7 ms·
The law here is totally reasonable to protect people's right to data privacy. It's just that every damn website is trying its best to trick their users into con
by milicat 5y ago
The law here is totally reasonable to protect people's right to data privacy. It's just that every damn website is trying its best to trick their users into consenting despite the law. Half the solution look illegal anyway, as you can't deny cookies with a single click. Plus the US Cloud Act is an authoritarian overreach and rightfully gives US providers a competitive disadvantage.
- kall 5y agoI too think these consent solutions are problematic, but the law as it is use here is a catastrophic overreach, if applied broadly. If you take the article at face value, it is illegal to create any kind of TCP/IP connection with a server that is operated by a company which does not operate exclusively in the EU. This is a strong interpretation, but it‘s really not far off from what the court did here: they declared it illegal that an IP Adress (!) was transmitted (not stored?) to a company that could potentially (?) be subject to non EU subpoenas. If NOYB managed to make the entire internet illegal just so they have a sharp axe to go after the things they don‘t like (Google Analytics, cookie "consent" banners), congratulations. They have built a slope so slippery it should have an ICU at the bottom.
- bbu 5y agoIt’s not noyb who built the slope, it’s the ever greedy companies trying to trick people I to all kinds of shady shit. Everything they get they deserve and I truly hope trustarc, onetrust and whatever their names are end up in bankruptcy.
- kall 5y agoSure those companies can go to hell, but is it really worth it? In my view there is no crime bad enough that it justifies having laws on the books that criminalize everyone just so we can selectively enforce them against the bad ones. It may be worth noting that this doesn‘t involve a fine, only that they cease the activity. That is my personal silver lining as someone operating services within the EU that clearly are not lawful.
- floatingatoll 5y agoYes, it’s worth it. The web was a better place without tracking cookies and without targeted advertising.
- kall 5y agoIf you honestly believe this cause is worth a scorched earth approach, fair enough. It‘s literally a scorched earth, because it will be pretty tricky to provide even gopher services to a global internet until we develop a TOR like alternative to TCP/IP.
- floatingatoll 5y agoPlease detail your claim that implementing Gopher in a GDPR-compliant way is “tricky”. It’s difficult to tell if you seriously believe this or if you’re exaggerating for polemic effect, and those details will help evaluate the merit of your viewpoint.
- kall 5y agoI am both exaggerating and serious. Say you are a US company and you run a gopher site. You are not allowed to have the IP addresses of European visitors transmitted to you, that is what this decision is saying right? You are not allowed to allow them to establish a connection to you at all. This seems impossible, but this is how I am reading this. I would (honestly) like to for someone to point out my error here, without any "they probably won't do this because it doesn't make sense" arguments. I don't know what makes a US company eligible to be sued in a EU member court. I guess you have to be doing some kind of business with European customers, so a non profit blog may be ok? How do you solve this? You have to create a legal entity not connected to you that can purchase a server within the EU and then somehow syndicate your content to them without establishing a strong legal connection.
- floatingatoll 5y ago(Apologies, a medical event delayed my reply by a week. I appreciate the time you spent replying, and I’ll try to keep it brief.) I think this only impacts EU providers who sublicense to US providers, if/when they record any ephemeral data collected prior to the user consenting. So an EU business logging the IP addresses of visitors might be not-okay until they consent, though GDPR has some flexibility around “IPs power the Internet”, so long as you don’t try to convert them into personal identifiers. That applies whether US or EU providers are involved, but as the courts point out, any non-ephemeral data within US territory or corporate boundaries is an automatic GDPR violation for an EU company. So, in the gopher example, as a US provider you can do whatever you want, and as long as you’re approximately complying with CCPA, you’ve got GDPR in the bag as well, especially if you just offer the same rights to all users (to not be tracked by default). But as an EU provider, if you host your Gopher server in the US, you may well be violating GDPR as a citizen of a signatory country, since a U.S. provider can’t honor the choice to not record ephemeral data, and therefore compliance is impossible even if the provider currently honors it. This means that AWS is probably not a legal provider for GDPR purposes, since they can be compelled to ignore GDPR, unless the US signs a new treaty. And that’s the terrifying reality of that safe harbor agreement expiring that may result in Amazon having to restructure itself to avoid losing the market; the US entity would have to become a subsidiary of a parent in a treaty-signed country.
- kall 5y agoSure those companies can go to hell, but is it really worth it? In my view there is no crime bad enough that it justifies having laws on the books that criminalize everyone just so we can selectively enforce them against the bad ones.
- deleted 5y ago[deleted]
- marcosdumay 5y agoYes, that's what they did. But the IP address wasn't from the company sharing it, it was from a 3rd party. It doesn't support your second paragraph.
- kall 5y agoDo you mean it was the processing by Akamai, not Cookiebot that was problematic? If so, that's my point. As far as I understand what Akamai does, they where probably just the conduit for establishing a TCP/IP connection to the Cookiebot service. The court neither felt the need to establish that Akamai stored the data, nor that it left the EU. The mere fact a non-EU company was involved in the connection was enough. I'm probably wrong, and I would like to know how, to maintain my sanity.
- marcosdumay 5y ago> conduit for establishing a TCP/IP connection You mean an ISP? No, Akamai isn't an ISP. Cookiebot is unambiguously using its own trustworthiness to let Akami access their users' personal data. There's nothing fuzzy or dubious here. The only news is that what many people expected to be perfectly legal, that is doing that with a confidentiality clause and never having the data leave the EU actually wasn't, because of a different detail.
- kall 5y agoIt‘s a CDN, so it very well may be a "conduit". Maybe they offer edge computing services, I don‘t know. I‘m almost certain they don‘t offer data processing services though. They provide hosting-like services and process data in the normal course of that operation. If I serve images from Akamai (or Cloudinary, FileStack…). Do you think that‘s problematic? Do you think apple is is deceiving me when I download a song from iTunes?
- marcosdumay 5y ago> It‘s a CDN Yes, the GDPR has rules that very clearly apply to CDNs, hosting providers, and etc. What is new is that Akamai breaks those rules. I don't know the situation of the other ones you cite.