5 ms·
Mini Ask HN: How would a small company, say a code forge, that is based in the US ensure that it is operating such that it is legal to have EU customers? All o
by ghoward 4y ago
Mini Ask HN: How would a small company, say a code forge, that is based in the US ensure that it is operating such that it is legal to have EU customers?
All operations will be in the US (interaction only through a website). The forge will be designed to allow all of a user's data to be downloaded by that user (easy access to all data). It will also allow wiping away any reference to a user in commits (right to be forgotten).
But PII does need to be collected, such as username, password, IP address, public keys, etc. There are zero plans to collect anything that is not needed; only the minimum data needed will be collected.
Edit: Oh, and the forge would not send data to third parties at all, unless such third parties are cloning code, but then they would be users, right?
Would it be legal to accept EU customers? If not, would there be anything to do to make it legal?
- judge2020 4y agoTo add, would EU privacy requirements apply even if you're just running some Gitlab or even Mastodon instance? Maybe running it as an individual vs llc changes things?
- Hanschri 4y agoGDPR applies to individuals as well as companies if they provide services to customers within the EU/EEA[0], as long as they are either a data controller or data processor, which are explained better than I can in the source below[1]. If the business is based in the US, things get a bit more complicated due to the CLOUD Act[2]. [0]: https://ec.europa.eu/info/law/law-topic/data-protection/reform/rules-business-and-organisations/application-regulation/who-does-data-protection-law-apply_en https://ec.europa.eu/info/law/law-topic/data-protection/refo... [1]: https://ec.europa.eu/info/law/law-topic/data-protection/reform/rules-business-and-organisations/obligations/controller-processor/what-data-controller-or-data-processor_en https://ec.europa.eu/info/law/law-topic/data-protection/refo... [2]: https://complior.se/cloud-act-and-how-the-new-american-law-can-impact-european-companies/ https://complior.se/cloud-act-and-how-the-new-american-law-c...
- Msurrow 4y agoIt doesnt apply to individuals if it is not a business. See article 2, §2, litra c https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:02016R0679-20160504&from=EN https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELE...
- 12baad4db82 4y agoIt would likely depend on the purpose and scope of the offering: https://gdpr.eu/recital-18-not-applicable-to-personal-or-household-activities/ https://gdpr.eu/recital-18-not-applicable-to-personal-or-hou...
- oytis 4y agoWell, that means anything public-facing really. You are allowed to keep contacts in your personal phone book though.
- martijnarts 4y agoGDPR applies to everyone, including individuals.
- donatj 4y agoDoes that mean I can send people requests to delete my contact info from their phone and they're legally required to comply?
- geofft 4y agoFrom GDPR article 2: > 2. This Regulation does not apply to the processing of personal data: > (c) by a natural person in the course of a purely personal or household activity My sense (I am neither a lawyer nor European so this is certainly not European legal advice) is that you cannot use GDPR to compel someone to delete your contact info if they're solely a social acquaintance, but you can use it to compel them to delete it if they're a one-person business of some sort (contractor, Etsy seller, lawyer, etc.).
- nolok 4y agoExactly, your baby sitter, your employer, your lawyer, the plumber you called two months ago ... Are covered. The person you traded phone at the bar last week, your neighbor or your coworker from last job are not.
- makeitdouble 4y agoIf they operate a service for you, yes. For instance the baby sitter you hire now and then probably keeps track of the contacts of their potential clients, and you could request deletion of your data if you don’t intend to work with them for a few years.
- dumbfounder 4y agoAnd does this mean I can do this to the collection agent trying to get me to pay 4x for a parking ticket I got in Italy 5 years ago?
- 12baad4db82 4y agoIn terms of the GDPR, your company would need to satisfy compliance of the GDPR. For small companies this is pretty straight forward, and it definitely helps to think about this early. https://gdpr.eu/compliance-checklist-us-companies/ https://gdpr.eu/compliance-checklist-us-companies/
- ghoward 4y agoOuch. That list looks onerous. Thank you for the link.
- oytis 4y agoDesignate a representative in the EU? That doesn't seem straightforward to me, especially for a small company.
- ghoward 4y agoI was thinking the same thing. Even if I managed to do everything else, having to hire someone to do that would be nigh impossible.
- tgv 4y agohttps://gdpr.eu/article-27-representatives-of-controllers-not-in-union/ https://gdpr.eu/article-27-representatives-of-controllers-no... The obligation laid down in paragraph 1 of this Article shall not apply to: * processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing; or * a public authority or body.
- ghoward 4y agoThat requirement would still apply to my hypothetical code forge, unfortunately.
- austinthetaco 4y agoI'm unfortunately able to find it, but I was pretty sure a lot of the restrictions around doing business in the EU require a certain $ amount transacted or web traffic. Citation definitely needed but that would make sense, as it's how a lot of laws are written.
- Aachen 4y agoThis might be about the digital services act or digital markets act. GDPR doesn't discriminate even between large businesses and individual consumers. Of course, a data protection authority will look at the circumstances, and the GDPR is 80% common sense, 15% communicating better what you do with people's data, and 5% required boilerplate that makes every privacy policy so redundant and dull and long that nobody reads it - but the point it, it does apply, as do most laws. Only when it's about monopoly positions that might disrupt the market, then exceptions are generally in place to protect newcomers that promote competition (or perhaps if you run a communications network only for friends noncommercially you might not be required to make it tap-able).
- deleted 4y ago[deleted]
- Msurrow 4y agoIANAL As it stands right now, it is not possible for a US owned busniess to provide a service to EU citizens legally, if the business handles PII. The reason is partly due to the basic rights of the registrant granted by GDPR must be ensured by the data processor (the company), and due to the Schrems II ruling [1] that determines that GDPR is incompatible with US law. The non-legalese version is that US law that gives Intelligence agencies (etc) the power demand a US owned (not just based) company to hand over any data including PII, means that the basic rights of the GDPR cannot be fullfilled. [1]: https://www.gdprsummary.com/schrems-ii/ https://www.gdprsummary.com/schrems-ii/
- ghoward 4y agoYeah, I was afraid of this. Perhaps my best solution is to block any user creation from the EU, any login from the EU, and any signed-in user request from the EU. Maybe I can allow non-signed-in users from the EU to browse?
- Msurrow 4y agoIf you dont handle/store PII then there is no problem. Or, you can just do it anyways. Its not like GDPR and Schrems II have stopped Microsoft, Amazon, Google, etc etc.
- ghoward 4y agoI can't get away from storing PII for signed in users. For non-signed-in users, I think it would be useful to avoid all PII.
- Msurrow 4y agoFair enough. Just wanted to make sure the take away wasnt that US companies cannot deliver services _at all_ to EU. Just curious whats your product/service? And how is PII used (high level)? As a dev and sw architect, and strong supporter of GDPR, I think its interesting to (attempt to) find engineering solutions for the challenges posed by GDPR (and Schrems)
- nolok 4y ago> How would a small company, say a code forge, that is based in the US ensure that it is operating such that it is legal to have EU customers? Do not store any kind of PII as defined by the GDPR, ever, anywhere. If you do, the PII data you store about your companies must be in respect of the GDPR and in particular access to it by law enforcement has to go through EU court. Because the US has decided with the CLOUD Act that US access to all data from US companies, or any company owned by a US company, only had to go through US court, it is not possible to comply at the moment. (before the CLOUD Act, storing the PII data within the EU and owned by a EU subsidiary was the best solution)
- messutied 4y agoIs it not even ok to store this data if the company is clear about the fact that they are hosting the data in servers of US company like AWS? Like making it clear in the DPA/PP?
- nolok 4y agoIt's not about saying where the data is / warning your customer, it's about protecting the data. You need to protect it under EU court / jurisdiction, and the US broke that and said they have jurisdiction over any piece of data your company ever touches. That's why the US now wants some sort of privacy shield 2. As an actual solution you can use: find another company, an EU company, one that you don't own, to handle your PII data for you, so you never store that data yourself. Also, be sure to read in the GDPR exactly what is and isn't PII under it, a lot of companies can work just fine without much or any PII, and a lot of people think "any" data is PII.
- messutied 4y agoWe definitely store PII as we have to store users emails an even phone numbers. So we basically need to migrate to a EU based could provider ASAP? Would this privacy shield 2 fix this problem? I suppose we can’t just wait for that.
- 4y ago
- pyrale 4y agoThe simple answer is that collecting personal data while being located in the US means that you can't guarantee that you will respect European law. > There are zero plans to collect anything that is not needed Unfortunately, it's not up for you to decide. The US has laws that makes it legal for your government to harvest data, and it has used these laws against EU citizen in the past. The US has also asked US services to collect data they were not previously collecting, with a gag order to prevent customers from learning it.
- nolok 4y agoExactly, it's not the EU overreacting about "what could be", those things have already happened
- ghoward 4y ago> Unfortunately, it's not up for you to decide. The US has laws that makes it legal for your government to harvest data, and it has used these laws against EU citizen in the past. Yeah, I was afraid of this. > The US has also asked US services to collect data they were not previously collecting, with a gag order to prevent customers from learning it. I'm so bullish on privacy that I would actually shut down my company if this happens. US courts cannot force me to remain in business.
- pyrale 4y ago> I'm so bullish on privacy that I would actually shut down my company if this happens. US courts cannot force me to remain in business. I believe that's what Lavabit did when they were served that kind of order. Not sure that helps with EU legality, though.
- stickfigure 4y agoThere's only one realistic solution and that's not to care. Focus on being good to your customers and ignore the geopolitics. Nobody's going to extradite you for running a normal run-of-the-mill web business in the US.
- nolok 4y agoSure if you're willing to violate the law, but if also need to accept never having any EU businesses as customer.
- latk 4y agoOffering a service to European consumers? Probably not a big issue. GDPR compliance can be challenging without a suitable mindset, but it's not impossible. * Consider that the GDPR has an extremely broad concept of “personal data” – it's not just identifying info but anything that can be reasonably linked to a person! * Data minimization – only collecting what is needed, and only using it as actually needed – is already a great step. * Writing a GDPR-compliant privacy notice can be a good exercise to understand what data you're processing for which purposes. Art 12–15 GDPR are the closest it gets to a checklist. * And you'll have to implement “appropriate” security measures, but what is appropriate is largely up to you. The more challenging part is ensuring that you're only using data processors/vendors that are contractually bound to use the data as you instruct, and that you protect “international transfers” where the recipient (e.g. vendor) is outside Europe. If you're looking for server locations in North America, I recommend looking at Canada since they have an “adequacy decision” from Europe. You will have to be GDPR-compliant if you “offer” your service to people who are in Europe, i.e. actively market to such people, or have testimonials from EU customers, offer French localization, accept payment in EUR, and so on. Mere availability of your service is not an offer. Offering a B2B SaaS service to companies that need to be GDPR-compliant? You're fucked. There is no legally safe way for a company to use an US-based data processor, i.e. to engage you as a vendor. However, and this is your “get out of jail” card, many customers don't care, and will be happy as long as they can sign “SCCs”.
- still_grokking 4y agoShort answer: Don't be based in the US until the US respects fundamental human rights, like the right to sue before a proper court. Simple, isn't it? The more pragmatic answer is: You can just ignore human rights. The other US companies operating in the EU also don't have issues with that. The EU isn't going to enforce its own laws in this regard anyway as more or less all EU governments are violating this laws themself. They currently all just waiting for the next round of the "safe harbor" smoke grenade. On the other side, the EU companies that use US cloud services (so more or less all EU companies) do by the way exactly the same. Nobody cares.
- ghoward 4y agoI'm going to respect human rights. And I'm going to act legally, even if it appears I can't do business in the EU, which appears to be true.
- still_grokking 4y agoPlease complain to your representative about that! All that's needed is that the USA start to recognize the rights of non US people. That's all. Nobody likes the current situation. Really. But it's not OK that governments collect data without proper court warrants, warrants which could be legally challenged. (And no, it's not only the US. We have here in the EU the exact same battle against our local authorities. Now that we've got some additional rights in form of the GDPR this rights need to get enforced finally. In all kinds of directions).
- ghoward 4y ago> Please complain to your representative about that! I have done that. Through all levels of government. But the establishment is going to do what it's going to do, regardless of party.