4 ms·
He makes the issue more complex than necessary for the benefit of his employer. There is no reason why private information needs to move across borders without
by forgotAgain 11y ago
He makes the issue more complex than necessary for the benefit of his employer. There is no reason why private information needs to move across borders without the express consent of the individual involved. At that point the individual agrees to be bound by the rules of the country where the data is going or no transaction is done.
Let each country have it's own set of rules and have all countries respect those rules for data located in the hosting country.
The idea that each country must be exactly the same and data is by default available for transmission across borders is only to the benefit of multinational companies.
- richmarr 11y ago> At that point the individual agrees to be bound by the rules of the country where the data is going or no transaction is done What does this look like? Another section in a EULA? A popup/banner thing like for cookies? An extra tickbox on the registration page? To me this feels like moving the problem of choosing sensible data protection juristiction onto the customer, rather than making a sensible choice yourself. Personally I prefer to keep all personal data within the EU and avoid bothering my end users with this stuff, and that rules out any services that aren't available here... reducing choice & competition, which sucks. In that respect I was a fan of the Safe Harbour.
- forgotAgain 11y agoI think you're overestimating the amount of times that data needs to move across borders to complete a transaction. As an example, you're buying an airline ticket to a foreign destination. There is a check box next to the purchase button. The check box says that to complete the transaction you agree that information will be transferred to the destination country.
- richmarr 11y ago> I think you're overestimating the amount of times that data needs to move across borders to complete a transaction. The word need in this context is an oversimplification. For example, if I want to build an app where data doesn't leave the UK I have very little choice in providers, so have to compromise other things, like convenience, cost, security, etc. If I accept that data will move across some borders (and the EU is really really really valuable in this regard) then I can locate the data in eu-west-1 in Dublin and many more options open up. That said... if I want to use any SaaS services that don't offer an EU hosting option then I still can't unless I want to accept much more variation in data protection law. That rules out plenty of analytics packages, centralised logging services, PaaS providers, etc. Every compromise choice subtracts value and reduces competitiveness, which affects the end-user. Do we need to move data across borders? No. Does it make sense to? Yes, frequently.
- forgotAgain 11y agoFor purposes of this discussion I would say the EU is one entity. If all citizens of the EU are sharing the same rights and those rights are defined in a single legal framework then I would say (for data privacy anyway) the EU is a single entity without borders. As far as the difference between need and sense I think what you're talking about is actually cost. If citizens want data privacy there will be a cost. If they think the cost is too high then they will decide that it doesn't make sense. They should have the opportunity to decide.
- richmarr 11y ago> They should have the opportunity to decide. "Opportunity to decide" implies that end users are prepared and waiting to make that decision, which I'd suggest is broadly untrue. When you say "have the opportunity to decide"... I hear "be forced to learn about then make a decision on a complicated thing in the middle of a buying decision". EU companies already have to inform users if personal data leaves the EU. Nobody reads it. People don't read T&Cs. You could force companies to summarise their privacy/data policies during the buying decision, but you'd have to compress so much you'd mislead as much as inform. Besides, I think if people cared enough about this stuff then P3P would still be a thing. The ones that DO care enough can read the privacy policy that already explains it.
- forgotAgain 11y agoAs I said before: There is a check box next to the purchase button. The check box says that to complete the transaction you agree that information will be transferred to the destination country. Not all that hard or complicated.
- richmarr 11y ago> Not all that hard or complicated. A checkbox isn't complicated in itself, but there are a few things about it that are complicated. (1) All the thinking the customer needs to do once they see the checkbox in order to understand exactly what information is shared with which legal entities in which territories. A checkbox that says "personal data shared with companies in the US" that might mean recording your email address with a centralised logging system in a comparatively secure datacentre... or it might mean sharing your photo, location data & bank balance with a mob front. If you don't include that detail you're not giving the customer a basis to make a sound decision... but if you do communicate it you're dumping a ton of cognitive load onto them while they're trying to transact, and hence shitting on your own conversion rate. (2) All the thinking in the creation & maintenance of that checkbox... involving web ops, legal, product management, most likely marketing & biz dev too as they're also likely candidates for using personal data in SaaS tools. Then add in work done by regulators & auditors to verify that the checkbox is actually represented truthfully... because I don't see how a sane P/L owner would agree to reduce their conversion rate voluntarily with no promise of a boost to LTV or CAC (3) Change management, when you have a database full of people who've consented to their data being stored in Ireland and your marketing team is screaming to use some shit-hot new CRM from Israel or wherever and you need to get in touch with every single one before being able to use it. In reality you'd just have to be allowed to just make 'reasonable effort' to contact them, which in reality would just be an email or a letter notifying them of intent... but still, rather than just being allowed to run your IT you now have to inform your customers how you're running your IT and expect them all to understand, risking misunderstandings and reduced LTV. Don't misunderstand, I like privacy, I'm a fan of Snowden, I want customers to own their own data. I just don't buy this checkbox idea.
- aidenn0 11y agoIn many jurisdictions, some rights cannot be legally signed away. Often the requirements on a non-negotiated contract are even higher. Lastly the US government is currently trying to coerce Microsoft into revealing data stored overseas, so even storing data in the country of origin may be insufficient protection.
- forgotAgain 11y agoI'm not saying that no changes are needed. What I am saying is that the proposals put forth by Smith are more complex than necessary and that the purpose of the added complexity is to benefit his employer and not individuals. In many jurisdictions, some rights cannot be legally signed away In those jurisdictions there would have to be changes to allow individuals to provide permission to move their information across borders. Lastly the US government is currently trying to coerce Microsoft into revealing data stored overseas, so even storing data in the country of origin may be insufficient protection. Which is why I said "Let each country have it's own set of rules and have all countries respect those rules for data located in the hosting country."
- vidarh 11y ago> At that point the individual agrees to be bound by the rules of the country where the data is going or no transaction is done. I'm not sure there's any opening in EU law for the individual signing away their rights like that.
- jfoutz 11y agoDoes routing work like that? I mean once data is stable on a machine, it won't move, but getting that data there, man that seems hard. I mean, copying a file between 2 London datacenters might go through New York, if conditions are right. I always thought moving between two machines to the fastest route, not the shortest route. I guess you could set up some fancy geolocation rules to ensure IPs of a certain range are only routable to other specific IPs. Still, there's no guarantee about the physical location of a given address.
- forgotAgain 11y agoYou make a good point. Changes to routing tables would be an added costs.
- comex 11y agoIt is to the benefit of anyone running an interactive website that wants to accept visitors from outside the hosting country. Multinationals, which have a physical presence in many countries that could handle local hosting if necessary, and the legal resources to work through the privacy laws of N different countries, are in many ways the least affected.