52 ms·
Use of Google Analytics declared illegal by French data protection authority
- einpoklum 5y agoFinally, a little dent in Google's mass surveillance project. Now if they could only declare GMail to be another kind of a racket we would really get somewhere :-)
- cowl 5y agoNow this is just being negative about nothing. Gmail can not be used without the user knowing like analytics or linking to google fonts can. If you don't want gmail is as simple as not using it. Other sites can not call gmail for you in a hidden way.
- rpadovani 5y agoJust two weeks after Austria, another EU country has deemed current Google Analytics implementation illegal in EU. From the article: > "It's interesting to see that the different European Data Protection Authorities all come to the same conclusion: the use of Google Analytics is illegal. There is a European task force and we assume that this action is coordinated and other authorities will decide similarily." I am really looking forward to seeing how this will play out in the rest of the EU, and which practical consequences it will have. And, as usual, fellow EU citizens, support NOYB work, if you care about data protection: https://noyb.eu/en/support-us https://noyb.eu/en/support-us
- GnarfGnarf 5y agoThe onus is on Google to suspend or anonymize Analytics. Individual Website managers can't be expected to discriminate based on geographical origin, as the document seems to imply.
- Macha 5y agoIf Google does not do so or fails to do so adequately, then the onus is on website owners to stop using a service which does not allow them to meet their data protection obligations. The data controller can't offload all responsibility to the data processor, in GDPR terms.
- robertlagrant 5y agoYes, this is correct. GA could make the controller's lives easier, but it isn't ultimately responsible for this.
- xxs 5y ago>Individual Website managers It's their responsibility to include or not google analytics, though.
- SquareWheel 5y agoIt's worth noting that GA4 does this already. GA3 (AKA Universal Analytics) requires owners to set the anonymize_ip flag though. I agree that Google should have retroactively changed this policy for GA3 accounts, even if it would cause some breakage. https://support.google.com/analytics/answer/2763052?hl=en https://support.google.com/analytics/answer/2763052?hl=en
- waffleiron 5y agoThe English post from CNIL makes it clear it's not just IP that's the issue: >In this context, a unique identifier is assigned to each visitor. This identifier (which constitutes personal data) and the associated data are transferred by Google to the United States.
- SquareWheel 5y agoFair point. The English link was not yet posted when I read the (translated) article, so the nature of the personal data wasn't that clear.
- dumbfounder 5y agoIf Google doesn't offer the ability then it is up to the customer to not use GA until Google complies. I hate this ruling, but implying it's just Google's job to do this and everyone else should just do nothing is crazy.
- deleted 5y ago[deleted]
- rightbyte 5y agoSurely Google has presense in France? Why not go after Google directly. It is way easier than processing 1000s of siteowners. Google are the ones spying. The aggregate put on GA dashboard are a minute of the personal info they collect.
- arlcode 5y agoReasons: 1. Legal: It's the site owners integrating GA and therefore taking on the liabilities just like they do with every other supplier. When a part in your car fails immediately after you bought it, it's the manufacturers job to fix it even if they acquired the parts from a third party (e.g. Bosch). 2. Practical: A website 100% located in France and catering to 100% french customers is much more likely to fix the problem than the international anonymous machine that is Google.
- V__ 5y ago> When a part in your car fails immediately after you bought it, it's the manufacturers job to fix it even if they acquired the parts from a third party (e.g. Bosch). And the manufacturer can go after Bosch, who is responsible in the end. > than the international anonymous machine that is Google. Except the law applies to Europe as a whole, and it's really not that much to ask one of the biggest technology companies in the world to use European servers and anonymize European traffic by default. They just don't want to or don't care. Which both should be reason enough to stronger regulate them.
- 5y ago
- southerntofu 5y agoI both agree and disagree. I agree what Google has been doing for years is morally/legally wrong. I disagree that they should change it, because it would still be triggering 3rd party requests from your browser to Google which is wrong for so many reasons (first and foremost latency and privacy). IMO we should break away Google entirely and trial their execs for crimes against humanity. They're cooperating with USA, China, Saudi Arabia... by helping murderous regimes deploy their techno-police, how many million people have they helped imprison/murder?
- vermilingua 5y agoEnglish link: https://www.cnil.fr/en/use-google-analytics-and-data-transfers-united-states-cnil-orders-website-manageroperator-comply# https://www.cnil.fr/en/use-google-analytics-and-data-transfe...
- andreisbc 5y agoAs a side note: Secret services have been using GA to identify and track targets for years
- lancesells 5y agoSource? I couldn't find anything reporting that
- p_l 5y agoHaven't seen mentions of GA itself, but it was obvious from context, as GA is part of wider ad targeting system - and those were explicitly used both by secret services as well as random hackers for target acquisition and initial hacks through vulnerable browsers of social engineering.
- can16358p 5y agoI don't like Google but seriously this whole GDPR thing is getting out of hand. Anyone who's concerned about their data being collected can just block Google-or-like-related domains. Rest is just making life of web developers/admins/tech company owners harder. Especially with these European intentions I frankly believe this is more of a political war against US and US-based companies. (No, I'm not from US as well)
- marian_ivanco 5y agoI don't want to comment on GDPR, but you must be kidding with 'can just block'. Do you expect that average joe can do that ? It like saying, we don't need police you can simply defend your self.
- can16358p 5y agoEverything comes at a price. I don't expect every average Joe to be tech savvy to use extensions. Though when visiting a site (an action that a personal deliberately takes) if they really care about their privacy on web, cookies, GA tracking they aren't probably average Joe and can use a blocker.
- jen20 5y agoYou are conflating "technically savvy" and "doesn't want to be spied on". I understand that these probably correlate in your world, but a simple moment to think about why most people click "no" to the iOS tracking opt-in prompts explains that these are orthogonal issues.
- ceejayoz 5y ago> Anyone who's concerned about their data being collected can just block Google-or-like-related domains. What percentage of the general population do you estimate a) will know enough to want to do this and b) will know how to do it?
- can16358p 5y ago
- aftergibson 5y agoIs anyone using an alternative that provides some basic analytics and isn't likely to get me in legal hot water in the future? I've already offloaded Google Fonts due to the German ruling. I'm happy to self-host piwik if needed, but could that fall foul of regulators?
- wongarsu 5y agoSelf hosted Matomo/piwik is pretty good. You probably want to make sure it's on servers in the EU owned by a EU company (Hetzner, OVH, Griscale, etc). Alternatively you can configure it in a way that avoids collecting PII [1] (which also removes the need for consent popup, privacy policy etc). You won't get much info about repeat visitors that way, but I imagine it's quite usable for many use cases. 1: https://matomo.org/faq/new-to-piwik/how-do-i-use-matomo-analytics-without-consent-or-cookie-banner/ https://matomo.org/faq/new-to-piwik/how-do-i-use-matomo-anal...
- lb_ 5y agoYes! I'm currently using https://usefathom.com/ https://usefathom.com/, works pretty great
- tsm 5y agoI just started using Goatcounter for a noncommercial site (music history research blog) and I'm happy with it. All I wanted was a glorified hit counter. It doesn't have the goal conversion metrics and other advanced features of GA, so obviously not a drop-in replacement for all use cases. https://www.goatcounter.com/ https://www.goatcounter.com/
- jandeboevrie 5y agohappy goatcounter user here to, for the same reasons as you say, way less complex than GA but it has more metrics I care about.
- abelaer 5y agoAnother very happy user here. Was super easy to add to my Jekyll site hosted on GH pages. I believe the creator is active here as well btw.
- marcus_cemes 5y agoFor those that missed it and are interested, there was a similar HN discussion around a German GDPR ruling last week. It already has quite a large debate and a lot of opinions on the matter: https://news.ycombinator.com/item?id=30135264 https://news.ycombinator.com/item?id=30135264
- ssijak 5y agoSo I can take follow someone in public, take picture of them in public places from some distance, follow them into stores, see what they are spending and what they are using, etc. Store owners can have cameras, track the behaviour of customers, etc But if I use a service which anonymously tracks which pages they opened on a website they voluntarily visited and are exploring, then I'm in trouble?
- vasco 5y agoYou're also in trouble if you send the data you collect by other methods without consent, to servers based in the USA for NSA to snoop around on and correlate with all their other data points. Unless your argument is "but how would they know about it", in which case that applies to any other crime.
- FridayoLeary 5y agoInstead you must give it to their European equivalents (which looks likely given the current state of affairs).
- vasco 5y agoYes, and NSA can read all communications anyway. This whole thing is a political issue not a technical one.
- xaedes 5y agoNo, you can't stalk people.
- ssijak 5y agoYou are not stalking, like doing it all the time. And you are not taking closeup in your face picture but from a distance. All that is not illegal in a lot of countries.
- Nekorosu 5y agoYou are in trouble in both cases.
- pSYoniK 5y agoThere are plenty of privacy respecting analytics out there - Plausible, Matomo or Simple Analytics. Depending on what your actual needs are, you can also just use something like GoAccess, logwatch, Splunk or multitail to check your logs and use those for analytics information. In one of my previous jobs the marketing department complained about Google Analytics not working on one of our pages. GA hadn't been working for about 10 months when they raised the incident. It was such a low priority that it took another 4 months for someone to fix it. While I get that someone people are slightly foaming at the mouth because of GDPR (and this starts an entire debate about an aging political population that doesn't understand technology AT ALL) going overboard, my question is - do we actually use all the analytics that are provided by GA? How many marketing teams/sales teams/etc actually use ALL the information provided by these tools. Aren't there other better ways to measure your campaign and product performance? Do you just want to see time on site/page? Abandon rate? I mean, most of these tools feel like they concentrate the Western mentality of "I need an SUV because I might have to put in more than 2 bags in my car". /endRant
- piva00 5y ago> While I get that someone people are slightly foaming at the mouth because of GDPR (and this starts an entire debate about an aging political population that doesn't understand technology AT ALL) going overboard, my question is - do we actually use all the analytics that are provided by GA? Who are these people foaming about GDPR?
- YXNjaGVyZWdlbgo 5y agoAdtech
- liveoneggs 5y agoCrUX data will be next. Using to be Chrome considered illegal in Germany.
- estaseuropano 5y agoNo, you download chrome. You agree to the analytics when you install/first open it. This is different from going on the site of your local company and feeding data into Google analytics involuntarily. The relevant legislation is about whether or not you agree to data being collected and shared, and the issue is that US companies are essentially data funnels for NSA & co.
- jklinger410 5y agoYou download a website when you visit it. Both analytics and chrome phone home information about your activity. They are the same.
- shadowgovt 5y agoTechnologically, yes. But if there's one thing we've learned from the GDPR, what matters is consumer perception, not the underlying tech. A web site isn't a browser.
- xtracto 5y agoSo why cant i ask my website users to AGREE on google analytics usage the first time they arrive? Its up to them to accept or not.
- userbinator 5y agoHaven't cookie consent prompts caused enough problems already...? My way of disagreeing is GA domains in the HOSTS file.
- nkg 5y agoI have just posted this link for everyone on the Slack of the french web agency - specialized in Google/Facebook/Instagram campaigns - I work for. Not one reaction. I was left on seen.
- vgeek 5y agoI've found that most agencies love to preach that they are data driven, but in reality they only care about the perception of being data oriented. They won't care until clients start asking questions, then it will be a panic.
- marginalia_nu 5y agoThey're probably too busy wiping the coffee they sprayed through their noses onto their keyboard to type a response.
- keraf 5y agoArticles mention GA, but is Metrica[0] similarly affected? I guess their data is also stored outside the EU. [0] https://metrica.yandex.com https://metrica.yandex.com
- M2Ys4U 5y agoThey store data in Russia, so probably. Each jurisdiction is going to be slightly different, depending on what the law regarding data protection is like in each place. Russia hasn't been deemed adequate by the Commission under the GDPR, but it is a member of the Council of Europe (and is thus bound by the ECHR) and it has ratified Convention 108 (and has signed, but not ratified, the modernised Convention 108). Of course Russia is a deeply authoritarian regime which has no problem violating human rights and international treaties at will so...
- p4bl0 5y agoSadly I don't see how this decision can be translated into practice, since I strongly doubt the CNIL will be able (or willing) to send formal notice, and fine after a grace period, all French companies that make use of Google Analytics on their website.
- Y-bar 5y agoWhy is the onus on the CNIL to notify companies on the law (which they actually did by issuing this press release) and not on companies to keep up-to-date with the law (which they could to by reading the news)?
- p4bl0 5y agoThis is just how it works. I'm not making the rules. The CNIL send "mise en demeure" to companies that do not complies with the GDPR and even before that with the "loi informatique et libertés" and if the companies ignore the "mise en demeure" after some time the CNIL can fine them. It also happens that the CNIL is notoriously more and more lenient on a lot of things.
- feupan 5y agoYou never catch all the law breakers, but fines can be a good deterrent. That’s how it works.
- Vosporos 5y agonul n'est censé ignorer la loi.
- p4bl0 5y agoYes and of course because of that everyone is respecting the law, especially companies when they're not at any risk if they don't. /s Yes I'm a bit pessimistic about this. Let's all hope I'm wrong.
- anticensor 5y agoTranslated into English: The law everyone ignores isn't.
- hobo_mark 5y agoPrevious discussion: https://news.ycombinator.com/item?id=30284820 https://news.ycombinator.com/item?id=30284820
- dang 5y agoThe current thread was actually posted first, so we merged the comments hither. Thanks!
- kragen 5y agoNote that Wikimedia has been not using Google Analytics since forever because they're concerned about precisely the same privacy problems as the regulators. This other post has more comments: https://news.ycombinator.com/item?id=30284820 https://news.ycombinator.com/item?id=30284820 I love that the plaintiff in this case is the "NOYB Association", as in None Of Your Fucking Business, Google.
- deleted 5y ago[deleted]
- Jack5500 5y agoYou might know that already, but NOBY indeed stands for "None of Your Business"(https://noyb.eu/en https://noyb.eu/en). The organisation has been involved in nearly all of the last privacy related rulings in the EU and is a real blessing for consumer rights.
- frabcus 5y agoAnd a note that you can donate to them, and I have done so for nearly four years.
- judge2020 5y agoIt would seem Wikimedia is still violating the law as they keep Analytics data/data of users[0], but haven't yet pulled the Microsoft move of creating a separate EU company that the US-based entity has no control of. 0: https://meta.wikimedia.org/wiki/Data_retention_guidelines https://meta.wikimedia.org/wiki/Data_retention_guidelines
- kragen 5y agoIt's totally plausible that Wikimedia and the EU have different, mutually incompatible responses to the same problem.
- akavel 5y ago"The CJEU had highlighted the risk that American intelligence services would access personal data transferred to the United States if the transfers were not properly regulated." As an EU citizen: Thank you Mr. Snowden, sir! <3
- deleted 5y ago[deleted]
- sfifs 5y agoA lot of this seems to be coming due to US regulations that compel US registered companies to hand over data from subsidiaries in Europe markets if asked by US intelligence and law enforcement agencies. With these various data locality regulations, i wonder if a standard operating approach could be to split tech companies into 3 legal entities, a technology licensing company, a US registered operations company and a Europe registered operations company and hand the shares in all three companies to the current shareholders. This would insulate the Europe entity.
- londons_explore 5y agoI think a lot of the big tech companies are very reluctant to split their operations inside/outside europe. They gain big benefits by having a single pool of datacenters able to serve users from anywhere in the world. If they needed to guarantee that an EU user would always be served with a machine in the EU, I can imagine it would add at least 20% to their operating costs. They'd need more equipment both inside and outside the EU to handle failover, maintanance, etc. They'd also have more complexity slowing development down (they can no longer have small services 'mastered' in just one region). And there is substantial extra complexity in application design (what when a tweet from an EU user is retweeted by a US user, but then replied to by an EU user. Where will the text of the tweet be stored? How will deletion be handled?). For example, will HN have to have seperate databases for "comments by EU users" and "comments by US users"? And will they need a process to migrate your account from one to the other?
- KingOfCoders 5y ago"I think a lot of the big tech companies are very reluctant to split their operations" Yes but they are even more reluctant to lose all EU revenue.
- pmontra 5y agoIt's not only "a machine in the EU" . It's a company in the EU totally separated from the main company in the US to be out of the reach of the US government and legal system. Maybe the EU company could license software and knowledge from the US one, to keep sending a steady flow of cash there. But it's going to have its own goals and it will want to go its way soon. A hard problem IMHO.
- southerntofu 5y agoIs the CNIL actually starting to do its job? Since the early 2000's they were doing literally nothing against the many crimes against users committed by big tech. In the past few years though they started to distribute fines when the law was obviously and willingly broken (eg. Google)... did they suddenly start to care for users? or do they care that they can fill the pockets of the government (who doesn't dare to tax those evil multinationals) while making it look like they care for users? I mean CNIL does not exactly have a reputation of helping/protecting users... they more have a reputation of being a watchdog who sees no problem with government surveillance programs and does not react when you send them reports of illegal activities surrounding personal data. For their defense, their budgets and prerogatives have been cut so many times they probably couldn't investigate/fine anyone if they wanted to.
- Fiahil 5y ago> Is the CNIL actually starting to do its job? IIRC, They got massive funding with GDPR
- zoobab 5y agoGDPR enforcement is big business for the government, but no money goes to the poor associations, like LQDN or NYOB. Quite the contrary, those associations have to survive on 'donations', and probably not very high salaries for their staff.
- southerntofu 5y agoNot sure why you're being downvoted. People from such non-profits were key to european institutions developing a proper understanding of the problem space, which directly led to GDPR legislation. If you're rich enough, be sure to donate some money to LQDN/EFF and others to protect human rights in the digital realm.
- malka 5y agoCNIL is not an association. It is part of the french state.
- TekMol 5y agoGoogle Analytics is the best analytics tool out there. By getting their companies off GA, European governments are weakening their industry. This probably holds true for many SAAS products. Many of the best are from the USA. Forbidding European companies to use them is a desaster for the European internet industry.
- wizzwizz4 5y agoGoogle Analytics is hugely overrated. Most people don't use it properly, many browsers block it entirely, and you can usually do a better job just by looking at server logs.
- TekMol 5y agoSaying so just tells me that you never been analyzing and optimizing websites with millions of users. Websites on which a whole company depends on. It would be a crazy approach to try and do it via server logs.
- wizzwizz4 5y agoActually, there are some nice tools (e.g. GoAccess) that produce pretty graphs. The vast majority of people just want pretty graphs; the more fancy data Google Analytics produces is nowhere near as accurate as the number of trailing non-zero digits would have you believe. Depending on your userbase, the regular traffic data can be off by significant proportions. I've seen pages where the number of logged-in interactions are higher than the number of Google Analytics hits.
- bovermyer 5y agoServer logs aren't the only alternative to Google Analytics. Matomo, Plausible, and Fathom are all perfectly viable.
- Semaphor 5y agoBut GA is indeed not very useful for many questions. FF blocks it by default. We use server-side stats and for last month I get 30.1% Chrome, 28.8% FF. Now when I compare that to GA: 40% Chrome, 16% FF…
- pl0x 5y agoWhat is the balance of privacy and analytics when even privacy friendly tools like Plausible are blocked.
- XCSme 5y agoI think the main thing is not to send your customers' data to third-parties without their consent. It's usually fine if you use internally analytics for the purpose of running the company, it's not fine if you send those data to other companies that use it for marketing purposes.
- marcosdumay 5y agoYou can't send the data of EU people to companies subject to spying states.
- XCSme 5y agoShameless plug: I have been building a self-hosted-only analytics platform for a long time: https://www.uxwizz.com https://www.uxwizz.com. It looks like a good time to switch to self-hosted analytics.
- Semaphor 5y agoIs it really such a rare occurrence for people to want to see statistics for a specific page or compare pages/articles? Because almost all new-wave analytics tools either do not support it, or it’s hidden and not easily discoverable.
- XCSme 5y agoAre you referring to stats such as time-spent on a specific page? From my experience, there are several thousands of people/companies using UXWizz and so far no one has requested this feature yet. But now that you mentioned, it seems like a pretty useful feature, especially if you can see top performing pages/articles. I think one reason why people don't care about the specific analytics for a page is that they usually write pages/articles for SEO purposes. To see how well a page is performing SEO-wise, you usually go to Google Search Console (or Bing Webmasters) and see search terms/click-through-rates for that page. Also, time spent on a specific page is not that useful, typically you want to see: if people are buying stuff, where do people that buy stuff come from and what page do they land on.
- Semaphor 5y agoGeneral information. How many views/visitors over time, referrers, etc. I did try to click on the top page lists, but those weren’t links. I found "Add segment" eventually, but at least on the demo page it’s not working (for the pages I tried, eventually I found a page with stats), and the interface is atrocious [0] for finding anything and breaks the site [1]. Our website is not posting articles to get people to buy other stuff, but the actual main part of the website (articles, and free or paid product tests; money is made both by selling tests and ads, with the ads not just being generic but specifically bought by companies with often contextual targeting). So my boss usually wants to know what articles do well (and not just from SE’s, we have a lot of repeat visitors), how soon interest drops, etc. [0]: https://i.imgur.com/Buf0Vgd.png https://i.imgur.com/Buf0Vgd.png [1]: https://i.imgur.com/wIO0d2B.png https://i.imgur.com/wIO0d2B.png
- zoobab 5y agoAnd billions of EUR of damages for the 'people farming'. Where is the money?
- Pooge 5y agoI contacted them approximately 4 years ago to denounce the developers of TrackMania that don't hash passwords [1]. I have not received an answer since, and I bet they do not even care. I'm sure they are a bunch of hypocrites and now that they've realized they can make a lot of money randomly fining Big Tech, this is just what they're going to do. [1]: If you clicked on "Password forgotten" on the log in page, they'd just send you your password unencrypted by email.
- calyhre 5y agoI've contacted them twice pre-GDRP era, about unsubscribe links not having any effect on some spam emails from French companies, and both time they took actions against the company and reported back to me. It took some times but they acted on every cases, no matter the company size, I was actually impressed. I guess it's a matter of luck.
- dgudkov 5y agoHow can French websites track conversions from Google Adwords without Google Analytics?
- speedgoose 5y agoGoogle Adwords should be next.
- iamacyborg 5y agoSend your ad traffic to a specific landing page - monitor anonymised hits to that page. Send you ad traffic to a unique form per campaign so you know what campaign is generating leads. This isn't rocket science.
- dgudkov 5y agoThat would count clicks, not conversions such as downloads or signups that can require going on another page or doing some other action. Not everything can be put on one page. Also, Google Adwords counts conversions for visits for 30 days. Which means on the 1st visit from the ad campaign, there can be no immediate conversion (and that's OK). But if the same person returns to the website (not from the ad) and downloads/signs up that would be counted as conversion attributed to the ad.
- iamacyborg 5y ago> downloads Track hits on a post-download URL > signups Count signups in your DB with a source from a hidden field on the form > Also, Google Adwords counts conversions for visits for 30 days This stuff is mostly meaningless.
- dgudkov 5y ago>Track hits on a post-download URL It will be mixed with downloads that come from organic search. >This stuff is mostly meaningless. I disagree.
- acnops 5y agoAFAIK, this could be pretty disastrous for French businesses that funnel conversion data to Google Analytics, which is then used to optimize their Google Search ads. Switching to another solution for analytics might be ok, but losing the ability to automatically optimize ads based on conversion data is a big pain.
- YXNjaGVyZWdlbgo 5y agoIt doesn't really matter micro targeting is not effective.
- viro 5y agosource? Since conventional wisdom disagrees with you.
- martin_a 5y ago> conventional wisdom You mean what the SEA people tell you? Yeah, we'll all probably be out of business tomorrow, if we don't run the whole Google stack.
- viro 5y ago
- martin_a 5y agoWell, in regards to what the OP said, this whole "we need to track our users" stuff is bullshit. I see those "highly optimized" campaigns too, when something goes wrong and the SEA people start to cry because somebody stepped in their sand castle. You don't need any of that.
- viro 5y agoThen why did Facebook lose 10b dollars from losing that tracking data on iOS?
- Dave3of5 5y agoDon't quite understand this at all. Can we cut through the clickbait and see what's wrong here. If my website askes users for their permission to use GA and they click yes then is that still illegal here? I see this as yes it's still illegal. Also is it illegal because there is an anonymised id number created when you send data. If that's the case then it's not just GA that's a problem but any tracking system i.e. Plausable. Furthermore given that a randomised unique id is personal data then there would appear no way to use any websites analytics on any website as you have to store this in a DB which will require a unique id per row by design. What about other data for example a webserver log will contain similar data is that not allowed? If it's not allowed how can I ensure my site is protected as I need those logs to identify and ban hackers.
- iamacyborg 5y ago> Can we cut through the clickbait and see what's wrong here. If my website askes users for their permission to use GA and they click yes then is that still illegal here? I see this as yes it's still illegal. Yes, because you're still passing personal data to the USA, which means US intelligence services can access it.
- Dave3of5 5y agoIs that the case for any data that is passed into the USA then rather than just GA? So if I hosted my servers in any of the AWS US regions that too would be illegal if they have any personal data in them. In this case personal data is a randomised unique id. So say I have a table of users and all I have is a username and a password and a unique id for the record that's personal data and the customer is not allowed to give their permission for me to store that in a US data center ?
- iamacyborg 5y agoPotentially, yes, though this hasn't been tested in court yet.
- 5y ago
- Vosporos 5y agoFinally some good news
- McHankHenry 5y ago
- matsemann 5y agoShouldn't Google etc. go after the draconian US laws making this an issue? I feel most of them try to attack EU or fight the courts there.
- jdrc 5y agois google making a lot of money from analytics?
- lopis 5y agoMaybe not directly, but analytics is what allowed Google to "see" the whole internet, with some help of Chrome. These 2 products allowed Google to track the majority of the internet traffic for the past 15 years.
- jdrc 5y agoAt this point they have so many channels and side-channels, that i think they can comfortably let go of GA.
- seapunk 5y agoFor other French people here: there is a great privacy-friendly alternative: https://simpleanalytics.com https://simpleanalytics.com
- jdrc 5y agoWhile i think these rulings are interesting in the sense of providing an opening to EU-grown businesses (if not too late), it does have a comical dimension in it. "Private" information is everywhere, it's in your DNS queries, which also gets propagated to servers in the evil US empire. Are we going to legislate DNS out of existence too? The EU seems to like having a completely private internet, but that's not gonna be possible unless we build one ourselves (how?) There is a load of hyperbole in the EU privacy business, and it s coming from the german side which is super sensitive to it. But germany is a worldwide exception, their laws for censorship and privacy exist for specific reasons, and they shouldn't be propagating them everywhere. Specifically in the analytics space, i don't think a lot of people are going to pay for analytics. A free verson makes sense because a lot of websites dont make money. Google provides it for free because they have a monetary incentive to keep marketers in their ecosystem, other companies don't. (Unless the other companies choose to monetize them just as google did) I think the biggest loser however is going to be the decentralized open web.
- anthk 5y agoIn Spain the Agencia Española de Protección de Datos (no translation needed I guess) is no joke.
- lopis 5y ago> Are we going to legislate DNS out of existence too? No, but we could ban ISPs from being allowed to log DNS requests. There's lots of things the ISPs are doing that should not be allowed. It's done completely without our consent. If regulating DNS would have as consequence "to legislate DNS out of existence", then be it.
- yxhuvud 5y agoComplicating the matter here is the Data Retention Directive, which while invalidated by the ECJ is still at least partially applied by some member states.
- philistine 5y agoDNS is not forced to leak private information forever. There are ways to dissociate the request from the person making it.
- rebelde 5y agoTaking this to the logical extreme: A French website can not use any American service, right? Because any American services "are not sufficient to exclude the accessibility of this data for US intelligence services".
- einpoklum 5y agoIndeed, a French website which keeps private information about its users must not - ethically, morally - use US services which are accessible to US intelligence agencies. That is irrespective of any legislation or court rulings, it's just common sense.
- verdverm 5y agoSince everyone is spying on everyone, what's the ethical or moral issue here?
- Ekaros 5y agoSomehow there is lot of complaining about China doing it... I really don't understand that one...
- zelphirkalt 5y agoThe issue would be, that the website developers / their management contributes to the issue, by enabling partier to do that spying. If no data was send to another party, then spying on that data is much harder and probably unattractive for most use-cases. GA data becomes valuable through collecting from many many senders. While the people doing the spying are already doing something ethically very questionable, the person deciding what data is collected on a webservice can still make the decision to contribute to the problem, or be vigilant about data protection.
- verdverm 5y agoSo you are saying the US intelligence agencies have some unfettered access to all of GA data? Or that it is sent unencrypted and intercepted in transit? It's not the DNS calls or phone companies that are more to worry about?
- ironman1 5y agoFor the french people on HN: There is a privacy-first alternative called: https://simpleanalytics.com/ https://simpleanalytics.com/
- ironman1 5y agoThere is a privacy-first alternative called: https://simpleanalytics.com/ https://simpleanalytics.com/
- SadWebDeveloper 5y agoHere is another a privacy-first alternative that works with a cloud subscription: https://awstats.sourceforge.io/ https://awstats.sourceforge.io/ If your needs exceed the data analyzed by it then you should consider rethinking your "analytics model".
- jmnicolas 5y agoThe cheapest plan is 19€ / month which is twice what I pay for my VPS. Not realistic. It's very easy to rack up bills while building a website: hosting, domain name, Wordpress plugins, analytics, publicity etc I don't have analytics yet on my site (it's a very recent side project). I didn't want to go the Google route because ethics, now I don't even have the choice (I'm French). I looked at the self-hosted options but it seems overly complicated (I'm afraid installing them on my VPS will kill perfs), so now I'm considering just writing a script to parse Apache's logs.
- TomGullen 5y agoSo what primary key are these other analytics using if not IP? (Their docs say they don't store IPs but do store user agents). It looks like it's based on browser fingerprinting - if I'm right OK it's not an IP but it's not much better and if things keep going the way they are pretty sure this will be up for the chop in the future.
- amai 5y agoGoogle stock is already dropping: https://www.google.com/finance/quote/ABEA:ETR?sa=X&ved=2ahUKEwjq8cOjq_X1AhXawAIHHaWZDrsQ3ecFegQIFBAe https://www.google.com/finance/quote/ABEA:ETR?sa=X&ved=2ahUK...
- IiydAbITMvJkqKf 5y ago-1 for obvious reasons
- ianschmitz 5y agoMeh, zoom out to 1 month.
- AdriaanvRossum 5y agoFor who needs a summary of what is happening in the EU [1] 1. Since 2020, it's illegal to send personal data to the US because of the invalidation of the Privacy Shield [2] 2. Google said it was okay in the EU to use anonymized IP addresses 3. The Austrian Data Protection Authority (DSB) [3] ruled differently and waived most of the arguments raised by Google. The DSB ruled that even anonymized IP addresses are personal data. 4. The Data Protection Authority of The Netherlands followed by implying that the use of Google Analytics might be banned in the future [4] 5. Now, the Data Protection Authority of France (CNIL) followed This is a sound decision, but not a new one. It's a confirmation of what has been ruled in July 2020, but now it seems to have more impact. PS: I'm the founder of Simple Analytics [5] - the privacy-first analytics tool that, unlike other privacy tools, does not use any identifiers. [1] https://blog.simpleanalytics.com/will-google-analytics-be-banned-in-the-eu https://blog.simpleanalytics.com/will-google-analytics-be-ba... [2] https://iapp.org/news/a/the-schrems-ii-decision-eu-us-data-transfers-in-question/ https://iapp.org/news/a/the-schrems-ii-decision-eu-us-data-t... [3] https://www.data-protection-authority.gv.at/ https://www.data-protection-authority.gv.at/ [4] https://autoriteitpersoonsgegevens.nl/nl/onderwerpen/internet-telefoon-tv-en-post/cookies#hoe-kan-ik-bij-google-analytics-de-privacy-van-mijn-websitebezoekers-beschermen-4898 https://autoriteitpersoonsgegevens.nl/nl/onderwerpen/interne... (in Dutch) [5] https://simpleanalytics.com/ https://simpleanalytics.com/ EDIT: changed "PII (personally identifiable)" to "Personal Data"
- phkahler 5y ago>> Since 2020, it's illegal to send PII (personally identifiable) data to the US because of the removal of the Privacy Shield Framework [ This sounds like some great politicized naming. Removal of the "Privacy Shield" seems to be increasing privacy in this case.
- the-dude 5y agoPar for the course. Peace mission.
- AdriaanvRossum 5y agoYou are right, rewrote it as "invalidated"
- jdrc 5y agoI suppose adsense is next? I think that would be total disaster to the already crippled european web And what about Chrome?
- yrgulation 5y agoWondering if this will also apply to gmail, google drive and so on. Also wondering if there is a way to agree to storing my data in the us. Nonetheless it appears that this a good opportunity for an eu based alternative to google analytics. Also what are the implications of cross eu-us chat apps where a person’s name is visible? Doesnt it mean that when a recipient in the us sees the name, the eu person’s data has been transferred to the us? Apologies if this comment is ignorant, i am not well versed in the topic, but to me it sounds like this is quite an issue for us-eu chat and email apps.
- M2Ys4U 5y ago>Also wondering if there is a way to agree to storing my data in the us. Consent is always a valid legal basis for the processing, or transfer, of data. But it has to be freely given, specific, informed and unambiguous.
- thallium205 5y agoSo just more annoying consent pop-up modals in the future?
- zelphirkalt 5y agoYep, and that means, that showing a huge, not easily dismissable popup basically demanding consent, just to watch a video or read an article, for which no tracking or cookies are necessary technically, is not really asking for consent and should be illegal.
- ApolloFortyNine 5y agoUnless the only way for online services to survive is with these targeted ads. Untargeted ads pay a tiny percentage of what targeted ads do, and I'm unsure things like free video hosting with unlimited bandwidth would last long without them. And though hacker news likes to be extreme and say "good" to things like this, there is an unbelievable amount of freely available information on the internet. If you had to pay a subscription by site, how many sites would you be willing to pay for? More importantly, how many would the average person pay for?
- kenjackz 5y agoWhy is that? It's called analytics for a reason.
- kornhole 5y agoFor those of you outside of the EU who would like to opt out of being tracked by Google analytics on web pages, install the browser add-on Ublock Origin.
- openplatypus 5y agoLuckily there is plenty to choose from. We entered the market recently with Wide Angle Analytics https://wideangle.co https://wideangle.co. But there is plenty alternatives. Depending on your needs. Some focus on visuals, we focus on filters and soon attribution. There is more on the list: https://european-alternatives.eu/category/web-analytics-services https://european-alternatives.eu/category/web-analytics-serv... Competition is a healthy thing. You DON'T HAVE TO use Google Analytics :) And if you wonder, yes, the fines are real. Enforcement of GDPR is picking up the pace: https://wideangle.co/blog/you-might-be-facing-gdpr-fine https://wideangle.co/blog/you-might-be-facing-gdpr-fine
- TomGullen 5y agoSo what primary key does WideAngle use to track users across sessions? It mentions anonymised IP? Isn't that what Google do? You mention you store anonymised IP's "Unlike some other vendors, our anonymization process is not reversible.", what is the methodology here?
- ApolloFortyNine 5y agoSince most people are still on ipv4, does this even mean anything? You'd need the salt stored in some way to reproduce hashes at all, and creating 4 billion hashes to find an ip won't take any meaningful amount of time. Even with a high cost algorithm, if the government requires finding the ip (because honestly Google wouldn't care here, the unique identifier is what they need), they'll be able to find it. If it's a truly irreversible hash, it would also be impossible too link up two separate requests no?
- openplatypus 5y agoGuessing IP would be unpractical. Absolutely. But without random component, it could be "reversed". For example, I would like to retroactively check when and where you, ApolloFortyNine visited my site. All I would need to get is your IP (residential IPs change, but not that often) and User-Agent. I could replicate hashing algorithm and identify your traffic. The random component prevents that. And yes, there is a trust component. You have to trust that we discard these salts after 24h. We operate in Germany in a legal framework that allows you to sue us if we mislead you. So at a certain point, technology must make place for the legal system. Because salt is rotated every few hours, never more than 24h, we can, with sufficient probability, determine that two requests are from the same visit/session. So have indication of new/unique visit in short window. Not days, but hours. If you were to transmit a parameter that additionally attached Personal Data (email, User ID) to that session, then that becomes identifiable and is no longer anonymous. But that is strictly AT YOUR DISCRETION. And we NEVER share it with anyone but you. You will also need to inform your guest, that you associate personal data and ask for consent. But until you do, we cannot identify anyone after the salts cycle.
- jimmaswell 5y ago
- stickfigure 5y ago
- ApolloFortyNine 5y agoIt is pretty insane we still allow Chinese companies to enter Western markets when going the other way, the Western company has to partner with a local Chinese company.
- xdennis 5y agoWhy are Europeans the bad guys here? It wouldn't be an issue at all of the US respected the privacy rights of Europeans. It's the same with cookies. Instead of blaming sites which spy on you, some blame the EU for protecting its citizens.
- VikingCoder 5y agoIf someone adds <img src="http://blah.us http://blah.us"> to their website, and that image is hosted in the United States, how does that not also violate French data protection? The user's browser makes a request to a US server, including the user's IP address. I legit do not understand how to make French people happy with these laws.
- cdot2 5y agoI've been having to remove google fonts because we had some germans say we're breaking their laws by using them
- littlecranky67 5y agoTo be fair, nowadays there is hardly any benefit. Since browsers use cache partitioning (mostly because CDNs were tracking users) there is no benefit in not serving it yourself (although yes, licensing restrictions now apply but there is plenty free fonts to use).
- tremon 5y agoWhy remove them? Why not proxy/cache the fonts from your own server?
- ihuman 5y agoDepending on the license, that might cost more, or not be an option at all. For example, Adobe doesn't allow you to host their fonts; you have to link to their CDN. https://helpx.adobe.com/fonts/using/font-licensing.html#web-host https://helpx.adobe.com/fonts/using/font-licensing.html#web-...
- mrunkel 5y agoExcept he explicitly referenced Google Fonts
- gjs278 5y ago
- mediascreen 5y agoI think we (in the EU) will soon realise the bizarre consequences of these regulations. European startups will not be able to use standard SaaS or PaaS tools (like AWS, Azure, Mailchimp, PayPal etc) if they are based in the US (like most of them are). No cloud services, no Office 365 or Google Workspace. It will take forever to build up a similar ecosystem in Europe and I think most successful European entrepreneurs will just end up starting companies in the US instead. There must be some reasonable middle ground before we fragment and destroy the entire Internet. Why not start by making a general exception for temporary storage of less sensitive data like IP-addresses for efficiently and cost effectively delivering a web service. If there is one thing they could start looking in to it would be handling of personal information by governmental organisations. I work a little bit with a few municipalities, and the number of documents with deeply personal information that are just emailed around over unencrypted email is shocking.
- deleted 5y ago[deleted]
- ballenf 5y ago> we fragment and destroy the entire Internet I would call fragmenting these things rebuilding the internet. Not sure how consolidating everyone on a few Mailchimp type services is in anyone's interest.
- brahadeesh 5y agoExactly. If this make European startups build their own ecosystem and provides me with an alternative for the services I use but don't track me, I'm going to switch - simple as. I see this as a win for the internet.
- mediascreen 5y agoWhy limit it to the EU? Shouldn't every country have their own AWS, Azure and Google Cloud? I think we underestimate just how difficult it is just to replicate existing services, let alone keep up with the innovation. It's like the Argentinian effort to stimulate its own computer manufacturing by banning Apple products.
- intrasight 5y ago"The IP anonymization feature in Analytics sets the last octet of IPv4 user IP addresses and the last 80 bits of IPv6 addresses to zeros in memory shortly after being sent to Google Analytics. " https://support.google.com/analytics/answer/2763052 https://support.google.com/analytics/answer/2763052 I don't understand how this can be construed as tracking users.
- ATsch 5y agoThis is a totally different question, in this case what matters is that Google can be compelled to release the full IP address by US intelligence agencies.
- intrasight 5y agoSo it's an easy fix for Google - change GA to only save those anonymized IPs
- ATsch 5y agoNot quite. Google still has access to those IPs when it receives the request from the browser and could be compelled to store them by US intelligence. Thus data are being transferred to a party that can not adequately protect them. So in this case, as I understand it, the solution would have to be something more elaborate, like proxying the analytics requests through the server to strip the original IP address. Which I presume Google isn't very eager to allow.
- intrasight 5y agoLots of other tech companies, as I understand it, choose not to be "compelled" to store something they don't want to store. Apple being the prime example.
- nicfab 5y agoBe prepared to read similar measures from other supervisory authorities as well. They will arrive soon. Stay tuned!
- deleted 5y ago[deleted]
- spullara 5y agoDo they somehow count the users browsers making a request to a US server as the website transferring data to the US? It is pretty clear that the users browser did that and not the website or Google.
- isbvhodnvemrwvn 5y agoAnd technically if you hit someone in the head with a hammer than it's the hammer that's hitting the head, and not you. It's a meaningless distinction made in bad faith.
- spullara 5y agoNo, this is like blaming the manufacturer of the hammer.
- isbvhodnvemrwvn 5y agoThe law is clearly meant to protect an average citizen. It's unreasonable to expect them to know how the web and browsers work. When you instruct the browser to display something, you should take full legal responsibility for what you are instructing the browser to do, because from users point of view it's the website owner who is displaying all of that.
- MikusR 5y agoThat means that Firefox is also illegal in France.
- swlkr 5y agoThe EU privacy regulations seem to have a side effect of creating a de facto EU internet, where EU competitors can become dominant because they pay closer attention to changes in law vs north american or chinese counterparts. It’s almost like a more subtle version of china or russia’s firewall
- chaostheory 5y agoImo that was the main goal.
- keewee7 5y agoThe goal is to create European state enterprises to replace Microsoft, Google, Facebook etc. These privacy regulations were championed by socialist MEPs.
- AlanYx 5y ago>The EU privacy regulations seem to have a side effect of creating a de facto EU internet, where EU competitors can become dominant because they pay closer attention to changes in law vs north american or chinese counterparts. Within EU government and diplomatic circles, there's actually a term for this: the "Brussels Effect". People who use the term "Brussels Effect" believe that by imposing aggressive rules first, the EU software industry will have a first-mover advantage and a kind of partial "firewall" against some foreign competitors. In my experience, the potential downsides of the "Brussels Effect" are rarely considered by these people (e.g., reduced competition within the EU, leading to increased costs for other businesses; overseas web service providers being forced to block EU customers, leading to reduced availability of services, etc.). Another area where you see the same "Brussels Effect" in EU policy/legislative circles are recent moves towards rather aggressvie regulation of "artificial intelligence". Not just the recent proposal that was tabled, but also the CAHAI work towards a binding international instrument.
- sam0x17 5y agoThis is really good news for consumer privacy everywhere. I was just in a meeting with some marketers in my org and they were quite dismayed so I'm conversely quite happy. I've been saying for years that content is king and tracking will only be sustainable for so long. It's only a matter of time before laws like this are the norm rather than the exception globally.
- duxup 5y agoI wonder if the user community on the web will ever adjust to a situation where they're not trading "free" services in exchange for their privacy. Users on the web love / demand free and aren't willing to pay for a lot of this stuff...
- seiferteric 5y agoRandom thought, maybe totally off base. This is Europe, so not equivalent but there seems to be a lot of people in the US as well who want private companies to be compelled to respect your privacy (4th amendment) but also many people who don't think websites should or could be compelled to respect your freedom of speech (1st amendment), I wonder if there is an overlap in these groups...
- RIMR 5y agoI don't think these concepts are comparable. My First Amendment rights cannot be violated by a private website, because I can always go to another website, or start my own. Being deplatformed isn't the same as being silenced, because nobody is preventing you from speaking, or punishing you legally for what you have said. My Fourth Amendment rights could absolutely be violated by a private website, as they could hand my potentially incriminating private data over to the US authorities, without a warrant and without my consent, and there's literally no opt-out or recourse for me if that data is then used against me by the government.
- seiferteric 5y agoHmm, but you could have not given the data or used the website in the first place.
- foxfluff 5y agoMy (European) perspective is that, just like we need laws to protect privacy online, we do also need laws to institute freedom of speech online. I'm not exactly sure what the right way to go about it is (obviously we shouldn't and cannot force every company online to publish whatever anyone wants to say), but fact is that right now you are at the mercy of private companies if you want to communicate online, and restricting freedom of speech to the proverbial "free speech zone" where discussion isn't actually happening is not a healthy state of affairs. I'd probably at least advocate for something like net neutrality.. ISPs and hosting providers should not work as censors and arbiters of good taste. They should be more like utilities; as long as you're not doing anything illegal, what you do or say is none of their business. Unfortunately this isn't a solution for the common person whose communications are limited to platforms like facebook and twitter.
- leobg 5y agoOne thing I find super crazy is that, while making a big fuss about IP addresses and cookies, the EU forces any website owner to publicly share his full name, address and phone number on the site’s imprint. If you’re not a corporation or a professional who has an office address, you’ll have to supply your own personal data. Visible to anyone on the internet.
- knorker 5y agoOh? I missed this. What regulation is that?
- iso1210 5y agoThere isn't one There's a German law which says all commercial webpages have to say who runs it.
- iggldiggl 5y ago1. The legal definition of what's "commercial" under that law and what's not isn't quite as straightforward as a layman might think. (For one, that law doesn't literally say "commercial" ("gewerbsmäßig"), but rather "geschäftsmäßig" ("business-like"), which doesn't require an intent to make money, but may include anything you plan on regularly doing). 2. Assuming you're referring to the Telemediengesetz, there's a second law (Medienstaatsvertrag) which mandates an imprint for anything that's not strictly for "personal or family purposes". Depending on who you ask, those two terms also require a rather narrow reading, so anything beyond a strictly private family diary (careful not to make references to any outside persons or businesses, though, because those entities will then have a legal interest in being able to identify you in case you malign them!) or family pictures or your private Dropbox replacement (ideally all the above should be password-protected and therefore not accessible by the general public anyway) might again already be in a grey area. 2b. Additionally, blogs can enter another grey area where depending on what and how you're blogging about, they might be classified as a journalistic service offering and therefore require an extended imprint, too.
- jmconfuzeus 5y agoFor people interested in hosting their own Plausible analytics instance. Use this Ansible bundle[0] against your Debian 11 server. It takes a few minutes to complete and you can start tracking visits in a privacy friendly manner quickly. [0]https://github.com/confuzeus/ansible-plausible https://github.com/confuzeus/ansible-plausible
- throwaway028383 5y agoBy extension, is it illegal to use Cloudflare for DNS?
- jfjrkickkfntk 5y agoIt is, if they log the visitors' IP addresses. _Some_ private individuals do have their own resolvers, after all.
- chayesfss 5y agoWhat if, say I’m using Microsoft to backend my user authentication and it’s keeping a record of ip/user here in the USA?
- throwawaymanbot 5y ago
- JRabo 5y agoThis was the only sane decision they could come to. Google's evil practices are death to any free society and a threat to the national security of any country but the U.S. where the deep-state pimps are busy siphoning Google's data to use against its own citizens. Here in the US we live in what only appears to be a free country where sociopaths, pimps and whores rise to the top and are protected by the DOJ, DHS and the whole alphabet soup of criminal organizations that protect the wealthy and the powerful. The transformation of the country from 1970 to 2022 is stark. We are headed to a dystopia led by the whores at Google.
- gigatexal 5y agoIs there a Europe-native company that could invest the tens of billions to spin up an EU-centric cloud to appease the regulators?
- srcreigh 5y agoAmazing news. Practical consequences: Huge opportunities for French tech entrepreneurs. Huge opportunities for immigrant tech entrepreneurs to France. Gets the ball rolling for other countries to implement this. And more advanced regulations. Finally, once US big tech intl influence is on a steep decline, maybe, just maybe, Google will be policed by the US government.
- sizzle 5y agoGood riddance, this is a win for giving people informed consent to be spied on via give hidden analytics.
- jbkiv 5y agoWait, I don't get it. Big tech companies don't park servers in the EU. Is it THAT difficult? Of course it is not, and they just don't want to do it. On the other hand, big tech companies are happy to park their IP in Ireland (a EU country) in a phony company, simply to avoid paying taxes. What's the logic?
- lawik 5y agoSo far they haven't solved something that resolves the problem of having US ownership as far as I can tell. The issue isn't where the servers are. The issue is what parties can compell them to hand over information. As far as I've read on it at least. And if there is US ownership you have US courts that can demand information they aren't legally allowed to hand over according to EU law.
- jfjrkickkfntk 5y agoQuestion: Shouldn't it be quite possible to use GA without client-side requests, and without sending personal data to Google? https://developers.google.com/analytics/devguides/collection/protocol/v1/devguide https://developers.google.com/analytics/devguides/collection...
- arlogilbert 5y agoIf you think that launching your app in a another region is hard, there is currently a case being evaluated in Europe which is evaluating the argument that even if the data never leaves the EU and the provider is a European entity but affiliated with or a subsidiary of a US company, that this is stil considered a violation. So unfortunately just moving hardware locations may be insufficient, even forming a new entity won't suffice. In my humble opinion we are witnessing the nationalization of the Internet, in the name of good intent, but eventually the risk vs reward calculation of doing business across the Atlantic (for either side) will tilt in the direction of avoiding the risk. Although it could be argued that "good, laws are made for people not for businesses" I'd counter that a great deal of the free information published by US companies and non-profits will become unavailable in the EEA. I'm hopeful that the DPAs and courts in Europe will decide to balance these concerns. FWIW: I run one of the more popular data privacy platforms, Osano, so this is an area we track very closely and which is near and dear to my heart. I built Osano as a Public Benefit (and certifeid B-Corp) to try and prevent the nationalization of the Internet by giving businesses an easy way to respect the rights of their customers & visitors.
- xg15 5y agoI mean, I assume the US are interested in this exchange as well. If they are, they could lead by example and reform the CLOUD act or implement some more effective data protection regulations themselves. We aren't in this mess because the EU somehow wants to nationalize the internet, we are because with current legislation, US companies can be forced to hand over whatever data they posess, no matter where it's stored. Not a lawyer, but my current understanding of the current events is more or less the EU saying "if it's subject to the CLOUD act, it violates the GDPR". That's a pretty clear indication of what's wrong.
- deleted 5y ago[deleted]
- Anthony-G 5y agoLast night I finally pulled the trigger on becoming a Supporting Member of NOYB¹ (My Privacy is None of Your Business). Seeing this story on Hacker News tonight reaffirms that decision and I’d recommend that other Hacker News users who care about data privacy do the same. Technological solutions that we use (Firefox containers, uBlock, etc.) are band-aids that work for a technically adept minority of citizens. The real struggle is political – and legal when there’s data protection legislation isn’t being enforced. ¹ https://noyb.eu/en/support-us https://noyb.eu/en/support-us
- Ourd3mocracy 5y agoIn my opinión analytics + android Should be the point of this talk.