3 ms·
Non-US companies must use a EU-owned servers (not just EU servers controlled by AWS, DigitalOcean) to process EU data subject traffic. If they don't, they're in
by JackWritesCode 5y ago
Non-US companies must use a EU-owned servers (not just EU servers controlled by AWS, DigitalOcean) to process EU data subject traffic. If they don't, they're in violation of Schrems II, which makes them in violation of the GDPR.
- cayleyh 5y agoThis doesn't seem consistent with the general Schrems II ruling (which was specifically about cross-border data transfer previously thought covered via EU-US Privacy Shield), and that AWS has specifically commented on https://aws.amazon.com/blogs/security/customer-update-aws-and-the-eu-us-privacy-shield/ https://aws.amazon.com/blogs/security/customer-update-aws-an... and https://aws.amazon.com/blogs/security/aws-and-eu-data-transfers-strengthened-commitments-to-protect-customer-data/ https://aws.amazon.com/blogs/security/aws-and-eu-data-transf.... Is there a specific ruling or case that says AWS as a provider, regardless of where the actual data processing happens, is prohibited, this out that you can point me to?
- JackWritesCode 5y agoYes, it dropped today: https://noyb.eu/en/austrian-dsb-eu-us-data-transfers-google-analytics-illegal https://noyb.eu/en/austrian-dsb-eu-us-data-transfers-google-... More EU member states will likely follow.
- estaseuropano 5y agoThis summary makes it sound like a protectionist measure but that is not the design. The issue is just the US overreach in that the US expects any company to provide any data it holds, even if that data is stored outside the US, owned by a subsidiary, etc. EU (or Canadian, Russian, Kenyan, ...) data is simply not safe from US security services' reach if it is stored by a company subject to CLOUD. The court decision is only a consequence of this overreach and the EU's sovereign right and attempt to protect its citizens. This is even more relevant as US data protection seems to only apply to US subjects - so an American using an EU service using a US host would be protected by US law (in theory, though likely not in practice), while an EU citizen using the same EU service is not protected by US law.