24 ms·
Austrian DSB: EU-US Data Transfers to Google Analytics Illegal
- rehamelbasha 5y agoThere are alternatives like snowplow. My former company and current one decided to move out from GA to snowplow as you have much more control on your data and do not so much depend on Google to be gdpr compliant.
- aspenmayer 5y agoFirst time hearing about Snowplow. Seems interesting, and hey, open source doesn’t hurt. Any company that openly suggests alternatives to their products instantly wins respect in my book. Nothing like laying your cards on the table. https://snowplowanalytics.com/blog/2021/01/05/the-top-14-open-source-analytics-tools-in-2021/ https://snowplowanalytics.com/blog/2021/01/05/the-top-14-ope...
- aspenmayer 5y agoThis is due to GDPR. Amazing ruling for privacy for all of EU. Detailed analysis: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2021-0.586.257_(D155.027) https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2021-0.58...
- zibzab 5y agoThis is supposed to be a side show for Google, they are not getting paid neither are they using your data behind your back. Now if that was really true, it shouldn't really matter for them to drop this service. Instead, I think we will see them investing millions to overrule this.
- aspenmayer 5y agoTheir lawyers are going to have to earn the wins, as the rulings against them don’t find their IP licensing to Google LLC (Ireland) to be particularly clever or cute. That this makes their tax avoidance strategy super obvious and fruitless in the EU is just the icing on the cake. No point for mama Google to license tech to their foreign subsidiary if they can’t phone home with the results. I’m laughing. They will have to store EU data in Europe, and European authorities will forward relevant data to the relevant US authorities. At least that’s the way the EU courts seem to be leaning. Google will likely appeal and waste everyone’s time, and maybe win. But they will only make calls for antitrust action louder if they were to do so.
- toyg 5y agoWhat? Analytics is not a sideshow, it allows them to have clear and essential first-hand data on the popularity of sites, which is then likely used (with other factors) to drive Adsense auctions - their bread & butter. If it were a free service "for the hell of it", Analytics would have long been discontinued.
- aspenmayer 5y agoBy sideshow, OP was charitably going along with what Google’s EU lawyers would have us believe, not the reality on the ground. Of course it’s necessary for their ad business model as currently implemented. They would have to setup a separate ad auction unit in EU for EU visitors, if the ruling stands. This reminds me of how IBM and Coca-Cola setup “independent” operations in Germany during the WWII embargo to provide products and services to the Nazi regime. Those units were later folded back into their original parent companies after the war, profits and all. That’s where Fanta came from. That’s what Coca-Cola Germany was called. I forget what the IBM one went by.
- 6510 5y agoAdsense in it self is just another analytics tools isn't it?
- toyg 5y agoYes, but Analytics gives them coverage of the nooks and crannies Adsense cannot reach.
- blitzar 5y ago> This is supposed to be a side show for Google, they are not getting paid neither are they using your data behind your back. Sarcasm doesnt translate well in written comments on the internet.
- aspenmayer 5y agoIt was pretty clear that they were incredulous from the context and awareness of Google’s ad business model. Generally, I’d agree, but in this case, it’s pretty obvious.
- ckastner 5y agoMax Schrems is just incredible. Just look at his Wikipedia page [1] and see how many EU-US data transfers he's challenged successfully. [1] https://en.wikipedia.org/wiki/Max_Schrems https://en.wikipedia.org/wiki/Max_Schrems At this point, I wonder why the EU doesn't consult him personally prior to enacting some law. It's not as if they don't consult with others as well.
- deleted 5y ago[deleted]
- Fnoord 5y ago> At this point, I wonder why the EU doesn't consult him personally prior to enacting some law. It's not as if they don't consult with others as well. Because it costs companies a lot of money to merge to EU-only market, while waiting for the wheels of justice to grind buys time (for EU-only market).
- Sporktacular 5y agoThat's right, but the US does this all the time with its military/intelligence networks, China does the same for it's public internet. It's not like their providers are running at a loss, they just need the right incentives.
- cblconfederate 5y agoWhat's the end goal of all this? Information (data) technology has essentially left europe The EU is never held accountable for the laws they make, and i m not aware with them consulting with local entrepreneurs. It seems only lobbyists and politicians have access
- no_time 5y ago>Tech has essentially left europe If your "Tech" can't work without siphoning up and selling people's personal data to the highest bidder, Good.
- phoronixrly 5y agoThe key points in the article for me: > Max Schrems, honorary chair of noyb.eu: "Instead of actually adapting services to be GDPR compliant, US companies have tried to simply add some text to their privacy policies and ignore the Court of Justice. Many EU companies have followed the lead instead of switching to legal options." > In the long run, there seem to be two options: Either the US adapts baseline protections for foreigners to support their tech industry, or US providers will have to host foreign data outside of the United States. > No penalty (yet). The decision is not dealing with a potential penalty, as this is seen as a "public" enforcement procedure, where the complainant is not heard. There is no information if a penalty was issued or if the DSB is planning to also issue a penalty. We need more trials related to GDPR breaches. While having the legislation is a huge achievement, it needs to be backed with enforcement. If there is no enforcement, a third long-term solution arises -- just ignoring the law until you manage to get the necessary amendments to it in order to keep operating as before without fear of penalty.
- jokoon 5y agoI'm really curious what would happen if those companies followed the law. My bet is that they would entirely stop doing business in the EU, because I'm suspecting that data collection is the cornerstone of google/facebook/etc's business model. They cannot properly advertise if they don't collect data. To me it's a bit similar to what happened with China. China doesn't want the US to get data on chinese people, but their solution was to just block those companies. The EU uses courts to protect itself, but I guess the result would be a bit similar.
- ReleaseCandidat 5y agoNo, they'll just host their data in europe
- aspenmayer 5y agoI think that’s all that the court is asking them to do, for the last 1.5 years or so.
- timgl 5y agoRelevant thread on open source alternatives to Google Analytics from earlier today: https://news.ycombinator.com/item?id=29888599 https://news.ycombinator.com/item?id=29888599
- cblconfederate 5y agoposthog seems to be hosted in Digitalocean - an american company plausible.io is hosted on AWS - an american company snowplowanalytics.com seems to be hosted in digitalocean as well as I understand they are equally illegal now. [Self-hosting and maintaining is not an option for the vast majority of mom-and-pop shops]
- markosaric 5y agoAll site data plausible.io stores on behalf of the customers is hosted in Germany on servers owned by Hetzner, a European-owned company. Previously it was hosted by Digital Ocean in Germany but the move to Hetzner was made last year. For our self-hosted version, you can install it with any cloud provider and in any country you wish. Even in the USA.
- volderette 5y agoPosthog as well as Snowplow are open source solutions that can be self hosted. Snowplow is always hosted in your cloud infrastructure even if you use their managed service.
- pimterry 5y agoFathom's EU docs (https://usefathom.com/features/eu-isolation https://usefathom.com/features/eu-isolation) seem to suggest that EU-hosted but US-owned cloud infrastructure isn't sufficient either though - you're exposing any data stored/transferred through there to access by the US government. That means Posthog self-hosted on an AWS server in Frankfurt wouldn't avoid this issue. What're the best options for non-US owned cloud providers? AFAICT Canada or many other countries with privacy laws would be fine, it's really the US specifically that's problematic.
- tjansen 5y agoThat stuff scares me. More than US government surveillance could ever scare me. The most likely outcome is that smaller companies just don't do business in the EU. At least before they are large enough to deal with GDPR. I am located in Germany, but if I would start a SAAS site today, I wouldn't try to sell to the EU. Just isn't worth the trouble. Over time, many people in the EU will start using VPNs to get access to the latest web sites without GDPR restrictions. Even today I have to use a VPN to access some websites (mostly news sites), but I suspect it will be much worse if noyb succeeds.
- cblconfederate 5y ago> but if I would start a SAAS site today, I wouldn't try to sell to the EU. You 'd still be liable for GDPR by non-europeans since you are located in germany It's like the EU is pushing entrepreneurs to emigrate.
- JanSt 5y agoWhat should really scare you is the vast amount of privacy violations, data collection and tracking that is happening around the web. Imagine someone following you everywhere in the real world, even getting into your apartment and noting down everything you do. If following the basic principles laid out in GDPR is too much of a hassle for you, you should probably not be in business anyway. It's not rocket science.
- cblconfederate 5y agoThe solution is to make a worldwide framework where people OWN their data. That's not what GDPR does, it in fact prevents people from selling their data at will. (People's privacy is protected by constitutions. That is orthogonal to the ability of people to choose how to use their data)
- M2Ys4U 5y agoSo only the rich should have their human right to privacy protected?
- 5y ago
- usr1106 5y agoThe deeper background is of course Google's business model of data and privacy prostitution: Users give their private life to Google and they get web search, email, and videos back. In a more reasonable world users would pay money for the services they want to use. Of course it needs to be noted that most users don't even understand that they are selling themselves. And of the few who do most still think it's better than paying money. This ruling, should Google comply in the end, will not change anything. Google will store the data in the EU and that's it. I don't think they share user data with the advertiser when they show an ad. So they could still show ads of US companies. And that's a niche business only anyway because when Europeans do business with Amazon, Disney, and the like they deal with the respective European subsidiaries already.
- moonchrome 5y ago>In a more reasonable world users would pay money for the services they want to use. >Of course it needs to be noted that most users don't even understand that they are selling themselves. And of the few who do most still think it's better than paying money. This is such pretentious snobbery. In a world where you have to pay for search engine I am still dirt poor working some shit entry-level job/doing manual labor because when I was a kid I couldn't even afford interned and had to hitch off a neighbour, having free access to Google, tons of free learning material, messaging boards, etc. is what got me out of that situation. I pay to avoid advertisement, but that's a luxury I can afford now days, and I have almost no concerns about privacy - I don't care at all that Google knows my interests, browsing history, purchase history, etc. The concerns about data collection I see are mostly blown way out of proportion and most people rightfully don't care TBH.
- simion314 5y ago>I don't care at all that Google knows my interests, browsing history, I also don't care that Google,NSA, KGB, CIA, ChIna knows my browsing history or what files I have on my PC but I care if this groups know everyone browsing history because they can affect me indirectly by blackmailing, manipulating key individuals or entire populations with targeted ads or propaganda. Is the same with fake news like "WiFi is illegal in Japan because causes cancer" , this fake shit won't affect me directly but affects people in my family so it affect me indirectly and I have to reduce the damage done.
- pieter_mj 5y agoGreat victory. I bet firebase crashlytics is illegal as well in EU. The reason I uninstalled the hacker news app 'Materialistic' is because it regularly crashed and was probably unvoluntarily siphoning off pii data through the crashlytics module.
- minkiu 5y agoYou can give Glider a go https://f-droid.org/en/packages/nl.viter.glider/ https://f-droid.org/en/packages/nl.viter.glider/
- YetAnotherNick 5y agoI really don't understand why countries are so persistent about storing data in their country. It's not like the enforcers could walk into the datacenter and plug in the usb drive and get the data. And it's even hard to see what all constitutes user data. Does logging constitute user data. Does that mean that to get logs for the error the developer need to travel to every country and remember the log messages in his head. And companies could easily copy their data in a click if they need to. A much saner approach should be limiting what the company is allowed to do with the data.
- deleted 5y ago[deleted]
- phaer 5y ago> It's not like the enforcers could walk into the datacenter and plug in the usb drive and get the data. They can ask and/or force a given company to hand data to them in many cases in most jurisdictions. > Does logging constitute user data. Logging of user-data? yes > A much saner approach should be limiting what the company is allowed to do with the data. GDPR does also regulate what a company is allowed to do with data. The thing is: whether the GDPR applies and is enforceable depends on where that data is stored.
- blitzar 5y ago> A much saner approach should be limiting what the company is allowed to do with the data. Perhaps we should have some sort of GENERAL rules or legislation specifically for DATA to define what companies, based in or with customers in a region, can and can't do for the PROTECTION of the data and end users, so the companies can stay compliant with this REGULATION.
- aspenmayer 5y agoWe could call it GDPR for short.
- zauguin 5y agoThe companies are already restricted in what they are allowed to do with the data, but allowing to transfer it without restrictions would allow this to be easily circumvented by just moving the data to a location where data protection can't/wouldn't be enforced. Therefore the EU rules are not at all persistent about storing data only in the EU, it's explicitly allowed to store data in other countries as long as the data is still protected there. This decision is a great example of this: The decision isn't made because it's not allowed to export data at all, instead it explicitly references US law which forces the affected companies to violate the data protection guarantees provided by the GDPR.
- ur-whale 5y agoThe EU regulating itself out from the market. Not for the first time, mind you.
- pacija 5y agoRegulating oneself out from the market where main merchandize is people's private data sounds like reasonable thing to do.
- boshomi 5y ago»Max Schrems: "In the long run we either need proper protections in the US, or we will end up with separate products for the US and the EU. I would personally prefer better protections in the US, but this is up to the US legislator - not to anyone in Europe."« That's the point: we need real data protection in US law for non-US citizens as well. Currently, US lawmakers treat EU citizens' data as US state property. Obviously, that's unfair.
- tut-urut-utut 5y ago> I would personally prefer better protections in the US, but this is up to the US legislator - not to anyone in Europe. I don't agree that Europe can't change anything in that regard. Deeming US-based services illegal and banning US-based companies doing business in Europe because of the way EU-customer data is treated in the US would speed up better regulations in the US tremendously. It's a fact that big corporations are ready to bend over backwards to the foreign governments, even when they require "immoral" [1] things, so they would have no problem complying with actual sensible requests [2] if they are forced to do it. [1] Chinese censorship rules, ... [2] Data protection, ...
- kilburn 5y ago> banning US-based companies doing business in Europe because of the way EU-customer data is treated in the US would speed up better regulations in the US tremendously Maybe it would, or maybe it would spur a tariff-war between the EU and US and a great deal of resentment between traditional allies. > they would have no problem complying with actual sensible requests Morality and sensibility don't play a role in modern big corps. The real question is: do these requirements impact their bottom line? Chinese censorship rules don't, but EU's data protection rules clearly do. Hence, their willingness to comply will adjust accordingly (i.e.: US corps will fight tooth and nail to prevent that from happening).
- thinkindie 5y ago> I don't agree that Europe can't change anything in that regard. Deeming US-based services illegal and banning US-based companies doing business in Europe because of the way EU-customer data is treated in the US would speed up better regulations in the US tremendously. I think it would do way more damage on the EU side than anything. Imagine having to migrate applications overnight because hosting with AWS has been outlawed, even with all the protections in place (e.g. location in EU, encryption etc etc).
- davidgerard 5y agoNothing about GDPR is hard ... unless your business model is to abuse your customers' personal data. Then it might be hard. I routinely see the loudest complainers about the onerous nature of GDPR compliance suddenly get vague or stop posting when you ask for details of precisely what bit is so hard for them in particular. Note lack of those details in this present discussion, for example. So far, it seems a safe assumption that the excuse makers are abusing personal data, and they know they're abusing personal data. Perhaps one day a clear exception will show up. I wrote up a thing here a few years ago with my actual on the ground experience of getting us compliant: https://reddragdiva.dreamwidth.org/606812.html https://reddragdiva.dreamwidth.org/606812.html tl;dr anything that might vaguely constitute personal data, down to Apache logs, must either be in a writable database for redactability, or deleted. Since then, our legal team - who are not your legal team! - has advised: * 30 days for operational purposes is fine actually. * Go feral on anything over 30 days. You need a named person responsible for GDPR redactions. * If you want to do analytics on those Apache logs, do them quickly and into a form that doesn't contain personal data. I'm in the UK, which is no longer in the EU, but the GDPR laws still hold here.
- TheGigaChad 5y ago
- tjansen 5y ago> unless your business model is to abuse your customers' personal data. Then it might be hard. It's not only your business model, but also the business model of all third-party services you are using on your site. Also, part of the reason why it's not that hard is that the GDPR is pretty much one of a kind. Imagine the US and maybe some countries in Asia having similar but different implementations of privacy laws, and you having to work with them simultaneously. Or even different laws in each US state (CCPA?). Imagine every country requiring you to store user data only the user's country of origin, thus managing a separate database for each country.
- M2Ys4U 5y ago>Also, part of the reason why it's not that hard is that the GDPR is pretty much one of a kind. Imagine the US and maybe some countries in Asia having similar but different implementations of privacy laws, and you having to work with them simultaneously. That's why treaties like Convention 108+[0] exist, to provide a common framework for implementing data protection laws. [0] https://search.coe.int/cm/Pages/result_details.aspx?ObjectId=09000016807c65bf https://search.coe.int/cm/Pages/result_details.aspx?ObjectId...
- etothepii 5y agoIn other news, king orders tide out.
- fideloper 5y agoTo my knowledge, Fathom Analytics is the only analytics app that has bothered to hire actual lawyers and navigate EU isolation. They wrote about it here: https://usefathom.com/features/eu-isolation https://usefathom.com/features/eu-isolation
- jbrooksuk 5y agoAnd that's why, as a responsible developer, I exclusively use Fathom for my own projects. As far as I know, they are the only analytics company who are correctly following the law here AND they always try to do more. They completely isolate EU analytics from their US databases, which you can read more about at https://usefathom.com/features/eu-isolation https://usefathom.com/features/eu-isolation Aside from this, unlike other startup analytic solutions, they've actually spoken to lawyers to read through the fine lines of the law and ensure their solution is legal. Go get it!
- eisa01 5y agoLooks interesting, but for hobby websites with low traffic the pricing is slightly steep at $14/month - I pay $5/month for the hosting (: Any alternatives?
- ben_w 5y agoWhy bother with analytics for a hobby website?
- iamacyborg 5y agoThis is the correct answer. There's precily nothing to gain from looking at the data from a small website.
- cblconfederate 5y agoanalytics is important to grow an audience. A big website doesn't need to care about SEO or analytics or anything really. Metcalfe's law
- jbrooksuk 5y agoIf you don't want to pay it, then you probably don't need it. I don't have experience with alternatives though - they just don't do as good of a job as Fathom does.
- mafuy 5y agoYou can still self-host a FOSS law compliant analytics suite. It will suffice for small websites.
- sebsebsn 5y agoIt looks like this makes Fathom Analytics the only provider for website analytics that you can use if you don't want to maintain a locally hosted version if an open source product – which blows my mind. A small company is the only service that is able to comply with the rules while huge ones simply fail. I assume that this regulation is also coming to other services soon and analytics isn't the only service that needs to be replaced when a business is in the EU and can't ignore these rules without risking fines. The team at Fathom wrote about alternatives for lots of services here: https://usefathom.com/blog/degoogle https://usefathom.com/blog/degoogle
- daenney 5y ago> A small company is the only service that is able to comply with the rules while huge ones simply fail. I think all the big ones can comply, but gambled they would be able to come up with creative constructs to get around the requirements. Wrong play it would seem. Fathom did the right thing, isolate by region. Which is handy for a lot more than complying with the GDPR.
- donohoe 5y agoNot the only provider, worth looking at Plausible. https://plausible.io/ https://plausible.io/
- sebsebsn 5y agoNope, they use US providers. The servers are in the EU but the providers are US companies and that means that they aren’t GDPR compliant at all. This is exactly what Schrems II targets.
- markosaric 5y agoAll site data plausible.io stores on behalf of the customers is hosted in Germany on servers owned by Hetzner, a European-owned company. Previously it was hosted by Digital Ocean in Germany but the move to Hetzner was made last year. For our self-hosted version, you can install it with any cloud provider and in any country you wish. Even in the USA.
- snowwolf 5y agoHas Google Analytics now adopted the latest European Commission approved SCCs (https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en https://ec.europa.eu/info/law/law-topic/data-protection/inte...) and does that mean using GA with those SCC's is now compliant going forwards. Or does this cases verdict that "SCCs and "TOMs" not enough" now mean those EC approved SCCs are now useless?
- tedivm 5y agoThis case is explicitly about US Law and how it contradicts the EU law. According to this case, as long as US law allows the US government to force US companies to share data with the US Government then you can't share data with those US companies. To quote directly- > SCCs and "TOMs" not enough. While Google has made submissions claiming that has implemented "Technical and Organizational Measures" ("TOMs"), which included ideas like having fences around data centers, reviewing requests or having baseline encryption, the DSB has rejected these measures as absolutely useless when it comes to US surveillance (page 38 and 39 of the decision): > "With regard to the contractual and organizational measures outlined, it is not apparent, to what extent [the measure] are effective in the sense of the above considerations." > "Insofar as the technical measures are concerned, it is also not recognizable (...) to what extent [the measure] would actually prevent or limit access by U.S. intelligence agencies considering U.S. law."
- snowwolf 5y agoExactly my point. However the European Commission has released "Approved" SCC's in June 2021. Does this case now invalidate those because "the DSB has rejected these measures as absolutely useless when it comes to US surveillance" in which case it is in conflict with the European Commissions guidance.
- deleted 5y ago[deleted]