Live data from Hacker News

Shopify Is Illegal in Germany

lsww.de

251–260 of 349 posts

Re: Shopify Is Illegal in Germany

#251
post #181

Earlier quoted context omitted.

> I don’t think you’re right about that? What I got from the article is that customer data is processed and stored in the EU, it doesn’t go through America. However, static assets are downloaded from CDNs operated by American companies (CloudFlare/Amazon/Fastly). This doesn't matter, EU sites have been getting fined for some time now for using CDNs like this, most popularly Google Fonts.

Regulators focusing on the important stuff once again. I guess if you fear Quantum inserts it might have some privacy/security gains.

You are allowed to dismiss your right to privacy is you so desire but the majority of EU citizens have decided not to.

Re: Shopify Is Illegal in Germany

#252
post #249

Earlier quoted context omitted.

Actually maybe it wasn’t clear because of the parent comment I commented in, but we are a EU company, but for our server hosting we use a US provider. Do you know if that that makes any difference? As a EU resident myself I completely understand, it just is a bit tough to make the changes as a small company, but if it’s legally required we’ll make them ASAP.

Oh yes then, you are fine if you migrate to a EU provider as long as you respect the general provisions of the GDPR (inform the user, allow access and deletion of PII, don't share it outside the EU, etc ...) ! Sorry I assumed you were a US citizen with a US company To ensure you don't have problem down the line, make sure they themselves store their data in the EU (for exemple, french OVH allows you to chose where yo…

Thanks a lot this is super helpful, much appreciated.

I was just thinking about the other services, for example would Cloudflare be ok? We proxy all our traffic through them, and they are key for DDOS prevention, I suppose data goes encrypted to them.

Re: Shopify Is Illegal in Germany

#253
post #33

Mini Ask HN: How would a small company, say a code forge, that is based in the US ensure that it is operating such that it is legal to have EU customers? All operations will be in the US (interaction only through a website). The forge will be designed to allow all of a user's data to be downloaded by that user (easy access to all data). It will also allow wiping away any reference to a user in commits (right to be fo…

IANAL As it stands right now, it is not possible for a US owned busniess to provide a service to EU citizens legally, if the business handles PII. The reason is partly due to the basic rights of the registrant granted by GDPR must be ensured by the data processor (the company), and due to the Schrems II ruling [1] that determines that GDPR is incompatible with US law. The non-legalese version is that US law that give…

Yeah, I was afraid of this.

Perhaps my best solution is to block any user creation from the EU, any login from the EU, and any signed-in user request from the EU.

Maybe I can allow non-signed-in users from the EU to browse?

Re: Shopify Is Illegal in Germany

#254

Earlier quoted context omitted.

> Don't sell user data left and right, and boom! Your poor small business is in the clear. It’s possible that I just misunderstand the landscape, I suppose. For my particular case though I work at a small business in the US that uses AWS cloud services for deployment of our application. One of the dependencies of our tech stack is an industry standard application (it’s ubiquitous in our space and has no accepted alte…

One more thing I would like to add: I generally think that some form of regulation limiting the abuse of personal data was long overdue and I must respect your zeal and vigor. I simply note the cost as I think it is important that we realize that this law (nor any law) is not without undesirable side-effect that should still be considered.

Now consider how Office 365, Windows, Intel CPUs and Ryzen+ CPUs... have similar issues in the sense that they have more or less likely backdoors for US intelligence agencies.

https://news.ycombinator.com/item?id=10458318

So, what is a reasonable way to deal with this if you're running a government agency or a company that has something worth spying on / getting remote control of for the USA ?

Re: Shopify Is Illegal in Germany

#255
post #248

Earlier quoted context omitted.

I was thinking the same thing. Even if I managed to do everything else, having to hire someone to do that would be nigh impossible.

https://gdpr.eu/article-27-representatives-of-controllers-no... The obligation laid down in paragraph 1 of this Article shall not apply to: * processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10, and is unlikely to result in a ris…

That requirement would still apply to my hypothetical code forge, unfortunately.

Re: Shopify Is Illegal in Germany

#256
post #229

Earlier quoted context omitted.

> So we basically need to migrate to a EU based could provider ASAP? Sadly no because you still own the data, which is the criteria the US has decided on. > Would this privacy shield 2 fix this problem? No idea since at this point it's merely a name for a vague demand being asked by the US. I'm sorry for the trouble this whole situation causes to your company, though to be honest as you can imagine I am very glad tha…

Actually maybe it wasn’t clear because of the parent comment I commented in, but we are a EU company, but for our server hosting we use a US provider. Do you know if that that makes any difference? As a EU resident myself I completely understand, it just is a bit tough to make the changes as a small company, but if it’s legally required we’ll make them ASAP.

I cannot answer your subcomment I believe the thread might be too deep ?

Anyway sadly no Cloudflare isn't ok, it's specifically one of the three provider that got Shopify convicted in the parent article (other two being Cloudfront and Fastly).

Re: Shopify Is Illegal in Germany

#257
post #251
post #181

Earlier quoted context omitted.

Regulators focusing on the important stuff once again. I guess if you fear Quantum inserts it might have some privacy/security gains.

You are allowed to dismiss your right to privacy is you so desire but the majority of EU citizens have decided not to.

We've actually never been asked. Some unelected bureaucrats decided "for our own good".

Re: Shopify Is Illegal in Germany

#258
post #248

Earlier quoted context omitted.

https://gdpr.eu/article-27-representatives-of-controllers-no... The obligation laid down in paragraph 1 of this Article shall not apply to: * processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10, and is unlikely to result in a ris…

That requirement would still apply to my hypothetical code forge, unfortunately.

But then it's precisely the kind of processing the EU rightly wants to address, and not only because it's the USA: China is a similar case.

But that doesn't matter to you. As long as you're too small to have a server and a (part-time) "controller" inside the EU, you seem to be out of luck (note: IANAL; there might be another way; cooperation with another small company, perhaps?).

Re: Shopify Is Illegal in Germany

#259

Earlier quoted context omitted.

GDPR core is pretty simple: You cannot do stuff (process, store, transfer to third parties) with PII unless X condition is met. An internet site, on first visit (being genuine first visit or just cookieless visit) cannot do things with PII, because there is just no way to even tell if X is met, therefore not only data storage (IP address in Apache access logs included) is illegal, but moreso transfer to third party v…

How is GDPR ugly? It's easy to build websites, even interactive ones, that comply. If you build a mobile app, you are also supposed to only ask for permissions once you actually need them. Replace interactive embeds with a dumb replacement of the actual content and e.g., "we want to show you an embedded tweet here, [allow once] [allow always]". Don't use CDNs for delivering assets, they've long stopped being useful a…

> Don't use CDNs for delivering assets, they've long stopped being useful anyway.

How do you handle large DDOS? Your provider won't, they'll nullroute your IP because they don't want to waste their bandwidth on your issues and impact all their other customers.

Also, using a global CDN with edge caching speeds up loading your site significantly if the user isn't close to the DC.

Regarding Hetzner: what's the verdict on them having to comply with the CLOUD Act via their US subsidiary?

Re: Shopify Is Illegal in Germany

#260

I'm somewhat concerned about an app I host. It's on Digitalocean and serves only EU customers. DigitalOcean says they are full GDPR compliant, but given the cloud act this seems impossible. What alternatives are available in Europe? It will be really frustrating to migrate

Scaleway

I was exploring options all morning, they all seem to miss the "bottom line" (I understand why, but my customer doesn't need much resources).

Scaleaway seemed way better than the competition though in terms of price for the bottom line, allowing to grow gradually rather than having to go all in in terms of pricing.

Post reply on HN