5 ms·
Funny thing is, us data is almost always maintained by people outside of the US, at least for banking. The servers may live in the us, but the people accessing
by pylua 2y ago
Funny thing is, us data is almost always maintained by people outside of the US, at least for banking. The servers may live in the us, but the people accessing it are probably located in Europe or India. This also means that the data lives their temporarily while it is being accessed.
The US definitely needs stronger laws here.
- ndsipa_pomu 2y agoIt shouldn't be a problem for Europeans to access/process U.S. data that belongs to U.S. citizens - GDPR doesn't cover that AFAIK, so it's fine for it to cross borders. The issue is with GDPR protected data of EU citizens, as the law does not permit that data to cross non-EU borders unless it's for specific exemptions such as law enforcement.
- mananaysiempre 2y agoOr, IIRC, if the destination country has privacy protections that are at least as strict as those in the EU, which the US legal regime for foreign intelligence definitely doesn’t provide (a non-US-citizen wouldn’t even have standing to sue wrt their personal data).
- ruthmarx 2y ago> a non-US-citizen wouldn’t even have standing to sue wrt their personal data Sure they would, I think? They would just have to foot the bill to travel and file in a US court. And whatever user agreements they 'agreed' to might come in to play without legislation to supersede it. But they would have standing, I'm pretty sure.
- mananaysiempre 2y agoNot a lawyer and not going to find the relevant references in the US’s vast body of law in reasonable time, so let’s check what the CJEU concluded? Schrems I [1] (the old CJEU judgment invalidating Safe Harbor) endorses (§90) the opinion that: > [D]ata subjects [whose personal data was transferred to the US] had no administrative or judicial means of redress enabling, in particular, the data relating to them to be accessed and, as the case may be, rectified or erased. In what reads like a reference to FISA, it continues (§95): > Likewise, legislation not providing for any possibility for an individual to pursue legal remedies in order to have access to personal data relating to him, or to obtain the rectification or erasure of such data, does not respect the essence of the fundamental right to effective judicial protection, as enshrined in Article 47 of the Charter [of Fundamental Rights of the European Union]. It then stops short of calling out FISA by name, instead (IIUC) invalidating on the basis that the adequacy of the legal regime was not addressed in the Safe Harbour decision to begin with. Privacy Shield came next and did, so Schrems II [2] (the newer judgment invalidating Privacy Shield) states (§181–2): > According to the findings in the Privacy Shield Decision, the implementation of the surveillance programmes based on Section 702 of the FISA is, indeed, subject to the requirements of PPD‑28. However, although the Commission stated, in recitals 69 and 77 of the Privacy Shield Decision, that such requirements are binding on the US intelligence authorities, the US Government has accepted, in reply to a question put by the Court, that PPD‑28 does not grant data subjects actionable rights before the courts against the US authorities. Therefore, the Privacy Shield Decision cannot ensure a level of protection essentially equivalent to that arising from the Charter [...]. > As regards the monitoring programmes based on E.O. 12333, it is clear from the file before the Court that that order does not confer rights which are enforceable against the US authorities in the courts either. It sounds like the official legal position of the US executive is that individual foreigners do not have standing to contest FISA 702 surveillance of them. (I could not quickly find the text of that position.) This is a 2020 judgment in a case from July 2018 regarding a European Commission decision from 2016, so the implications of the CLOUD Act, signed in March 2018, do not look to be in scope. [1] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62... [2] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62...
- ruthmarx 2y agoI think you are right. I lost the context the original comment was made in, and was thinking more about damage coming from company negligence, and not government sanctioned surveillance.
- pylua 2y agoYou could be a citizen of the eu and us.
- mjw_byrne 2y agoNAL, but I think GDPR has exceptions for remote access, i.e. if a worker in India is viewing data held in the US, that is not necessarily formally considered a transfer from the US to India, even though the data clearly has made it to India if it's being displayed on a screen there.
- theptip 2y agoUnder GDPR I believe if the data access is from an employee of the company (eg Uber) then there aren’t location checks. (Been a while so I could be mistaken here.) But if you are subcontracting to an agency you need to list them as Subprocessors in your DPA. So subcontracted support staffing companies for example would be required to be listed and explicitly consented to. This is all assuming you set up the base contractual protections for the data required to export the data at all, which Iber apparently didn’t do here.
- Puts 2y agoWell technically data transfer according to GDPR has nothing to do with where the data is geographically. It’s what legal jurisdiction the controller or processor is under that matters. If you move data to a processor under another jurisdiction that is a transfer.
- organsnyder 2y agoGDPR absolutely does have requirements for the physical location of data.
- lolinder 2y ago> The US definitely needs stronger laws here. Can someone clarify for me why the physical location where data is stored is a big deal? Why does the US need stronger laws here? This is probably just my inner naive technologist speaking, but I really enjoyed the moment of time during which the internet was a global network of computers that created a virtual space where physical borders were largely irrelevant. So it's a bit jarring for me to see people take for granted the idea that borders matter on the internet after all. Edit: 0x62 has a good explanation here: https://news.ycombinator.com/item?id=41357888 https://news.ycombinator.com/item?id=41357888 I hadn't considered the recursive nature of suppliers.
- bayindirh 2y ago> Can someone clarify for me why the physical location where data is stored is a big deal? What can you do if your data is silently copied by third parties and used for other activities? What if I build a ghost profile of you and steal your identity when I have enough data? What if I relay that you have a fancy car to some people who have the means to get that from you while sleeping? What if I craft a good scam by targeting you with your own data? It's not about data is sent to where, it's about what happens when it arrives to the physical servers, who has access to these files, and what can they do with it. When I visited the states, I got EZ-Pass spam/scam e-mails for a year, on an e-mail I gave to nobody when I was there. So, these laws matter.
- lolinder 2y ago> It's not about data is sent to where, it's about what happens when it arrives to the physical servers, who has access to these files, and what can they do with it. Right, but the EU can only enforce its laws on companies that have a presence in the EU. A company that doesn't do business in the EU and never will do business in the EU will not obey EU law regardless of what those laws say. Meanwhile, a company that does business in the EU would be subject to fines by the EU and wouldn't be able to dodge them without just stopping doing business in the EU. So why do the laws not just say "here's how you have to treat data belonging to our citizens if you want to continue to do business in the EU"? Why does the physical location of the data that is being thus protected matter at all?
- begueradj 2y agoExcept that the US authorities have the right to access the data you stored on Apple or Google & Co. servers whenever needed, without your consent and even if you are completely innocent.