7 ms·
I would go quite a step further than that. If this was not an unfortunate incident/mistake, then GitHub/Microsoft has become quite the active enforcer of US (le
by elmo2you 6y ago
I would go quite a step further than that. If this was not an unfortunate incident/mistake, then GitHub/Microsoft has become quite the active enforcer of US (legal) foreign policy.
If they do that within the US market, that might be justifiable. But in this particular case, GitHub appears to enforce US foreign policy on what appears to be a company on the EU market. Also in what to me appears to be a rather ruthless, totalitarian, maybe even draconian way.
I'm pretty certain that absent this US law within the EU market, this action is arbitrarily discriminatory, and very likely constitutes inflicting serious damage on another company without a legal basis (within the US, yes .. outside the US, no).
GitHub may find itself stuck, between adhering to US laws and laws elsewhere (in this case EU, but China is probably a good example too). Still, is ultimately is a choice for GitHub to offer their products on multiple markets. If they have issues with that, they are free to exit a particular market. It certainly is never a valid excuse to start violating law in any market outside whatever country your headquarter might be located.
Tangentially, this rather typical popular belief that US companies can simply absolve themselves from legal liability, just by crafting clever TOS/EULA that supposedly does just that, has always confused to me. It was always my understanding that you can not create contracts that violate laws. In most countries with a somewhat sane state of law, governments really do not like or tolerate when companies start essentially making their own law in parallel. But apparently you can rewrite (even basic) law in the USA, as long as you can somehow get both parties to agree on it. Be that by free will or coercion.
Maybe it's time, for other parts of the world to no longer put up with this kind of bullshit, and demand that US companies actually adhere to the laws (and legal protections) that exist within their markets, or be free to buzz off and only operate on the US market alone.
With US foreign policy becoming increasingly self-serving, legally dubious, and in some case downright insane, having internationally operating companies enforcing those policies is becoming a seriously risky proposition for anyone outside the USA.
- mc32 6y ago...” , this action is arbitrarily discriminatory, and very likely constitutes inflicting serious damage on another company without a legal basis...” Isn’t that what YouTube and FaceBook do day in day out when their influencers run afoul of policy?
- vezycash 6y agoAdd other Apple and Blizzard to the list.
- elmo2you 6y agoThose other companies certainly do too, yes. Or at least that is what I am convinced of. I would say that what I wrote about GitHub should equally apply to these companies too, or any company for that matter. Not just US companies, but any company that operates internationally.
- gnopgnip 6y agoIf a user runs afoul of policy, the action was not arbitrarily discriminatory.
- elmo2you 6y agoPolicy set by whom? That of a commercial company, which does not have a legal mandate (at least not in the EU) to make make rules that violate EU law (including legal protections), or the US government, which does not have legal jurisdiction over the EU market? Pick your poison
- mc32 6y agoWhat? Your position is that if it’s policy and you enforce policy then it’s not discriminatory? So if a policy or a law says X is disallowed or is unlawful, ipso facto, X can only run afoul of those bodies of governance and can’t be discriminatory? That’s interesting!
- epc 6y agoGiven the pressure by the EU and China on US companies to enforce local laws globally (GDPR, RTBF, Taiwan), I don't see how Github, operating in the US, as a US company, has any chance absolving itself of enforcing US laws and regulations (though in this specific case they appear to have overreacted, likely due to regulatory enforcement via algorithm and not common sense). If you expect US companies to respect GDPR and cookie banners and the right to be forgotten, globally; you cannot be surprised that they will respect and enforce US law globally as well.
- watwut 6y agoEU is not forcing American companies to enforce their laws for third party companies operating on non-EU market. Also, American company does not have to follow GDPR for Iranian customers. EU wants American companies to follow GDPR when acting in EU market.
- JamesBarney 6y agoI'm in the U.S. and I still have to click all those super annoying "Accept using a cookie" popups everywhere. So that EU law certainly does affect me a U.S. citizen interacting with U.S. companies.
- watwut 6y agoThat is because it is cheaper to show it to everybody. Not because EU would demand it to be shown for Americans. Also, law do not require it to be shown for all cookies. Only for tracking ones.
- PeterisP 6y agoTo nitpick, while for non-EU companies GDPR applies to individuals in EU (and their data) as per GDPR article 3.2, any EU companies have to apply this for all personal data as per GDPR article 3.1. So while foreign companies can decide whether they want to apply their GDPR policies (which generally should not require "cookie banners", though it is a popular choice) only to people in EU or all their users, an EU company does not have a choice, they have the obligation to treat personal data of Americans and Iranians and everyone else in a GDPR-appropriate manner.
- michaelt 6y ago> But in this particular case, GitHub appears to enforce US foreign policy on what appears to be a company on the EU market. Surely enforcing your politics outside of your jurisdiction is the whole point of an embargo?
- elmo2you 6y agoAs a government, yes. As a commercial company, operating on a market outside of US jurisdiction, please explain me the legal basis for that (if you can).
- JamesBarney 6y agoThe legal basis is they are using a U.S. company (GitHub) that has to has to follow U.S. laws. And that makes certain things inconvenient for them.
- scott_s 6y agoThe government where the commercial company is based expects the company to do so, and will hold that company accountable if they do not. You may not agree with this situation, but it is how it works. The US government will investigate and penalize companies that violate US sanctions, even if the parts of those companies involved did so entirely outside of the US.
- delfinom 6y agoYep, the current US administration is somewhat to blame on the shift. It has always been a requirement, it's just that the government up until this admin mostly didn't care to enforce it. It's pretty obvious a number of companies got threatening letters to comply or face jail time.
- scott_s 6y agoWhen I did some googling, I found an article from 2012 about sanctions enforcement (https://www.itproportal.com/2012/10/26/ibm-questioned-over-alleged-dealings-iran/ https://www.itproportal.com/2012/10/26/ibm-questioned-over-a...). I am unaware of new behavior regarding sanctions enforcement, although I know that the current administration imposed additional sanctions. But my understanding is that with existing sanctions, this is what the US government has always done.
- A4ET8a8uTh0 6y ago"I would go quite a step further than that. If this was not an unfortunate incident/mistake, then GitHub/Microsoft has become quite the active enforcer of US (legal) foreign policy." I am not sure if most people realize this, but OFAC compliance is rather rigid with no room for error ('strict liability'). And US treasury enforces it hard. Recently, Amazon got caught in its cross-hairs ( though it managed to get away with a low fine relative to its size ). I guess what I am saying, according to OFAC, everyone is responsible for enforcing US foreign policy. edit: Everyone as in US person, person on US soil or someone using US dollar. I really should avoid exaggeration.
- elmo2you 6y agoThere is no doubt about US companies having to follow US law. But this is an internationally operating company, which means it has to also follow whatever law might apply to whatever market they operate on. GitHub, as any other US company, has a choice/freedom to stop offering services to customers outside the US market, if the particulars of providing those services causes them to violate laws in at least one of the jurisdictions. Of course, US companies should be rightfully pissed, if the US government puts them in a situation where they can not (legally) operate abroad. But that's something they should take up with US lawmakers. At the end of they day, they are still (most likely) operating illegally on a foreign market, even if they are unlikely ever to be substantially punished for that. The thing is, the US has a rather questionable track record of coming to the rescue, whenever a US companies get into trouble for (illegally) doing business abroad. Ironically, whenever another country does that (e.g. China) the US immediately have a long list of choice words an allegations at the ready. Long story short: pure hypocrisy.
- deleted 6y ago[deleted]
- PeterisP 6y ago"this action is arbitrarily discriminatory" - if so, this action is permitted. While there often are restrictions on specific, enumerated types of discrimination (e.g. religion, ethnicity, gender, etc - though almost universally they apply to discrimination of people, not companies), those are exceptions to the general principle of "freedom of association" where people and companies are free to arbitrarily decide with whom they want to do business and whom they want to exclude - as far as they don't violate some of the specific restrictions listed in law. If a supplier does not want to sell to your company for an arbitrary reason, it's their right to do so. "constitutes inflicting serious damage on another company without a legal basis" - again, that does not indicate any wrongdoing. Inflicting serious damage on another company is, by default, permitted (matching the core principle of "everything which is not forbidden is allowed") and is regularly done in the course of normal competition, winning over some other company in bids, recruiting key employees by offering them lots of money, targeting their customers with specific discounts, etc, etc. If you're inflicting serious damage on another company, then both the intent and result is by itself legal, the only question is about the means. If you're inflicting serious damage on another company by legally prohibited means (e.g. theft or arson or illegal access to computer systems) or violating some established legal duty (e.g. "duty of care" as required by law in various service relationships), then the other company would be entitled compensation. But in the absence of that, if there's no specific legal prohibition to your action (for example, laws on anti-competitive actions tend to impose various restrictions), if your action is legally permitted, then if some company suffers because of that, it's not your problem. There are restrictions on what actions are legally permitted (law on tortious interference might apply here, and if there's some fraud, injurious falsehood etc then it matters) but if they do have the right to arbitrarily end the contract, then that's it, they are not responsible for the damages.