4 ms·
If mere IP addresses are PII, I do not see how me looking at my GCP logs is any different (i.e. not allowed), and by extension how any US cloud provider can ope
by hobo_mark 4y ago
If mere IP addresses are PII, I do not see how me looking at my GCP logs is any different (i.e. not allowed), and by extension how any US cloud provider can operate in Europe within these rules?
- ocdtrekkie 4y agoGood. US cloud providers are so abusive and monopolistic, we basically need regions that exclude them entirely to give better alternatives a place to develop.
- pb7 4y agoI love the premise that the only way Europe can compete in a free market is if all other competitors are outright banned. What a sad state of affairs.
- ocdtrekkie 4y agoIt has nothing to do with Europe. It's just that competing with monopolies is generally impossible, which is why they're supposed to be illegal. The US has failed to enforce its own laws about monopolies for decades.
- pb7 4y agoIn what way are three major cloud competitors + many more focused cloud offerings a monopoly? “Monopoly” doesn’t mean “successful company I don’t like”. Europe has failed to innovate for decades and that’s why it’s perpetually backed into a corner.
- geewee 4y agoYou as an individual are free to peruse any site you want. In practice, it might be hard to use US cloud providers in Europe lawfully to process PII, although some exceptions have been ruled - such as the french DPO ruling the use of AWS lawfully for the state vaccine program, as the PII was only encrypted in AWS, and AWS did not have the encryption keys.
- foepys 4y agoQuite a few people in the EU already consider US cloud providers to break GDPR just by existing because of US legislature like the CLOUD act. A view that was (is?) at least partially shared by Microsoft [1]. MS created a (now closed) dedicated Azure data center in Germany where they got into trouble with the US government because MS didn't comply with a three letter agency request to obtain data from there. 1: https://en.wikipedia.org/wiki/Microsoft_Corp._v._United_States https://en.wikipedia.org/wiki/Microsoft_Corp._v._United_Stat...
- notimetorelax 4y agoIt’s about the use for said collected data.
- slackner 4y agoThere are a few justifications that allow you to process PII. One of them is to fulfill a contract (e.g. storing the address when a user purchases a product). The same justification is also used to store IPs in logs as you might need this information to debug issues or report illegal activity to authorities. The same reasoning cannot be applied to analytics as there are no technical or legal requirement to have them and they are rather an optional addon. Moreover, there is also a restriction how long you are allowed to retain logs that have PII in them. You must not store them any longer than required (or anonymize them). I think 7 days is a commonly used limit for this.
- openplatypus 4y agoThey can in very limited scope. https://wideangle.co/blog/scc-definiteve-guide#case-study-standard-contractual-clauses-and-aws https://wideangle.co/blog/scc-definiteve-guide#case-study-st...