Live data from Hacker News

Use of Google Analytics declared illegal by French data protection authority

cnil.fr

311–320 of 1001 posts

Re: Use of Google Analytics declared illegal by French data protection authority

#311
post #285

For who needs a summary of what is happening in the EU [1] 1. Since 2020, it's illegal to send personal data to the US because of the invalidation of the Privacy Shield [2] 2. Google said it was okay in the EU to use anonymized IP addresses 3. The Austrian Data Protection Authority (DSB) [3] ruled differently and waived most of the arguments raised by Google. The DSB ruled that even anonymized IP addresses are person…

> the privacy-first analytics tool Don't be coy. Call it what it is - an analytics service . And as such it falls largerly in the same bucket as GA, because if someone's using Simple Analytics, my surfing data - against my wishes - is being shared with some random third party. Whether it's less, more or comparably evil as GA is secondary.

Yes, and when you go shopping and pay with cash in a store with no surveillance, your shopping habits are being shared against your wishes with a random third party (the external company bookkeeper).

It's disingenuous to have problems with websites collecting entirely anonymous browsing data -- that goes beyond any arguments for privacy and just steers into "yelling at clouds" territory.

Re: Use of Google Analytics declared illegal by French data protection authority

#312
post #285

For who needs a summary of what is happening in the EU [1] 1. Since 2020, it's illegal to send personal data to the US because of the invalidation of the Privacy Shield [2] 2. Google said it was okay in the EU to use anonymized IP addresses 3. The Austrian Data Protection Authority (DSB) [3] ruled differently and waived most of the arguments raised by Google. The DSB ruled that even anonymized IP addresses are person…

> the privacy-first analytics tool Don't be coy. Call it what it is - an analytics service . And as such it falls largerly in the same bucket as GA, because if someone's using Simple Analytics, my surfing data - against my wishes - is being shared with some random third party. Whether it's less, more or comparably evil as GA is secondary.

You raise an interesting point. Who's data is it?

If you walk into a grocery store, and cameras record which aisle you walk down, which items you stop to look at and which things you buy. Is that legal?

What if the cameras block out your face and all identifying features. Is that legal?

Do you own a blob of a person walking down an aisle? Does the grocery store?

Re: Use of Google Analytics declared illegal by French data protection authority

#313

For who needs a summary of what is happening in the EU [1] 1. Since 2020, it's illegal to send personal data to the US because of the invalidation of the Privacy Shield [2] 2. Google said it was okay in the EU to use anonymized IP addresses 3. The Austrian Data Protection Authority (DSB) [3] ruled differently and waived most of the arguments raised by Google. The DSB ruled that even anonymized IP addresses are person…

Point 1 isn't true. You've been able to send personal data (PII being the specific US legal term) to the US no problem - as long as you had "standard contractual clauses" (SCCs) as part of your contract with them that the company meets GDPR requirements. This is the same agreement to send data to any country outside the EU where there isn't a pre-existing agreement. I believe this ruling is saying that it's not possi…

The original ruling was nuanced, and this ruling is clarifying some gray area inside of it.

The ruling on Schrems II (the court case that struck down Privacy Shield) did not state that SCCs on their own would be sufficient. It said that SCCs + "additional safeguards" would be allowable. There have been several rulings already that SCCs on their own are not sufficient.

The "additional safeguards" must include a risk analysis of US access to EU residents' data. Every court case I've seen from Schrems II onward identifies the US CLOUD Act as the privacy risk to address. CNIL is basically ruling that you cannot transfer data to a US company subject to the CLOUD Act, and an SCC cannot deal with that. This still leaves open the possibility of using US services that are not subject to the CLOUD Act. This is consistent with all rulings to date.

Re: Use of Google Analytics declared illegal by French data protection authority

#314

For who needs a summary of what is happening in the EU [1] 1. Since 2020, it's illegal to send personal data to the US because of the invalidation of the Privacy Shield [2] 2. Google said it was okay in the EU to use anonymized IP addresses 3. The Austrian Data Protection Authority (DSB) [3] ruled differently and waived most of the arguments raised by Google. The DSB ruled that even anonymized IP addresses are person…

Point 1 isn't true. You've been able to send personal data (PII being the specific US legal term) to the US no problem - as long as you had "standard contractual clauses" (SCCs) as part of your contract with them that the company meets GDPR requirements. This is the same agreement to send data to any country outside the EU where there isn't a pre-existing agreement. I believe this ruling is saying that it's not possi…

Isn't that the same as point 1?

Re: Use of Google Analytics declared illegal by French data protection authority

#315
post #57

Is anyone using an alternative that provides some basic analytics and isn't likely to get me in legal hot water in the future? I've already offloaded Google Fonts due to the German ruling. I'm happy to self-host piwik if needed, but could that fall foul of regulators?

We’re using our own logs with https://goaccess.io processing over 300M requests a month with no issues. No privacy issues to worry about using trackers.

If your logs are storing IP addresses without consent from users, you are probably (IANAL, but heard this from lawyers) infringing GDPR.

Re: Use of Google Analytics declared illegal by French data protection authority

#316
post #299
post #83

A lot of this seems to be coming due to US regulations that compel US registered companies to hand over data from subsidiaries in Europe markets if asked by US intelligence and law enforcement agencies. With these various data locality regulations, i wonder if a standard operating approach could be to split tech companies into 3 legal entities, a technology licensing company, a US registered operations company and a…

It's not as clear cut. If someone is running a global web site and wants analytics, which of the 2 entities, or both, would he reference in HTML? Even if we're going to region-lock Europe to the European Analytics servers, analytics today often involves some computation done over the entire data set, including both US and the EU, done on the backend. Which backend would that be? The privacy aspect has become somethin…

> barriers to entry

It's easy to do things online as a company of any size, post-GDPR: Don't scrape user data. Done - no compliance required, because the law is not about you in that case.

Re: Use of Google Analytics declared illegal by French data protection authority

#317
post #77

Note that Wikimedia has been not using Google Analytics since forever because they're concerned about precisely the same privacy problems as the regulators. This other post has more comments: https://news.ycombinator.com/item?id=30284820 I love that the plaintiff in this case is the "NOYB Association", as in None Of Your Fucking Business, Google.

[deleted]

Re: Use of Google Analytics declared illegal by French data protection authority

#318
post #164

Earlier quoted context omitted.

The EU part cannot be owned by the US entity since the US government can compel the US mother company to have it's subsidiary hand over data. In fact this is how most of the companies operate already to cheat on taxes. The way microsoft did it for a while here in Norway was to license azure cloud stuff to a sub operator (EVRY) that is completely insulated except for the licensing agreement.

Hmm, that's interesting. I suppose more cloud providers could do something like that, for the benefit of customers and GDPR? E.g. Amazon already bills me through some Norwegian entity of some kind, to get VAT done right etc. If they had servers in Norway, I suppose it would have been possible to proxy everything - not just billing - in AWS Norway through this sub operator?

To fall out of scope of the CLOUD act, the subsidiary needs to be independent and prevent any data access by its holding company. The holding company can in no way have "possession, custody or control", which are not well defined so that doesn't make it easier to assess if a subsidiary is out of scope.

https://jnslp.com/wp-content/uploads/2020/05/Defining-the-Sc...

Re: Use of Google Analytics declared illegal by French data protection authority

#319
post #297

Wondering if this will also apply to gmail, google drive and so on. Also wondering if there is a way to agree to storing my data in the us. Nonetheless it appears that this a good opportunity for an eu based alternative to google analytics. Also what are the implications of cross eu-us chat apps where a person’s name is visible? Doesnt it mean that when a recipient in the us sees the name, the eu person’s data has be…

>Also wondering if there is a way to agree to storing my data in the us. Consent is always a valid legal basis for the processing, or transfer, of data. But it has to be freely given, specific, informed and unambiguous.

So just more annoying consent pop-up modals in the future?

Re: Use of Google Analytics declared illegal by French data protection authority

#320
post #83

A lot of this seems to be coming due to US regulations that compel US registered companies to hand over data from subsidiaries in Europe markets if asked by US intelligence and law enforcement agencies. With these various data locality regulations, i wonder if a standard operating approach could be to split tech companies into 3 legal entities, a technology licensing company, a US registered operations company and a…

Exactly, the CLOUD act is the one of the main problems here: https://en.wikipedia.org/wiki/CLOUD_Act
Post reply on HN