5 ms·
This is silly, next up CDNs violate GDPR.
by viro 5y ago
This is silly, next up CDNs violate GDPR.
- jaywalk 5y agoThis ruling basically does say that embedding any third-party resources in your page is a GDPR violation. It is silly, and I'm not sure why you're getting downvoted. This ruling can't be allowed to stand.
- Lascaille 5y ago>This ruling can't be allowed to stand. Sounds like a great ruling from a security and user perspective. Just changes a design paradigm. If it kills a business model that's based on intrusive user-tracking and the user being totally unable to know who has their data and who their computer should vs shouldn't be connecting to - great. Trying to figure out from traffic analysis alone these days whether a website is malicious or not is an absolute nightmare as every single site pulls in 20 or 30 externally-hosted resources for totally impenetrable purposes. Let's migrate to an easily understandable model where sites host 100% of their own resources. If that means the site engine has to run CI behind the scenes and pull in those resources, great, it centralises responsibility.
- rezonant 5y agoHow about for video? This effectively kills the ability for a small website to pay for video hosting services from a well scaled video CDN. This effect can be generalized: At some point the only organizations with the resources to comply with the GDPR are in fact the big tech companies.
- jaywalk 5y ago> If it kills a business model that's based on intrusive user-tracking and the user being totally unable to know who has their data and who their computer should vs shouldn't be connecting to - great. What are you talking about? You can always block whatever you want, and we're not talking about "intrusive user-tracking" here but literally just an IP address. You can have the opinion that websites shouldn't use third-party resources, but legislating that requirement is beyond ridiculous. There are countless good reasons for using third-party resources on websites, and disallowing it will absolutely make the web a worse place regardless of any "privacy" benefits it could have.
- dleslie 5y agoOnly third party CDNs.
- gred 5y agoI wonder where the line is drawn? If you set up AWS CloudFront, does that count as third party? Or is this taking us back to colo / in-house data centers?
- lmkg 5y agoSo far, the line that has been drawn by the courts is "is the IP address visible to a company subject to the CLOUD Act in the United States?" AWS CloudFront would meet that definition: Amazon is covered by the CLOUD Act, and the visitor's IP address is visible when using that service.
- gred 5y agoThanks for the clarification. Seems crazy to me, but hopefully a compromise is worked out soon.
- lmkg 5y agoThat already happened. Cookiebot (Danish) was fined for using Akamai CDN. Note that it's not all CDNs, fonts, etc. It's ones that are subject to the CLOUD Act in the United States. Non-American companies, or even US companies which are not subject to the CLOUD Act, might be OK.
- jeroenhd 5y agoIt's not just American companies, though; African, Australian, Canadian, Mexican and Russian companies have the exact same restrictions. The general rule is "privacy enforcement and protections must be as good or better than the EU's". It's possible for a country to get certification from the EU that the privacy protections of said country are strong enough. When that happens (see the failed Privacy Shield and friends for an example), you can let companies from those countries process PII if there are significant protections built into the contract (say, a huge fine to you if they mess up and leak the data of your customers, as the EU cannot impose their own fines as easily). From what I can tell, the contracts and DPAs most American cloud providers eagerly send you are good enough to satisfy this constraint if the companies weren't subject to American law.
- lmkg 5y agoI see where you're coming from, but that's not quite true. GDPR basically puts international transfers into two buckets: Adequacy Decision, and Other. Adequacy decision means the other country's laws are "good enough," and your obligations are literally just to put the words "Adequacy Decision" in your privacy policy somewhere. Other means you need to take "additional safeguards" to ensure data privacy is protected. This is a bit of a bother, but eminently feasible. The "standard" way to do this is put additional terms in the contracts you sign with third parties (and only use third parties where you have signed contracts). The situation with the United States is unique: the EU have ruled that no possible safeguards are good enough. US law enforcement's needs override any contract you can sign, so it is legally literally not possible for an American company to safeguard data. This makes data transfers to the US substantially more restricted than data transfers to any other third-party country.
- jeroenhd 5y agoIf those CDNs are hosted in countries complying with the GDPR, then they're not. If the CDNs don't, they are.
- lmkg 5y agoSadly, no. Cookiebot was fined for using Akamai CDN, even though the court accepted the CDN servers were located in the EU and operated by Akamai's EU subsidiary. The EU court ruled that the American CLOUD Act still claims to have jurisdiction.
- jeroenhd 5y agoYou're right, but that's because exchanging data with the EU subsidiary isn't accepted by the GDPR. Like I said, a GDPR-compliant CDN is permitted. The problem is that this precludes most, if not all, American CDNs.
- Silhouette 5y agoBut given that many governments now grant themselves similar legal powers to inspect data held by corporations under national security legislation, in some cases including data held abroad but by a corporation within their reach, that is roughly equivalent to saying that only CDNs operated entirely within the jurisdiction of EU member states are allowed (because the GDPR conveniently allows similar intrusive behaviour if it's an EU member state that's doing it).
- draw_down 5y agoPeople wonder why sites just throw up their hands and block Europe instead of playing the EU’s game. Actions have consequences.
- vntok 5y agoSites are perfectly allowed to do just that... of course doing that they deprive themselves of an enormous, rich and growing market, a market that will surely be tackled by regional companies more respectful of their customers.
- jokethrowaway 5y agoAs a European, I hate this. It deprives me of choice in name of a privacy I don't care about. Google is welcome to track me. The net effect is that half of the us newspapers I try to read don't allow me to even read the content. I guess I need a VPN, Europe is slowly turning into China
- draw_down 5y ago
- Lutger 5y agoIt is not silly to protect the personal information of citizens. Whats silly is how the web is entangled with violating privacy and ownership of data, and it is considered as the just and normal thing to do.