9 ms·
Austrian DSB: EU-US Data Transfers to Google Analytics Illegal
- rehamelbasha 5y agoThere are alternatives like snowplow. My former company and current one decided to move out from GA to snowplow as you have much more control on your data and do not so much depend on Google to be gdpr compliant.
- aspenmayer 5y agoFirst time hearing about Snowplow. Seems interesting, and hey, open source doesn’t hurt. Any company that openly suggests alternatives to their products instantly wins respect in my book. Nothing like laying your cards on the table. https://snowplowanalytics.com/blog/2021/01/05/the-top-14-open-source-analytics-tools-in-2021/ https://snowplowanalytics.com/blog/2021/01/05/the-top-14-ope...
- aspenmayer 5y agoThis is due to GDPR. Amazing ruling for privacy for all of EU. Detailed analysis: https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2021-0.586.257_(D155.027) https://gdprhub.eu/index.php?title=DSB_(Austria)_-_2021-0.58...
- zibzab 5y agoThis is supposed to be a side show for Google, they are not getting paid neither are they using your data behind your back. Now if that was really true, it shouldn't really matter for them to drop this service. Instead, I think we will see them investing millions to overrule this.
- toyg 5y agoWhat? Analytics is not a sideshow, it allows them to have clear and essential first-hand data on the popularity of sites, which is then likely used (with other factors) to drive Adsense auctions - their bread & butter. If it were a free service "for the hell of it", Analytics would have long been discontinued.
- aspenmayer 5y agoBy sideshow, OP was charitably going along with what Google’s EU lawyers would have us believe, not the reality on the ground. Of course it’s necessary for their ad business model as currently implemented. They would have to setup a separate ad auction unit in EU for EU visitors, if the ruling stands. This reminds me of how IBM and Coca-Cola setup “independent” operations in Germany during the WWII embargo to provide products and services to the Nazi regime. Those units were later folded back into their original parent companies after the war, profits and all. That’s where Fanta came from. That’s what Coca-Cola Germany was called. I forget what the IBM one went by.
- 6510 5y agoAdsense in it self is just another analytics tools isn't it?
- toyg 5y agoYes, but Analytics gives them coverage of the nooks and crannies Adsense cannot reach.
- aspenmayer 5y agoTheir lawyers are going to have to earn the wins, as the rulings against them don’t find their IP licensing to Google LLC (Ireland) to be particularly clever or cute. That this makes their tax avoidance strategy super obvious and fruitless in the EU is just the icing on the cake. No point for mama Google to license tech to their foreign subsidiary if they can’t phone home with the results. I’m laughing. They will have to store EU data in Europe, and European authorities will forward relevant data to the relevant US authorities. At least that’s the way the EU courts seem to be leaning. Google will likely appeal and waste everyone’s time, and maybe win. But they will only make calls for antitrust action louder if they were to do so.
- blitzar 5y ago> This is supposed to be a side show for Google, they are not getting paid neither are they using your data behind your back. Sarcasm doesnt translate well in written comments on the internet.
- aspenmayer 5y agoIt was pretty clear that they were incredulous from the context and awareness of Google’s ad business model. Generally, I’d agree, but in this case, it’s pretty obvious.
- YetAnotherNick 5y agoI really don't understand why countries are so persistent about storing data in their country. It's not like the enforcers could walk into the datacenter and plug in the usb drive and get the data. And it's even hard to see what all constitutes user data. Does logging constitute user data. Does that mean that to get logs for the error the developer need to travel to every country and remember the log messages in his head. And companies could easily copy their data in a click if they need to. A much saner approach should be limiting what the company is allowed to do with the data.
- phaer 5y ago> It's not like the enforcers could walk into the datacenter and plug in the usb drive and get the data. They can ask and/or force a given company to hand data to them in many cases in most jurisdictions. > Does logging constitute user data. Logging of user-data? yes > A much saner approach should be limiting what the company is allowed to do with the data. GDPR does also regulate what a company is allowed to do with data. The thing is: whether the GDPR applies and is enforceable depends on where that data is stored.
- deleted 5y ago[deleted]
- simion314 5y ago>I really don't understand why countries are so persistent about storing data in their country It is about having some rights. So say if you are from USA then Google or NSA should follow the laws , but if say I am a politician from some other country the Google and NSA employees can just read my emails and then blakmail me (or grab my paypal code and grab my money) because US laws only protect US citizens, terms of service are not laws and we know that we can't attribute morality to Google,Apple or NSA.
- kmlx 5y ago> the Google and NSA employees can just read my emails and then blakmail me this is a new level of conspiracy theory.
- snowwolf 5y agoHas Google Analytics now adopted the latest European Commission approved SCCs (https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en https://ec.europa.eu/info/law/law-topic/data-protection/inte...) and does that mean using GA with those SCC's is now compliant going forwards. Or does this cases verdict that "SCCs and "TOMs" not enough" now mean those EC approved SCCs are now useless?
- tedivm 5y agoThis case is explicitly about US Law and how it contradicts the EU law. According to this case, as long as US law allows the US government to force US companies to share data with the US Government then you can't share data with those US companies. To quote directly- > SCCs and "TOMs" not enough. While Google has made submissions claiming that has implemented "Technical and Organizational Measures" ("TOMs"), which included ideas like having fences around data centers, reviewing requests or having baseline encryption, the DSB has rejected these measures as absolutely useless when it comes to US surveillance (page 38 and 39 of the decision): > "With regard to the contractual and organizational measures outlined, it is not apparent, to what extent [the measure] are effective in the sense of the above considerations." > "Insofar as the technical measures are concerned, it is also not recognizable (...) to what extent [the measure] would actually prevent or limit access by U.S. intelligence agencies considering U.S. law."
- snowwolf 5y agoExactly my point. However the European Commission has released "Approved" SCC's in June 2021. Does this case now invalidate those because "the DSB has rejected these measures as absolutely useless when it comes to US surveillance" in which case it is in conflict with the European Commissions guidance.
- pieter_mj 5y agoGreat victory. I bet firebase crashlytics is illegal as well in EU. The reason I uninstalled the hacker news app 'Materialistic' is because it regularly crashed and was probably unvoluntarily siphoning off pii data through the crashlytics module.
- minkiu 5y agoYou can give Glider a go https://f-droid.org/en/packages/nl.viter.glider/ https://f-droid.org/en/packages/nl.viter.glider/
- ckastner 5y agoMax Schrems is just incredible. Just look at his Wikipedia page [1] and see how many EU-US data transfers he's challenged successfully. [1] https://en.wikipedia.org/wiki/Max_Schrems https://en.wikipedia.org/wiki/Max_Schrems At this point, I wonder why the EU doesn't consult him personally prior to enacting some law. It's not as if they don't consult with others as well.
- Fnoord 5y ago> At this point, I wonder why the EU doesn't consult him personally prior to enacting some law. It's not as if they don't consult with others as well. Because it costs companies a lot of money to merge to EU-only market, while waiting for the wheels of justice to grind buys time (for EU-only market).
- Sporktacular 5y agoThat's right, but the US does this all the time with its military/intelligence networks, China does the same for it's public internet. It's not like their providers are running at a loss, they just need the right incentives.
- deleted 5y ago[deleted]
- cblconfederate 5y agoWhat's the end goal of all this? Information (data) technology has essentially left europe The EU is never held accountable for the laws they make, and i m not aware with them consulting with local entrepreneurs. It seems only lobbyists and politicians have access
- iqanq 5y ago>The EU is never held accountable for the laws they make Of course it is. The tech sector is practically non-existant here, and if something works out, they leave for the US. Isn't that what being accountable is?
- phoronixrly 5y agoThe key points in the article for me: > Max Schrems, honorary chair of noyb.eu: "Instead of actually adapting services to be GDPR compliant, US companies have tried to simply add some text to their privacy policies and ignore the Court of Justice. Many EU companies have followed the lead instead of switching to legal options." > In the long run, there seem to be two options: Either the US adapts baseline protections for foreigners to support their tech industry, or US providers will have to host foreign data outside of the United States. > No penalty (yet). The decision is not dealing with a potential penalty, as this is seen as a "public" enforcement procedure, where the complainant is not heard. There is no information if a penalty was issued or if the DSB is planning to also issue a penalty. We need more trials related to GDPR breaches. While having the legislation is a huge achievement, it needs to be backed with enforcement. If there is no enforcement, a third long-term solution arises -- just ignoring the law until you manage to get the necessary amendments to it in order to keep operating as before without fear of penalty.
- sofixa 5y agoYou might be interested in https://www.enforcementtracker.com/ https://www.enforcementtracker.com/ I agree we need more enforcement, but it's reassuring to see the current levels.
- anonymousab 5y agoViolations outpace enforcement both in current volume and rate of growth, by orders of magnitude. This is the opposite of reassuring.
- sofixa 5y agoBut the fines are getting very significant, and major types of violations are awarded with fines ( so other violators might see that and stop, or at least when they get caught the ruling will be faster due to precedents).
- jokoon 5y agoI'm really curious what would happen if those companies followed the law. My bet is that they would entirely stop doing business in the EU, because I'm suspecting that data collection is the cornerstone of google/facebook/etc's business model. They cannot properly advertise if they don't collect data. To me it's a bit similar to what happened with China. China doesn't want the US to get data on chinese people, but their solution was to just block those companies. The EU uses courts to protect itself, but I guess the result would be a bit similar.
- timgl 5y agoRelevant thread on open source alternatives to Google Analytics from earlier today: https://news.ycombinator.com/item?id=29888599 https://news.ycombinator.com/item?id=29888599
- cblconfederate 5y agoposthog seems to be hosted in Digitalocean - an american company plausible.io is hosted on AWS - an american company snowplowanalytics.com seems to be hosted in digitalocean as well as I understand they are equally illegal now. [Self-hosting and maintaining is not an option for the vast majority of mom-and-pop shops]
- nabla9 5y agoI don't think the home country of a company matters that much. International companies must comply to the local laws and regulations. EU is so large market that they will implement anything EU requires. For example, AWS can host and collect EU data and fully comply with EU regulations, never moving data to the US. With AWS customers can determine where their customer data will be stored, including the type of storage and geographic region of that storage.
- juanani 5y ago[dead]
- wgas 5y agoThis is why we went with Fathom as their edge locations are isolated regional (EU). So if I understand it correctly, core hosting is AWS, but on the edge locations run by an EU company in the EU process the data and remove the sensitive data. For me, it makes no sense when companies like plausible say they have EU based hosting when they pay for hosting from a US-only company (DigitalOcean)
- markosaric 5y agoAll site data plausible.io stores on behalf of the customers is hosted in Germany on servers owned by Hetzner, a European-owned company. Previously it was hosted by Digital Ocean in Germany but the move to Hetzner was made last year.
- tjansen 5y agoThat stuff scares me. More than US government surveillance could ever scare me. The most likely outcome is that smaller companies just don't do business in the EU. At least before they are large enough to deal with GDPR. I am located in Germany, but if I would start a SAAS site today, I wouldn't try to sell to the EU. Just isn't worth the trouble. Over time, many people in the EU will start using VPNs to get access to the latest web sites without GDPR restrictions. Even today I have to use a VPN to access some websites (mostly news sites), but I suspect it will be much worse if noyb succeeds.
- JanSt 5y agoWhat should really scare you is the vast amount of privacy violations, data collection and tracking that is happening around the web. Imagine someone following you everywhere in the real world, even getting into your apartment and noting down everything you do. If following the basic principles laid out in GDPR is too much of a hassle for you, you should probably not be in business anyway. It's not rocket science.
- tjansen 5y ago> What should really scare you is the vast amount of privacy violations, data collection and tracking that is happening around the web. Even if it would scare me (it really doesn't), as an EU citizen I would care about surveillance by the EU, not by the US. > Imagine someone following you everywhere in the real world, even getting into your apartment and noting down everything you do. To do what? Collect a lot of useless information? I would bother me if someone I know does it. I don't care if some abstract entity in a different country thousands of miles away does it.
- fauigerzigerk 5y agoWhat I'm concerned about is that companies collecting data on me may not be able to keep it safe (e.g Equifax). I could become a victim of identity theft, fraud, extortion, blackmail, corrupt officials, litigious opponents or authoritarian regimes.
- usr1106 5y agoThe deeper background is of course Google's business model of data and privacy prostitution: Users give their private life to Google and they get web search, email, and videos back. In a more reasonable world users would pay money for the services they want to use. Of course it needs to be noted that most users don't even understand that they are selling themselves. And of the few who do most still think it's better than paying money. This ruling, should Google comply in the end, will not change anything. Google will store the data in the EU and that's it. I don't think they share user data with the advertiser when they show an ad. So they could still show ads of US companies. And that's a niche business only anyway because when Europeans do business with Amazon, Disney, and the like they deal with the respective European subsidiaries already.
- moonchrome 5y ago>In a more reasonable world users would pay money for the services they want to use. >Of course it needs to be noted that most users don't even understand that they are selling themselves. And of the few who do most still think it's better than paying money. This is such pretentious snobbery. In a world where you have to pay for search engine I am still dirt poor working some shit entry-level job/doing manual labor because when I was a kid I couldn't even afford interned and had to hitch off a neighbour, having free access to Google, tons of free learning material, messaging boards, etc. is what got me out of that situation. I pay to avoid advertisement, but that's a luxury I can afford now days, and I have almost no concerns about privacy - I don't care at all that Google knows my interests, browsing history, purchase history, etc. The concerns about data collection I see are mostly blown way out of proportion and most people rightfully don't care TBH.
- simion314 5y ago>I don't care at all that Google knows my interests, browsing history, I also don't care that Google,NSA, KGB, CIA, ChIna knows my browsing history or what files I have on my PC but I care if this groups know everyone browsing history because they can affect me indirectly by blackmailing, manipulating key individuals or entire populations with targeted ads or propaganda. Is the same with fake news like "WiFi is illegal in Japan because causes cancer" , this fake shit won't affect me directly but affects people in my family so it affect me indirectly and I have to reduce the damage done.
- ur-whale 5y agoThe EU regulating itself out from the market. Not for the first time, mind you.
- pacija 5y agoRegulating oneself out from the market where main merchandize is people's private data sounds like reasonable thing to do.
- boshomi 5y ago»Max Schrems: "In the long run we either need proper protections in the US, or we will end up with separate products for the US and the EU. I would personally prefer better protections in the US, but this is up to the US legislator - not to anyone in Europe."« That's the point: we need real data protection in US law for non-US citizens as well. Currently, US lawmakers treat EU citizens' data as US state property. Obviously, that's unfair.
- iqanq 5y ago
- m-s 5y ago“willingly” is a bit of a stretch
- iqanq 5y agoIt depends. I understand that ad networks for example take identifying data (such as IP addresses) without consent. But if I sign up to Facebook and I put there my name and my face, it's because I want to. No one has put a gun to my head. And I don't see that it matters whether that data is in a hard disk in the US or the EU. These regulations seem a power move more than anything else.
- hobs 5y agoThe proof of a problem isn't "someone put a gun to my head" - its a meaningful part of our society put behind a rich man's walled garden because only he had enough money to bribe every telecom and buy every competing platform.
- nickpp 5y agoEvery competing platform? I can think of a few alternatives, starting with this one we are on right now. But some people are still choosing Facebook, and they are choosing it willingly, happy they do not have to pay for it with anything more than some targeted ads...
- davidgerard 5y agoNothing about GDPR is hard ... unless your business model is to abuse your customers' personal data. Then it might be hard. I routinely see the loudest complainers about the onerous nature of GDPR compliance suddenly get vague or stop posting when you ask for details of precisely what bit is so hard for them in particular. Note lack of those details in this present discussion, for example. So far, it seems a safe assumption that the excuse makers are abusing personal data, and they know they're abusing personal data. Perhaps one day a clear exception will show up. I wrote up a thing here a few years ago with my actual on the ground experience of getting us compliant: https://reddragdiva.dreamwidth.org/606812.html https://reddragdiva.dreamwidth.org/606812.html tl;dr anything that might vaguely constitute personal data, down to Apache logs, must either be in a writable database for redactability, or deleted. Since then, our legal team - who are not your legal team! - has advised: * 30 days for operational purposes is fine actually. * Go feral on anything over 30 days. You need a named person responsible for GDPR redactions. * If you want to do analytics on those Apache logs, do them quickly and into a form that doesn't contain personal data. I'm in the UK, which is no longer in the EU, but the GDPR laws still hold here.
- TheGigaChad 5y ago
- tjansen 5y ago> unless your business model is to abuse your customers' personal data. Then it might be hard. It's not only your business model, but also the business model of all third-party services you are using on your site. Also, part of the reason why it's not that hard is that the GDPR is pretty much one of a kind. Imagine the US and maybe some countries in Asia having similar but different implementations of privacy laws, and you having to work with them simultaneously. Or even different laws in each US state (CCPA?). Imagine every country requiring you to store user data only the user's country of origin, thus managing a separate database for each country.
- M2Ys4U 5y ago>Also, part of the reason why it's not that hard is that the GDPR is pretty much one of a kind. Imagine the US and maybe some countries in Asia having similar but different implementations of privacy laws, and you having to work with them simultaneously. That's why treaties like Convention 108+[0] exist, to provide a common framework for implementing data protection laws. [0] https://search.coe.int/cm/Pages/result_details.aspx?ObjectId=09000016807c65bf https://search.coe.int/cm/Pages/result_details.aspx?ObjectId...
- etothepii 5y agoIn other news, king orders tide out.
- fideloper 5y agoTo my knowledge, Fathom Analytics is the only analytics app that has bothered to hire actual lawyers and navigate EU isolation. They wrote about it here: https://usefathom.com/features/eu-isolation https://usefathom.com/features/eu-isolation
- jbrooksuk 5y agoAnd that's why, as a responsible developer, I exclusively use Fathom for my own projects. As far as I know, they are the only analytics company who are correctly following the law here AND they always try to do more. They completely isolate EU analytics from their US databases, which you can read more about at https://usefathom.com/features/eu-isolation https://usefathom.com/features/eu-isolation Aside from this, unlike other startup analytic solutions, they've actually spoken to lawyers to read through the fine lines of the law and ensure their solution is legal. Go get it!
- eisa01 5y agoLooks interesting, but for hobby websites with low traffic the pricing is slightly steep at $14/month - I pay $5/month for the hosting (: Any alternatives?
- mafuy 5y agoYou can still self-host a FOSS law compliant analytics suite. It will suffice for small websites.
- ben_w 5y agoWhy bother with analytics for a hobby website?
- iamacyborg 5y agoThis is the correct answer. There's precily nothing to gain from looking at the data from a small website.
- cblconfederate 5y agoanalytics is important to grow an audience. A big website doesn't need to care about SEO or analytics or anything really. Metcalfe's law
- jbrooksuk 5y agoIf you don't want to pay it, then you probably don't need it. I don't have experience with alternatives though - they just don't do as good of a job as Fathom does.
- sebsebsn 5y agoIt looks like this makes Fathom Analytics the only provider for website analytics that you can use if you don't want to maintain a locally hosted version if an open source product – which blows my mind. A small company is the only service that is able to comply with the rules while huge ones simply fail. I assume that this regulation is also coming to other services soon and analytics isn't the only service that needs to be replaced when a business is in the EU and can't ignore these rules without risking fines. The team at Fathom wrote about alternatives for lots of services here: https://usefathom.com/blog/degoogle https://usefathom.com/blog/degoogle
- donohoe 5y agoNot the only provider, worth looking at Plausible. https://plausible.io/ https://plausible.io/
- sebsebsn 5y agoNope, they use US providers. The servers are in the EU but the providers are US companies and that means that they aren’t GDPR compliant at all. This is exactly what Schrems II targets.
- markosaric 5y agoAll site data plausible.io stores on behalf of the customers is hosted in Germany on servers owned by Hetzner, a European-owned company. Previously it was hosted by Digital Ocean in Germany but the move to Hetzner was made last year. For our self-hosted version, you can install it with any cloud provider and in any country you wish. Even in the USA.
- zeusly 5y agoCan someone tell me if this is even true? Plausible doesn't save any GDPR related data as far as I know? https://plausible.io/privacy-focused-web-analytics#no-personal-data-is-collected https://plausible.io/privacy-focused-web-analytics#no-person... And the backend is hosted @ Hetzner in Germany
- deleted 5y ago[deleted]