4 ms·
> This consideration is key, even when Akamai servers are hosted in the EU. Is the fix as easy as that Akamai creating a subsidiary in the EU? I am in the EU
by runarb 5y ago
> This consideration is key, even when Akamai servers are hosted in the EU.
Is the fix as easy as that Akamai creating a subsidiary in the EU?
I am in the EU and use AWS a lot, but I am not a customer of Amazon Inc. Instead, it sees this on the bill as who is the seller: "Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, L-1855 Luxembourg".
- fxtentacle 5y agoYes it is. The whole point of that decision is to make sure Akamai cannot says "we're an US entity, so EU privacy laws don't apply to us". That's why they are now forced to create a local subsidy, which will then be forced to follow local laws.
- detaro 5y agoAkamai did not claim "EU privacy laws don't apply to us", and that's really not what the case is about.
- akie 5y agoThe way I read the article, this will only work if the EU entity is legally able to tell the parent US entity to "get lost" in case the US government has decided it wants something from the EU entity. So it needs to be truly independent, at least that's the sense I got from the court's decision.
- gls2ro 5y agoIANAL but I dont think a parent company can ask a local branch to not follow local rules. So for example if in EU is forbidden to store information without consent the local branch cannot do that on EU servers.
- luckylion 5y agoI don't know whether they can, but Microsoft tried to work around that by having (one of?) their German Azure DCs be managed bei Deutsche Telekom for exactly that reason: their relationship would be defined by a contract, but Microsoft does not own Telekom and thus can't send them a memo to ignore the contract. I don't know the details, but I'm sure Microsoft considered whether it would be enough to just stick a "Microsoft Deutschland GmbH" label on it.
- Loic 5y agoI am not sure, doing my business taxes in Germany (of course not the same as here), a lot of rules are applied in a way or another depending on the majority stake holder in the company. So, if the subsidiary is fully owned by a US company, this may still not be accepted. This is why at some point (I am not sure if this is still the case), the Azure cloud in Germany was fully owned and operated by Deutsche Telekom. Microsoft was basically providing software, consulting and brand. This way, it was legally not possible for Microsoft to access the data.
- emteycz 5y agoIt must be fully acceptable. There is zero legal distinction between foreign-owned companies and local ones. This is not China. Of course then the infrastructure and control must be fully separated, which might be why MSFT did the deal you're talking about.
- piaste 5y ago> It must be fully acceptable. There is zero legal distinction between foreign-owned companies and local ones. This is not China. Who is the "this" you're referring to? The US has forced this distinction into existence via the CLOUD Act, which applies to US-owned companies operating abroad. The EU ought to deal with this fait accompli, and if that means reducing US companies' ability to operate in the EU as if they were in their home country, so be it. They can complain to their government about it.
- SaltySolomon 5y agoBut there are already many laws in many countries that distinguish. For example airlines where for example to count as a EU Airline more than 50% must be owned by EU citizens.
- detaro 5y agoDepends, can Amazon Inc be ordered by the US government to access data hosted by the subsidiary?
- dsign 5y agoI think this question is moot. If you are a US citizen, the US government has effectively ordered any bank, anywhere in the world, to report the status of your bank account to them. It may just be a matter of time until they find a way to strong-arm EU data protections, if they haven't already.
- floatingatoll 5y agoYes. The subsidiary has no right of refusal encoded into law.
- tzs 5y agoThe following assumes that the subsidiary is incorporated in a jurisdiction other than the US and so is legally an entity of that jurisdiction that happens to be owned by a US company. Was the data put there by Amazon Inc and retrievable by Amazon Inc? If so then yes, Amazon Inc can be ordered by the US government to retrieve it. If not, then the US government would have to ask the subsidiary directly for it or ask whoever is using the subsidiary to hold the data. How whoever they ask responds to that would be determined by the law of wherever the responder is incorporated or located. There's nothing really special about the cloud in these matters. It works similarly with data stored on paper. If I am in the US and store my papers in a box that I send to a storage company in the US to hold for me the US government could (1) subpoena the documents from me, and I'd have to retrieve them from the storage company and give copies to the US government, or (2) get a search warrant to grab the documents themselves from the storage company. If instead I pick a storage company that is incorporated and located in another country that eliminates the search warrant option because US search warrants don't apply in that other country. It doesn't affect the subpoena option because the subpoena is not asking the non-US storage company to do anything. It is just asking a US entity (me) to turn over documents I legally control.
- jefftk 5y ago> Is the fix as easy as that Akamai creating a subsidiary in the EU? The article has "Importantly, the Wiesbaden court appeared to accept that Akamai may have stored Cookiebot data on EU servers, and not in the U.S., which suggests Cookiebot’s agreement is with Akamai’s German affiliate."