Live data from Hacker News

Use of Google Analytics declared illegal by French data protection authority

cnil.fr

571–580 of 1001 posts

Re: Use of Google Analytics declared illegal by French data protection authority

#571

Earlier quoted context omitted.

Why limit it to the EU? Shouldn't every country have their own AWS, Azure and Google Cloud? I think we underestimate just how difficult it is just to replicate existing services, let alone keep up with the innovation. It's like the Argentinian effort to stimulate its own computer manufacturing by banning Apple products.

It'd help if the United States wasn't allowed to aggressively brain drain most of the rest of the world.

That's nice for countries and bad for people.

Re: Use of Google Analytics declared illegal by French data protection authority

#573
post #328

Earlier quoted context omitted.

Wouldn't that cut off a vast swath of the internet from France though ? Some of the main big providers of internet services use US based data centres. I'm meaning: * Amazon * Google * Facebook * Netflix * Microsoft * Twitter * Uber I mean the list goes on but these are a really big part of the internet.

Yes, of course. It's possible that the they will sue every single big company, but quite possible. I think it's a good way for the EU to build pressure against the US to revise the CLOUD act.

This will only happen if the EU makes a true effort to go after as many big US companies as possible. If corporations actually start to lose access to the EU market, the US will follow suit and change its laws.

Re: Use of Google Analytics declared illegal by French data protection authority

#574
post #56

Earlier quoted context omitted.

Who's concerned about Google collecting data? No.

So we should accept facial recognition in public because there are people who don't care?

Why not? No, seriously. If people that are concerned by it are in minority - they should wear masks.

Re: Use of Google Analytics declared illegal by French data protection authority

#576

Earlier quoted context omitted.

> If it's not allowed how can I ensure my site is protected as I need those logs to identify and ban hackers. Server logs are allowed as "technically necessary" as long as you show "good will" (I'd call it that way) in keeping the saved data to a minimum. 14 days of log keeping? Fine, that's cool for technical reasons. 14 weeks of log keeping? That's excessive and could get you in trouble.

Ok so what's the actual minimum you've said two weeks here but where is this actually defined ?

With GDPR and personal data, if you can justify your use then it's legit. Working out which justifications are acceptable is left -- at least partly -- as an exercise for the reader ('s legal team).

But we may observe that some practices are easy to justify, while others are more challenging. Some attempts at justification have been rejected, which means that trying to rely on them in the future is a bad plan.

Also, intent matters. If you're trying to do the right thing, you're unlikely to get into real trouble. The most likely consequence is that you're told you should stop, and given a deadline. If you don't stop by the deadline then it's fairly obvious that you're now not trying to do the right thing.

Re: Use of Google Analytics declared illegal by French data protection authority

#577

Earlier quoted context omitted.

If you pay by cash the shop has no personal data about you.

Not necessarily, they might have timestamps and register # that could be correlated to build a "unsupervised" profile of a customer. Extreme case: you are the only person that ever buys product X around time Y, so that fact can be used as an anchor to build a profile. You need to be way more paranoid if you want to be a true privacy warrior.

Also be careful not to leave any fingerprints or strands of hair around!

Re: Use of Google Analytics declared illegal by French data protection authority

#578

I think we (in the EU) will soon realise the bizarre consequences of these regulations. European startups will not be able to use standard SaaS or PaaS tools (like AWS, Azure, Mailchimp, PayPal etc) if they are based in the US (like most of them are). No cloud services, no Office 365 or Google Workspace. It will take forever to build up a similar ecosystem in Europe and I think most successful European entrepreneurs…

> No cloud services, no Office 365 or Google Workspace.

I think you are overestimating the problem. Before Facebook decided that it wanted the European market we had hundreds of similar services. We will have local replacements the moment these US companies with their near unlimited war chests finally fuck off and give European companies room to breathe again.

Re: Use of Google Analytics declared illegal by French data protection authority

#579
post #307

Earlier quoted context omitted.

a randomised unique ID and username/password are not personal data if they can't be used to identify a person. IF you associate that uniqueID or username with something that can identify the user (like IP/ Personal name etc) than yes it's illegal for you to store that data in US even with the consent of the user.

I feel like this is either a mis-interpretation, or the scope of this law would prevent 95% of websites from existing in the EU (including hackernews which stores your email). So any US company cannot store PII on an EU citizen? If someone from the EU comes to my site to make a purchase, I can't allow them to do that?

Yes that is my interpretation of it. The whole point being that any data stored in US can not be guaranteed to respect GDPR because the US government can request access to that data and the EU citizens don't have a recourse to that. any US buisness that want to have EU citizens PI needs to have a host in EU.

Re: Use of Google Analytics declared illegal by French data protection authority

#580

Earlier quoted context omitted.

> If it's not allowed how can I ensure my site is protected as I need those logs to identify and ban hackers. Server logs are allowed as "technically necessary" as long as you show "good will" (I'd call it that way) in keeping the saved data to a minimum. 14 days of log keeping? Fine, that's cool for technical reasons. 14 weeks of log keeping? That's excessive and could get you in trouble.

This whole set of laws is so absurd. I should have the right to retain my server logs as long as I want. I bet in the future in Europe people will have the right to have others' brains forcibly zapped to remove embarrassing memories.

The whole point is that "your" logs contain personal data about others. That data is theirs not yours. Moreover if you get asked about "your" logs by the US government you have to hand "their" data over to them, for which there is no legal recourse for the person owning the data.

To make this more obvious, the EU is essentially saying that you can create a post service that routes all their letters through the US where they can be opened by the FBI, without any legal recourse.

I'm always amazed how people (even very technical) argue that things are perfectly fine for electronic data when they would completely oppose the same thing for physical things, e.g. letters. I guess years of propaganda have worked

Post reply on HN