Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is there some kind of "we are in the EU and understand our data will be stored in the US and can be surveilled" consent box?

What about platforms that connect people from all over the world? Yeah you can store EU users' data on an EU server but what if a US user checks out a EU user's profile. Or are we supposed to completely disconnect each continent?



You work to the most restrictive set of rules. EU users data is stored in places that comply with the rules in question, that could be the US, if the US complies with EU rules.

If US user wants to interact with EU content, then they need to comply with relevant EU rules. They might not have to give the same level of enthusiastic consent, but the data of their interaction should still stored in EU compliant manner.


That's not quite correct. It depends entirely on what jurisdiction/s you fall under, where you do business.

If you're a US entity you can freely store EU data on US servers entirely without EU permission or consent, and do anything with it that you want to (within US law), so long as you don't operate within the EU. For exactly the same reason that you can safely ignore GDPR if you don't operate in the EU.

If I build a service that runs its servers only in the US, in nearly all cases I don't need to concern myself with EU laws. I'll be operating by US laws. I can allow EU users to sign up and use my service and store their data in the US. There's nothing the EU can do about that.

The EU will have to enable a draconian Chinese firewall to stop this. They have no power or influence to dictate to the world such rules, so the only thing they can potentially do is put their own people in a safety box and lock them off from the rest of the world.


>If you're a US entity you can freely store EU data on US servers entirely without EU permission or consent, and do anything with it that you want to (within US law), so long as you don't operate within the EU.

No, this was what was invalidated; Privacy Shield enabled this behavior

>The EU-U.S. and Swiss-U.S. Privacy Shield Frameworks were designed by the U.S. Department of Commerce and the European Commission and Swiss Administration to provide companies on both sides of the Atlantic with a mechanism to comply with data protection requirements when transferring personal data from the European Union and Switzerland to the United States in support of transatlantic commerce. [1]

With Privacy Shield being invalidated, and nothing else to currently take its place, EU data will technically have to sit within EU (as I understand it). Enforcement of this law will take sometime and won't impact a little startup that's breaking all sorts of rules, as you won't have enough valuable assets for a legal team to go after.

If you are a large multi-national corporation though this is trouble..especially if you aren't using informed consent to notify EU users on what's happening with their data.

>Despite the invalidations made by the judgment, absolutely "necessary" data flows can continue to flow under Article 49 of the GDPR. Any situation where users want their data to flow abroad is still legal, as this can be based on the informed consent of the user, which can be withdrawn at any time. Equally the law allows data flows for what is "necessary" to fulfil a contract. [2]

[1] https://www.privacyshield.gov/welcome

[2] https://noyb.eu/en/cjeu


No, this was what was invalidated

I think you missed the point. They're arguing they don't care what the EU thinks. If some EU court invalidates some EU specific thing they didn't care about previously, they still don't care about it afterwards.

Enforcement of this law will take sometime

Like, forever? How many US firms has the EU taken to court in the USA and won, over their cookie law?

EU cannot enforce these laws on US firms, only EU firms, but even then, such things are basically never actually enforced except for political reasons. So they might try and cause trouble to Google and Facebook or Apple, because they're big sources of money. Everyone else will just ignore it or go through some compliance motions if they feel like it.

As always with the EU there are regulations everywhere and they don't mean anything. As you state yourself, "necessary" data can continue to move. This is the same as saying "we'll make it up as we go along".


This is wrong?

It doesn't matter where your servers are, if you offer a service to people in the EU and you store their personal data, you need to safeguard that data and comply with GDPR.

It's a law, so it can be enforced through mutual international treaties.

However, common sense prevails in the EU and especially with GDPR, so no one will go after you because you use Google Analytics and didn't give an option to opt-out. But if you start collecting personal addresses, emails and phones disguised as a charity doubling their contributions and then sell that information to callcenters abroad for tax scams and upload it to 4chan, then yes, EU's reach will be tested.

https://gdpr.eu/compliance-checklist-us-companies/

https://gdpr.eu/companies-outside-of-europe/


This doesn't make any sense to me. So I'm German, I go to Thailand. I buy a Jet Ski to be used solely in Thailand? Is that Jet Ski under EU law now? Why is it different if I virtually go to Thailand?

or don't like the purchase aspect? Okay I go to Thailand and rent a car. To rent the car I need to give them my personal info. A copy of my passport, a copy of my international drivers license. If we follow the same logic that Thai car rental company somehow has to treat the PII under EU laws.

The EU has no jurisdiction is Thailand and the Thailand car rental company should not have to do things differently just because the person renting is from a different country. That they happen to be online, like say I reserved the car while in Germany before my travel, seems like it would have zero barring on this.

Can a restaurant in SE Asia take a reservation from an EU citizen? They need to store PII to do it. How does the EU send their enforcers over to that mom and pop restaurant to make sure their reservation system is protecting that EU citizen's PII?

I'm not trying to argue it's okay to use PII. I'm instead trying to understand how these laws actually work because they seem basically impossible to enforce or even implement.

I see the link above tries to cover this. Unfortunately it covers it in nonsense and doublespeak.

> Suppose you run a golf course in Manitoba focused exclusively on your local area, but sometimes people in France stumble across your site. Would you find yourself in the crosshairs of European regulators? It’s not likely. But technically you could be held accountable for tracking these data.


So I'm German, I go to Thailand. I buy a Jet Ski to be used solely in Thailand? Is that Jet Ski under EU law now?

No, not until you bring the Jet Ski though German customs.

Why is it different if I virtually go to Thailand?

Because now, the Jet Ski operator is operating in the EU, and the EU could always choose to null-route said website. There's plenty of precedent for that, even in the US (DHS seizing torrent sites under counterfeit regulation, ISP's de-listing pirate bay DNS entries).

Okay I go to Thailand and rent a car. To rent the car I need to give them my personal info. A copy of my passport, a copy of my international drivers license. If we follow the same logic that Thai car rental company somehow has to treat the PII under EU laws.

Perhaps, but as you say, the EU currently has no way to enforce its GDPR outside its jurisdiction.

How do you think the US enforces its take on copyright and patent law outside its borders? Through treaties and trade deals. If the EU wanted to, it could do the same with the GDPR.


The law applies to your non-EU company when you target EU citizens and people currently physically in the EU. E.g. if you sell goods and offer shipping to the EU, GDPR applies to you. If you do not ship to the EU and do not offer services to EU residents, GDPR doesn't apply to you.

There are some areas in need of examples:

For your restaurant in Bangkok that takes a reservation from the EU: not covered by the GDPR because they don't target EU residents, that a resident used their reservation page is incidental and an exception.

For some purely-online service, if you somehow target world-wide or all speakers of an official EU language, GDPR applies. That means your french language online newspaper in New Orleans is affected, if they have an international section. If it is chinese language, you are fine. Geoblocking helps.


That's not what the EU guideline says above. See the Manitoba example


Yes, there is a grey area as the guideline says, and "targeting EU residents" is interpreted very widely. We will have to wait for the courts for an exact interpretation there.


To add to this: while EU law might not be able to reach you in the US and extradition over such issues might not happen, travelling to Europe for you or your subordinates might be "interesting", at least after a successful court decision. Also, freezing assets and payments is possible, as well as forbidding doing business with you. But that all depends on the kind of exposure you have there.


There are no mutual international treaties that enforce GDPR.


As far as I know that is not allowed as it would just be used to override any data protection laws.

In the end if part of the world refuses to implement even the most basic working privacy protection laws what choice does the EU have.

I'm certain companies and governments alike would be thrilled to put in place the next iteration of this agreement, however the US refuses to move even an inch.


US could solve this by granting all humans same rights and not have the ability to read private data of all non-US citizens with no restrictions.


That would be obviously the right thing to do in quite a lot of cases. Immigration and elections are about the only cases where being a citizen should matter. And conscription, if we keep digging.


Consent might not be necessary or might not be possible, depending on the situation. You need a legal basis for processing of data, one possible (but the worst possible) is consent. A popular better one is "fulfilment of a contract". All that is largely (but not completely) independent from how and where the data processing is done. You usually do not need consent to have data processed by a third party or abroad, if you have a legal basis for processing said data. You just need to keep your customer informed.

Exceptions to all this apply for special kinds of data (minors, medical, biometric,...) and invasive processing (AI decisions, scoring). In those cases you might need special consent or you might not be able to export the data at all, even with consent.


I think the expectation is that data of a European citizen remains in the European union except otherwise needed and consented.

In sense of the GDPR, a European User Account does not need to synced to the US but only the communicated exchange between a European and a US user.

There are a lot of reasonable usage and solutions. They just cost money, time and are annoying architecturally.


No, the data can be held anywhere that has enforceable protections equivalent to the EU’s. Japan was explicitly ruled to be. The UK will almost certainly be found not to be because it’s intelligence services are even more out of control than the US’.


Agree. I think my statement of "within the European Union" is indeed a bit too restrictive. Your comment is indeed pointing the right thing: enforceable and equivalent protection. That is exactly what Privacy Shield and the predecessor was aiming for.


Under the GDPR, consent boxes cannot be mandatory. The service must work even if you don't consent.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: