3 ms·
It's interesting that people begin to realize now to which ridiculous conclusions GDPR taken at its word leads: - IP addresses are personally identifiable info
by dkyc 5y ago
It's interesting that people begin to realize now to which ridiculous conclusions GDPR taken at its word leads:
- IP addresses are personally identifiable information (PII), and hence require consent to process
- Transferring PII to servers outside of Europe, or servers owned by organizations with legal residence outside of Europe (aka American tech companies), is not allowed
That means it is non-compliant to host your website at e.g. AWS, because it would mean AWS has technical means of accessing your customer's IP addresses, and AWS is owned by an American company. It doesn't matter whether you use a EU-based data center, because he jurisdiction of the parent company matters. This effectively rules out AWS, Google Cloud, Azure, and of course pretty much all CDN providers.
And effectively everyone is non-compliant.
- krageon 5y ago> ridiculous conclusions > - IP addresses are personally identifiable information I really thought you were going to go in a different direction than this. This is very obvious and there's nothing ridiculous about it. To most people in the EU, an IP address gives a very high resolution to a person. > That means it is non-compliant to host your website at e.g. AWS Yes, this is correct. AWS, Azure and GCP cannot possibly be compliant. It's taking everyone a while to figure this out. There's nothing wrong with that, privacy-sensitive information should never touch the US. No US-based company can guarantee your privacy. > effectively everyone is non-compliant. This is of course hyperbole. If you don't log or track you are perfectly compliant in every case.
- dmitriid 5y agoAdditionally, for data that's strictly needed for your business, you don't even need to ask consent, but you're responsible for keeping data safe. It's weird how the whole "you need to keep your users' data safe and not collect more than is necessary" is such a controversial topic for some on HN.
- krageon 5y ago> It's weird how the whole "you need to keep your users' data safe and not collect more than is necessary" is such a controversial topic for some on HN. I think it stems from a long lawless time online where everyone was free to aggressively exploit everyone else. The fact that such behaviour is becoming frowned upon is something that we should expect will generate some friction. That said, I also find it hard to empathise with.
- dkyc 5y ago> If you don't log or track you are perfectly compliant in every case. But that is simply not true, right? If I host my website on AWS and 'log or track' nothing I am still not compliant. It's not about what I do as a website provider, it's effectively outlawing working with companies based in other jurisdictions.
- krageon 5y ago> based in other jurisdictions. Instead of this we can just say "the US" and only because of local laws and hyper-invasive corporate culture.
- dkyc 5y agoIt's definitely 'other jurisdictions'. There's a (short) whitelist of countries that are deemed adequate, which you can find here: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en https://ec.europa.eu/info/law/law-topic/data-protection/inte... To save you the click, it's Andorra, Argentina, Canada, Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, the United Kingdom and Uruguay. These are 14 countries.
- krageon 5y agoYou can use a provider from anywhere, as long as you know they do not track. "The effect of such a decision is that personal data can flow from the EU (and Norway, Liechtenstein and Iceland) to that third country without any further safeguard being necessary." operant words being "without any further safeguard".
- freemint 5y agoMy impression was they can very much be compliant as long as they sign a contract with you that they only process data themselves in manner compliant with GDPR in the services you make available for EU citizens.
- erik_seaberg 5y ago> If you don't log or track you are perfectly compliant in every case The GDPR is not merely a list of bad things not to do. You must also hire people to carry out slow and expensive processes to continually demonstrate compliance, e.g., https://gdpr-info.eu/art-36-gdpr/ https://gdpr-info.eu/art-36-gdpr/.
- martin_a 5y ago> And effectively everyone is non-compliant. You know that's blatantly wrong. Choose an EU-based webhosting provider, don't use "the usual suspects" in regards of tracking or run your own Matomo instance and save as little data as necessary. Compliance done.
- dkyc 5y agoOne data point, that I just found after a few clicks: Homepage of the 'Council of the European Union' (https://www.consilium.europa.eu/en/ https://www.consilium.europa.eu/en/). On opening, loads resources from 'newsroomcdnakamai.azureedge.net'. If compliance is such a breeze, I wonder why the very institutions that took part in creating those regulations are not able to comply (after almost 5 years now)?
- jlokier 5y agoAre you sure newsroomcdnakamai.azureedge.net is non-compliant? From client IPs within the EU, that domain resolves to EU-based hosting locations, so it's plausible that all of the PII protections and contracts are in place.
- dkyc 5y agoYes: the point is that it is owned & controlled by Microsoft. The actual location of the data processing doesn't matter if the parent company is bound to US jurisdiction (which Microsoft is).
- lmkg 5y agoQuick fact check. GDPR says IP Addresses are personal data, although this is a clarification of a previous court ruling. Personal data does NOT need consent to process. Consent is only necessary in a minority of cases, and certainly not regular website access. The idea that GDPR <==> is a misunderstanding. (This is closer to true when dealing with website cookies, because of a different and stupider law.) GDPR does not prevent transferring data outside of Europe. It just says that data privacy must be respected, in one of a variety of ways. The problem is the US CLOUD Act, which basically says US companies are bound by US law even when operating in other jurisdictions. EU Courts have ruled that US companies bound by the CLOUD Act cannot safeguard data. And they aren't wrong. By comparison, data transfers to the UK or Japan require nothing more than putting the words "adequacy decision" in your privacy policy. This is because those countries have laws safeguard privacy, as opposed to laws safeguarding law enforcement's access to personal data.
- dkyc 5y agoThanks for the corrections. What my original statement meant to convey was not simply disagreement with GDPR, but more that two somewhat unrelated edge case decisions ("do 'just' IP addresses count as PII", and "can one work with American suppliers") gave this regulation a scope that I believe wasn't even intended by the original lawmakers (as evident by their own failure to be compliant, see other comment thread), and that very much goes against the realities of the Internet of the past 25 years. That being said, your corrections are valid and give a more precise description of the situation rather than my initial comment.
- lmkg 5y agoThat's a fair point. At the time GDPR was passed, there was an Adequacy Decision in place (Privacy Shield), so the political expectation was that US<->EU data transfers would be OK. One way of looking at things is that the political landscape ("we can work with the US") were not in alignment with the legal landscape (US law does not prioritize privacy safeguards). Max Schrems & noyb are forcing Europe to reconcile that schism and bring practice into alignment with legal requirements rather than political requirements. This is causing disruption, but I'm of the mind that it's not unjust, it's a matter of finally having to pay the piper.