4 ms·
From here: https://docs.hetzner.com/general/general-terms-and-conditions/data-privacy-faq/ https://docs.hetzner.com/general/general-terms-and-condition... Conc
by q-base 4y ago
From here: https://docs.hetzner.com/general/general-terms-and-conditions/data-privacy-faq/ https://docs.hetzner.com/general/general-terms-and-condition...
Conclusion:
In summary, you as a customer do have influence - to a certain extent - on shaping who has access to the data on your servers. EU and US authorities do have to follow the laws and legal procedures in requesting data. However, this may give you a false sense of security since some authorities have been known to stretch or violate agreements. If you require a web hosting company that has absolutely no connections to the USA, then unfortunately, we may no longer be the best choice for you. Since Hetzner US LLC is part of the Hetzner Group, there certainly is a connection. We hope that we have explained things clearly from our point of view using the two above case studies.
- shafyy 4y agoOk, but: "US authorities do not have direct access to your server or its content in the EU. US authorities have to comply with the regulations of the EU legislation.". So, because Hetzner is not owned by a US company, stuff like the CLOUD act doesn't apply to them. So, if you have a contract with the German entity of Hetzner and use a German server, you should be fine in terms of GDPR.
- q-base 4y agoI think it depends on how you read the Schrems II ruling and how you read Hetzners words. Any of the big cloud providers can claim that they comply with EU legislation, but they also have to comply with US-legislation and if 3-letter agency wants to have some data from one of their subsidiaries in EU, then they can/will decide which contract to breach. I read Hetzners statements as being that they can no longer guarantee that they will not be forced to do the same - but that can be my reading of their statement that is wrong. If I already had them as hosting-partner for a solution that fell under Schrems II, I would have them confirm this, to be sure.
- deleted 4y ago[deleted]
- zelphirkalt 4y agoBut what does "direct" mean here? Indirect could still be ordering them to give US authorities data and to keep silent about being ordered. Maybe (hopefully) that would be against EU regulations?
- fulafel 4y agoLots of EU countries have their intelligence agencies doing close cooperation with five eyes (NSA and equivalent agencies of the smaller countries) and willing to turn a blind eye or actively collude in compromising security of IT infra in the EU. Or going further, a oft reported pattern is that when they want to spy on their own citizens but are forbidden by law, they ask the foreign allies to do the dirty work of spying on their soil and pass back the intelligence.
- zelphirkalt 4y agoOK, be that as it may, in IT stuff, the question often becomes "Who is responsible?". If a state or its institutions violate the law, at least no one can blame you for GDPR violations, which you did not commit.
- fulafel 4y agoThe GDPR largely came about as a response to the Snowden revelations of pervasive surveillance of netizens globally, and it says you need to protect PI from non-EU state actors. So you're possibly right as far as EU state adversaries go but you for defending against foreign state actors it's different.
- shafyy 4y agoExactly this, and I think this is granted with Hetzner.
- cstpdk 4y agoThe content of that link sounds fine in terms of GDPR if one only uses the EU servers. Am I missing something?
- q-base 4y agoI read it differently, especially in light of Schrems II. EU-datacenters from any of the big US-based providers does not automatically make you comply either.
- arlcode 4y agoAs I read it the issue is that the American HQ can order their European subsidiary to provide the data. Hetzner US does not have a European subsidary and therefore cannot violate GDPR (assuming US personal can't access EU customer data). Hetzner HQ is in Germany and is not allowed to enforce the CLOUD Act outside the US
- q-base 4y agoThat could also be correct. But if I was under legal/contractual obligations, with Hetzner as my hosting provider, I would have their legal department confirm this. Since Hetzner found the need for appending the paragraph I referenced, they must have become aware of something.
- arlcode 4y agoTrue. Now that they are entangled with US law there might be an incentive to be as a cooperative as possible. Yet, Hetzner is still a "better" option (with regards to data protection) than any of the big US-based cloud providers.
- baridbelmedar 4y agoNot sure I follow, in what way are they better? Imho, as soon as you do business with the US or trade in US Dollars, you need to play nice with the relevant authorities. If I understood it correctly, Hetzner is now "infected" in the same way as the three US cloud providers are. The Schrems II verdict and Cloud ACT basically concludes that no European company can exist in the US and vice versa without having to deal with the same pesky legislation. An alternative could of course be that Hetzner created a new US based company where the EU parent Hetzner company only holds a minority ownership in the new US-based company. The EU based parent company in turn then "sells" its technology to the new US company. This way, the arrangement becomes more reminiscent of how IBM has sold its mainframe to European companies...
- piperswe 4y agoThe way I read that is: Hetzner Europe is owned by Hetzner Group, a German company. Hetzner US is also owned by that German company. Hetzner Europe isn't owned by a US company, it's just a sibling to one.