20 ms·
Shopify Is Illegal in Germany
- wusel 4y agoSorry for the German only link, but this is from today and didn't make the rounds yet. It is not really about Shopify itself, but about the use of CDNs - which would be even more worrisome. Shopify Support couldn't help the shop owner.
- 2000UltraDeluxe 4y agoIIRC, the Portugese authorities already deemed CloudFlare as non-compliant. Same issue as with Google Fonts, etc.
- friendzis 4y agoGDPR core is pretty simple: You cannot do stuff (process, store, transfer to third parties) with PII unless X condition is met. An internet site, on first visit (being genuine first visit or just cookieless visit) cannot do things with PII, because there is just no way to even tell if X is met, therefore not only data storage (IP address in Apache access logs included) is illegal, but moreso transfer to third party via CDNs and what not. GDPR is ugly. The only thing it allows you to do before you get confirmation to process PII is to show static page requesting for permissions. That's basically it. You can't do any "cloudy" stuff prior.
- iso1631 4y agoStoring IP addresses for technical requirements is legal (for example you need to keep the IP address in memory because you have an open TCP session). Likewise a session cookie is fine too. Keeping those IP logs for security reasons is also legal (assuming you keep them safe for an applicable amount of time) Using that data for analysis is not legal.
- dmitriid 4y ago> GDPR is ugly. The only thing it allows you to do before you get confirmation to process PII is to show static page requesting for permissions. That's basically it. You can't do any "cloudy" stuff prior. No, GDPR is not ugly. Yes, you can do "cloudy stuff". The bullshit narratives around GDPR need to stop, however people driving the narrative are extremely incentivized to siphon and sell all the data they can get your data, so the narrative is always bullshit.
- throwaway13337 4y agoYou're just incorrect here. Part of the GDPR does good things against bad actors like ad/tracking companies. But most of these companies are so big that it just works as a moat to keep out small competitors in that space. The more widely-affecting thing that the GDPR is doing is to make it impossible to legitimately run a business like the one that the article is talking about. An online shop that uses shopify which uses a CDN. A small online shop using a CDN is who is actually hurt with GDPR.
- dmitriid 4y ago> You're just incorrect here. I was expecting you to show where I'm incorrect. And yet, it's the same emotionally-charged "omg moat, large companies, impossible to run a business". Which doesn't disprove what I say, but further supports my case: the bullshit narrative around GDPR persists even if it has literally no basis in reality. > A small online shop using a CDN is who is actually hurt with GDPR. Most CDNs have GDPR-compliant services in the EU. Those listed in the article literally have separate pages specifically addressing compliance with GDPR. There are banks in the EU handling sensitive customer data which use the very same CDNs and services under significantly stricter laws than GDPR. But sure. Tell me how it's impossible to legitimately run a small business that operates under significantly fewer obligations, and retains significantly less customer data.
- throwaway13337 4y agoOddly this argument feels familiar - like we've sparred in the past over GDPR on another hacker news article. I won't continue this as it seems like it's more a flame war where no side can convince the other. I'll say this, though: please imagine who I am who feels so passionately about this. Likely, I am a small business that has been affected personally by the GDPR though I am not in advertising or tracking. Maybe I'm just a small business owner trying to navigate the uncertain waters created by these rules. That's what brings out the passion. I imagine you are someone who is passionate about privacy and against adtech. As am I. We're probably ideologically similar. So please try to square why someone who is ideologically similar has such a strange idea. It might be that I am misinformed but it might be that you don't have the same experience as me.
- allisdust 4y agoGDPR is simple. It's a mechanism to keep foreign tech companies out of EU while not explicitly banning them (as it would result in reciprocal measures) by increasing the cost of doing business in EU. For those that do go all the way and try to follow the laws, periodic flaws found in implementation (which are inevitable given how complex these laws) are penalised heavy enough to make them think twice. If this is not there, software companies in EU which aren't competitive in general will be steamrolled by companies from other countries (but primarily from USA). China also does this to ensure home grown tech eco system while at least being more truthful about.
- kuschku 4y agoHow is GDPR ugly? It's easy to build websites, even interactive ones, that comply. If you build a mobile app, you are also supposed to only ask for permissions once you actually need them. Replace interactive embeds with a dumb replacement of the actual content and e.g., "we want to show you an embedded tweet here, [allow once] [allow always]". Don't use CDNs for delivering assets, they've long stopped being useful anyway. Don't use Google Analytics. In general, build websites like we used to in the early 2000s. And yes, you can even do cloud-y stuff like that. You can run k8s on your hetzner dedicated servers, you can run MinIO as your s3 store, none of that is stopped at all by these rules. You can even run an interactive website like HN without any GDPR violation or cookie prompts at all.
- oytis 4y agoSo no embeds, no CDNs, no analytics, lots of popups asking for permissions and going back to 2000s (just with cookie banners) in general. Isn't that ugly?
- kuschku 4y agoOf course you can have embeds. Just replace them with a blurhash and make them click to load. That also avoids pretty much all of the popups. Sure, no CDNs and no analytics, but that's what I'd call an absolute win. Nothing of value was lost.
- indrora 4y ago> only ask for permissions once you actually need them Hard on Android, where "did my wifi go away" means asking "can I have access to your phone's internal state including call logs and if you're in a call right now?" > replace interactive embeds with a dumb replacement Sucks when you depend on that content or the content has to be interactive under the TOS of the service you're using. > [CDNs have] stopped being useful Not at all. In many a corporate network as well as situations where you're paying for transit (e.g. AWS) they still make sense. > build websites like we used to in the early 2000s Ah yes with Flash for our interactivity, __Just throw an executable format that has a hard to render, proprietary ISA running unsupervised__, that worked for us then it should work fine today? I'd say "Let's build more websites like we did in 2010". That's right around when Javascript peaked. > Minio due to their licensing change, a lot of legal departments have banned minio.
- pvg 4y agoYou just wait for an English version of the story to appear. From scripture: re: language https://hn.algolia.com/?dateRange=all&page=0&prefix=true&query=author%3Adang%20english%20language%20site&sort=byDate&type=comment https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que... re: from today https://hn.algolia.com/?dateRange=all&page=0&prefix=true&query=author%3Adang%20no%20harm%20in%20waiting&sort=byDate&type=comment https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
- scarface74 4y agoSafari’s built in translation is surprisingly good. It didn’t even read like a machine translation.
- notamy 4y agoEnglish (machine) translation: https://lsww-de.translate.goog/shopify-illegal/?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=en https://lsww-de.translate.goog/shopify-illegal/?_x_tr_sl=aut...
- moffkalast 4y agoOr you know, right click page -> Translate to English. I'll miss that the most when manifest v3 rolls out and chrome becomes unusable.
- deleted 4y ago[deleted]
- ale42 4y agohttps://www.mozilla.org/en-US/firefox/features/translate/ https://www.mozilla.org/en-US/firefox/features/translate/ never tried, but seems promising
- moffkalast 4y agoSeems like it just takes the text and pastes it into google translator? Not even close to the same functionality of translating the entire page in situ with 2 clicks.
- ale42 4y agoOh, sorry, I posted the wrong link. Can't any more edit the original message, so here is the right link: https://addons.mozilla.org/fr/firefox/addon/firefox-translations/ https://addons.mozilla.org/fr/firefox/addon/firefox-translat...
- kmlx 4y agoi’ve been on safari for the past 3 years. nothing will change. ad blockers will still work.
- jrmg 4y ago
- fxtentacle 4y agoI believe the authorities are correct here. Shopify is sending all personal data to CloudFlare, CloudFront (Amazon) and Fastly, so 3 US companies. They could sign so-called "data processing agreements" where they promise to safeguard personal data. But the Shopify FAQ explicitly states that they are unwilling to do so. As the result, Shopify is legally considered to not be processing data under the instructions of the shop owner, because they didn't sign the processing agreement. Instead, Shopify is legally considered to be the owner of the user data. And that's a problem with EU clients because they are a US company working with US CDNs. Still, all of this could easily be rectified by Shopify if they would just care enough to sign the correct paperwork.
- AdrianB1 4y agoAs the author showed the volume of business and revenue in Germany is tiny, there may be not worth the effort for Shopify to do it. It may be the correct business decision. The differences in laws and requirements by country is one of the biggest factors to consider when providing international services of any sort.
- fxtentacle 4y agoI believe that's misleading, because while not many sellers are located in Germany, this affects any Shopify shop who sells to customers anywhere in the EU. So I'd estimate roughly 30% of their revenue might be affected. But of course, Shopify can just push this responsibility onto their customers, meaning the shop owners. That's what they currently do.
- radicalbyte 4y agoThis affects the entire EU. I try to hammer it into people's heads here in NL. Using US-based cloud services if you touch PII is a huge risk as they're all getting like crazed addicts fighting over their next high PII-high.
- boringg 4y agoIt's the way the EU can protect their own tech industry.
- shafyy 4y agoAll EU companies sending any PII to US-owned companies, regardless if the actual data stays in the EU or not, are in danger to be sued similarly to the author of this post. This is, among other laws, because of the US CLOUD act: > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requested data stored on servers regardless of whether the data are stored in the U.S. or on foreign soil. So, it's not a Shopify specific issue. https://en.wikipedia.org/wiki/CLOUD_Act https://en.wikipedia.org/wiki/CLOUD_Act
- fxtentacle 4y agoIn theory, yes. In practice, the issue is that Shopify refuses to sign a data processing agreement: https://gdpr.eu/what-is-data-processing-agreement/ https://gdpr.eu/what-is-data-processing-agreement/
- canucklady 4y agoI know some of the team that worked on GDPR and CCPA compliance for Shopify and let's just say it is not surprising they're cutting corners.
- judge2020 4y agoDPAs do not protect against ramifications of the CLOUD act. See this thread (mainly the reply to it)[0]: SCC = standard contractual clauses, aka DPA/GDPR clauses that govern when and how data transferred to the US is used. > The ruling on Schrems II (the court case that struck down Privacy Shield) did not state that SCCs on their own would be sufficient. It said that SCCs + "additional safeguards" would be allowable. There have been several rulings already that SCCs on their own are not sufficient. > The "additional safeguards" must include a risk analysis of US access to EU residents' data. Every court case I've seen from Schrems II onward identifies the US CLOUD Act as the privacy risk to address. CNIL is basically ruling that you cannot transfer data to a US company subject to the CLOUD Act, and an SCC cannot deal with that. This still leaves open the possibility of using US services that are not subject to the CLOUD Act. This is consistent with all rulings to date. In summary, Schrems II + this ruling[1] mean that US corporations can't be involved with EU at all besides via licensing software to a completely independent EU corporation (which isn't a given either, though, since the US company could threaten withholding software updates/revoking the software license to pressure the EU corporation to hand over EU citizen data to US Law Enforcement - or otherwise implement a backdoor at the request of US Law Enforcement). 0: https://news.ycombinator.com/item?id=30286642 https://news.ycombinator.com/item?id=30286642 1: https://news.ycombinator.com/item?id=30284372 https://news.ycombinator.com/item?id=30284372
- generationP 4y agoWait, does this imply that running a website behind CloudFlare is illegal in the EU? After all, webshop or not, IPs will be transmitted... Or are IPs only a problem in connection with getting user data like name and address? Or is it the IP+cookie combo?
- bombcar 4y agohttps://bluecatnetworks.com/blog/is-an-ip-address-pii-the-answer-is-nuanced/ https://bluecatnetworks.com/blog/is-an-ip-address-pii-the-an... may provide some insight. IPs are sometimes PII. It seems that if you're the ISP, the IP is PII, but if you're a website, the IP alone may NOT be PII.
- lmkg 4y agoThis blog post is incomplete with respect to Breyer. An IP address is always personal data to an ISP. It's also personal data to anyone who can ask/request/compel the ISP to identify someone based on the IP address. And one of the main conclusions of Breyer is that only happens in an obscure edge-case scenario, that's enough for IP addresses to be considered personal data all the time. The case specifically was that in the local jurisdiction, there's a law that if a company gets DDOSed they can request the local regulator to ask the ISP to identify a user. This law only gets triggered in very exceptional circumstances, but its existence means that IP addresses are always personal data in that jurisdiction. While that law only covers one part of Germany, the analysis applies to any similar law, of which it is safe to assume there are many.
- anfogoat 4y agoSometimes as in it rarely is not. This is the reason you'll risk fines serving images, CSS, JS, fonts, and whatever from a third party web server without first ensuring users' consent to having their IP exposed to those servers.
- lmkg 4y agoSomeone has previously gotten fined for using Akamai, because it involves disclosing the user's IP address to a US company. (In fact, it was to a EU subsidiary of a US company, but due to the CLOUD Act this doesn't matter.) In theory, IP address is considered personal data only under certain conditions. In practice, those "certain conditions" almost universally apply and you should treat IP addresses as always being personal data.
- Barrin92 4y agotwo issues are mentioned in the post. One is a rather boring cookie consent issue which the user was able to solve, the thornier one is that Shopify's use of American CDNs runs into privacy issues. A user in the comments points out that the Trans-Atlantic Data Privacy Framework, which is basically the next iteration of Privacy Shield (which was canned in 2020) will probably alleviate these issues. Personally I think though the onus should be on Shopify. Although only 20% of their revenue appears to be in the EU region I think that warrants managing user s private data locally.
- croes 4y agoAs long as the CloudAct exists all laws, frameworks, contracts are useless and just deception
- anonymousab 4y ago> Trans-Atlantic Data Privacy Framework Unless it completely upends both FISA and the CLOUD act, it won't be valid at all. And there's really no way that the US government will ever accept real, significant limitations on its data gathering reach and authority. But it will buy companies more time and rope, because it will have to be litigated again. And then we'll go through this whole song and dance again after Schrems III.
- blueflow 4y agoNot unsurprising. At work (Germany) we are forbidden to use any US cloud services, i wonder why this hasn't been the new normal yet.
- andrewmutz 4y agoSounds like great news for home-grown German alternatives to US cloud services. And bad news for the competitiveness of all other German companies.
- arlcode 4y agoMuch of German business is in B2B, engineering and manufacturing. Many cloud offerings are not required if your product is physical and/or not directed at consumers. For others there are home grown alternative. But it'll suck for a few businesses until GDPR compliment products are available. The big one is Office 365 but, I think Microsoft is setting up licensing agreements where a European company (which is not a subsidiary of MS) is running the stack and Microsoft has no direct access. Other large US companies are probably planing sth similar
- deleted 4y ago[deleted]
- openplatypus 4y agoHead in the sand approach of some EU companies is flabbergasting.
- 6510 4y agoPretty incompetent to communicate the issues with the shop rather than the platform.
- DocTomoe 4y agoNah, that's not incompetence, it's by design: The actual violation of the GDPR was committed by the local shop owner. The owner also is responsible for any fines. The shop owner could have chosen a data-protection-compliant solution, but choose not to do so. The platform did not violate any local laws - it's outside the jurisdiction of the GDPR. They chose - and are within their right to do so - to cooperate with a legislative framework that is data-protection-averse (the US CLOUD act). This makes them incompatible with the EU, which they must be aware of. So why bother them?
- 6510 4y agoWhen looking to solve a problem you find ways to solve it as good as possible with the minimum effort. The problem is 93689 German shops violating the law. Laws are written to accomplish goals. Execution is sometimes hard/impossible. You have to find ways that work, keep the eyes on the goal. We have big institutions like government and shopify that should abstract their smaller components. These are not always constructive abstractions but they usually work just fine. Apparently here a customer filled a complaint about 1 shop with the government. Government should to the best of its ability detect those issues before such complaint comes in. Given how big shopify is in Germany that becomes remarkably easy! Are they seriously going to wait for a customer for each of the 93689 shops to bother to fill a complaint and then take up the issue with each of those 93689 shop owners? The tax money would be better spend by giving it to shopify to fix the issue. That might not be legal but it would sure be cheap! They could also communicate to the list of shop owners that they are to stop using the platform. That would be more work but quite doable. Could send the draft to shopify first and give them some time to resolve the issue if they desire it. Surely losing 93689 clients at once is worth some internal dialog. He is suppose to be busy selling coffee so that he can bring in more tax revenue. The idea was to keep the personal data in the EU. To what extend does all the current expensive busy work accomplish that? Not at all?
- whywhywhydude 4y agoFor people who are unaware, Shopify is a Canadian company and they use CDNs just like most of the highly trafficked websites in the world. Most CDNs just happen to by owned by US based companies.
- Aerroon 4y agoWith all of this popping up: how are you even supposed to run an internet service in the EU? Do you have to write all pieces of the software yourself or what? Since all the big services seem to be off-limits.
- ronsor 4y agoAt least if you're US-based and not accepting money, I have one bit of advice: just don't care. Even if they complain, don't care. The Internet is global; if they really have an issue, they can block your site, or they can just put up with it. If you're gonna sell a product or service, then worry about figuring stuff out.
- anonymousab 4y agoIn theory you could individually be sanctioned, prevented from entering EU countries (or face the courts upon doing so), etc. Gotta cross a bunch of countries off of your vacation list. But in practice that's never going to happen.
- ronsor 4y agoI don't think the EU would do that (except maybe against some mega billionaire?). That would at least begin to sour their relationship with the US and potentially many other countries.
- lagrange77 4y agoDoes this generalize to every US hoster, when used by an EU publisher? I mean, it's impossible to get consent or even information disclosure for the exposure of IP info, since the consent banner logically is loaded over that IP connection.
- throwaway13337 4y agoThough the intentions of GDPR were good, Following the GDPR to the letter is not feasible for any company that isn't a monopoly. We're in a situation where no one is following it all the way as it's not even clear what that means. More of the same will continue and the GDPR will only be used coercively as an attack against competition or companies others don't like. It's really a major blow for small businesses that want to work in the EU. EU desperately needs more small tech business so it's quite sad. I would love a law that said what people think GDPR says. That you have to tell people if you were selling their data to third parties and to please not do that. This is simply not what GDPR is in practice. The road to hell is paved with good intention.
- iso1631 4y agoIn the UK it's illegal to pay a bribe to allow your company to operate, despite it being normal behaviour in many areas [0], I assume other countries have similar laws. In the same way, just because normal behaviour in some countries is to misuse customer data, it doesn't mean it should be legal for an EU company to operate in that way. [0] https://www.bbc.co.uk/news/business-13977221 https://www.bbc.co.uk/news/business-13977221
- throwaway13337 4y agoWhen you make common practice illegal, you invite corruption into your system because selective enforcement of the rules becomes the new normal. Laws need to understand the environment that they are made in or will never be effective and oftentimes counter productive. As is the case here. GDPR goes even further than would be reasonable for any small business that handles email addresses. Requiring a salaried data protection officer is not feasible. Unless you want to make small businesses illegal to operate online, you either are for selective enforcement or you do not want the GDPR.
- dmitriid 4y ago> When you make common practice illegal, you invite corruption into your system because selective enforcement of the rules becomes the new normal. Child labor. Drugs and radioactive substances in medicine. Water pollution. The list of practices that used to be common is extremely long. And yet here we are. > GDPR goes even further that would be reasonable for any small business that handles email addresses. Of course it doesn't go "even further". Don't sell user data left and right, and boom! Your poor small business is in the clear. > Requiring a salaried data protection officer is not feasible. The law doesn't require a separate salaried DPO. > Unless you want to make small businesses illegal to operate online, you either are for selective enforcement or you do not want the GDPR. The one thing I want is for people to stop saying fantastical bullshit about GDPR that has no basis in reality.
- ghoward 4y agoMini Ask HN: How would a small company, say a code forge, that is based in the US ensure that it is operating such that it is legal to have EU customers? All operations will be in the US (interaction only through a website). The forge will be designed to allow all of a user's data to be downloaded by that user (easy access to all data). It will also allow wiping away any reference to a user in commits (right to be forgotten). But PII does need to be collected, such as username, password, IP address, public keys, etc. There are zero plans to collect anything that is not needed; only the minimum data needed will be collected. Edit: Oh, and the forge would not send data to third parties at all, unless such third parties are cloning code, but then they would be users, right? Would it be legal to accept EU customers? If not, would there be anything to do to make it legal?
- judge2020 4y agoTo add, would EU privacy requirements apply even if you're just running some Gitlab or even Mastodon instance? Maybe running it as an individual vs llc changes things?
- Hanschri 4y agoGDPR applies to individuals as well as companies if they provide services to customers within the EU/EEA[0], as long as they are either a data controller or data processor, which are explained better than I can in the source below[1]. If the business is based in the US, things get a bit more complicated due to the CLOUD Act[2]. [0]: https://ec.europa.eu/info/law/law-topic/data-protection/reform/rules-business-and-organisations/application-regulation/who-does-data-protection-law-apply_en https://ec.europa.eu/info/law/law-topic/data-protection/refo... [1]: https://ec.europa.eu/info/law/law-topic/data-protection/reform/rules-business-and-organisations/obligations/controller-processor/what-data-controller-or-data-processor_en https://ec.europa.eu/info/law/law-topic/data-protection/refo... [2]: https://complior.se/cloud-act-and-how-the-new-american-law-can-impact-european-companies/ https://complior.se/cloud-act-and-how-the-new-american-law-c...
- Msurrow 4y ago
- gok 4y agoThe EU is try to copying China's playbook of propping up local service providers by imposing impossible-to-follow rules on foreign tech companies. In both cases, the rest of the world should retaliate by limiting access to advanced technology until laws change.
- systemvoltage 4y agoI can’t see EU’s balkanization in positive light either. Seems good ol protectionism instead of actually innovating. Privacy is a trope, they give away data at US’s whim.
- almostnormal 4y agoThe EU isn't "the" EU. The GDPR was created by the elected representatives of the EU citizens. The EU commission consisting of representatives of the EU member state's governments are giving away the data.
- gok 4y agoElections have consequences.
- someweirdperson 4y agoWe wanted data protection, we got data protection. The commission is losing in court with its idea to give data away (e.g. privacy shield invented by commission, stopped by the court).
- croes 4y ago>In both cases, the rest of the world should retaliate by limiting access to advanced technology until laws change. That part is ok,but the problem isn't the GDPR but the CloudAct. The US made it impossible to use any service of an US company by demanding access to all their data no matter where it's stored. Imagine the US government could enter any house just because the lock is manufacturered by an US company. And the US has a proven history of using wiretap data for economic benefits. See Echolon and Airbus vs Boing
- photochemsyn 4y agoCorporations are increasingly multinational, and the stated 'national affiliation' is really just 'flag-of-convenience' (a notion that probably arose in the global marine shipping industry, but which has spread everywhere). Look at the number of businesses incorporated in Delaware or other states that provide additional layers of legal shields as another example. As far as this, it's probably related to this story from one month ago (Oct 7 2022): https://www.reuters.com/business/retail-consumer/eu-says-shopify-improve-platform-make-online-shopping-safer-2022-10-07/ https://www.reuters.com/business/retail-consumer/eu-says-sho... > "Shopify committed to change the design of its templates to include fields for company information and contact details, to provide clear guidance to traders on relevant EU consumer law and to provide company details about any EU trader when requested by any national consumer authority. The company also agreed to take down web shops in breach of EU consumer law, as well as to provide the relevant company details."
- dontbenebby 4y ago
- captainmuon 4y agoIt is ridiculous that data protection officials focus on CDNs, third party resources and cookies. And at the same time it is totally legal for Google to collect advertizing data from some random websites so they can create a profile that follows you around. All that sites have to do is to put up obnoxious cookie banners that nobody reads. If they were really concerned about my privacy, they would ban creating cross-product profiles for advertizing purposes. I don't care at all that some CDN gets my IP, or that some website uses cookies to count users. Also I don't care if somebody stores my data on Google Docs or Office365. If Google or MS go rouge and employees there so shenenigans with my data, we have bigger problems. They control the OS anyway. It makes more sense to regulate the "happy path" assuming they are law abiding, and just say you can't do targeted ads for European users.
- shafyy 4y agoIt's not legal for EU companies to use Google Analytics, because of the same legal reasons.
- pjc50 4y agoThis either isn't true or nobody has noticed yet. It's on all sorts of EU sites.
- shafyy 4y agoIt it true, e.g. see here: https://isgoogleanalyticsillegal.com/ https://isgoogleanalyticsillegal.com/ https://plausible.io/blog/google-analytics-illegal https://plausible.io/blog/google-analytics-illegal Law is a code that needs to be interpreted by society. This interpretation is done by judge rulings. There is a growing number of rulings that Google Analytics, and in fact any sending of customer PII to US-owned legal entities, is illegal. Naturally, smaller companies won't be sued, right now. But the more time passes, the clearer it becomes that given the current GDPR and US laws, it's illegal.
- anonymousab 4y agoMost cookie content popups and forms that you see are also flagrantly illegal under the GDPR. The problem is that enforcement is rare and small scale compared to the overall scope of the problem. In both of these cases it's a day late and orders of magnitude short. The Schrems II stuff is a situation where many of the politicians and the businesses really don't want to have to do anything and so they just kinda ignore the law until privacy advocates force their hand. So enforcement is effectively non-existent; the hope being that they can just run out the clock until some sort of legislation magically fixes the issue.
- erik1332 4y agoWhen this google-font stuff came up here in Germany, I was wondering if using CDNs also need permission first. I did some googeling for my ghost blog with no clear solution (ths standard gost blog uses jsdelivr). After reading the text: you need permission to load scrips etc. through CDNS. This is bad, since most of the software does not offer to locally host the required scripts.
- formerly_proven 4y agoYeah, a lot of (paid) themes for Wordpress and similar "DIY" CMSes are in violation by default, often without a way to change anything without editing the theme's code. On the other hand, using X different CDNs will increase load times for most sites and has no caching benefits anyway (browsers segregate caches by requesting origin to avoid the cross-origin signal that not doing so would provide). It's probably quite difficult to perform better than subsetting your fonts yourself and just shipping them as a single zopfli'd CSS file from your static domain.
- someweirdperson 4y agoWhile reading this story, the TV running in the background was showing an ad from shopify (german TV channel).
- RcouF1uZ4gsC 4y agoThis is getting ridiculous. The EU is waging a protectionist war on US tech companies. The US should ban all EU produced cars from the US until the EU figures out a solution.
- thenaturalist 4y agoWhile I am by no means a fan of GDPR and this behavior by, especially in Germany, tiny federal data protection agencies spouting toxic, perfectionist legal interpretations onto entrepreneurs for mostly making a name for themselves... You do realize that there is a fair share of protectionism alive and well in the US as well, right? Probably not the most productive way to argue to start a tit for tat comparison, let's just be honest withourselves that everyone kinda does it in areas where they lag behind (digital in EU, some engineering, cars in the US).
- jillesvangurp 4y agoIt's a war on casual privacy invasion by US companies that can't be bothered to pay attention to what's happening in a legal sense in key markets that are important to them (from a revenue point of view). There are plenty of US companies that get a lot of revenue from the EU market. Including some big names like Azure, Amazon, etc. And they aren't being banned but they are being forced to comply with locally applicable law. As they should. As for cars, the US has already forced many EU based car manufacturers to produce in the US. So, when it comes to protectionism, the US is way ahead of you.
- TekMol 4y agoIf using a CDN that is owned by a US company is illegal in Germany, then how can Germans run international websites? How would it be possible to hide a host that is behind CloudFront from Germans? I don't think is it possible. Even if you run an extra host like www.yourdomain.de for Germans, they could still type www.yourdomain.com into their browser and this alone would cause tcp packets to flow from their machin to CloudFront. There is no way to avoid this. What can German indiemakers do now? Register a company outside of the EU?
- capableweb 4y ago> If using a CDN that is owned by a US company is illegal in Germany, then how can Germans run international websites? Just like US companies can run computers outside of the US border, so can other companies. A German CDN can setup their own infrastructure within US borders, then German companies can work with that CDN to speed up connections within the US for users coming from there. > There is no way to avoid this. There is. GeoDNS ("Regional Records") is one way, where you reply with different IPs to the instances based on where the DNS query comes from. So US visitors to domain.com gets a different IP than German visitors to domain.com. > What can German indiemakers do now? Register a company outside of the EU? Use European infrastructure, make sure you follow GDPR. As a fellow European (mostly) "indiemaker", it's really not that hard.
- TekMol 4y ago> A German CDN can setup their own infrastructure Ok, but what if you just want to run a website and not build a billion doller global CDN. > GeoDNS According to the GDPR you have to protect the data of your visitors no matter where they are.
- capableweb 4y ago> Ok, but what if you just want to run a website. Not build a billion doller global CDN. Ah, from the perspective of website owners, not the CDN owner... Well, use a European CDN, they tend to follow European regulation, just like US companies follow US regulation. The two companies that comes first to mind is BunnyCDN and KeyCDN, but I'm sure there are many others. Both of them have global networks. > According to the GDPR you have to protect the data of your visitors no matter where they are. Yes, of course, that's the ground truth we're assuming here. Is that some sort of gotcha? I'm not sure I'm understanding if you're arguing against what I said or just adding information on top without disagreeing.
- Fire-Dragon-DoL 4y agoI'm somewhat concerned about an app I host. It's on Digitalocean and serves only EU customers. DigitalOcean says they are full GDPR compliant, but given the cloud act this seems impossible. What alternatives are available in Europe? It will be really frustrating to migrate
- oytis 4y agoHetzner Cloud (sarcasm, kind of)
- Fire-Dragon-DoL 4y agoHetzner and OVH are famously used for seedboxes, but that's all I know about them. This is very limiting
- password4321 4y agoScaleway
- Fire-Dragon-DoL 4y agoI was exploring options all morning, they all seem to miss the "bottom line" (I understand why, but my customer doesn't need much resources). Scaleaway seemed way better than the competition though in terms of price for the bottom line, allowing to grow gradually rather than having to go all in in terms of pricing.
- BlueTemplar 4y agoThis discussion might help ? https://news.ycombinator.com/item?id=27393854 https://news.ycombinator.com/item?id=27393854
- Fire-Dragon-DoL 4y agoYou mean to avoid OVH? I reviewed their terms and their managed DB pricing is way out of budget anyway (starts at 60€/month), so that's disregarded. Unfortunately the app I manage is way smaller than that scale
- jmartens 4y agoEurope is ruining the internet.
- quantum_magpie 4y agoIn this case it's the US gov that's ruining the internet.
- keewee7 4y agoWhat are the current options for EU companies that use Cloudflare? Can we keep using Cloudflare?
- TekMol 4y agoWho decides what is legal and what is illegal? The politicians, the courts or agencies like the one that send letter to the author of this article. I would say it is the politicians. By making laws. Since the GDPR is the same in all EU countries, Shopify is either illegal in all EU countries or in none, right?
- openplatypus 4y agoGDPR is same in whole EU. Ruling about country's specific laws is relegated to local Data Protection Authorities. That's why Facebook was able to get away with Irish DPA from ruling against it. There was even a suggestion of foul play. In theory, a DPA in your country must make a ruling. That's why Google Analytics is officially "illegal" in certain, but not all EU countries. That said, it would be weird if subsequent rulings were not in line with previous.
- thejoeflow 4y agoTG;DR?
- keewee7 4y agoAs an EU citizen I support EU legalisation to protect our privacy. However can some Americans tell when your law makers will consider this to be protectionism and throw retaliatory measures against EU companies? Because I don't think they're going to repel the CLOUD Act anytime soon.
- kypro 4y agoLast time I checked half the internet is either illegal or blocked in the EU - is this even news? It's kind of ingenious. If you make practically every online service illegal then instead of taxing your citizens you can just fine foreign companies for doing business with you.
- sleepybrett 4y agoMy American bank has been rejecting payments to shopify for the last few weeks because of some kind of fraud spike revolving around them.
- OJFord 4y agoDoesn't this reduce (from the slightly convoluted shop->Shopify->CDN case here) to simply using say AWS as an EU company, or just being a US company? Assuming you have some kind of PII to store, the US CLOUD Act essentially means AWS (or whatever US company) can't possibly (no matter which region you use or anything like that) GDPR-compliantly act as a third-party data processor or whatever the terminology is? In which case... someone (as in country, legislation) is clearly going to back down? UK government sites take plenty of PII and run on AWS...
- still_grokking 4y agoThis is a tempest in a teapot. We (still) don't have any court ruling here. Of course more or less all US based cloud services are illegal in the EU currently. At least in theory. That's no news. (CLOUD Act & Co. was pointed out already by others). But until we don't have some crystal clear rulings form the highest courts that get actually enforced this makes no difference. The main point why this illegality does not mater in practice: Our own governments are using AWS and MS products, and all such stuff. They're completely in vendor lock-in there, and they could not change that for (at least) the next one or two decade, even if they would start right now trying to replace this stuff. But of course nobody even thinks about changing anything in this regard… They put hopes in the next, also clearly illegal, version of the "safe harbor" regulations that's about to surface "soonish". When implemented it will take again 5 to 10 years to go through all legal instances to finally find out that a "safe harbor" agreement, no matter how you call it this time, is still fundamentally incompatible with EU law. But they will win this way another 5 to 10 years! Than this game will start anew, and they will first ignore the law and the court ruling (like they do currently with the last one), than the EU government will try to implement the next version of "safe harbor", or something like that, to "avoid further legal uncertainty", and than it will take another 5 to 10 years to sue that into oblivion. And so forth. (We're currently already in round three of this shit show!) The linked post would be much more interesting if this case would actually go to court. But of course Shopify is not interested in this. They're just waiting for the next "safe harbor"; like everybody else. Of course they won't stop doing business in the EU. Exactly like MS, AWS, Apple, Meta, and this like, won't. Because there is just nobody to actually enforce the law as more or less all EU governments are also violating it.
- openplatypus 4y agoThat's why we host everything in the EU, with EU cloud. Cloud: OVH. CDN: OVH. Email/support: HKN. ... and few other smaller ones. You do not need AWS/GCP to be successful. Just shop around. Solutions we picked, ended up being cheaper and friendlier (human support) than US counter parts. https://wideangle.co/blog/saas-business-without-us-cloud https://wideangle.co/blog/saas-business-without-us-cloud