7 ms·
I am curious what about Mailchimp make them illegal to use ? On the face of it they seem to have support for the required stuff: https://mailchimp.com/gdpr/ ht
by hrktb 5y ago
I am curious what about Mailchimp make them illegal to use ?
On the face of it they seem to have support for the required stuff:
https://mailchimp.com/gdpr/ https://mailchimp.com/gdpr/
- hyperman1 5y agoI was also curious, so I found this: https://edpb.europa.eu/news/national-news/2021/bavarian-dpa-baylda-calls-german-company-cease-use-mailchimp-tool_en https://edpb.europa.eu/news/national-news/2021/bavarian-dpa-... The core: ... transfers of personal data to the U.S.- were not lawful. So the problem is that an US company cannot be GDPR compliant, because that conflicts with US law. Which sucks for mailchimp but makes sense.
- deleted 5y ago[deleted]
- kjakm 5y agoA US company can be compliant. They just have to host EU user data in the EU.
- hrktb 5y agoJudging from this > Mailchimp may in principle be subject to data access by US intelligence services on the basis of the US legal provision FISA702 (50 U.S.C. § 1881) It might not be just a matter of where the data is stored, but also who can get access to it. From my reading, any US based conpany would be affected. This feels like a super huge impact that would have made more waves, but the ruling also seems recent. And perhaps there will be more twists and turns yet ?
- majewsky 5y agoThere was a contract between the US and EU that was supposed to address this: https://en.wikipedia.org/wiki/EU%E2%80%93US_Privacy_Shield https://en.wikipedia.org/wiki/EU%E2%80%93US_Privacy_Shield As described in the Wikipedia article, the contract has been thrown out by the European Court of Justice for exactly the reasons stated by the parent comment. > [Standard contractual clauses] do not necessarily protect data in countries where the law is fundamentally incompatible with the Charter of Fundamental Rights of the EU and the GDPR, like the US.
- KingOfCoders 5y agoThey would need to a have an independent legal entity in the EU on top of hosting data in the EU, perhaps only owning shares in that entity. The construct would need to be setup in a way that three letter agencies in the US (and courts) would have no way of forcing the US company to hand over data - not sure this is possible IANAL.
- danShumway 5y agoWait, is that really the standard? Wouldn't that imply that virtually any service doing business with EU customers would need to be either a multinational business or based in the EU? And just buying server hosting in the EU won't actually change that much about data access; if I'm a purely American business and I buy hosting in the EU, I think I'm still subject to US data requests. None of that goes away as far as I know, so I don't see how a hosting restriction would even help unless I literally move my business to the EU. I thought that I understood GDPR at least reasonably well: be specific about what data you collect, don't collect unneeded data, allow deletion of data, and a couple other minor caveats. But if I sell software in multiple countries, and part of my account process is collecting an email address or other PII, is that not GDPR compliant unless I set up offices in the EU? That can't possibly be what the law actually says; nobody except the biggest US companies would be able to do any business online with EU customers if that was the case. What am I missing?
- KingOfCoders 5y agoIt's most specific to the US because of CLOUD ACT and FISA courts. It would be the same for countries that have a similar structure in place. If you're an US company you would at least need to setup a independent EU subsidiary that you do not directly operationally control (perhaps owning shares works).
- danShumway 5y agoSo what are the full implications of that? I hate FISA too, but most non-EU countries have FISA-like structures in place as far as I know. Sublime Text 4 just came out. That's based in Australia, where courts have similar data access, including the ability to require companies to circumvent encryption. Part of the purchasing process requires providing an email and other billing information. Is it legal to sell Sublime Text 4 to a European? If Sublime Text was based in the US, would it be legal to sell it to a European citizen? What you're implying is that the EU can't legally have access to the majority of US-based Internet services, and that just seems so extreme that I feel like I wouldn't be hearing about it on Hackernews if that was the case. But I don't know, I can't really confidently say you're wrong. Maybe it's just been under-covered, or I'm just not paying attention to the right news sources. At the very least, this can't apply to business-necessary information, right? Otherwise, it seems like you're saying that EU data in general can't be legally exported from the EU to most of the world, which seems like it would be a massive problem for the majority of the software industry. There are a lot of software services based in countries with intrusive government data access: Fastmail (Australia), DuckDuckGo (US), Github (US), Itch.io (US). You're claiming EU residents don't legally have access to them? Again, I don't have any basis to argue that you're wrong, it's just... why wouldn't that be covered on basically every single tech blog if that was the case?
- throwaway210222 5y ago> A US company can be compliant. They just have to host EU user data in the EU. Actually since the 2018 Cloud Act, no US company can be ever be GDPR compliant. Here is a possible sequence of events: 1. the US has secret courts (FISA, 1978) 2. and these courts can insist on access to EU hosted data (CLOUD Act, 2018) 3. its illegal for a US corp to indicate whether such access has been demanded 4. so a FALSE 'no' must be the answer to an EU data subject asking about access to his/her data 5. which is a breach of the GDPR. Everyone knows this. They just ignore it. The EU ties itself in knots (Schrems II) trying to justify all of this.
- hrktb 5y agoThank you. This looks like a pretry fresh ruling judging from the date of the article, good to know.
- dvfjsdhgfv 5y ago> So the problem is that an US company cannot be GDPR compliant, because that conflicts with US law. This is completely not true. First, most US companies are GDPR-compliant because they don't gather, store and process personal data of EU citizens. Now, those that do - mainly Internet companies - they need to abide by the terms of the GDPR (or not to serve EU customers, which for some is the easiest way - like New York Daily News). If you decide to store personal data of EU citizens, you need to do it using servers located in the EU, which, depending on the nature of your business, might or might not be easy, but companies had several years to prepare for that. There is no any conflict with US law anywhere. Personally I was in a similar position and instead of choosing Mailchimp I choose Mailerlite, which is Europe-based and, being less popular than Mailchimp, (much) less expensive for the customers I have (with mailing lists in the range of 5k-50k contacts). It has its quirks but it works and I have no much reasons to complain.
- KingOfCoders 5y agoA US company can decalare themselves whatever they want, that doesn't make it legal in the EU. They don't get in trouble for saying this, EU companies are those that get in trouble when they believe the link you have provided.