18 ms·
Usage of EU subsidiaries of US cloud providers deemed unlawful by German court
- jiggywiggy 4y agoYeah wondering about the consequences. By this logic almost every non-EU Saas would be forbidden. For sure Stripe is also not allowed, huge amount of customer data in US hands.
- superchroma 4y agoIMO that could be good, I would welcome more competition in the payment processor space.
- nickff 4y agoBut this won't encourage more competition in the EU, it will limit the number of competitors by creating an insurmountable barrier to entry for foreign providers. This is akin to import controls, which often cause stagnation, and generally lead to more costly and inferior goods.
- arlort 4y ago> non-EU The problem isn't non EU services, it's the US CLOUD act Other countries have legal systems which are considered as offering equivalent protection: > The European Commission has so far recognised Andorra, Argentina, Canada (commercial organisations), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland , the United Kingdom under the GDPR and the LED, and Uruguay as providing adequate protection. And for many more countries standard contractual clauses would probably be enough
- Ekaros 4y agoUruguay? I wouldn't exactly call them for known being a tech nation... So why does USA fail at this? Or are they just too big and diverse for that sort of stuff? And you can't really expect such nation to succeed... In anything...
- arlort 4y ago> I wouldn't exactly call them for known being a tech nation And? > So why does USA fail at this? Because, and I'm going from memory here, should be Schrems I or Schrems II if you want to dig deeper, in the view of the ECJ (which invalidated a similar recognition for the US) the US doesn't provide a satisfactory way for EU citizens to contest their data being accessed by US government agencies
- simsla 4y agoIt's not a tech issue, but a govt issue. Look up the cloud act. It essentially makes it impossible for any US company to truly comply with GDPR.
- deleted 4y ago[deleted]
- wewxjfq 4y agoStill works with consent.
- rubito 4y agoThis is about getting qualified in comunal/state procurement and not general public business.
- jiggywiggy 4y agoAs far as I understand the reasoning is that the accepting of a bid of on of the companies in not allowed because they don't comply with the GDPR law. Although it was filed by a competing company it theoretically would mean according to this judge cloud hosting is not in line with GDPR. In that line, wether you are a governmental organisation or company doesn't matter if they decide to enforce it as such.
- srrr 4y agosummary (English): https://gdprhub.eu/index.php?title=VK_Baden-W%C3%BCrttemburg_-_Az._1_VK_23/22 https://gdprhub.eu/index.php?title=VK_Baden-W%C3%BCrttemburg... news article (German): https://www.golem.de/news/vergabekammer-clouddienste-von-us-firmentoechtern-sind-nicht-dsgvo-konform-2208-167456.html https://www.golem.de/news/vergabekammer-clouddienste-von-us-... primary source (German): https://rewis.io/s/u/PjK/ https://rewis.io/s/u/PjK/ press statement of law firm (German): https://gruendelpartner.de/newsroom/gruendelpartner-erwirkt-weitreichende-entscheidung-zur-unzulaessigkeit-von-cloud-und-it-dienstleistungen-durch-us-tochterunternehmen-in-deutschland/ https://gruendelpartner.de/newsroom/gruendelpartner-erwirkt-...
- tpmx 4y agoGolem.de article key phrase: "The use of a US cloud service can justify exclusion from a public procurement process." (The emphasis is mine. Almost all commenters here so far seem to think it's broader than this, which it isn't.)
- nslzk 4y ago
- barbazoo 4y agoWhat's the "proof" here and what is "this" referring to?
- jimbob45 4y agoIsn’t this sort of what we accuse the Chinese of doing? The US designs the technology and then the Chinese manufacturers steal that design to make their own? Except now, the EU is more or less forcing American companies to sell unaffiliated spin-offs to the EU to continue doing business there. Seems a bit underhanded to change the rules now after so long, especially considering the fact that the EU can’t make these companies for themselves or they would have already.
- pfortuny 4y agoThis is germany still, not the whole of the EU. But it does show how an all-reaching law like gdpr can have stramge consequences…
- f-jin 4y agoisn't the crux of the matter the all-reaching laws of the US that allows their intelligence agencies to order EU-subsidiaries of US companies to offer up their data..?
- xyzzyz 4y agoI would be frankly shocked if EU countries did not have the same laws on the book. If German court serves Volkswagen AG a warrant for data kept by Volkswagen America, can Volkswagen AG just not comply?
- angio 4y agoThey can fight in an american court. The issue is the cloud act which was passed explicitly to fight eu companies fighting in eu courts us govt data requests.
- solar-ice 4y agoPretty sure EU countries cannot in fact (in general) demand personal data of anyone from EU companies without due process. If you can find law to the contrary, let me know.
- fvdessen 4y agoLooking for an informed opinion; what are the practical consequences for European companies using American cloud providers (which I guess is most of them) ?
- deleted 4y ago[deleted]
- londons_explore 4y agoImmediate consequences... None. While all of your competitors are still using american cloud services, you won't get fined. But as soon as competitors start moving to european hosting solutions, you need to too - because if you're slow to move over you can bet the courts will be chasing after people with fines.
- rubito 4y agoNot a problem with consumer facing services but usually problematic with comunal and state related projects that store personal data.
- kazen44 4y agoin my opinion, most european companies are not using the cloud (especially if they are not in the tech space). Colocated hosting is very, very large in europe, and many small/medium bussinesses operate out of a couple of VM's on a server in some datacenter, usually managed by some MSP. Also, Egress fees are very expensive in the cloud, especially if you look at the cost of data transfer inside colocated facilities. data transfer in the US seem expensive even if you look at colo/private circuits compared to europe.
- miohtama 4y agoDoes anyone know the Company A and Company B in the question? Microsoft? AFAIK public procurement documents are often public.
- srrr 4y agoSearching for "12.1 Regions. Customer can specify the location(s) where Customer Data will be processed within the" (as mentioned in the verdict) yields AWS as the problematic sub-processor for company A: https://d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdf https://d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdf
- plandis 4y agoUS needs to economically retaliate in kind. If the US has the same data protections as the EU they’d make up some other excuse to attack US companies. This is what happens when you can’t compete you make up regulatory excuses. I’m sure I’ll get downvoted by Europeans but it’s the truth. Look at the valuable companies and where they are located :)
- ROTMetro 4y agoYou should see how the EU screws American 'certain industry' companies and fails to honor reciprocity deals. Then add that it is legal and tax deductible for German business' to bribe/kickback to corrupt businesses overseas and man does Europe have a sweet deal without our 'open and reciprocal trade'. Unfair denied access to European markets but open access for Europe in the USA. Overseas company's officials expecting bribes/kickbacks like the Germans give overseas.
- superchroma 4y agoThe American government tolerates this and other things besides (e.g. lax NATO contributions) so it's evidently not that big an issue?
- lizardactivist 4y agoThe NSA and the CIA have been at that for decades. But of course people like you believe it is and has always been fully in their right.
- superchroma 4y agoSure, they can champion their own citizens' rights on issues of where and how data is stored, and prevent American user data from being sent offshore in Europe. That would be ideal. :)
- plandis 4y agoIt’s not about that. Even if the US copied German law verbatim Germany would just find some other excuse to harm the US. They can’t compete so they unfairly try to prop up their own companies via regulatory means.
- michaelbuckbee 4y agoThe context for this: say you're a SaaS and you want to tap into the EU market. Per GDPR, personally identifiable data shouldn't leave the jurisdiction of the EU so you should use EU hosted servers, storage etc. So you might then split your app to an EU hosted datacenter of your preferred cloud provider. This ruling says that's insufficient as while the data remains functionally in the EU it's still possible for it to be accessed on the backend by non EU entities.
- CGamesPlay 4y ago> it's still possible for it to be accessed on the backend by non EU entities. Why is this the case? Why aren't EU employees who allow the data to leave the EU negligent?
- jaywalk 4y agoWhat if there are no EU employees?
- rad_gruchalski 4y agoDo you mean "liable" instead of "negligent"?
- michaelbuckbee 4y agoIt's not the employees so much as the legal aspects of it: aka could the FBI compel a cloud provider to give them all the data in the EU datacenter?
- intunderflow 4y agoAnd slowly but surely the tidal wave of the consequences of GDPR versus the CLOUD Act come into view. It will take many years to of delays and fretting (due to the dependence on US clouds) but fundamentally the current legal position is that GDPR is fundamentally incompatible with any personal data transfer to the USA, that's how Google Analytics keeps getting banned too. At some point this will all come to a head and something will have to budge given the gigantic consequences of such a position, from AWS to GCP to Stripe to even basic things like your Domain Registrar.
- the_duke 4y agoThe cloud providers can work with independent operators that run their cloud solutions in Europe. Basically an on-premise setup, just on a huge scale. Microsoft initially did this for Azure, I believe. Certainly will cause a lot of friction.
- xdennis 4y ago> The cloud providers can work with independent operators that run their cloud solutions in Europe. Does that exempt them from the CLOUD Act? If US companies have access to independent operators in Europe, presumably they can still be compelled to give that data to the US.
- eli 4y agoBut couldn't the NSA still spy on European cloud providers and domain registrars?
- rubito 4y agoThere is no tidal wave, Telekom partnered a long time ago with Microsoft for an EU only azure offering and it was sacked quickly because the demand from public procurements where too low since those largely require on-prem solutions.
- Lx1oG-AWb6h_ZG0 4y ago> It followed that company A's service qualified as an unlawful transfer of data to a third country because their parent company was located in the US, violating relevant data protection law (Article 44 GDPR). > The Chamber explained that a transfer in this context must also be assumed when data can be accessed from a third country, regardless of whether this actually takes place. The fact that the physical location of the server that provides such access was located in the EU was irrelevant. I think this is an interpretation of GDPR that most companies are not prepared for. You could write an implementation that restricts access to EU data, but if the parent company is not in EU, I guess the implementation could always be changed to allow access. Ergo, GDPR violation?
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- mgraczyk 4y agoSounds like blatant protectionism to me. If I'm reading the ruling correctly, the relevant legal standard applied here is completely bogus. They find that it is a violation of GDPR because the parent company could access the data, in principle if they wanted to. It doesn't matter if there are safeguards, technical, or institutional preventions in place. However, the exact same argument applies to any EU company with any internet connection, and directly applies to any EU company with infrastructure in the US. EU companies could, in principle, transfer data to the US intentionally or by accident. If technical, institutional, and legal prevention isn't good enough for US companies, why is it good enough for EU companies? Seems like GDPR has to also be construed to prevent EU companies from doing business in the US. If the counter argument is that US companies could be compelled by the US government to hand over data, while EU companies cannot be, that is factually untrue.
- testaccountfor 4y agoUS cloud companies can be forced by the US government to spy on European citizens. That's the reasoning behind this ruling. Are you not aware of the NSA spying programs?
- wins32767 4y agoI'm sure industrial policy and thus economics had no factor in those laws being written.
- testaccountfor 4y ago
- mgraczyk 4y agoRight, that's why I included my last paragraph. EU companies can also be forced by the US government to spy on European citizens. It happens all the time.
- xdennis 4y ago
- webmobdev 4y agoThank god at least some government has the sense to take steps to protect their country's sovereignty. All the US has to do to regain trust is to stop using BigTech for spying on other countries. To begin with, it can start by creating laws and regulations like the GDPR (or better) and move on to breaking up the monopolies of BigTech.
- Gwypaas 4y agoSimply the CLOUD Act [1] which is incompatible with GDPR. No problem transferring to a third country [2] as long as you can uphold GDPR. [1]: https://en.wikipedia.org/wiki/CLOUD_Act https://en.wikipedia.org/wiki/CLOUD_Act [2]: https://www.imy.se/en/organisations/data-protection/this-applies-accordning-to-gdpr/transfer-of-data-to-a-third-country/ https://www.imy.se/en/organisations/data-protection/this-app...
- light_hue_1 4y agoThe US parent company was given access to the EU data. That's the problem here. > A included clauses in the offer that stated, among other things, that it will not access, use, or disclose customer data to any third party, except as necessary to maintain or provide the Services, or as necessary to comply with the law or a valid and binding order of a governmental body. Of course giving a US company control over EU data at a whim means that it's a transfer to the US. The court made the only reasonable decision.
- blocked_again 4y agoI think this kind of affirms the general opinion that Germany and many traditionally powerful European countries is doing poorly when it comes to modern tech. What went wrong with Germany and Europe? They used to be the front runners in tech once upon a time.
- lizardactivist 4y ago"European countries doing poorly when it comes to modern tech" has never been an opinion. You're confused, and your petty vindictiveness is unmotivated. The EU as a space of commerce is not yours to do with as you wish. You have to follow rules and regulations just like our own companies have to. And if your country had not been engaging in espionage and sabotage then there would never have been a need for these "unfair" and "underhanded tactics".
- blocked_again 4y ago
- 3836293648 4y agoIf the goal was to stop US companies, the EU parliament wouldn't've thought that the US lived up to the requirements of the GDPR. They assumed they did until courts struck it down
- xdennis 4y ago> You really think laws like this is going to stop US government/NSA from accessing data of whoever they are interested? 1) So if you're helpless you're supposed to not defend yourself at all? 2) Why did they pass the CLOUD Act if they already have access?
- dang 4y agoPlease don't take HN threads further into flamewar. It's not what this site is for, and it destroys what it is for. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html Edit: actually, I'm seeing so many abusive comments in your account history that I've banned the account. See also https://news.ycombinator.com/item?id=32393867 https://news.ycombinator.com/item?id=32393867.
- throwaway4good 4y agoHey America - stop spying on our our citizens or we will stop buying your tech. Seriously. We talk about this cloud stuff like it is rocket science. It is not. It is a box in a basement. We are capable of doing that ourselves. And no. It ain’t cool for NSA to sniff around some German governmental software, even though you are the good guys and on our side.
- jaywalk 4y ago> We are capable of doing that ourselves. Then do it.
- kreeben 4y agoYou typed that silly reply on an operating system created by a European. You don't think we can host the shit out of that OS in Europe? I think you're just butt hurt because someone said something bad about the greatest country in the whole world that you know of.
- AnonMO 4y agoIf you're talking about linux an operating system based on unix from bell labs. then it just an operating system created by a European which is based on an operating system created by Americans. without one the other wouldn't exist.
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- kreeben 4y agoWithout beating around the bush, can you state your point please?
- 4y ago
- lizardactivist 4y agoKeep rocking. I have no beef with US companies doing business here as such, but as long as they're supporting espionage and sabotage by handing crucial data to the NSA and CIA they should simply not be allowed to operate here.
- legalcorrection 4y ago
- bettysdiagnose 4y ago
- htkibar 4y agoPeople like being edgy in the end, I guess. They literally claim that "EU is an American protectorate". At this point, it is literally pointless to even have a dialogue, as they is far gone.
- bettysdiagnose 4y ago
- deleted 4y ago[deleted]
- dang 4y agoWe've banned this account for repeatedly breaking the site guidelines, not just in this thread but elsewhere. Please don't create accounts to do that with. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- mopsi 4y ago> they are too poor to afford ubiquitous air conditioning And I could say that americans are too poor to have heated bathroom floors, but that'd be ignorant. Europe is much further north and has significantly colder climate than the US: https://imgur.com/oIjh5eQ https://imgur.com/oIjh5eQ The main concern is insulation and heating, not cooling, hence much more expensive buildings overall compared to cheap wooden homes in the US.
- dang 4y agoWe've banned this account for repeatedly breaking the site guidelines, not just in this thread but elsewhere. Please don't create accounts to do that with. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- throwaway4good 4y agoThis is EU law. That is why you are seeing similar court rulings / administrative rules coming out of Denmark, France, Italy ...
- rad_gruchalski 4y agoFor public services, as in government public. From the page: The case concerns a decision by the Vergabekammer Baden-Württemberg ("Procurement chamber Baden-Wuerttemberg"), the administrative authority that reviews the public procurement procedures. On 3.11.2021, a public authority issued a Europe-wide invitation to tender for the procurement of software for digital management via an open procedure. The award criteria contained, among other things, requirements for data protection and IT security. The public authority received offers from company A and company B.
- blocked_again 4y agoSimple question. Who do you trust your data with? 1. A company in your own country which got marketshare mostly because of legal reasons and government interference. 2. A company which got marketshare by building products that people loved all over the world, has the smartest people working for them and have generated more value than the vast majority of the companies that existed previously in the world combined.
- Jensson 4y ago1. A foreign government with a tendency to imprison and torture foreign citizens without any process. 2. Your own government that is held accountable to local laws.
- htkibar 4y agoI'd agree with the implication here, if it weren't for the fact that the company on #2 would be _legally compelled to spy on me or my countrymen at the whim of 3 letter agencies_. That rubs some people, such as I, the wrong way. I wonder why :)
- deleted 4y ago[deleted]
- tzs 4y agoIt is not clear to me from that what the relationships are between company A, the EU subsidiary (which I'll call S), and the US cloud provider (which I'll call C). 1. Would A be dealing directly with S, or is A dealing with C which is using S to store A's data. 2. Is S incorporated in the EU? 3. Does C have access to data stored in S, other than data that C itself put there using the APIs that S makes available to all its storage customers?
- rubito 4y agoTelekom and Microsoft partnered together a long time ago to fix this problem but it turns out in european public comunal and state procurement projects that cloud offerings play a very insignificant role since its largely all on-prem IT projects and so that partnership was closed. I'm just writing this because a lot of comments are getting the wrong idea from this and causing some weird mix of hysteria and europhoby. In the grand scheme of things, there is no money lost for Azure and AWS, the potential of the once in a full moon cloud projects from public european institutions wouldn't even amount to something that would be described as pocket chance.
- dang 4y agoAll: the hellish and puerile flamewar that many of you stooped to in this thread is exactly what HN is not for. We ban accounts that post like this, so please don't post like this. What an embarrassment. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html I suppose I'd better add that this isn't about which side you're on. It's just about having an international forum that doesn't suck and doesn't destroy itself. All of you flaming each other in this thread have made HN suck (in this neighborhood) and contributed to destroying it. No more of this, please. You can make your substantive points without any of that. If you can't, please don't post until you can.
- alaricus 4y agoThere was no flame war in this thread. But there is clear evidence of abuse and harassment by a mod. I'm flagging dang's post in the hope that a real moderator will look at it. What an embarrassment indeed. Hackernews deserves better moderation.
- dang 4y agoCertainly, people can and do have different ideas of what counts as a flamewar. In that sense it's just a difference of opinion and that's fine. However, we're trying for HN to be a particular kind of web forum. The principles of what we're trying for are expressed at https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html. Many comments in this thread broke those principles quite badly.