Live data from Hacker News

Use of Google Analytics declared illegal by French data protection authority

cnil.fr

811–820 of 1001 posts

Re: Use of Google Analytics declared illegal by French data protection authority

#811

I think we (in the EU) will soon realise the bizarre consequences of these regulations. European startups will not be able to use standard SaaS or PaaS tools (like AWS, Azure, Mailchimp, PayPal etc) if they are based in the US (like most of them are). No cloud services, no Office 365 or Google Workspace. It will take forever to build up a similar ecosystem in Europe and I think most successful European entrepreneurs…

On the contrary, it only forces those providers to have a European presence. We're not fragmenting the internet by looking after our own interests. This wouldn't be an issue if Americans viewed rights (and in this case privacy rights) as belonging to human being as opposed to Americans citizens. The US's policy is what led to this: > Agencies shall, to the extent consistent with applicable law, ensure that their priv…

Wow

> Agencies can snoop on non-US citizens but shouldn’t snoop on US citizens

and they went and snooped on US citizens anyway.

Re: Use of Google Analytics declared illegal by French data protection authority

#812
post #807

Earlier quoted context omitted.

> The EU part cannot be owned by the US entity since the US government can compel the US mother company to have it's subsidiary hand over data. Is this true for ownership by individuals too? If I, an American citizen & resident, owned and operated a company registered to a European nation to serve my European customers (with European hosting), does that make me compliant? Does an American solo founder have a path to…

If you are subject to the cloud act in the US then you are not compliant or in anyway can be compelled by the US to hand over data on EU citizens. As a private individual I suspect you would not have much to stand on if the NSA knocked on your door. Another way to be compliant is to not collect PII.

> Another way to be compliant is to not collect PII.

The GDPR extends far beyond the US notion of PII. As I understand it, it covers basically all user-submitted or user-related data if it's possible for that data to be hypothetically tied to an individual in the EU (even if that can be done without your service holding traditional PII).

> As a private individual I suspect you would not have much to stand on if the NSA knocked on your door.

Yeah, a federal agent with a wrench can do anything they want to me (https://xkcd.com/538/), but I'm trying to figure out my options.

Re: Use of Google Analytics declared illegal by French data protection authority

#813

Earlier quoted context omitted.

>I think we (in the EU) will soon realise the bizarre consequences of these regulations. Could this not also be said about US regulations such as CLOUD act, Section 702 of the Foreign Intelligence Surveillance Act and Executive Order 12333. I don't think it's accurate to solely blame the EU when this is in response to legislation that gives/gave the US access to all types of personal data on European citizens.

I agree. Hopefully this is temporary and they can figure out a reasonable compromise. As a Swede I do feel that parts of the EU (with Germany and France) are heading in the wrong direction. Those are not countries famous for their entrepreneurship and it seems like their first instincts in relation to the US are usually protectionist.

I'm also European and I completely agree with you. They're basically taking the whole EU as a hostage to protect their own inefficient domestic companies =(

Re: Use of Google Analytics declared illegal by French data protection authority

#814

Earlier quoted context omitted.

The issue would be, that the website developers / their management contributes to the issue, by enabling partier to do that spying. If no data was send to another party, then spying on that data is much harder and probably unattractive for most use-cases. GA data becomes valuable through collecting from many many senders. While the people doing the spying are already doing something ethically very questionable, the p…

So you are saying the US intelligence agencies have some unfettered access to all of GA data? Or that it is sent unencrypted and intercepted in transit? It's not the DNS calls or phone companies that are more to worry about?

If US intelligence wants to have access, they will, via their law, as far as I understand. They will require Alphabet to give the data, Alphabet will get it from Google, and that is it. No need to listen or intercept anything.

Best thing you can do is not to make use of GA in the first place, so that no such data of visitors of your websites exists in Google infrastructure.

Re: Use of Google Analytics declared illegal by French data protection authority

#816
post #446

Earlier quoted context omitted.

I don't think it can. Maybe they can buy yandex, but i think europe has drained its talent tothe US. And even if they build it, how will they monetize it?

Europe isn't drained of talent by a long shot. It has surely been tapped to some extent by the bay area exodus, but there's plenty of tech success stories and talented people here still.

Yeah the talented people are getting paid 3x as much to work for US companies with like two or three exceptions.

Re: Use of Google Analytics declared illegal by French data protection authority

#817

Earlier quoted context omitted.

We did our research, and settled on the French cloud provider that fit our parameters. They made promises about support hours that they did not keep. Changing cloud service providers is not cheap. We were a small team, and this cost us lots of effort. We didn't fork our code, we forked our services. We ran everything on Azure. Then we had to configure our kiosk devices to either talk to Azure, or to talk to our serve…

Do cloud service providers like Azure not have a way to "pin" some of your service instances to servers in specific countries? Seems like this capability would be important differentiating feature given EU privacy laws about where user data is hosted.

They do, in fact Azure is totally compatible with French law for handling private data. Many large companies use it.

Re: Use of Google Analytics declared illegal by French data protection authority

#818
post #722

Earlier quoted context omitted.

On the contrary, it only forces those providers to have a European presence. We're not fragmenting the internet by looking after our own interests. This wouldn't be an issue if Americans viewed rights (and in this case privacy rights) as belonging to human being as opposed to Americans citizens. The US's policy is what led to this: > Agencies shall, to the extent consistent with applicable law, ensure that their priv…

I think fragmentation and looking after one's interests aren't even opposites. Analytics in particular seem like a very lopsided value prop: the american entity (Google) stands to gain from collecting analytics but doesn't really provide a perceivable equivalent value through the analytics service to the affected parties (EU consumers) in return, as you'd normally expect in a fair trade policy between two countries.…

> lopsided value prop

But that's not what CNIL is basing their decision on: "The CNIL concludes that transfers to the United States are currently not sufficiently regulated...Indeed, although Google has adopted additional measures to regulate data transfers in the context of the Google Analytics functionality, these are not sufficient to exclude the accessibility of this data for US intelligence services."

I probably don't understand the legal issues fully, but it seems the worry is that US intelligence services may be tapping the lines and databases of Google, may have agents working at Google as badged employees, or may be able to subpoena Google (or any US service provider). [for the record, I wouldn't doubt if all the above are true]

I don't see how Google Docs is less susceptible to Google tracking user activity (and by extension US intelligence).

> "CNIL recommends that these tools should only be used to produce anonymous statistical data"

So the tools are not anonymous because the request headers of the client are being logged and used to identify a session, along with what resources on the site were accessed in that session.

Any site operator has this data on their visitors.

CNIL doesn't want sites hosted in France to be making client-side calls to services provided by Google (whether analytics, fonts, etc) or theoretically any US-based service provider because the client request will be logged by that resource host and open to access by US law enforcement? Do I understand that correctly? What's the solution? A site builder can't let web clients make direct calls to any resources in the US? That seems... sweeping, profound, surprising, impactful. Have fun with that.

Re: Use of Google Analytics declared illegal by French data protection authority

#819
post #807

Earlier quoted context omitted.

If you are subject to the cloud act in the US then you are not compliant or in anyway can be compelled by the US to hand over data on EU citizens. As a private individual I suspect you would not have much to stand on if the NSA knocked on your door. Another way to be compliant is to not collect PII.

> Another way to be compliant is to not collect PII. The GDPR extends far beyond the US notion of PII. As I understand it, it covers basically all user-submitted or user-related data if it's possible for that data to be hypothetically tied to an individual in the EU (even if that can be done without your service holding traditional PII). > As a private individual I suspect you would not have much to stand on if the N…

> The GDPR extends far beyond the US notion of PII.

That's a good thing. The US notion of PII is ridiculously naive.

Re: Use of Google Analytics declared illegal by French data protection authority

#820

Earlier quoted context omitted.

Do cloud service providers like Azure not have a way to "pin" some of your service instances to servers in specific countries? Seems like this capability would be important differentiating feature given EU privacy laws about where user data is hosted.

They do, in fact Azure is totally compatible with French law for handling private data. Many large companies use it.

[deleted]
Post reply on HN