2 ms·
> If you don't log or track you are perfectly compliant in every case. But that is simply not true, right? If I host my website on AWS and 'log or track' nothi
by dkyc 5y ago
> If you don't log or track you are perfectly compliant in every case.
But that is simply not true, right? If I host my website on AWS and 'log or track' nothing I am still not compliant. It's not about what I do as a website provider, it's effectively outlawing working with companies based in other jurisdictions.
- krageon 5y ago> based in other jurisdictions. Instead of this we can just say "the US" and only because of local laws and hyper-invasive corporate culture.
- dkyc 5y agoIt's definitely 'other jurisdictions'. There's a (short) whitelist of countries that are deemed adequate, which you can find here: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en https://ec.europa.eu/info/law/law-topic/data-protection/inte... To save you the click, it's Andorra, Argentina, Canada, Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, the United Kingdom and Uruguay. These are 14 countries.
- krageon 5y agoYou can use a provider from anywhere, as long as you know they do not track. "The effect of such a decision is that personal data can flow from the EU (and Norway, Liechtenstein and Iceland) to that third country without any further safeguard being necessary." operant words being "without any further safeguard".