7 ms·
So really every website, even HN, that doesn't shard all EU data away in a separate EU datacenter (if they aren't already based in the EU) is illegal?
by cyral 4y ago
So really every website, even HN, that doesn't shard all EU data away in a separate EU datacenter (if they aren't already based in the EU) is illegal?
- jacquesm 4y agoNo.
- mminer237 4y agoCorrect. Also note that IP address are counted as PII, so even sending an IP address (as required by any TCP/IP request) to a US-located or US-controlled server is illegal without getting consent beforehand.
- tomkarho 4y agoI'm not sure that's how it works. Couple of things (IANAL): 1. I don't think ip address alone constitutes PII but needs to be combined with other data to be applicable 2. Even if it were, I would imagine it falls under article 6 provisions where ip is required information to fulfill a contract which in case of HN as an example means delivering the web page to the browser
- josefx 4y ago> 1. I don't think ip address alone constitutes PII but needs to be combined with other data to be applicable According to courts just the IP is considered enough: The decision says IP addresses represent personal data because it's theoretically possible to identify the person associated with an IP address, and that it's irrelevant whether the website or Google has actually done so.[1] [1]https://www.theregister.com/2022/01/31/website_fine_google_fonts_gdpr/ https://www.theregister.com/2022/01/31/website_fine_google_f... Of course this was a case where sending the IP to Google was not necessary to operate the site, as self hosting the fonts was an option.
- jacquesm 4y agoYes, but that's not using the site, that's logging the IP.
- raverbashing 4y ago> even sending an IP address (as required by any TCP/IP request) to a US-located or US-controlled server is illegal Nope. Having the IP for making a TCP/IP connection is a technical requirement, one of the exceptions of GDPR (this also applies for logging, etc as long as you don't keep it forever, etc) Let's not make up requirements where they don't exist
- srrr 4y agoThat is not true. IP addresses are explicitly stated as personal data. That they are a technical requirement for a connection only has repercussions on how you are allowed to store and process this data and the consent you need to get from the user for your data processing. You are not allowed to send IP addresses (even if they are a technical requirement for connection set up) to companies under US government control before you get full consent from the EU user. The "technical requirement" exception (to process data without consent) only applies to GDPR complaint data processors which US companies can't be because of the Cloud Act. https://ec.europa.eu/info/law/law-topic/data-protection/reform/what-personal-data_en https://ec.europa.eu/info/law/law-topic/data-protection/refo...
- jacquesm 4y agoThere is a huge difference between using your IP address in the course of the technical implementation of the IP protocol and the subsequent logging and re-transmission of that address to others, effectively you are agreeing with the GP while starting your comment with 'that is not true'. It is true. And you confirmed it.
- srrr 4y agoFrom what I understand the legal exception to process personal data without consent is written down in Article 6 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN#d1e1888-1-1 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... (paragraph b) "(1) Processing shall be lawful only if and to the extent that at least one of the following applies: (b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;" This is ok for GDPR complaint data processors. The reason why US companies can't be GDPR complaint is because of Article 5 and the conflict with the Cloud Act: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN#d1e1807-1-1 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... (paragraph f) "(1) Personal data shall be: (f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’)." See also Schrems II: https://en.wikipedia.org/wiki/Max_Schrems#Schrems_II https://en.wikipedia.org/wiki/Max_Schrems#Schrems_II It doesn't even matter if you asked for consent or have other reasons to process the data (Article 6) if you are not complying with Article 5.
- kmeisthax 4y agoNo. This part of the rules only applies to EU businesses. If an EU citizen deals with a US business, the US business still has to follow GDPR, but not the export rules. EU businesses do have to follow said rules.
- ricardobeat 4y agoOnly if they are storing personal data (including IP addresses).
- GekkePrutser 4y agoHN doesn't use Google analytics AFAIK and they don't have any of my personal data, not even my real name. So it's not as much of an impact.
- _Algernon_ 4y ago~~You register with email, so they definitely do have personal information.~~ Edit: you don't have to register with email, so I was wrong. My bad.
- jacquesm 4y agoEmail can be personal information but does not have to be, and no, you don't have to register with an email at all for HN, that's just nonsense, and your own account is pretty much proof of this.