Live data from Hacker News

Shopify Is Illegal in Germany

lsww.de

271–280 of 349 posts

Re: Shopify Is Illegal in Germany

#272
post #116

Earlier quoted context omitted.

Also, since the EU considers an IP address to be PII, anyone in the EU is not even allowed to connect to any website owned by a US company, as the IP address is a necessary piece of data to make the most basic TCP/IP connection work. Basically, the EU has put up a legal firewall between the US and the EU. Somehow this hasn't been realized fully or openly talked about, the the implication of their law is very clear.

> Also, since the EU considers an IP address to be PII As far as I know, it’s only one German court which once considered that an IP address was PII in a specific case. There is nothing in the law that explicitly says that IP addresses are PII. I think you might be confused about the implications the German ruling has because you are from a common law country. One court ruling something doesn’t make it the law in Eur…

> As far as I know, it’s only one German court which once considered that an IP address was PII in a specific case. There is nothing in the law that explicitly says that IP addresses are PII.

CJEU ruled back in 2016 that IP address is personal data if provider has legal means to identify the person. This includes, as example that was given in the case, laws that give means for service provider to identify the users in the case of cyber attack by requesting help from other authorities.

This ruling is from before GDPR and relates to the older Data Protection Directive, but the relevant chapters are largely same (GDPR mostly increased the explicit scope).

Ruling: https://curia.europa.eu/juris/document/document.jsf?docid=18...

The "tl;dr" parts are 30 (the question) & 47-49.

The old directive: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...

Re: Shopify Is Illegal in Germany

#273
post #185

Earlier quoted context omitted.

The simple answer is that collecting personal data while being located in the US means that you can't guarantee that you will respect European law. > There are zero plans to collect anything that is not needed Unfortunately, it's not up for you to decide. The US has laws that makes it legal for your government to harvest data, and it has used these laws against EU citizen in the past. The US has also asked US service…

> Unfortunately, it's not up for you to decide. The US has laws that makes it legal for your government to harvest data, and it has used these laws against EU citizen in the past. Yeah, I was afraid of this. > The US has also asked US services to collect data they were not previously collecting, with a gag order to prevent customers from learning it. I'm so bullish on privacy that I would actually shut down my compan…

> I'm so bullish on privacy that I would actually shut down my company if this happens. US courts cannot force me to remain in business.

I believe that's what Lavabit did when they were served that kind of order. Not sure that helps with EU legality, though.

Re: Shopify Is Illegal in Germany

#274
post #258

Earlier quoted context omitted.

That requirement would still apply to my hypothetical code forge, unfortunately.

But then it's precisely the kind of processing the EU rightly wants to address, and not only because it's the USA: China is a similar case. But that doesn't matter to you. As long as you're too small to have a server and a (part-time) "controller" inside the EU, you seem to be out of luck (note: IANAL; there might be another way; cooperation with another small company, perhaps?).

I agree with you. I also think consumer privacy protection is important, so I'm not mad at the EU here. I'm mad at the US government for the CLOUD Act.

Re: Shopify Is Illegal in Germany

#275
post #229

Earlier quoted context omitted.

We definitely store PII as we have to store users emails an even phone numbers. So we basically need to migrate to a EU based could provider ASAP? Would this privacy shield 2 fix this problem? I suppose we can’t just wait for that.

> So we basically need to migrate to a EU based could provider ASAP? Sadly no because you still own the data, which is the criteria the US has decided on. > Would this privacy shield 2 fix this problem? No idea since at this point it's merely a name for a vague demand being asked by the US. I'm sorry for the trouble this whole situation causes to your company, though to be honest as you can imagine I am very glad tha…

> to be honest as you can imagine I am very glad that my representative in the EU didn't back down and protect my rights.

I'm the asker of the question that started this discussion. I'm a US citizen.

I'm actually on the side of the EU here. There needs to be privacy protections for consumers. Even though the requirement for a rep in the EU is impossible for me to fulfill, I admire the fact that they prioritized native EU companies over foreign ones because that is what's best for the EU inside the EU.

I'm mad at the US government for the CLOUD Act, which is egregarious and doesn't serve the interests of the US; it only serves the interests of the US government.

Re: Shopify Is Illegal in Germany

#276

Earlier quoted context omitted.

IANAL. Although I imagine you could, presumably they'd argue that (while your parking tickets are unpaid) they have a legal basis other than consent for processing your personal data. In that case, you'd probably have to find grounds for erasure other than withdrawal of consent. 1d or 1e of Article 17 look most relevant (but maybe not very promising): https://gdpr-info.eu/art-17-gdpr/

So Italy issued the ticket, gets my contact info from the rental company, then hands it over to the collection agency. Is it reasonable that all of that is something I agreed to beforehand? I have no idea. If you rent a car in the EU should you immediately send them a GDPR request after you are done to get them to remove your data so you can't be found? Or is there a legal requirement for them to hold on to the data?…

I assume (but I don't know) that GDPR applies fully if any party is in/from the EU. (In practice, if the data processor is outside the EU, enforcement might be difficult, but in your case it sounds like the data processor is inside the EU, so I imagine you have the same rights in this case as those who do reside in the EU.) However, my understanding is that

1) if your data is processed for contractual purposes, the data processor has a right not to delete it on request

2) if your data is processed for law enforcement purposes, the data processor has a duty not to delete it on request

There are several legal grounds for processing personal data under GDPR, and consent is only one of them. I think most of the others outweigh any request for deletion by the data subject.

Re: Shopify Is Illegal in Germany

#277
post #95
post #72

Earlier quoted context omitted.

I think it's good that the EU is forcing the US to get their privacy laws in order.

I don't think the EU will force the US to do anything w.r.t. privacy. Instead, we'll see EU based CDNs start to take over customers from US CDNs. Less "get your act together", more "we'd rather do this ourselves...".

That is true, tho I don't think it will happen in practice.

But regardless: one has to admit that it is not different from how the current embargos affect Russian people. Punish the citizens so they (try to) put pressure on the government to act better.

Re: Shopify Is Illegal in Germany

#278
post #156

Earlier quoted context omitted.

The EU isn't "the" EU. The GDPR was created by the elected representatives of the EU citizens. The EU commission consisting of representatives of the EU member state's governments are giving away the data.

Elections have consequences.

We wanted data protection, we got data protection. The commission is losing in court with its idea to give data away (e.g. privacy shield invented by commission, stopped by the court).

Re: Shopify Is Illegal in Germany

#279

Earlier quoted context omitted.

IANAL As it stands right now, it is not possible for a US owned busniess to provide a service to EU citizens legally, if the business handles PII. The reason is partly due to the basic rights of the registrant granted by GDPR must be ensured by the data processor (the company), and due to the Schrems II ruling [1] that determines that GDPR is incompatible with US law. The non-legalese version is that US law that give…

Yeah, I was afraid of this. Perhaps my best solution is to block any user creation from the EU, any login from the EU, and any signed-in user request from the EU. Maybe I can allow non-signed-in users from the EU to browse?

If you dont handle/store PII then there is no problem.

Or, you can just do it anyways. Its not like GDPR and Schrems II have stopped Microsoft, Amazon, Google, etc etc.

Re: Shopify Is Illegal in Germany

#280
post #16

Earlier quoted context omitted.

This affects the entire EU. I try to hammer it into people's heads here in NL. Using US-based cloud services if you touch PII is a huge risk as they're all getting like crazed addicts fighting over their next high PII-high.

It's the way the EU can protect their own tech industry.

Disagree. Privacy is a human right. It protects people's mental and economic wellbeing. Further, it can save millions of lives. Or, if you prefer, lack of privacy can lead to millions of deaths.
Post reply on HN