8 ms·
European citizen here, and as much as i welcome a step like this, it's also pretty interesting to see, what this means for smaller (online) businesses outside o
by axx 11y ago
European citizen here, and as much as i welcome a step like this, it's also pretty interesting to see, what this means for smaller (online) businesses outside of europe.
Sure, you want to host customer data from europe in europe (latency-wise) anyways, but now that this will be more or less required it will be interesting to see how people will solve this. The good thing is, with "the cloud" you have a lot of option (locations) to choose from.
- pjmlp 11y agoAlso European citzen here, I also appreciate the ruling. It is already an interesting experience trying to explain to off-shore companies that they cannot just take our data like that. Well they can in practice, but then better prepare some good explanations in case the company gets a security audit from the local government.
- Niten 11y agoIt's interesting to see the regional differences in this discussion, because that attitude is pretty foreign to the way I think about the Internet. I know that if I use Yandex, at least some of my data is going to reside in Russia. If Dailymotion, France. I consider it up to me as a consumer to decide whether that's what I really want. I don't consider it my local government's job to force those companies to change their business models.
- copsarebastards 11y ago> I know that if I use Yandex, at least some of my data is going to reside in Russia. If Dailymotion, France. I consider it up to me as a consumer to decide whether that's what I really want. I don't consider it my local government's job to force those companies to change their business models. This is a ridiculous position to take, because it requires a humanly impossible amount of research to know whether the privacy of your data is protected. And that's when the information is even available. Privacy is a basic human right. When corporations collect your data it becomes the responsibility of those corporations to protect your privacy. Individuals simply do not have the resources to enforce this, which is why we elect people to enforce this. This isn't some crazy responsibility for governments: this is the fundamental reason why governments exists: to protect the interests of their citizens collectively when it's infeasible to protect those interests individually.
- onnoonno 11y ago> This is a ridiculous position to take, because it requires a humanly impossible amount of research to know whether the privacy of your data is protected. And that's when the information is even available. How about looking at this from another angle? Why the heck should your browser and Internet connection leak anything that allows to single you out as an individual to any corporation or individual in the world? The focus should IMO be on providing secure tools to end users for browsing the web.
- copsarebastards 11y agoI come across this response quite frequently and I remain mystified why anyone would think that it's important or even a good idea for the millions of people interested in privacy to try to solve privacy issues from the same angle. Skillsets don't even fit for this: as a developer I am well-suited for working on network technologies that don't leak information about their users, but a lawyer for example is much better suited at changing legislation so corporations are responsible for protecting privacy. We don't need a "focus", we need everyone to use their skills to protect our right to privacy.
- onnoonno 11y agoCall me cynical, but I see the usual business of lawyers creating/making-up jobs for themselves here, nothing else. Just look at the idiotic E.U. cookie rule.
- RaleyField 11y agoI'm from EU and I don't like it. EU should offer standards of data protection that foreign companies could choose to adhere to, then those companies could advertise to EU citizens that they comply with said EU standards. Same penalties that exist or are proposed now could exist under that model. Maybe even incentivize adoption with modest taxes if you feel really statist. Then EU citizens can choose whether they value these protections or not. Personally, I don't care what Facebook does with data I provided them with freely, but for online purchases I would strongly favor companies who protected my data.
- estefan 11y agoYeah good luck setting up a startup now. If other countries follow Russia's suit, we'll soon end up having to somehow determine where a user is from (what if they're roaming, etc.?) so we can shard the datastore across multiple geographic locations. So obviously this = increased costs & complexity which will slow the speed of iteration :-(
- Majestic121 11y agoThe easiness of setting up a startup should not be held in higher regard than people's right to privacy.
- axx 11y agoWhile this is true, it's interesting to see what kind of effect this will have on the market. I also didn't talk about startups, i mean small business in general. This could be a reason not to launch your business in europe, if the cost of "deployment" is to high. Sure, someone else will fill that hole for you, but that's less money in your bank account. :)
- estefan 11y agoExactly. There's a bit of "pulling up the ladder" here. The guys who got in when the Internet was still the wild west got established without all this overhead. There will be an enormous burden on new businesses satisfying these laws - previously we've got away with privacy policies but could still code the same. If we need to maintain N servers for N countries customers could be from, that's a massive operational overhead that is bound to do nothing other than stifle innovation. Now, I'm all for privacy, but if each country starts fragmenting the internet on country boundaries - to the level of physical servers and data storage locations, bringing a new idea to market is going to much much harder. This is different to, e.g. different tax regulations, etc, because you can still benefit from centralised computation while processing orders for different localities. And while today this might be just about Europe, it sets a trend. Before it was just Russia and China. How long before all countries want to see the code a la the Chinese? So the NSA has screwed things up for all of us now who are trying to start businesses. If my costs go from: developer -> developer + global devops team + legal, etc., that's a massive burden that will affect the "bedroom/garage" startups.
- k__ 11y agoAs a European citizen, I appreciate the ruling, too. It's sad to see how the judges of the courts are more on the side of the people than the politicians they elected...
- deleted 11y ago[deleted]
- jpgvm 11y agoThis is actually very common. Politicians have to care about getting re-elected, and that often means chasing after campaign contributions more so than it does actually being on the side of the people. Judges usually have tenure, this makes a huge difference to someones impartiality.
- cLeEOGPw 11y agoWhat I see here is just a simple data center service which offers to store company data and ensures in complies with EU requirements for these countries. If each country has different laws that require data to store physically in that country's location, then it's just a matter of setting up at least one such data center in each country and provide storage for any company willing to do business. Then you can make service order in bundles with multiple countries and that's it.
- lagadu 11y agoPretty similar to what the big IaaS and PaaS like MS and Amazon already do with their regions.
- weddpros 11y ago_with "the cloud" you have a lot of option (locations) to choose from_ Without replication between locations, you're stuck: replication IS data transfer. With such a ruling, you can't implement an intercontinental social network anymore.
- madez 11y agoYou can replicate within groups of datacenters which fall under the same privacy rules. Thats more than enough to run a centralized global social network, even though I'd love it for making it impossible.
- weddpros 11y agoI'm not talking about replication for disaster recovery, but replication to avoid intercontinental round trips. If my actual name is stored in Europe, my US friend must request the data from the USA just to show his friends list on an HTLM page... (is that a transfer too? is it forbidden too?)
- rbehrends 11y ago> European citizen here, and as much as i welcome a step like this, it's also pretty interesting to see, what this means for smaller (online) businesses outside of europe. I'm not sure if it means anything for them. If a company does not have a business presence in the EU, it likely isn't subject to EU jurisdiction at all. This case happened because Facebook is a multinational company with a European subsidiary in Ireland and was sued before the Irish courts. Companies that may be affected by this are: * Multinationals that exchange personal data between their US and their EU branches. * Companies in the EU that are in a business relationship with companies in the US and as part of that business relationship send personal data to the US. * Companies in the EU that avail themselves of US data centers and store personal data in those data centers.
- rmc 11y ago> was sued before the Irish courts Actually they were sued before the European courts. Specially the European Court of Justice, which is in Luxembourg. I don't believe there was any case in the Irish courts.
- rbehrends 11y agoThe case was referred to the ECJ by the Irish High Court, which sought a preliminary ruling.
- roel_v 11y agoDid you even just skim the article? Besides, you cannot sue before the ECJ, only appeal to it.
- Vespasian 11y agoThe EU is not a state and therefore typically you cannot directly sue in its courts. In most cases (such as this) a national court refers the case to a european level if european directives and interests are involved. Fun fact: the EU commission/parliament has also not the power to pass any binding laws. They pass directives which are than implemented into national laws by the legislative bodies of it's member states and can also be overthrown by courts of each state individually (e.g. happened in germany with EU data preservation directives)
- hoorayimhelping 11y agoThis seems less about privacy and doing what's right for EU citizens and more about European countries enacting some kind of protection scheme to give American companies a disadvantage when doing business there.
- onnoonno 11y agoIn a more cynical light, maybe build up some 'value' that can then be 'traded' in a US/EU TTIP deal? "Look, the EU is reasonable and wants to get rid of the cookie ruling and the high bar for startups on geographical server requirements - TTIP would allow all this to happen!"