7 ms·
Speaking of adapting the product, the article explicitely states : "Is it possible to set the Google Analytics tool so that personal data is not transferred ou
by kmitz 4y ago
Speaking of adapting the product, the article explicitely states :
"Is it possible to set the Google Analytics tool so that personal data is not transferred outside the European Union?"
"No."
So right now it is practically impossible to use Google Analytics in a legal way in France.
- jeppester 4y agoIt's a very common misunderstanding (which is happily spread by US cloud providers) that it matters where the data is stored. What matters is that the data is stored by - and accessible to - a company which submits to the US laws.
- 8ytecoder 4y agoI don’t think it has been tested in court. It’s akin to a U.S. Court issuing a search warrant on a house in Paris.
- Gwypaas 4y agoWhich is exactly what happened and is causing this mess. https://en.wikipedia.org/wiki/CLOUD_Act https://en.wikipedia.org/wiki/CLOUD_Act No problem at all with GDPR and third countries. They simply need to have a regulatory framework making compliance possible. https://www.imy.se/en/organisations/data-protection/this-applies-accordning-to-gdpr/transfer-of-data-to-a-third-country/ https://www.imy.se/en/organisations/data-protection/this-app...
- GekkePrutser 4y agoThe problem is that frameworks we have with the US keep being shot down by the EU judiciary. First Safe Harbor and now Privacy Shield. For good reason I might add.
- moontear 4y agoYes, it has been tested: https://amp.theguardian.com/technology/2015/sep/09/microsoft-court-case-hotmail-ireland-search-warrant https://amp.theguardian.com/technology/2015/sep/09/microsoft... And that’s exactly what it would be like, though the house in Paris would be owned by a company that has a legal entity in the United States.
- retcon 4y agoEqually it's a sorry indictment of our economic times that the meaning of unlawful has been hammered into a understanding that non prohibition is permission. This aggressive and putative new use is refuted by every founding principle of the common law in Anglo Saxon countries and most of the western world. See the argument of letter vs. spirit for a effect. Ed. cleared up phrasing around new use, replaced meaning with use for .. meaning.
- Georgelemental 4y ago> non prohibition is permission That is exactly how things work. Unless the government goes through the effort of passing a law to prohibit something (and getting approval of the people's elected representatives, and the courts), then the thing is legal. How else do you propose things should work?
- cmroanirgo 4y agoThose "pushing the boundaries" always end up using a similar logic. However, there's always going to be a large segment of society whose rules are based around non financially oriented methodologies, such as: "morals", or directly from spiritual texts which disallow certain practices, or historical "customs". Such things are not "illegal" per se, but it's largely held as being reprehensible by a large number of people nevertheless & causes a large amount of friction within society. Then there's the issue of marketing/propaganda (which the parent mentions as "hammered") whose sole purpose it's to change people's minds in an emotional way. I wish people would learn about Edward Bernays, nephew of Freud, who instituted this. In and of itself, propaganda has never been illegal, but no one likes to admit to being emotionally manipulated. (But when you begin to pay attention to your emotions, you can spot this stuff from a mile away).
- judge2020 4y agoNot sure what the stance being argued is. Should we require companies run morality polls and submit a pre-rollout court to determine the legality of new products that push the limits of human innovation? Also, it's important to note that humans are actually quite bad at this sort of judgement. I'm sure if you showed everyone in Germany in 1980 a computer, and how it can instantly store and retrieve files and documents, and asked them 'is this moral?' they would be against it on the grounds that it would put hundreds of office workers out of a job.
- e98cuenc 4y agoWhy are then things like AWS, Azure, Google Cloud, … legal? Are they? I assume Amazon can access data stored in any of their servers, right?
- darkwater 4y ago> I assume Amazon can access data stored in any of their servers, right? If you encrypt the data with your own key, they should not be able to access it.
- fauigerzigerk 4y agoOnly if you encrypt before upload and decrypt after download, which renders almost all AWS/Azure/GCP services completely useless.
- darkwater 4y agoIn-transit encryption protects you against this attack scenario specifically (if you own the keys obviously).
- fauigerzigerk 4y agoHow so? Amazon, Google and Microsoft need access to your unencrypted data in order to provide most of their services (such as databases, analytics, machine learning). There's not much they can do with encrypted data. They can store it. They can pass it through. That's it. This problem has to be solved on a political level. There is no technical fix and the legal workarounds appear to be exhausted.
- darkwater 4y agoMy RDS data is stored encrypted on disks with a private key AWS operators has no access to [1] (or at least that's what they tell you), and the application layer connection is controlled by a password transmitted over a TLS-only connection, whose private key - again - AWS has no access to. [1] https://aws.amazon.com/blogs/database/securing-data-in-amazon-rds-using-aws-kms-encryption/ https://aws.amazon.com/blogs/database/securing-data-in-amazo...
- verisimi 4y agoIn what sense does it matter? Corporations such as google have legal and financial centers all over the world and these will be structured towards providing the best circumstances for the corporation (tax, legal). On the other hand, don't all these corporations have data centers all over, that replicate data to provide a better service? Which is to say that pretty much most data is available to all legal jurisdictions. At least as I understand it..
- zagrebian 4y agoWhat personal data does GA collect?
- Nextgrid 4y agoIP addresses for starters, which are considered personal data under the GDPR. Keep in mind that the mere transfer of the IP address (which is inherent in a TCP connection and cannot be avoided in the default setup without proxying it yourself) is enough, regardless of whether Google will actually store said IP or anonymize it (not that you should trust them in any case).
- judge2020 4y ago> IP addresses for starters, https://support.google.com/analytics/answer/2763052?hl=en https://support.google.com/analytics/answer/2763052?hl=en
- Nextgrid 4y agoHave you read the second paragraph of my reply?
- fooster 4y agoIP addresses by themselves are not personal data.
- manuelmoreale 4y agoThey are according to the GDPR and that’s all that matters when it comes to the issue discussed here.
- martin_a 4y agoThey can be used to track and identify users, so they are personal data. My IP address hasn't changed in some time, so if someone was to connect various sources of information, he would be able to identify me personally
- corobo 4y agoYou should be able to put the GA loading script behind your cookie banner -- never even load the script until the user allows third party cookies. Is there an issue with this technique? I've not managed to poke holes in it yet but have at it.
- hedora 4y agoThe article also makes it pretty clear that it would be illegal (in the US) for Google to offer a version that is legal in the EU, barring some major technological and algorithmic breakthrough, or changes to the law.