Live data from Hacker News

Shopify Is Illegal in Germany

lsww.de

301–310 of 349 posts

Re: Shopify Is Illegal in Germany

#301

Earlier quoted context omitted.

The author of the submission? Or the person claiming it's ugly? "Human activity is a complex thing and no law can describe it with 100% accuracy, news at 11". I doubt anyone arguing against GDPR read it. Or read recitals. Or read even high-level descriptions of the law, say, at gdpr.eu. Or read any laws in general, to compare.

We can all see the results of it. It made the web experience worse for everyone and it’s so complicated it solidified the power of the few companies that either can comply with it or afford to ignore it and deal with the slap on the wrist. Thought experiment: why didn’t any major ad tech company announce any harmful affects of the 99 section GDPR. But they did announce billions in revenues shortfall (ie Meta) when Ap…

> We can all see the results of it. It made the web experience worse for everyone

This bullshit again. It wasn't the GDPT that made the web worse. This is is entirely on the companies who took a look at GDPR and said: no, we're going to ignore it, continue siphoning user data, and trick users into "consent" through dark patterns (actually illegal under GDPR).

> Thought experiment: why didn’t any major ad tech company announce any harmful affects of the 99 section GDPR. But they did announce billions in revenues shortfall (ie Meta) when Apple made tracking opt in by one three line dialog box?

Funny how you don't conduct a thought experiment on why cookie pop-ups exist and what GDPR has to say about this.

Re: Shopify Is Illegal in Germany

#302

Earlier quoted context omitted.

> You're just incorrect here. I was expecting you to show where I'm incorrect. And yet, it's the same emotionally-charged "omg moat, large companies, impossible to run a business". Which doesn't disprove what I say, but further supports my case: the bullshit narrative around GDPR persists even if it has literally no basis in reality. > A small online shop using a CDN is who is actually hurt with GDPR. Most CDNs have…

> Tell me how it's impossible to legitimately run a small business that operates under significantly fewer obligations You make a strawman here, as that was not what was claimed is impossible. Tell us how it is possible to use Shopify to run a small shop in Germany.

> You make a strawman here, as that was not what was claimed is impossible. Tell us how it is possible to use Shopify

See this comment on who is responsible for user data and how it's relevant when chosing third parties for your business https://news.ycombinator.com/item?id=33566437

Re: Shopify Is Illegal in Germany

#303
post #116
post #7

All EU companies sending any PII to US-owned companies, regardless if the actual data stays in the EU or not, are in danger to be sued similarly to the author of this post. This is, among other laws, because of the US CLOUD act: > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requ…

Also, since the EU considers an IP address to be PII, anyone in the EU is not even allowed to connect to any website owned by a US company, as the IP address is a necessary piece of data to make the most basic TCP/IP connection work. Basically, the EU has put up a legal firewall between the US and the EU. Somehow this hasn't been realized fully or openly talked about, the the implication of their law is very clear.

[deleted]

Re: Shopify Is Illegal in Germany

#304
post #244

Earlier quoted context omitted.

> Most CDNs have GDPR-compliant services in the EU. How can a US company have a GDPR compliant service in the EU? The US government can force them to give up any data they own, which isn't compliant.

When there's a will, there's a way. Also, https://news.ycombinator.com/item?id=33566243

I'm sorry, I don't understand your point.

Re: Shopify Is Illegal in Germany

#305

Earlier quoted context omitted.

We can all see the results of it. It made the web experience worse for everyone and it’s so complicated it solidified the power of the few companies that either can comply with it or afford to ignore it and deal with the slap on the wrist. Thought experiment: why didn’t any major ad tech company announce any harmful affects of the 99 section GDPR. But they did announce billions in revenues shortfall (ie Meta) when Ap…

> We can all see the results of it. It made the web experience worse for everyone This bullshit again. It wasn't the GDPT that made the web worse. This is is entirely on the companies who took a look at GDPR and said: no, we're going to ignore it, continue siphoning user data, and trick users into "consent" through dark patterns (actually illegal under GDPR). > Thought experiment: why didn’t any major ad tech company…

It’s amazing that the excuse for the web being worse is always “the web being worse is not caused by the law being bad. It’s caused by it being badly enforced”.

The fact is that the cookie pop ups would never be necessary if the GDPR hadn’t been passed.

Re: Shopify Is Illegal in Germany

#306
post #33

Mini Ask HN: How would a small company, say a code forge, that is based in the US ensure that it is operating such that it is legal to have EU customers? All operations will be in the US (interaction only through a website). The forge will be designed to allow all of a user's data to be downloaded by that user (easy access to all data). It will also allow wiping away any reference to a user in commits (right to be fo…

Offering a service to European consumers?

Probably not a big issue. GDPR compliance can be challenging without a suitable mindset, but it's not impossible.

* Consider that the GDPR has an extremely broad concept of “personal data” – it's not just identifying info but anything that can be reasonably linked to a person!

* Data minimization – only collecting what is needed, and only using it as actually needed – is already a great step.

* Writing a GDPR-compliant privacy notice can be a good exercise to understand what data you're processing for which purposes. Art 12–15 GDPR are the closest it gets to a checklist.

* And you'll have to implement “appropriate” security measures, but what is appropriate is largely up to you.

The more challenging part is ensuring that you're only using data processors/vendors that are contractually bound to use the data as you instruct, and that you protect “international transfers” where the recipient (e.g. vendor) is outside Europe. If you're looking for server locations in North America, I recommend looking at Canada since they have an “adequacy decision” from Europe.

You will have to be GDPR-compliant if you “offer” your service to people who are in Europe, i.e. actively market to such people, or have testimonials from EU customers, offer French localization, accept payment in EUR, and so on. Mere availability of your service is not an offer.

Offering a B2B SaaS service to companies that need to be GDPR-compliant?

You're fucked. There is no legally safe way for a company to use an US-based data processor, i.e. to engage you as a vendor. However, and this is your “get out of jail” card, many customers don't care, and will be happy as long as they can sign “SCCs”.

Re: Shopify Is Illegal in Germany

#307
post #7

All EU companies sending any PII to US-owned companies, regardless if the actual data stays in the EU or not, are in danger to be sued similarly to the author of this post. This is, among other laws, because of the US CLOUD act: > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requ…

What is the difference between the CLOUD Act and the actual state of data protection in EU countries like Bulgaria, Romania, and Hungary? Why should I as a Danish entrepreneur trust a Hungarian hosting provider more than a US hosting provider?

You are allowed to trust the Hungarian hosting provider because they are legally bound to comply to GDPR.

You are not allowed to trust the US provider, since there are US laws that are not GDPR compliant. It is not possible to provide a compliant hosting service under US jurisdiction.

Re: Shopify Is Illegal in Germany

#308

Wait, does this imply that running a website behind CloudFlare is illegal in the EU? After all, webshop or not, IPs will be transmitted... Or are IPs only a problem in connection with getting user data like name and address? Or is it the IP+cookie combo?

Yes, US CDNs are definitely illegal under GDPR. They've fined people before for using Google Fonts' CDN because it transmitted residential EU residential IP addresses to someone within the reach of the US government. The law is that you have to have prior consent or it has to be necessary to take steps requested by the Data Subject. US CDNs are not considered necessary because an EU server could host those assets ins…

What about Github/Gitlab Pages?

Re: Shopify Is Illegal in Germany

#309
post #122
post #43

Earlier quoted context omitted.

No one knows yet, because the successor to Privacy Shield is still currently more of an "agreement to do something" rather than an actual law. There is at least some movement in the right direction, which is to say the US is paying lip service to the notion updating domestic law to curtail law enforcement's access to data. But that hasn't actually happened yet.

The problem is that the US wants an agreement (saying data can be stored in the US as long as the US can't access it and EU privacy laws are applied to it), but the US also doesn't actually want to lose the right to warrant the data from US companies without respecting EU laws. The history of the situation is like this: - Privacy shield exists - EU users data are stored and owned by Microsoft Ireland - US goes agains…

I'm not sure that is quite correct. From what I recall reading at the time, Microsoft US owned the user's email account and was the service provider providing email service.

To store email, Microsoft US made use of the services of several network storage providers around the world so that they could store email for a given user someplace that had low latency for that user.

Microsoft Ireland was one of those storage providers. Microsoft Ireland was not directly involved with the email user or even aware that they had any data on that user.

To Microsoft Ireland, Microsoft US was just another customer using Microsoft Ireland's storage service.

In particular, Microsoft US had full access to the data anytime they wanted, using the normal APIs that storage customers used.

Re: Shopify Is Illegal in Germany

#310
This is a tempest in a teapot.

We (still) don't have any court ruling here.

Of course more or less all US based cloud services are illegal in the EU currently. At least in theory. That's no news. (CLOUD Act & Co. was pointed out already by others).

But until we don't have some crystal clear rulings form the highest courts that get actually enforced this makes no difference.

The main point why this illegality does not mater in practice: Our own governments are using AWS and MS products, and all such stuff. They're completely in vendor lock-in there, and they could not change that for (at least) the next one or two decade, even if they would start right now trying to replace this stuff. But of course nobody even thinks about changing anything in this regard…

They put hopes in the next, also clearly illegal, version of the "safe harbor" regulations that's about to surface "soonish". When implemented it will take again 5 to 10 years to go through all legal instances to finally find out that a "safe harbor" agreement, no matter how you call it this time, is still fundamentally incompatible with EU law. But they will win this way another 5 to 10 years!

Than this game will start anew, and they will first ignore the law and the court ruling (like they do currently with the last one), than the EU government will try to implement the next version of "safe harbor", or something like that, to "avoid further legal uncertainty", and than it will take another 5 to 10 years to sue that into oblivion. And so forth. (We're currently already in round three of this shit show!)

The linked post would be much more interesting if this case would actually go to court.

But of course Shopify is not interested in this. They're just waiting for the next "safe harbor"; like everybody else.

Of course they won't stop doing business in the EU. Exactly like MS, AWS, Apple, Meta, and this like, won't. Because there is just nobody to actually enforce the law as more or less all EU governments are also violating it.

Post reply on HN