Earlier quoted context omitted.
> I don’t think you’re right about that? What I got from the article is that customer data is processed and stored in the EU, it doesn’t go through America. However, static assets are downloaded from CDNs operated by American companies (CloudFlare/Amazon/Fastly). From what I can tell, Shopify itself uses Cloudflare, so your domain that is connected to Shopify is passing all the traffic through Cloudflare, e.g. one of…
The article quotes Shopify explicitly saying otherwise.
Shopify Is Illegal in Germany
161–170 of 349 posts
Re: Shopify Is Illegal in Germany
#162Earlier quoted context omitted.
> GDPR is ugly. The only thing it allows you to do before you get confirmation to process PII is to show static page requesting for permissions. That's basically it. You can't do any "cloudy" stuff prior. No, GDPR is not ugly. Yes, you can do "cloudy stuff". The bullshit narratives around GDPR need to stop, however people driving the narrative are extremely incentivized to siphon and sell all the data they can get yo…
It’s a 99 section 11 chapter monstrosity. It is ugly.
As laws go, it's fine.
Re: Shopify Is Illegal in Germany
#163Earlier quoted context omitted.
Wait, do you think law enforcement agencies in Europe can't force companies to reveal ip addresses and/or other customer information?
They can do whatever the local laws allow. If the local laws forbid it, then they can't.
Re: Shopify Is Illegal in Germany
#164Earlier quoted context omitted.
Wait, do you think law enforcement agencies in Europe can't force companies to reveal ip addresses and/or other customer information?
They can do whatever the local laws allow. If the local laws forbid it, then they can't.
Re: Shopify Is Illegal in Germany
#165All EU companies sending any PII to US-owned companies, regardless if the actual data stays in the EU or not, are in danger to be sued similarly to the author of this post. This is, among other laws, because of the US CLOUD act: > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requ…
Does it also mean I can't use AWS in Europe?
Re: Shopify Is Illegal in Germany
#166All EU companies sending any PII to US-owned companies, regardless if the actual data stays in the EU or not, are in danger to be sued similarly to the author of this post. This is, among other laws, because of the US CLOUD act: > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requ…
Also, since the EU considers an IP address to be PII, anyone in the EU is not even allowed to connect to any website owned by a US company, as the IP address is a necessary piece of data to make the most basic TCP/IP connection work. Basically, the EU has put up a legal firewall between the US and the EU. Somehow this hasn't been realized fully or openly talked about, the the implication of their law is very clear.
Well, it's certainly not this:
> anyone in the EU is not even allowed to connect to any website owned by a US company
Re: Shopify Is Illegal in Germany
#167Earlier quoted context omitted.
Also, since the EU considers an IP address to be PII, anyone in the EU is not even allowed to connect to any website owned by a US company, as the IP address is a necessary piece of data to make the most basic TCP/IP connection work. Basically, the EU has put up a legal firewall between the US and the EU. Somehow this hasn't been realized fully or openly talked about, the the implication of their law is very clear.
Honestly, I think if the GDPR had been around before HTTP, we would have seen HTTP as the unreasonable part in this system. You don't have to make a direct TCP/IP connection for two people to communicate. We had systems like Usenet and UUCP that replicated data through a series of servers. Even today, when you use email, you talk to your email provider who talks to the recipient's email provider, and they have no nee…
So when you misbehave, I have the means to block you in particular.
Re: Shopify Is Illegal in Germany
#168Earlier quoted context omitted.
> A German CDN can setup their own infrastructure Ok, but what if you just want to run a website and not build a billion doller global CDN. > GeoDNS According to the GDPR you have to protect the data of your visitors no matter where they are.
> Ok, but what if you just want to run a website. Not build a billion doller global CDN. Ah, from the perspective of website owners, not the CDN owner... Well, use a European CDN, they tend to follow European regulation, just like US companies follow US regulation. The two companies that comes first to mind is BunnyCDN and KeyCDN, but I'm sure there are many others. Both of them have global networks. > According to t…
Re: Shopify Is Illegal in Germany
#169Earlier quoted context omitted.
> Ok, but what if you just want to run a website. Not build a billion doller global CDN. Ah, from the perspective of website owners, not the CDN owner... Well, use a European CDN, they tend to follow European regulation, just like US companies follow US regulation. The two companies that comes first to mind is BunnyCDN and KeyCDN, but I'm sure there are many others. Both of them have global networks. > According to t…
I was addressing your point "US visitors to domain.com gets a different IP". How does that relate to GDPR?
> Even if you run an extra host like www.yourdomain.de for Germans, they could still type www.yourdomain.com into their browser and this alone would cause tcp packets to flow from their machin to CloudFront. There is no way to avoid this.
If you're adamant on running US infrastructure for US users and EU infrastructure for EU users, you can do that by using GeoDNS/Regional Records.
But personally I find it easier to treat everyone as a EU user, and I store no personally identifiable information what so ever except information given by users themselves (like emails for registration), so maximum privacy for my users.
Re: Shopify Is Illegal in Germany
#170Earlier quoted context omitted.
When you make common practice illegal, you invite corruption into your system because selective enforcement of the rules becomes the new normal. Laws need to understand the environment that they are made in or will never be effective and oftentimes counter productive. As is the case here. GDPR goes even further than would be reasonable for any small business that handles email addresses. Requiring a salaried data pro…
> When you make common practice illegal, you invite corruption into your system because selective enforcement of the rules becomes the new normal. Child labor. Drugs and radioactive substances in medicine. Water pollution. The list of practices that used to be common is extremely long. And yet here we are. > GDPR goes even further that would be reasonable for any small business that handles email addresses. Of course…
It’s possible that I just misunderstand the landscape, I suppose. For my particular case though I work at a small business in the US that uses AWS cloud services for deployment of our application. One of the dependencies of our tech stack is an industry standard application (it’s ubiquitous in our space and has no accepted alternative in our industry) whose per-instance licenses cost are nearly half my yearly salary. After factoring in a second instance for HA, it’s a full engineer‘s pay. In order to make sure that we have a cloud offering that can be used without any data leaving the EU or talking to a US company, our overhead increases to the point that we’re running with one less engineer than if we could all use the same stack.
We do not collect any PII for longer than is needed to fulfill requests and we have no other revenue stream (no ads or connection to ads) other than customer subscriptions.
So, for my team, the impact of compliance has been painful.
If it turns out that I misunderstand some aspect of compliance here, I’m happy as that is good news for me.