Live data from Hacker News

Italian watchdog bans use of Google Analytics

gpdp.it

601–610 of 614 posts

Re: Italian watchdog bans use of Google Analytics

#601
post #96

Earlier quoted context omitted.

How does one "simply make a universal law"?

By publishing a RFC.

An RFC won't compel people or companies in the way you hope. An RFC is a request and nothing more. A law is driven by the legal authority of a state and is backed by corporate & financial penalties, prisons, and guns.

Re: Italian watchdog bans use of Google Analytics

#602

Earlier quoted context omitted.

Maybe a race where the finish line is maximum exploitation of the digital population isn't a race worth running.

here I thought maximum exploitation would be selling someones identity on the dark web but I come to find on HN that it's actually hashed analytics data D: !!!

No post body was provided.

Re: Italian watchdog bans use of Google Analytics

#603

Earlier quoted context omitted.

If it's inadvertent, then they can remedy the error once they've been notified. If an IP address is sent to the USA, then whether it's stored or not ceases to be a matter that European courts can oversee. Since US courts and European courts are not in accord on these matters, Europeans are faced with either banning the export of IP addresses to the USA, or giving up on legislating privacy at all. We chose the former.…

"remedy the error"? Care to put that in a sentence like "Remedy the error of using the internet" You expect a business that's invested in the AWS stack to up and move overnight because some illiterate morons in Brussels decided that?

I don't care much what decisions random businesses make.

It has been my view for a long time that entrusting your infrastructure to the tender mercies of a firm like Amazon is reckless. Here we have a situation where the legal environment has changed; AWS hasn't changed to match; so those companies that chose to rely on a 3rd-party infrastructure provider appear to have made a mistake.

If I had been advising one of those companies, I would have advised them to bring critical infrastructure in-house. But there might have been other options, like using Europe-based infrastructure providers.

I've never been involved with budgets and so on. It's not my concern how much different solutions cost. I just think the principals of companies have a responsibility to avoid third-party risk - which is what you have, if you rely on a third-party for critical company infrastructure.

That's why I was able to persuade my employers to bring their email service in-house. It worked, and the bosses were pleased with the improved service and reliability. We also constructed our own in-house build and deployment train; that worked very nicely too.

Maybe the cost-benefits vary according to the type and size of business. I'm not a researcher, and I only know about the things I've looked into. But my guess is that AWS works well for companies that are after a quick buck (e.g. an IPO).

Re: Italian watchdog bans use of Google Analytics

#604

Earlier quoted context omitted.

What does that mean? Europeans use my website.

It's your responsibility to not export PII of Europeans to America, and/or to stop them from accessing your content.

My website does not care where you live.

What exactly will happen me if I do not block Europeans from using my website?

Re: Italian watchdog bans use of Google Analytics

#605
post #125
post #12

We are based in Europe and self-host our analytics exactly for this reason. I feel this is just the beginning.

Same here. We’ve been using goaccess for years on a 300M hits a month. Self-host is the way to go for us.

Comparing goaccess to GA is like comparing an abacus to a MacBook Pro.

Re: Italian watchdog bans use of Google Analytics

#606

If I understand this correctly, the issue isn't Google Analytics specifically, but "because it transfers users’ data to the USA, which is a country without an adequate level of data protection". So this could also apply to any company that sends PII to the USA?

Any company that sends personal data to the USA, yes.

Re: Italian watchdog bans use of Google Analytics

#607

Earlier quoted context omitted.

The EU hasn’t shaken off their roots in monarchy. Using the power of the state to go after a single private entity since they have a blood feud with said entity and are now finding all sorts of excuses to hit them economically. I’ve been following the cases with regard to privacy in the EU and it’s a complete joke. You have all these onerous rules against any web technology making it near impossible for startups to f…

> The UK is sick and tired of this and has recently begun moving to ignore these onerous rules. All power to them. I don't think so; the UK passed the Data Protection Act 2018 just 4 years ago, to bring GDPR into UK law. That is: the DPA is normal statute legislation, unlike the GDPR itself, which is a bureaucrat-made regulation. The DPA was passed by both houses of Parliament. So what are these mysterious moves to i…

>I don't think so; the UK passed the Data Protection Act 2018 just 4 years ago, to bring GDPR into UK law.

This is wrong.

The Data Protection Act did not bring the GDPR in to UK law, GDPR became part of UK law as soon as it was passed because it's an EU regulation, and regulations have direct effect in all member states (which at the time it was passed included the UK).

The GDPR then became "retained EU law" by virtue of Section 3 of the European Union (Withdrawal) Act 2018, and was then modified (turning it in to the UK GDPR) by the The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019. These regulations also amended the Data Protection Act, fwiw.

Re: Italian watchdog bans use of Google Analytics

#608

Earlier quoted context omitted.

There's nothing US companies can do to make themselfes legal to use here. The legal framework in the US allows dragnet spying on every non-american and american companies are forced to participate in that effort.

They're perfectly legal if they don't process any PII. If a US company serves static content there's no need to fear the EU; they'll just have to disable illegal external integrations like Google Analytics/Fonts/etc. A company doing business with other companies might find themselves in a position where they can comply perfectly. Not every company needs to collect PII, though these days every company likes to pretend…

>They're perfectly legal if they don't process any PII.

Personal data, not PII. The GDPR does not care about PII (except to the extent that the set of things that are PII is a subset of things that are personal data).

Re: Italian watchdog bans use of Google Analytics

#609
post #445

Earlier quoted context omitted.

Let me guess, you're from the US and user surveillance is beneficial to your business so naturally everyone with non-capitalist (read not $$$-centric) ideology is plain wrong. EU startups don't have to "catch up" or even compete with US start ups.

Does this imply that the EU is "non-capitalist" or something? "EU startups don't have to "catch up"..." then don't get surprised when EU talent is poached by US and Asian HRs for x2-x3 rates. And before you're gonna talk about all those "free" (taxpayer funded) services and how no European would ever move to Asia or NA, i'd like to remind you that we're in the remote work world now :)

Replying to a comment that states: "not everything revolves around money" with "but we make more money".

Re: Italian watchdog bans use of Google Analytics

#610

I don't understand. They can host locally the data and remotely query it. What's important is the "intelligence" the data does provide: giving critical and unfair advantage for those who have the whole data. For instance, microsoft has an unfair advantage almost anywhere because they have access to the whole linkedin database.

European companies are not allowed to share PII with American companies. That goes for companies with a headquarters in the USA or subsidiaries that may be forced to share data thanks to laws like the US Cloud Act. Previously, the EU exempted the USA through an "adequacy decision". That was later deemed illegal under EU law as American laws could not guarantee the privacy of EU citizens to the extend the GDPR prescri…

That does not change the issue: EU microsoft has a local unfair advantage in EU because it has access to the whole database of linkedin (which they own).

Additionaly, denying remote access is almost impossible to enforce. It would require a efficient and permanent deep monitoring of their servers.

linkedin should be illegal since this data should not be privately own.

Post reply on HN