Live data from Hacker News

Use of Google Analytics declared illegal by French data protection authority

cnil.fr

271–280 of 1001 posts

Re: Use of Google Analytics declared illegal by French data protection authority

#271
post #164

Earlier quoted context omitted.

The EU part cannot be owned by the US entity since the US government can compel the US mother company to have it's subsidiary hand over data. In fact this is how most of the companies operate already to cheat on taxes. The way microsoft did it for a while here in Norway was to license azure cloud stuff to a sub operator (EVRY) that is completely insulated except for the licensing agreement.

MS did the same in Germany with Deutsche Telekom as a partner, that shut down around 2018 [1]. [1]: https://nextcloud.com/blog/microsoft-and-telekom-no-longer-o...

They still do in China: https://docs.microsoft.com/en-us/office365/servicedescriptio...

Re: Use of Google Analytics declared illegal by French data protection authority

#272
post #187

Earlier quoted context omitted.

Quoted post unavailable.

Nothing to do with warrants. And this was done by the highest level of EU courts, overriding the commission (which allowed data to be transferred) The decision is here: https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX:62... And it's all about warrantless surveillance . "As regards the limits on intelligence activities, the referring court emphasises the fact that non-US persons are covered only by PPD‑28, wh…

> So, basically, the US security services can hoover up data about EU citizens, and those EU citizens aren't allowed any legal redress about it. Which, unsurprisingly, they aren't okay with.

Nothing about this stops that. Like I said to the other person this is protectionism. Requiring every US-based tech company to duplicate its infrastructure in the EU, Which in turn gives EU competitors an unfair advantage.

Re: Use of Google Analytics declared illegal by French data protection authority

#273
post #223
post #200

While i think these rulings are interesting in the sense of providing an opening to EU-grown businesses (if not too late), it does have a comical dimension in it. "Private" information is everywhere, it's in your DNS queries, which also gets propagated to servers in the evil US empire. Are we going to legislate DNS out of existence too? The EU seems to like having a completely private internet, but that's not gonna b…

> Are we going to legislate DNS out of existence too? No, but we could ban ISPs from being allowed to log DNS requests. There's lots of things the ISPs are doing that should not be allowed. It's done completely without our consent. If regulating DNS would have as consequence "to legislate DNS out of existence", then be it.

Complicating the matter here is the Data Retention Directive, which while invalidated by the ECJ is still at least partially applied by some member states.

Re: Use of Google Analytics declared illegal by French data protection authority

#274

Earlier quoted context omitted.

> If it's not allowed how can I ensure my site is protected as I need those logs to identify and ban hackers. Server logs are allowed as "technically necessary" as long as you show "good will" (I'd call it that way) in keeping the saved data to a minimum. 14 days of log keeping? Fine, that's cool for technical reasons. 14 weeks of log keeping? That's excessive and could get you in trouble.

Ok so what's the actual minimum you've said two weeks here but where is this actually defined ?

There's no hard limit here provided by the law or otherwise. Some of the local data protection offices say that they find something of "up to 30 days" reasonable, so I guess that's a good starting point. Cutting that time in half will show good faith and you'll still be able to analyze logs, I think.

Re: Use of Google Analytics declared illegal by French data protection authority

#275
post #263

Earlier quoted context omitted.

Do you really think we are in a better place now with GPDR and all these annoying cookie banners all over the place?

100%. (Also, the GDPR is not responsible for cookie banners)

Good law understands consequences.

The market responding to the law with billions of cookie banners was as predictable as prohibition leading to bootlegging.

Re: Use of Google Analytics declared illegal by French data protection authority

#276
Wondering if this will also apply to gmail, google drive and so on. Also wondering if there is a way to agree to storing my data in the us. Nonetheless it appears that this a good opportunity for an eu based alternative to google analytics.

Also what are the implications of cross eu-us chat apps where a person’s name is visible? Doesnt it mean that when a recipient in the us sees the name, the eu person’s data has been transferred to the us?

Apologies if this comment is ignorant, i am not well versed in the topic, but to me it sounds like this is quite an issue for us-eu chat and email apps.

Re: Use of Google Analytics declared illegal by French data protection authority

#277
post #200

While i think these rulings are interesting in the sense of providing an opening to EU-grown businesses (if not too late), it does have a comical dimension in it. "Private" information is everywhere, it's in your DNS queries, which also gets propagated to servers in the evil US empire. Are we going to legislate DNS out of existence too? The EU seems to like having a completely private internet, but that's not gonna b…

> "Private" information is everywhere This was the case before da interwebz as well: Your attending physician/doctor, your local grocery store, your local post office, your employer, your school - they all have a bunch of your private information, and should really not propagate it to the evil US empire, or anywhere for that matter. > Are we going to legislate DNS out of existence too? Apparently we haven't legislate…

"to the evil US empire"

Or to everyone, by leaving it in a giant publically exposed database enabling massive financial fraud. Thanks equifax

Re: Use of Google Analytics declared illegal by French data protection authority

#278

For who needs a summary of what is happening in the EU [1] 1. Since 2020, it's illegal to send personal data to the US because of the invalidation of the Privacy Shield [2] 2. Google said it was okay in the EU to use anonymized IP addresses 3. The Austrian Data Protection Authority (DSB) [3] ruled differently and waived most of the arguments raised by Google. The DSB ruled that even anonymized IP addresses are person…

> 1. Since 2020, it's illegal to send PII (personally identifiable) data to the US because of the removal of the Privacy Shield Framework [2]

Minor nit - "PII" really isn't the right term to use, because it suggests the info itself must be personally identifiable to an individual. The GDPR covers much more than this, and uses the term "Personal Data".

Re: Use of Google Analytics declared illegal by French data protection authority

#279
post #203

Earlier quoted context omitted.

Asking permission for something users don't understand is tantamount to not asking in the first place.

Will you defrob my balancator? Of course not, because you don't know what it is. The same applies here: if you don't know what something means then say no. If you say yes then it's understood that you know what you signed up to.

An agreement requires a meeting of the minds. Blindly clicking "yes, accept cookies" in popups does not rise to that level. People just want to read the article, they do not understand or care about the data retention policy. So it is very hard to claim they consented.

Re: Use of Google Analytics declared illegal by French data protection authority

#280
post #261

Earlier quoted context omitted.

This! GDPR is a big block towards technological improvement. Do virtually any business that involves user registration at some point, and now you need to be sure that you're compliant with all those rules, spending limited resources on that to avoid ridiculous fines. It benefits only the big players who has lawyers to know exactly what to do and not, and a nightmare for anyone who tries to grow a small business or ha…

> GDPR is a big block towards technological improvement. It's exactly the opposite. It forces technology to be developed in a way that protects human rights (specifically the right to privacy). Innovation is not automatically good if you're innovating in the wrong direction. Think of it as a vector, not a scalar.

Who is deciding what is the wrong and good direction to innovate in for everybody else?
Post reply on HN