Live data from Hacker News

Shopify Is Illegal in Germany

lsww.de

61–70 of 349 posts

Re: Shopify Is Illegal in Germany

#61
post #27
post #7

All EU companies sending any PII to US-owned companies, regardless if the actual data stays in the EU or not, are in danger to be sued similarly to the author of this post. This is, among other laws, because of the US CLOUD act: > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requ…

To clarify: Shopify is a Canadian company (edit: but as mentioned elsewhere in this thread: they send data to CloudFlare, CloudFront (Amazon) and Fastly, which are US companies.)

Yes, you're right. If Shopify were an American company, it wouldn't even matter if they sent data to the CDNs are not - it would be illegal in any case.

Re: Shopify Is Illegal in Germany

#62
post #3

English (machine) translation: https://lsww-de.translate.goog/shopify-illegal/?_x_tr_sl=aut...

Or you know, right click page -> Translate to English. I'll miss that the most when manifest v3 rolls out and chrome becomes unusable.

https://www.mozilla.org/en-US/firefox/features/translate/

never tried, but seems promising

Re: Shopify Is Illegal in Germany

#63
post #3

English (machine) translation: https://lsww-de.translate.goog/shopify-illegal/?_x_tr_sl=aut...

Or you know, right click page -> Translate to English. I'll miss that the most when manifest v3 rolls out and chrome becomes unusable.

i’ve been on safari for the past 3 years. nothing will change. ad blockers will still work.

Re: Shopify Is Illegal in Germany

#64
post #33

Mini Ask HN: How would a small company, say a code forge, that is based in the US ensure that it is operating such that it is legal to have EU customers? All operations will be in the US (interaction only through a website). The forge will be designed to allow all of a user's data to be downloaded by that user (easy access to all data). It will also allow wiping away any reference to a user in commits (right to be fo…

In terms of the GDPR, your company would need to satisfy compliance of the GDPR. For small companies this is pretty straight forward, and it definitely helps to think about this early. https://gdpr.eu/compliance-checklist-us-companies/

Ouch. That list looks onerous. Thank you for the link.

Re: Shopify Is Illegal in Germany

#65
post #33

Mini Ask HN: How would a small company, say a code forge, that is based in the US ensure that it is operating such that it is legal to have EU customers? All operations will be in the US (interaction only through a website). The forge will be designed to allow all of a user's data to be downloaded by that user (easy access to all data). It will also allow wiping away any reference to a user in commits (right to be fo…

To add, would EU privacy requirements apply even if you're just running some Gitlab or even Mastodon instance? Maybe running it as an individual vs llc changes things?

GDPR applies to individuals as well as companies if they provide services to customers within the EU/EEA[0], as long as they are either a data controller or data processor, which are explained better than I can in the source below[1].

If the business is based in the US, things get a bit more complicated due to the CLOUD Act[2].

[0]: https://ec.europa.eu/info/law/law-topic/data-protection/refo...

[1]: https://ec.europa.eu/info/law/law-topic/data-protection/refo...

[2]: https://complior.se/cloud-act-and-how-the-new-american-law-c...

Re: Shopify Is Illegal in Germany

#66
post #33

Mini Ask HN: How would a small company, say a code forge, that is based in the US ensure that it is operating such that it is legal to have EU customers? All operations will be in the US (interaction only through a website). The forge will be designed to allow all of a user's data to be downloaded by that user (easy access to all data). It will also allow wiping away any reference to a user in commits (right to be fo…

To add, would EU privacy requirements apply even if you're just running some Gitlab or even Mastodon instance? Maybe running it as an individual vs llc changes things?

It would likely depend on the purpose and scope of the offering:

https://gdpr.eu/recital-18-not-applicable-to-personal-or-hou...

Re: Shopify Is Illegal in Germany

#67
It is ridiculous that data protection officials focus on CDNs, third party resources and cookies. And at the same time it is totally legal for Google to collect advertizing data from some random websites so they can create a profile that follows you around. All that sites have to do is to put up obnoxious cookie banners that nobody reads.

If they were really concerned about my privacy, they would ban creating cross-product profiles for advertizing purposes. I don't care at all that some CDN gets my IP, or that some website uses cookies to count users.

Also I don't care if somebody stores my data on Google Docs or Office365. If Google or MS go rouge and employees there so shenenigans with my data, we have bigger problems. They control the OS anyway. It makes more sense to regulate the "happy path" assuming they are law abiding, and just say you can't do targeted ads for European users.

Re: Shopify Is Illegal in Germany

#68
post #32
post #27

Earlier quoted context omitted.

To clarify: Shopify is a Canadian company (edit: but as mentioned elsewhere in this thread: they send data to CloudFlare, CloudFront (Amazon) and Fastly, which are US companies.)

But their CDN providers (CloudFlare, Amazon and Fastly) aren’t. That’s the claim made in the article, that using American owned CDNs makes your business illegal in Europe, even if no data processing or storage happens outside Europe. I find this hard to believe …

It is illegal according to many recent court verdicts, there are some examples with Google Fonts, too. Now, of course in practice you won't be sued if you only run a small business (or you might, if you get unlucky like this guy in the article).

Re: Shopify Is Illegal in Germany

#69

Earlier quoted context omitted.

In theory, yes. In practice, the issue is that Shopify refuses to sign a data processing agreement: https://gdpr.eu/what-is-data-processing-agreement/

DPAs do not protect against ramifications of the CLOUD act. See this thread (mainly the reply to it)[0]: SCC = standard contractual clauses, aka DPA/GDPR clauses that govern when and how data transferred to the US is used. > The ruling on Schrems II (the court case that struck down Privacy Shield) did not state that SCCs on their own would be sufficient. It said that SCCs + "additional safeguards" would be allowable.…

Exactly, it wouldn't matter if Shopify signed those.

Re: Shopify Is Illegal in Germany

#70
post #14

Wait, does this imply that running a website behind CloudFlare is illegal in the EU? After all, webshop or not, IPs will be transmitted... Or are IPs only a problem in connection with getting user data like name and address? Or is it the IP+cookie combo?

https://bluecatnetworks.com/blog/is-an-ip-address-pii-the-an... may provide some insight. IPs are sometimes PII. It seems that if you're the ISP, the IP is PII, but if you're a website, the IP alone may NOT be PII.

This blog post is incomplete with respect to Breyer. An IP address is always personal data to an ISP. It's also personal data to anyone who can ask/request/compel the ISP to identify someone based on the IP address. And one of the main conclusions of Breyer is that only happens in an obscure edge-case scenario, that's enough for IP addresses to be considered personal data all the time.

The case specifically was that in the local jurisdiction, there's a law that if a company gets DDOSed they can request the local regulator to ask the ISP to identify a user. This law only gets triggered in very exceptional circumstances, but its existence means that IP addresses are always personal data in that jurisdiction. While that law only covers one part of Germany, the analysis applies to any similar law, of which it is safe to assume there are many.

Post reply on HN