Live data from Hacker News

Shopify Is Illegal in Germany

lsww.de

231–240 of 349 posts

Re: Shopify Is Illegal in Germany

#231

Earlier quoted context omitted.

How do you collect consent from people before you receive their IP addresses?

Them giving their IP address is consent. If I put a dollar bill in your hand, I can come around a year later and ask for it back since I didn't "consent" explicitly.

When I load a website I have no idea what third-party assets are being loaded in or from where, and have no meaningful information ahead of time to know what I'm actually consenting to by typing "example.com" into the URL bar. Obviously, my IP will be sent to example.com, and I've arguably consented to that, but not to all the other third-party stuff that example.com might have loaded the page up with.

(this is also the argument around cookie consent: yes, the browser chooses to accept the cookie. users don't really get an opportunity to refuse them, though. So "the browser accepted the cookies" is not sufficient consent, as far as the EU is concerned)

Re: Shopify Is Illegal in Germany

#232
post #122
post #43

Earlier quoted context omitted.

No one knows yet, because the successor to Privacy Shield is still currently more of an "agreement to do something" rather than an actual law. There is at least some movement in the right direction, which is to say the US is paying lip service to the notion updating domestic law to curtail law enforcement's access to data. But that hasn't actually happened yet.

The problem is that the US wants an agreement (saying data can be stored in the US as long as the US can't access it and EU privacy laws are applied to it), but the US also doesn't actually want to lose the right to warrant the data from US companies without respecting EU laws. The history of the situation is like this: - Privacy shield exists - EU users data are stored and owned by Microsoft Ireland - US goes agains…

The US has been slowly extending its extraterritorial prerogatives for decades now. It’s unsurprising they would end up getting some push back at some point.

Re: Shopify Is Illegal in Germany

#233
post #225
post #122

Earlier quoted context omitted.

The problem is that the US wants an agreement (saying data can be stored in the US as long as the US can't access it and EU privacy laws are applied to it), but the US also doesn't actually want to lose the right to warrant the data from US companies without respecting EU laws. The history of the situation is like this: - Privacy shield exists - EU users data are stored and owned by Microsoft Ireland - US goes agains…

- EU is not fooled at all and ends the privacy shield This is not entirely correct, the EU kept on pretending for a while that the problem didn't exist, until Max Schrems (from noyb.eu) forced a court ruling on the inadequacies of the Privacy Shield agreement. As shown on their homepage, NOYB does a lot more than just investigate EU-US data transfers.

Apologies, you're abolutely right

Re: Shopify Is Illegal in Germany

#234

Earlier quoted context omitted.

There is an option for a service provider not to store the IP address anywhere. For users with accounts the standard ToS can handle it.

Who in their right mind would not store a visitor's IP address. How are you supposed to handle abuse or performance issues a visitor might have? Or perform analytics? It makes sense to not store if you're running some kind of privacy service.

Hash the IP so you can tie sessions, and do frequency analysis for abuse, without having the raw IP that can be geo-decoded?

Re: Shopify Is Illegal in Germany

#235

Earlier quoted context omitted.

AWS is owned by a US company subject to subpeonas, so yes, regardless of where you are, you are technically not allowed to receive EU PII (including residential IP addresses) without prior consent or unless it's necessary for the performance of a contract or to take steps requested by the Data Subject.

Sounds like FUD to me. The Internet would cease to operate if you could not "receive" IP addresses. It is logging that is the "concern."

Well, apart from IP addresses. Say I am running a service in Europe, GDPR compliant etc. All the PII are in some database running on AWS, in one of the European regions of course. If what is said here about CLOUD act etc. is true, then it looks like I'm in a breach of GDPR in this scenario - which sounds afwul to me frankly.

Re: Shopify Is Illegal in Germany

#236

Earlier quoted context omitted.

> GDPR is ugly. The only thing it allows you to do before you get confirmation to process PII is to show static page requesting for permissions. That's basically it. You can't do any "cloudy" stuff prior. No, GDPR is not ugly. Yes, you can do "cloudy stuff". The bullshit narratives around GDPR need to stop, however people driving the narrative are extremely incentivized to siphon and sell all the data they can get yo…

You're just incorrect here. Part of the GDPR does good things against bad actors like ad/tracking companies. But most of these companies are so big that it just works as a moat to keep out small competitors in that space. The more widely-affecting thing that the GDPR is doing is to make it impossible to legitimately run a business like the one that the article is talking about. An online shop that uses shopify which…

> But most of these companies are so big that it just works as a moat to keep out small competitors in that space.

Google is among the biggest and Google Analytics is getting absolutely shredded in the EU. How's that moat coming along?

Re: Shopify Is Illegal in Germany

#237
post #195

Earlier quoted context omitted.

Nah, that's not incompetence, it's by design: The actual violation of the GDPR was committed by the local shop owner. The owner also is responsible for any fines. The shop owner could have chosen a data-protection-compliant solution, but choose not to do so. The platform did not violate any local laws - it's outside the jurisdiction of the GDPR. They chose - and are within their right to do so - to cooperate with a l…

When looking to solve a problem you find ways to solve it as good as possible with the minimum effort. The problem is 93689 German shops violating the law. Laws are written to accomplish goals. Execution is sometimes hard/impossible. You have to find ways that work, keep the eyes on the goal. We have big institutions like government and shopify that should abstract their smaller components. These are not always const…

> (The government) could also communicate to the list of shop owners that they are to stop using the platform.

They just did. It's called a fine.

> He is suppose to be busy selling coffee so that he can bring in more tax revenue.

He is to bring in tax revenue AND follow the law. If the government was just interested in tax income, drugs, racketeering and murder-for-hire would be legal as long as they filed taxes on that income.

Re: Shopify Is Illegal in Germany

#238
Doesn't this reduce (from the slightly convoluted shop->Shopify->CDN case here) to simply using say AWS as an EU company, or just being a US company?

Assuming you have some kind of PII to store, the US CLOUD Act essentially means AWS (or whatever US company) can't possibly (no matter which region you use or anything like that) GDPR-compliantly act as a third-party data processor or whatever the terminology is?

In which case... someone (as in country, legislation) is clearly going to back down? UK government sites take plenty of PII and run on AWS...

Re: Shopify Is Illegal in Germany

#239

Earlier quoted context omitted.

AWS is owned by a US company subject to subpeonas, so yes, regardless of where you are, you are technically not allowed to receive EU PII (including residential IP addresses) without prior consent or unless it's necessary for the performance of a contract or to take steps requested by the Data Subject.

Sounds like FUD to me. The Internet would cease to operate if you could not "receive" IP addresses. It is logging that is the "concern."

No, the processing of personal information is a concern too.

Re: Shopify Is Illegal in Germany

#240
post #229

Earlier quoted context omitted.

We definitely store PII as we have to store users emails an even phone numbers. So we basically need to migrate to a EU based could provider ASAP? Would this privacy shield 2 fix this problem? I suppose we can’t just wait for that.

> So we basically need to migrate to a EU based could provider ASAP? Sadly no because you still own the data, which is the criteria the US has decided on. > Would this privacy shield 2 fix this problem? No idea since at this point it's merely a name for a vague demand being asked by the US. I'm sorry for the trouble this whole situation causes to your company, though to be honest as you can imagine I am very glad tha…

Actually maybe it wasn’t clear because of the parent comment I commented in, but we are a EU company, but for our server hosting we use a US provider.

Do you know if that that makes any difference?

As a EU resident myself I completely understand, it just is a bit tough to make the changes as a small company, but if it’s legally required we’ll make them ASAP.

Post reply on HN