18 ms·
Europe's highest court has rejected the 'safe harbor' agreement
- julianpye 11y agoDoes this effectively render any Parse or Firebase application (they only have US servers) that stores user information (e.g. email account) illegal in the EU?
- kuschku 11y agoI am not a lawyer, so do not take this as legal advice, please consult a lawyer if you want actual advice. This said: Probably yes. EU data laws are mostly about private information, for example private chat messages, etc. If you only store email accounts, you might get around the laws, but if you store anything like payment information, communication between users, etc, you effectively now have to follow EU data laws, which mean: You can’t give any third party (not even your government or hoster) access, you can’t store it in countries where the government might just seize your data (like the US), etc.
- rmc 11y agoAmericans: This is time to get your government to change your laws if you still want to be the leader in the tech field.
- sarciszewski 11y agoEven if we adopted identical laws, the government would just ignore them. We're a nation of criminals.
- A_Beer_Clinked 11y agoThe full ruling is available here: http://www.politico.eu/wp-content/uploads/2015/10/schrems-judgment.pdf http://www.politico.eu/wp-content/uploads/2015/10/schrems-ju... These bit jumped out at me: >Furthermore, national security, public interest and law enforcement requirements of the United States prevail over the safe harbour scheme, so that United States undertakings are bound to disregard, without limitation, the protective rules laid down by that scheme where they conflict with such requirements. The United States safe harbour scheme thus enables interference, by United States public authorities, with the fundamental rights of persons, and the Commission decision does not refer either to the existence, in the United States, of rules intended to limit any such interference or to the existence of effective legal protection against the interference. >This judgment has the consequence that the Irish supervisory authority is required to examine Mr Schrems’ complaint with all due diligence and, at the conclusion of its investigation, is to decide whether, pursuant to the directive, transfer of the data of Facebook’s European subscribers to the United States should be suspended on the ground that that country does not afford an adequate level of protection of personal data. My reading (not a legal expert) is that data residency is the important bit here. Which in my view is a small step but not sufficient.
- armada651 11y agoI think it means a lot more than just data residency. Without the safe harbor agreement you can no longer avoid EU privacy regulations by storing the data in the US. This means that a lot of US companies are now exposed to EU privacy regulations where previously they only had to account for US privacy regulations. The US privacy regulations are no longer considered compatible with the EU privacy regulations. That has much more impact than just data residency.
- cm2187 11y agoWhat I am curious about is how do we define "doing business in the EU"? If I am american, create a blog stored in the US, and allow users to register an account to comment on the blog, am I doing business in the EU if a EU person creates an account or are my visitors more akin to foreign tourists visiting a US shop in the US and therefore outside the reach of EU regulation? In the financial sector, the extra-territoriality of US laws has been a problem for decades. Securities issued in the EU, by EU entities and marketed to EU investors end up having some language referring to which US regulation they fall under out of fear that a US person will end up buying it, and the US applying their laws and regulations.
- nolok 11y ago> What I am curious about is how do we define "doing business in the EU"? If I am american, create a blog stored in the US, and allow users to register an account to comment on the blog, am I doing business in the EU if a EU person creates an account or are my visitors more akin to foreign tourists visiting a US shop in the US and therefore outside the reach of EU regulation? De facto, it's when you take money from EU customers and/or have an official office in some EU country.
- cm2187 11y agoso a non profit wouldn't require to follow EU regulations on personal data?
- axx 11y agoEuropean citizen here, and as much as i welcome a step like this, it's also pretty interesting to see, what this means for smaller (online) businesses outside of europe. Sure, you want to host customer data from europe in europe (latency-wise) anyways, but now that this will be more or less required it will be interesting to see how people will solve this. The good thing is, with "the cloud" you have a lot of option (locations) to choose from.
- pjmlp 11y agoAlso European citzen here, I also appreciate the ruling. It is already an interesting experience trying to explain to off-shore companies that they cannot just take our data like that. Well they can in practice, but then better prepare some good explanations in case the company gets a security audit from the local government.
- Niten 11y agoIt's interesting to see the regional differences in this discussion, because that attitude is pretty foreign to the way I think about the Internet. I know that if I use Yandex, at least some of my data is going to reside in Russia. If Dailymotion, France. I consider it up to me as a consumer to decide whether that's what I really want. I don't consider it my local government's job to force those companies to change their business models.
- copsarebastards 11y ago> I know that if I use Yandex, at least some of my data is going to reside in Russia. If Dailymotion, France. I consider it up to me as a consumer to decide whether that's what I really want. I don't consider it my local government's job to force those companies to change their business models. This is a ridiculous position to take, because it requires a humanly impossible amount of research to know whether the privacy of your data is protected. And that's when the information is even available. Privacy is a basic human right. When corporations collect your data it becomes the responsibility of those corporations to protect your privacy. Individuals simply do not have the resources to enforce this, which is why we elect people to enforce this. This isn't some crazy responsibility for governments: this is the fundamental reason why governments exists: to protect the interests of their citizens collectively when it's infeasible to protect those interests individually.
- cfv 11y agoDoes this mean right to be forgotten will have to apply cross-borders too?
- SimplyUseless 11y agoWhile this is a massive ruling, there are valid exceptions that allow companies who have agreed with their clients to transmit their data from EU to US while keeping data separation and with respect to the data protection law. This is not a blanket-panic for all US/EU companies as the media are projecting.
- chopin 11y agoThe difference to Safe Harbour is that the client can revoke their consent at any time. After that the data must be pulled off US servers. If I ask Facebook to delete my data, they are absolutely bound by this. There is no legal way anymore to just hide the data from me.
- lucaspiller 11y agoSalesforce has put up a page for you to give them the permission to do exactly this. http://www.salesforce.com/company/privacy/data-processing-addendum-faq.jsp http://www.salesforce.com/company/privacy/data-processing-ad... What if I don't want my data going to the US though?
- a_bonobo 11y agoThis is good, and a direct result of the Snowden revelations - without those, the US would still considered to be a safe harbor for your data. I'm hopeful that this will create the kick that the US needed, now that actual income (and high income, at that) is becoming threatened by the NSA. Of course this isn't the end to their data theft. They're likely to get the data from their Five Eyes European friends instead, but still - a good victory. Amazing to see what one determined person can do!
- rurban 11y agoSure. The next step would be to demand EU nations which violate the safe harbor EU rules be either thrown out of the EU (GB, but probably also Neitherlands, Sweden and Denmark), or fix their privacy laws. It cannot be that the GHCQ acts on behalf of the US on EU data and allows easy circumvention of basic privacy principles.
- pjc50 11y agoSadly, the data protection laws have always had "national security" exemptions.
- M2Ys4U 11y ago>The next step would be to demand EU nations which violate the safe harbor EU rules be either thrown out of the EU There is no safe habor inside the EU because EU privacy law already applies there and the regular legal mechanisms apply.
- walterbell 11y agoMeanwhile, TPP prohibits countries from having data sovereignty laws, http://www.zdnet.com/article/tpp-moves-toward-killing-off-government-mandated-data-sovereignty/ http://www.zdnet.com/article/tpp-moves-toward-killing-off-go..., with similar prohibitions sought in TTIP and TISA, https://blog.ffii.org/a-license-to-spy-cross-border-data-flows-in-ttip/ https://blog.ffii.org/a-license-to-spy-cross-border-data-flo... "Governments in Australia, the United States, New Zealand, Canada, Singapore, Vietnam, Malaysia, Japan, Mexico, Peru, Brunei, and Chile will be unable to force companies from those countries to store government data in local datacentres ... governments will not only be prevented from mandating data sovereignty provision, they will also be unable to demand access to source code from companies incorporated in TPP territories."
- toyg 11y agoIt's incredible how deep the ideological split is, on data protection and surveillance. On one side, you have lawyers saying "hey, this is a problem, this law says you can't do that, we have to find ways to make you comply"; and on the other you have business lobbies and security agencies saying "hey, this is a problem, we need to remove all laws".
- PythonicAlpha 11y agoOf course, the business lobbies say that. Restricting laws are always costly: Environment laws for example -- how costly it is, not to be able to pollute the air, the water, the people. Have filters, have restrictions, use of alternative fuels ... this all costs. And reduces the growth rates of our economies .... Better remove those laws and instead install strict intellectual property laws with unrestricted duration of protection. That is, how (capitalistic) economy works: Put the costs of the business on the shoulder of many (the people of the country) and the benefits (the profits) on few people.
- 1stop 11y agoYou mean capitalism, not economy.
- kornakiewicz 11y agoProhibition of storing behavioral data would be great next step.
- Oletros 11y agoWhy?
- kornakiewicz 11y agoBecause storing and processing data that about user who is unconscious that such are even collected is de facto spying?
- Oletros 11y agoCan you give an example of a company storing and processing data without telling it in the service policies? And you have said that ALL the behavioral data collection must be forbidden. Even if the user agrees with that? By the way, spying is already illegal. If you know about that behavior you can sue those companies
- kuschku 11y agoAny ToS that contain "unexpected" or "surprising" clauses are automatically null and void under EU law. Even if the user agrees with them.
- Oletros 11y agoPerhaps the clauses are void, but what the OP said is that there is no information about data being collected. This is what I´m asking, an example of one of those companies "spying"
- neppo 11y agooff topic, but why does the article use a picture of Mark Zuckerberg with lip stick photoshopped on?
- blisterpeanuts 11y agoI was going to ask the same question! Is it some kind of rendering incompatibility between this jpeg and most browsers, or just a really crappy photography touch-up job?
- weddpros 11y agoEdit: I'm reacting to "Facebook and Twitter [...] could be forced to host European user data in Europe" Border control with data is the worst idea ever. Think of it: my Facebook friends lists has EU and US people in it. This list can't reside in EU or US. This webpage can't be served by either a EU or US web-server. By law. LOL Plus I'm a EU citizen, and I can choose to give my data to whoever I want... no more. That's sad. This ruling only shows the dismal tech knowledge of lawyers and lawmakers. It's impossible to implement Facebook with data spread between EU and US. Same for Tweeter and others. Say goodbye to social networks. Because of model denormalization, because of network latency and intercontinental bandwidth. Some mention cloud zones, but they're only useful with replication, which IS data transfer. OR... social networks will cheat. And one day, they'll be sued for cheating the impossible regulations (think VW...)
- IBM 11y agoIt's interesting that certain bloggers such as Dustin Curtis and Ben Thompson have claimed that Apple's privacy stance will ultimately hurt them because they'll be at a disadvantage to competitors, but it seems like they've shown some real foresight when you take this ruling into consideration.
- Oletros 11y agoHow this ruling affects differently Apple from Facebook or Google?
- tomp 11y agoApple's business isn't based on exploiting the user's data and shitting all over their users' privacy (as has been the case with Facebook in the past, and Google too to some extent), and they've taken explicit steps to safeguard their users' privacy (e.g. encryption, ad-blocking).
- Oletros 11y agoWhat has to do what you say with the ruling? What has to do the business model with a ruling that states that user data can't be transferred? How is different iCloud than Google Drive?
- tomp 11y agoThe point is that Google will have to adopt much more than Apple. Sure, iCloud and gDrive might be equivalent, but there is no Apple equivalent to e.g. G+ or G-ads.
- mhandley 11y agoI wonder if there are additional ramifications of this, even for European companies dealing with European customers. For example, what happens when personal data from a European datacentre to a European customer transits a US network on the way (such routing diversions are fairly common)? In the light of Snowden's revelations, this would seem incompatible with EU privacy regulations unless the data were encrypted. Of course personal data should always be encrypted, but where are the CAs located? Is a European company negligent if they don't use a European CA and do certificate pinning? Interesting times.
- MichaelGG 11y agoThis sounds great! Though if the owning company is in the US, then the US views this as reason to be able to access customer data no matter where its stored. More fun to come mm? Question: Why do companies HQ themselves in the US? Why not pick a friendlier country, then turn their US parts into a simple contractor that supplies software development and engineering resources? Then the US company would not have actual ownership of any data. Forcing them to reveal customer records would be the same as forcing an individual to steal data right?
- lagadu 11y agoBecause the bigger companies were established long ago, when the US had the much bigger market. Nowadays that's not true but the US startup VC is a lot stronger in the US for a bunch of reasons, so new startups tend to be established there much more often (with the financial tech field being the exception I believe). If you're making a new company you're going to make it where you live just out of sheer convenience.
- saalweachter 11y agohttps://xkcd.com/1053/ https://xkcd.com/1053/ Today you get to learn about: American Exceptionalism! It is important to realize that, within the US, there is essentially a universal belief that the US is the best place to live, work, or be in the entire world. The debate is not so much whether the universe revolves around the United States, but which city exactly the axis passes through -- New York, DC, San Francisco, LA. It is very important that a universal axis has a commonly used two letter acronym, which is why not even a Chicagoan seriously believes the axis is through Chicago. When the EU makes privacy complaints against US companies, the common perception -- even among US citizens who disapprove of domestic spying programs -- is that something is wrong with the EU. The idea that the EU could be right to hold a US corporation accountable to their laws never even occurs. No American could ever conceive of establishing the HQ of a US corporation outside the US -- except maybe as part of a skeevy tax dodge. The US is the best place in the world to live, work, and run a business. Why would you want to go anywhere else? To be fair, most of the US companies that do establish some sort of off-shore setup are engaging in some sort of skeevy tax dodge.
- finnjohnsen2 11y agoPerhaps it's time to p2p everything.
- nabla9 11y agoMy reading of the judgment is that it just throws the decision back to the national courts to decide what constitutes safe harbor. Safe Harbour agreement between US and EU streamlined the process for getting access to EU data. Now it mus be decided in national level. http://www.politico.eu/wp-content/uploads/2015/10/schrems-judgment.pdf http://www.politico.eu/wp-content/uploads/2015/10/schrems-ju...
- mtgx 11y agoCouldn't we get a better source than Business Insider?
- asgard1024 11y agoFor example: http://www.theguardian.com/world/2015/oct/06/us-digital-data-storage-systems-enable-state-interference-eu-court-rules http://www.theguardian.com/world/2015/oct/06/us-digital-data...
- UserRights 11y agoThe "good" companies should relocate their business central away from USA and come to Europe! Some big companies should finally stop talking and start acting, this is the only chance for a real change. Cut the NSA-Brotherhood ties! These little Hitlers from all the affiliated "Clubs of Distopians" and the War-Industry completely destroyed the most important association of "USA == Freedom" in the world. Face it. Deal with it. Act accordingly. For people interested in history: it might be interesting to look at the post-ww-2 de-Nazification process in germany to understand how hard it is to remove established circles of anti-democratic bureaucrats from power structures. This will take a very long time (if it happens at all). The better immediate reaction would be to support progressive and freedom-oriented societies with your technical powers until "good old USA" is restored. Europe is not perfect, but what happens in USA nowadays is pure distopia, a very unhealthy development that will lead to a negative outcome for all of us. Once people came to The USA because of suppression and lack of freedom in their home countries. Just a few generations later if you have the same sense and longing for freedom like these ancestors of you, it is now time to leave that continent as the suppressors followed your trails - come home to Europe and together we can build a better future!
- makeitsuckless 11y agoIt's interesting how this is described as a potential "bureaucratic nightmare". Having to follow the law of the country your doing business in has been standard operating procedure for, well, basically all of human history. Somehow the tech industry seems to think it should be exempt from that, even if it means being allowed to piss all over the basic civil rights of citizens of modern Western democracies. Yes, this is a problem that needs to be solved given the reality modern cross-border online services. But it can't be solved by the corrupt political elite simply selling their citizens hard fought rights to corporations operating from countries that lack respect for such rights.
- davidw 11y agoWhat sucks about it is that the EU, rather than presenting one set of rules and regulations to follow, and, say, allowing you to host data within the EU to be compliant, seems to have kicked the question down to individual European countries, each of which might do something different. And you wonder why it's tougher to do startups in Europe... I'm pleased by what the ruling says about the NSA and the pressure it puts on the need for reform, but less than pleased about the practical implications.
- M2Ys4U 11y agoWell the data protection principles are common across the EU - so there's only limited scope for national DPAs to disagree and there's always the opportunity to ask the ECJ for a ruling to clarify.
- mtgx 11y ago> The average consumer will not see any restrictions in daily use, but will hopefully soon be able to use online services without potentially being subject to mass surveillance > However, US companies that obviously aided US mass surveillance (e.g. Apple, Google, Facebook, Microsoft and Yahoo) may face serious legal consequences from this ruling when data protection authorities of 28 member states review their cooperation with US spy agencies. Can't wait. This is going to be good. http://www.europe-v-facebook.org/CJEU_IR.pdf http://www.europe-v-facebook.org/CJEU_IR.pdf
- unfamiliar 11y ago>That could be a bureaucratic nightmare: In theory, American companies with European customers could now end up trying to follow 20 or more different sets of national data privacy regulations. Good. If you want to be a multinational company, then you should have to obey the laws of each country.
- rogeryu 11y agoIt's moderate punishment for abuse of power. And I don't mean here that Google or Faceboo is the abuser here - it's the American government.
- coldcode 11y ago> Good. If you want to be a multinational company, then you should have to obey the laws of each country Good luck with that. If the US mandates you do X and EU mandates you do !X.
- unfamiliar 11y agoSo, lets say for example that the US requires that you keep data on customers so that law enforcement can use it, but the EU requires that you don't so that privacy is protected. Are you are suggesting that one of those laws should be changed to make it easier for multinational companies to operate, even though there was a good reason for the law in the first place? Because I would say that if the company absolutely has to keep customer data then they shouldn't operate in a country where that is illegal, and if they refuse to keep customer data then they shouldn't be operating in the country where it is required.
- VikingCoder 11y agoNo, this is terrible. These countries are demanding we run our services in their countries. This is a money grab. Note that these same countries expect the United States to act as World Police, and do not contribute as much money as they should. They want the US to know about attacks ahead of time. I wonder how the US could possibly know about attacks ahead of time? I deplore mass surveillance. I really do. But I think wiretapping with a warrant is a necessary tool for fighting crime, and terror, and bad state actors. There's a part of me that desperately hopes all major internet services just shut off Europe entirely. Welcome back to the Stone Age.
- tljr 11y ago"Note that these same countries expect the United States to act as World Police". Nobody (except some Americans) want this. "I deplore mass surveillance. I really do. But I think wiretapping with a warrant is a necessary tool for fighting crime, and terror, and bad state actors." I hate X but Y is necessary (because I said so) so let's do X anyway. "There's a part of me that desperately hopes all major internet services just shut off Europe entirely. Welcome back to the Stone Age." If by stone age, you mean 2006, great.
- the-dude 11y ago> Note that these same countries expect the United States > to act as World Police, Why do you think that? And how about https://en.wikipedia.org/wiki/United_States_and_the_United_Nations#The_U.S._arrears_issue https://en.wikipedia.org/wiki/United_States_and_the_United_N... I am actually appalled the Netherlands actually contributed to your shitty conflicts.
- VikingCoder 11y agoWow a billion dollars. That would pay for about 60 seconds of the war against the Taliban.
- the-dude 11y agoWhy do you want to wage war with the Taliban?
- karavelov 11y agoThis is just small victory. AFAIK, US government can still ask without a court order Facebook or MS or any other US company to handle them the data of/for european citizens that hosted in Europe.
- M2Ys4U 11y agoThat's one thing that the GDPR (General Data Protection Regulation)[0] which is in the legislative pipeline at the moment is looking to fix. The proposals include being able to levy a fine up to €1,000,000 or up to 5% of the annual worldwide turnover (whichever is greater) if they fail to comply with EU data protection rules. [0] https://en.wikipedia.org/wiki/General_Data_Protection_Regula.. https://en.wikipedia.org/wiki/General_Data_Protection_Regula....
- jsudhams 11y agoThis is good and I see no reason why this cannot be done easily for most corps (except the ones who mine personal data). For why would you not have critical personal data in the specific country table/database that is in that specific country. If you do not provide the service in that country and some one signs up then inform that the data is not safe and give visible warning. Is that really difficult. I used to have DB library layer earlier where based employee location it will direct their data to that location.
- mcintyre1994 11y agoAre you allowed to breach these rules if you provide a visible warning?
- jupp0r 11y agoSo this is what I think will happen: a lot of companies (maybe even the likes of facebook and google) will move out of europe and just serve everything from the US. There is not really an alternative to that, how could my EU-hosted facebook profile not be transferred to the US so my friends can see my book favourites?
- jarek 11y agoHave you ever tried to do ad-selling on Google's scale without local sales offices?
- JulianMorrison 11y agoGood. Hopefully this puts pressure on the USA to rein in its out of control security state.
- Aloisius 11y agoIf I'm a US company that does business in the EU, is there any reason that personal information collection can't just happen through a US web server? That way it is the user who is transferring the data to the US, not the company. Updating your name, birthday and other personal information would take an extra 100 ms in order to POST to the US, but it could then be replicated back out to the EU for reads if necessary for performance.
- pinaceae 11y agowell, I guess LinkedIn is hosed. and AWS which does global replication. and and and. this ruling ignores the decentralized nature of the internet. worst case is Europe being shut off from any tech advances, while the Pacific region from Cali to China takes off.
- protomyth 11y agoIts been asked by multiple people in the thread, but I'm not clear on the answer. If I host a website that has user accounts in the US, and do not stop people from the EU from registering, do I, with no offices outside the US, need to do something different because of this ruling?
- fauigerzigerk 11y agoI'm not a lawyer, but I think that if you are a US resident or the company you run is incorporated in the US without any offices or hosting in the EU, then you are not bound by EU data protection law.
- deleted 11y ago[deleted]
- blazespin 11y agoAnother question is what if I have a friends list and someone from europe is on it? Does that mean all of my friends data has to be stored in europe?
- codedokode 11y agoList of friends probably is not personal data. Personal data are things like real name, photo, phone number, address, credit card number.
- thomasz 11y agoIt is. > For the purposes of this Directive: > (a) 'personal data' shall mean any information relating to an identified or identifiable natural person ('data subject'); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural or social identity; http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:31995L0046&from=DE http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELE...
- copsarebastards 11y agoThis is good for everyone's privacy. By making it difficult for businesses to centralize the storage of US and European data, the European court has incentivized businesses to pressure the US government toward laws that respect our privacy better.
- peter303 11y agoThe Euros are jelly they did not invent profitable Big Data. So they will be putting every roadblock possible against those who did.
- icebraining 11y agoBy retroactively passing a Directive? I'd take time travel over big data any day!
- chaitanya 11y agoSo we are building a messaging product for organizations. I am wondering how this can impact us if an org that uses our product has employees in both EU and US (assuming that national regulators in EU go ahead and bar personal data transfer to US). * Will we need to partition user data based on location, even if they are in the same organization? * What happens when a user in EU sends a message to one in US? So right now the chat history for one-on-one conversation pairs is stored in one place, does this ruling mean that now we have to duplicate this chat history for both the users? * Even worse, what if multiple EU and US users are part of the same chat group? Is there any way we can store the group's chat history in one place?
- icebraining 11y agoSure, store it all in the EU. The US has no equivalent legislation, after all.
- srj 11y agoHow is it possible that people don't discuss the GCHQ in the same breath as the NSA? From news reports it seems they may as well be the same agency. Keeping data out of the US isn't enough, and it's dangerous for Europeans to think that their own governments are looking out for their privacy. They should be looking instead to make encryption ubiquitous. This may be limiting corporate data storage, but I don't think this impacts intelligence gathering for the US at all.
- M2Ys4U 11y agoWell it's not just about the NSA - although that is what triggered the case that this judgement is from. Even if the NSA (and GCHQ) wasn't collecting everything, US law still wouldn't provide enough protection to comply with EU privacy norms.
- erikb 11y agoGreat success! They should try it the other way around. Looking for the set of things they can do that are correct in the European countries and then apply it to the US as well. If the biggest argument is to simplify ruling and management then this approach would be just as good as allowing US rules to overwrite European rules, right?
- deleted 11y ago[deleted]
- codedokode 11y agoHosting data locally in EU doesn't solve privacy problem because the servers are still operated by USA companies that can (and obviously will) share the data with NSA. The solution is to create more local services so the data never leave the country. It is also better economy-wise so the money stay in the country too.
- M2Ys4U 11y agoThat's one thing that the GDPR (General Data Protection Regulation)[0] which is in the legislative pipeline at the moment is looking to fix. The proposals include being able to levy a fine up to €1,000,000 or up to 5% of the annual worldwide turnover (whichever is greater) if they fail to comply with EU data protection rules. [0] https://en.wikipedia.org/wiki/General_Data_Protection_Regulation https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
- codedokode 11y agoSuch violation would be extremely hard to prove if the data were exported to US via secure channels.
- _of 11y agoI wish the title was "EU's highest court". Europe != EU.
- AndrewKemendo 11y agoWhile this is a win for individual privacy, it does truly make scaling web services significantly harder and more costly. Being in compliance is fairly easy for large companies, but it's going to be a challenge for startups.
- cmurf 11y agoI wonder if some companies have sufficiently complex operations globally, that they end up with mutually incompatible laws and would have to either stop doing business in a country or split itself in two to continue to operate?