8 ms·
Some time ago Google gave EU admins the option to select a local regional (EU) server. This means the data is not send to the US. But! It’s still nog fully lega
by digitalengineer 4y ago
Some time ago Google gave EU admins the option to select a local regional (EU) server. This means the data is not send to the US. But! It’s still nog fully legal as the Google HQ (and thus the US government( can still access all the data.
- y42 4y agoLike Adobe, who uses tracking servers in the EU, but Data Processing happens in the US?
- googlryas 4y agoWhy is that not fully legal? Wouldn't the same law prevent Google USA from querying PII data from Google Italia?
- marcosdumay 4y agoItalian laws do not apply to Google USA.
- googlryas 4y agoNot generally, but they do apply to Google Italia, who would not legally be allowed to respond to requests from Google USA for European PII.
- marcosdumay 4y agoYes, the Italian law that prohibits sending data abroad applies to Google Italia, but Google USA is submitted to the USA law, that says that the USA government can request any data from Google Italia and they are required to get it. So the existence of Google USA makes Google Italia operation illegal.
- baq 4y ago...in USA.
- Knufferlbert 4y agoWell, depends, fundamentally it's a paradox. Either US company get's the data from the Italian one, making the Italian operation illegal in Italy Or The US company doesn't get the data from the Italian one (despite ownership), making the US company illegal in the US. I don't think anyone is under the illusion that the latter option is chosen when push comes to shove.
- lovich 4y agoThe Italian market doesn’t have to apply to Google USA either. Companies can always choose to ignore a specific nation’s laws[1], they don’t still get access to that nations markets. At the borders the nation state is the one with the guns and firewalls [1] unless you piss off a nation that can project global power, lol if you piss off China or America
- justinclift 4y agoFirst time I've heard of China projecting "global power". Are there cases of it happening?
- dmitriid 4y agoApple complying with Chinese laws, and providing Chinese government access to private data. Google, Facebook etc. being blocked in China. etc.
- hef19898 4y agoAll over Africa, in a more heo political sense. Also along the new silk road all the way to Europe. Just to name two.
- lovich 4y agohttps://www.scmp.com/news/china/article/1714248/more-chinese-police-officers-sent-overseas-hunt-down-its-fugitives?linker=1%2a1m2xfne%2aclientId%2aYW1wLXRwcVlzTk1jNzBCbUhPaEF2eXJHdkE https://www.scmp.com/news/china/article/1714248/more-chinese.... Chinese and American police forces both operate abroad and like to flex their power. The NYPD was in a similar situation post 9/11 when they started trying to police nearby states and when they sent operatives to other countries even against their own federal government [1]. Russias also sent operatives overseas in some fairly public assassinations. It’s not really surprising that China does this, it appears to be the default operating procedure of powerful countries [1] http://america.aljazeera.com/watch/shows/the-stream/the-stream-officialblog/2014/1/7/nypd-s-overseas-presencecriticizedbyfederalofficials.html http://america.aljazeera.com/watch/shows/the-stream/the-stre...
- 4y ago
- connicpu 4y agoBut someone will have to foot the bill when their branch in Italy is fined by the government for violating Italian law
- wonderbore 4y agoOh yes they do. GA is part of a company that also sells services in Italy. They should follow the law if they want to keep earning that non-US Adwords money that allows GA to remain free.
- digitalengineer 4y agoIf Google US can access the data, that means the US government by extension can also. This is exactly what GDPR doesn’t want happening. More details in this open letter by Max Schrems “ the Court has clearly held that US surveillance laws and practices violate Article 7, 8 and 47 of the Charter of Fundamental Rights” https://noyb.eu/en/open-letter-future-eu-us-data-transfers https://noyb.eu/en/open-letter-future-eu-us-data-transfers
- kixiQu 4y agoif anyone is curious about why that gives the govt. access: https://en.wikipedia.org/wiki/CLOUD_Act https://en.wikipedia.org/wiki/CLOUD_Act (God willing they repeal it, even if only for the international commerce implications...)
- DyslexicAtheist 4y agosomething I'm not getting here. If you buy a EU engineered IoT home appliance that has PII including, whether a user is presently inside their home, then every company I know operating in this market uses US based clouds (what other options are there LOL) to do things like digital twin or device shadows but by using a local availability zone. So this is very different than GA, but depending on the threat-model can be worse. Also very similar metrics can be gathered from the data as from a GA cookie (are they eating, cooking, showering, watching TV). CloudAct would (or should) in this case also apply here or what am I missing?
- undefinedzero 4y agoThe watchdogs are extremely slow and have a huge backlog. You’re right that storing that data in the US or without transferring ownership to an EU subsidiary would not be legal.
- toyg 4y agoYou're not missing anything. A lot of companies just have no idea of the legal landscape, or simply ignore it in the name of convenience. That's because consumers are even more ignorant of their rights around technology and don't sue them. It will take a lot of civil litigation for this to change.
- spockz 4y agoI am only aware of Hetzner. (German) The other day I was checking out there offerings and I was amazed at how easy it is to order a vm. And then it is live the next second. It is amazing. Obviously they don’t have full range of services the big three have. But maybe just enough anyway.
- cavisne 4y agoThe article has the watchdog suggesting exactly that (the specific site has 90 days to use GA in a compliant way, no direct complaint against GA), so it seems from their point of view it's legal. The title of this post and a lot of the comments are projecting what they want GDPR to be (all non european online entities banned from doing business in the EU) vs how its being enforced.
- sebazzz 4y agoOn the last point: how does that work with cloud computing providers, as all the big ones are US-based?