8 ms·
Honest question: If a Facebook user in the US are friends with a user in the EU, how are they able to communicate and share profiles without transferring data
by hanspeter 3y ago
Honest question:
If a Facebook user in the US are friends with a user in the EU, how are they able to communicate and share profiles without transferring data from the EU to the US?
- tgv 3y agoA US user can see EU information. It's the storage and processing that's restricted. So, I would guess that the US user's facebook app would have to get its data from an EU server and show it to the US user, without storing it elsewhere.
- jtbayly 3y agoThat just tells me that the EU is requiring all storage and processing to be in the EU, for every profile that is friends with somebody in the EU. Otherwise they can’t store the fact that we are friends.
- tchaffee 3y agoTo be more accurate, the EU is requiring all storage and processing to be in a country which doesn't violate EU privacy laws. That's reasonable and flexible.
- scarface_74 3y agoSo people in the EU just can’t have friends in the US or communicate with people in the US? How do I process a communication between a group of friends - some in the US and some in the EU - without the data being in the US?
- kingnothing 3y agoProcess all of it in Europe.
- tantalor 3y agoMissing the /s
- tchaffee 3y agoAs a start you'd need to read the details of GDPR laws. And probably hire a lawyer.
- scarface_74 3y agoSo now to create any web page compliant with the EU, I need to hire a lawyer to help me understand the 11 chapter 99 section GDPR?
- tchaffee 3y agoDo you collect and store personal information for this website? I bet you could find a dozen or more websites summarizing your legal obligations if you wanted to create one web page. Since the context was Facebook, I was speaking about what businesses should do. And especially large businesses. As far as I've heard, the EU isn't chasing folks who run a small website.
- drusepth 3y ago>As far as I've heard, the EU isn't chasing folks who run a small website. But they could, which has already had a chilling effect on small businesses. Even though the intent (and current enforcement) is to punish large companies, GDPR is written in a way that puts a large compliance burden on many small companies and startups.
- tchaffee 3y agoI have zero problem saying your startup or small business doesn't deserve to collect my personal info if you can't protect it. Doing your accounting, paying taxes, and following labor laws are also burdens on small businesses. Not every small business is profitable enough to manage those things and that's ok.
- SideburnsOfDoom 3y agoIn order to collect, store and process data about people in the EU, you have to do so in a manner compliant with the EU law on that. Collecting that data on a web page is a choice. A semi-hidden security benefit of GDPR is that it makes people think twice before collecting and keeping data - you can't leak data that isn't in your database in the first place.
- tgv 3y agoA US server could store the id of the European friend, and then let the app collect the data. It's not unheard of.
- scarface74 3y agoAnd if they go to the website?
- tgv 3y agoThen their browser can get that data from another server. It may be more complex, no, it is more complex than storing everything in one large database, but it can be done.
- scarface74 3y agoAnd that also gets rid of caching closer to the user and now you have multiple servers and no source of truth. You really don’t see the added complexity of this and how this makes a worse user experience?
- tgv 3y ago> You really don’t see the added complexity of this and how this makes a worse user experience? Bluntly said: IDGAF, and neither should you. Who cares if it's harder for facebook/meta to program? Must we waive our rights because of incompetent or cheap engineering?
- scarface74 3y agoIt’s not harder for Facebook. It makes a worse user experience - just like the GDPR. You didn’t waive your rights. You as an adult have the right to not use Facebook instead of waiting for the nanny state to “protect you”
- tgv 3y ago
- piaste 3y agoI do not understand if or how the physical location of the servers matters. As I remember, the EU-US data sharing agreement was killed (Schrems II) because of the US CLOUD Act, which infamously doesn't care where the data is stored - as long as the company is under US jurisdiction, it has to let the government snoop at will. So, it seems to me that Facebook putting data on EU servers wouldn't matter? A three-letter agency could still go to their SV office and legally demand "give me an API key to query through your Irish datacentre and don't tell anyone". To protect EU citizens from that, the Facebook servers in the EU should treat non-EU FB servers exactly like third parties, using OAuth or similar restricted access protocols.
- detaro 3y agoI don't think Schrems II mentioned the CLOUD ACT.
- di4na 3y agoNo as it was pursued before it. There are not yet any enforcement or complaint i know targeting the CLOUD Act because everyone agree it would be unenforceable right now. Try to have an EU tech scene without Microsoft, Azure, Google, Google Cloud or AWS. Or Salesforce. Datadog. Etc It will take time until this one get enforced.
- Nemo_bis 3y agoActually, there are several enforcement actions which mention the CLOUD Act. https://gdprhub.eu/index.php?search=%22cloud+act%22&title=Special%3ASearch&go=Go https://gdprhub.eu/index.php?search=%22cloud+act%22&title=Sp...
- iruoy 3y agoMicrosoft made it work for governments/universities. But not the rest of us. https://www.privacycompany.eu/blogpost-en/new-dpia-for-the-dutch-government-and-universities-on-microsoft-teams-onedrive-and-sharepoint-online https://www.privacycompany.eu/blogpost-en/new-dpia-for-the-d...
- 3y ago
- detaro 3y agoAFAIU It's not a blanket ban on all data transfers, so if a user clearly wants and authorizes it Facebook can still show their profile and posts to people in the US and transfer data as needed for that. But the legal situation is such that a controller needs to be very precise about what they transfer and how they justify doing that. Which is difficult, which is why there has been so much noise about trying to find something that again lets companies just say "processing in the US is possible under the same standards as in the EU, so we can do all our processing wherever we think is convenient", which saves them a ton of work. But I'd expect until the US is actually willing to make legal changes any such thing will be rightfully rejected by the courts again.
- berkes 3y agoI guess if you shift that question around and stretch it, the answer is quite obvious: If a Facebook user in the US is friends with a user in North Korea, how much data are the North Korean authorities allowed to get on that US user? Aside from the fact that Facebook has no presence in NK (hence the stretch), the answer quite likely is "none".
- nitwit005 3y agoPrivacy laws generally ignore the problematic case where a piece of data relates to both someone inside of the jurisdiction, and someone outside of it. You can hypothetically have a case were two jurisdictions both demand that data be stored locally.