall between the US and the EU. Somehow this hasn't been realized fully or openly talked about, the the implication of their law is very clear.

> anyone in the EU is not even allowed to connect to any website owned by a US

These laws don't bind individual citizens, but companies offering services.

One might however ask, whether EU ISPs are allowed to route to U.S. as that passes IP addresses to U.S. companies. Maybe if they implement NATing?

Re: Shopify Is Illegal in Germany

#125
post #16

Earlier quoted context omitted.

It's the way the EU can protect their own tech industry.

Yeah, not letting startups use any kind of US companies is a great way to protect your tech industry. Right now, there's a trend towards hosting on the edge—cloudflare workers, deno deploy, fly.io–european companies can't use any of this. And as far as I know, there are no european alternatives.

I never said it was a smart idea but if you don't understand technology (i.e. majority of politicians/public) it might seem like a great protectionist idea. The simple idea the politicians believe is protect our privacy by forcing big tech companies to change for our benefit -- if they don't our own population will build the technology. Win win in their eyes.

Re: Shopify Is Illegal in Germany

#127

Earlier quoted context omitted.

To add, would EU privacy requirements apply even if you're just running some Gitlab or even Mastodon instance? Maybe running it as an individual vs llc changes things?

It would likely depend on the purpose and scope of the offering: https://gdpr.eu/recital-18-not-applicable-to-personal-or-hou...

Well, that means anything public-facing really. You are allowed to keep contacts in your personal phone book though.

Re: Shopify Is Illegal in Germany

#128
post #112

If using a CDN that is owned by a US company is illegal in Germany, then how can Germans run international websites? How would it be possible to hide a host that is behind CloudFront from Germans? I don't think is it possible. Even if you run an extra host like www.yourdomain.de for Germans, they could still type www.yourdomain.com into their browser and this alone would cause tcp packets to flow from their machin to…

> If using a CDN that is owned by a US company is illegal in Germany, then how can Germans run international websites? Just like US companies can run computers outside of the US border, so can other companies. A German CDN can setup their own infrastructure within US borders, then German companies can work with that CDN to speed up connections within the US for users coming from there. > There is no way to avoid this…

> A German CDN can setup their own infrastructure

Ok, but what if you just want to run a website and not build a billion doller global CDN.

> GeoDNS

According to the GDPR you have to protect the data of your visitors no matter where they are.

Re: Shopify Is Illegal in Germany

#129
post #116
post #7

All EU companies sending any PII to US-owned companies, regardless if the actual data stays in the EU or not, are in danger to be sued similarly to the author of this post. This is, among other laws, because of the US CLOUD act: > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requ…

Also, since the EU considers an IP address to be PII, anyone in the EU is not even allowed to connect to any website owned by a US company, as the IP address is a necessary piece of data to make the most basic TCP/IP connection work. Basically, the EU has put up a legal firewall between the US and the EU. Somehow this hasn't been realized fully or openly talked about, the the implication of their law is very clear.

People are free to give away their PII

Re: Shopify Is Illegal in Germany

#130
post #116
post #7

All EU companies sending any PII to US-owned companies, regardless if the actual data stays in the EU or not, are in danger to be sued similarly to the author of this post. This is, among other laws, because of the US CLOUD act: > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requ…

Also, since the EU considers an IP address to be PII, anyone in the EU is not even allowed to connect to any website owned by a US company, as the IP address is a necessary piece of data to make the most basic TCP/IP connection work. Basically, the EU has put up a legal firewall between the US and the EU. Somehow this hasn't been realized fully or openly talked about, the the implication of their law is very clear.

I thought it was the storage of such data that is illegal not the connection? Obviously logs and analytics are an issue in some cases for this law, but I slightly agree with it; should we not all want our digital footprint to be as small as possible?
Post reply on HN