11 ms·
Usage of EU subsidiaries of US cloud providers deemed unlawful by German court
- throwaway4good 4y agoThis is EU law. That is why you are seeing similar court rulings / administrative rules coming out of Denmark, France, Italy ...
- fvdessen 4y agoLooking for an informed opinion; what are the practical consequences for European companies using American cloud providers (which I guess is most of them) ?
- deleted 4y ago[deleted]
- londons_explore 4y agoImmediate consequences... None. While all of your competitors are still using american cloud services, you won't get fined. But as soon as competitors start moving to european hosting solutions, you need to too - because if you're slow to move over you can bet the courts will be chasing after people with fines.
- rubito 4y agoNot a problem with consumer facing services but usually problematic with comunal and state related projects that store personal data.
- kazen44 4y agoin my opinion, most european companies are not using the cloud (especially if they are not in the tech space). Colocated hosting is very, very large in europe, and many small/medium bussinesses operate out of a couple of VM's on a server in some datacenter, usually managed by some MSP. Also, Egress fees are very expensive in the cloud, especially if you look at the cost of data transfer inside colocated facilities. data transfer in the US seem expensive even if you look at colo/private circuits compared to europe.
- srrr 4y agosummary (English): https://gdprhub.eu/index.php?title=VK_Baden-W%C3%BCrttemburg_-_Az._1_VK_23/22 https://gdprhub.eu/index.php?title=VK_Baden-W%C3%BCrttemburg... news article (German): https://www.golem.de/news/vergabekammer-clouddienste-von-us-firmentoechtern-sind-nicht-dsgvo-konform-2208-167456.html https://www.golem.de/news/vergabekammer-clouddienste-von-us-... primary source (German): https://rewis.io/s/u/PjK/ https://rewis.io/s/u/PjK/ press statement of law firm (German): https://gruendelpartner.de/newsroom/gruendelpartner-erwirkt-weitreichende-entscheidung-zur-unzulaessigkeit-von-cloud-und-it-dienstleistungen-durch-us-tochterunternehmen-in-deutschland/ https://gruendelpartner.de/newsroom/gruendelpartner-erwirkt-...
- tpmx 4y agoGolem.de article key phrase: "The use of a US cloud service can justify exclusion from a public procurement process." (The emphasis is mine. Almost all commenters here so far seem to think it's broader than this, which it isn't.)
- nslzk 4y ago
- barbazoo 4y agoWhat's the "proof" here and what is "this" referring to?
- jimbob45 4y agoIsn’t this sort of what we accuse the Chinese of doing? The US designs the technology and then the Chinese manufacturers steal that design to make their own? Except now, the EU is more or less forcing American companies to sell unaffiliated spin-offs to the EU to continue doing business there. Seems a bit underhanded to change the rules now after so long, especially considering the fact that the EU can’t make these companies for themselves or they would have already.
- ad404b8a372f2b9 4y agoI hope you are aware that "the cloud" is not some secret, mysterious piece of technology that the EU can't figure out. We have software engineers as well as data centers and EU-based cloud companies. Digital consumer networks were established here long before the U.S and the internet was invented here. Your arrogance is grating.
- kazinator 4y ago> Digital consumer networks were established here long before the U.S Really? In some places in Europe, people were starting to get excited about dial-up BBSes in the mid nineties, a decade after they were on their way out in North America. In 1994 I was doing contract work in Vancouver on a website with paying subscribers.
- kazen44 4y ago> Really? In some places in Europe, people were starting to get excited about dial-up BBSes in the mid nineties. What is your point exactly? Half of europe was still transitioning to a market economy or in a (civil) war/conflict in the 90's. I am also sure, that a lot of places in the US didn't have internet access in the 90's.
- kazinator 4y ago> Half of europe was still transitioning to a market economy Sure, but not, oh, Sweden.
- miohtama 4y agoDoes anyone know the Company A and Company B in the question? Microsoft? AFAIK public procurement documents are often public.
- srrr 4y agoSearching for "12.1 Regions. Customer can specify the location(s) where Customer Data will be processed within the" (as mentioned in the verdict) yields AWS as the problematic sub-processor for company A: https://d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdf https://d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdf
- plandis 4y agoUS needs to economically retaliate in kind. If the US has the same data protections as the EU they’d make up some other excuse to attack US companies. This is what happens when you can’t compete you make up regulatory excuses. I’m sure I’ll get downvoted by Europeans but it’s the truth. Look at the valuable companies and where they are located :)
- lizardactivist 4y agoThe NSA and the CIA have been at that for decades. But of course people like you believe it is and has always been fully in their right.
- ROTMetro 4y agoYou should see how the EU screws American 'certain industry' companies and fails to honor reciprocity deals. Then add that it is legal and tax deductible for German business' to bribe/kickback to corrupt businesses overseas and man does Europe have a sweet deal without our 'open and reciprocal trade'. Unfair denied access to European markets but open access for Europe in the USA. Overseas company's officials expecting bribes/kickbacks like the Germans give overseas.
- superchroma 4y agoThe American government tolerates this and other things besides (e.g. lax NATO contributions) so it's evidently not that big an issue?
- superchroma 4y agoSure, they can champion their own citizens' rights on issues of where and how data is stored, and prevent American user data from being sent offshore in Europe. That would be ideal. :)
- plandis 4y agoIt’s not about that. Even if the US copied German law verbatim Germany would just find some other excuse to harm the US. They can’t compete so they unfairly try to prop up their own companies via regulatory means.
- jiggywiggy 4y agoYeah wondering about the consequences. By this logic almost every non-EU Saas would be forbidden. For sure Stripe is also not allowed, huge amount of customer data in US hands.
- superchroma 4y agoIMO that could be good, I would welcome more competition in the payment processor space.
- nickff 4y agoBut this won't encourage more competition in the EU, it will limit the number of competitors by creating an insurmountable barrier to entry for foreign providers. This is akin to import controls, which often cause stagnation, and generally lead to more costly and inferior goods.
- arlort 4y ago> non-EU The problem isn't non EU services, it's the US CLOUD act Other countries have legal systems which are considered as offering equivalent protection: > The European Commission has so far recognised Andorra, Argentina, Canada (commercial organisations), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland , the United Kingdom under the GDPR and the LED, and Uruguay as providing adequate protection. And for many more countries standard contractual clauses would probably be enough
- Ekaros 4y agoUruguay? I wouldn't exactly call them for known being a tech nation... So why does USA fail at this? Or are they just too big and diverse for that sort of stuff? And you can't really expect such nation to succeed... In anything...
- arlort 4y ago> I wouldn't exactly call them for known being a tech nation And? > So why does USA fail at this? Because, and I'm going from memory here, should be Schrems I or Schrems II if you want to dig deeper, in the view of the ECJ (which invalidated a similar recognition for the US) the US doesn't provide a satisfactory way for EU citizens to contest their data being accessed by US government agencies
- michaelbuckbee 4y agoThe context for this: say you're a SaaS and you want to tap into the EU market. Per GDPR, personally identifiable data shouldn't leave the jurisdiction of the EU so you should use EU hosted servers, storage etc. So you might then split your app to an EU hosted datacenter of your preferred cloud provider. This ruling says that's insufficient as while the data remains functionally in the EU it's still possible for it to be accessed on the backend by non EU entities.
- CGamesPlay 4y ago> it's still possible for it to be accessed on the backend by non EU entities. Why is this the case? Why aren't EU employees who allow the data to leave the EU negligent?
- jaywalk 4y agoWhat if there are no EU employees?
- rad_gruchalski 4y agoDo you mean "liable" instead of "negligent"?
- michaelbuckbee 4y agoIt's not the employees so much as the legal aspects of it: aka could the FBI compel a cloud provider to give them all the data in the EU datacenter?
- intunderflow 4y agoAnd slowly but surely the tidal wave of the consequences of GDPR versus the CLOUD Act come into view. It will take many years to of delays and fretting (due to the dependence on US clouds) but fundamentally the current legal position is that GDPR is fundamentally incompatible with any personal data transfer to the USA, that's how Google Analytics keeps getting banned too. At some point this will all come to a head and something will have to budge given the gigantic consequences of such a position, from AWS to GCP to Stripe to even basic things like your Domain Registrar.
- the_duke 4y agoThe cloud providers can work with independent operators that run their cloud solutions in Europe. Basically an on-premise setup, just on a huge scale. Microsoft initially did this for Azure, I believe. Certainly will cause a lot of friction.
- xdennis 4y ago> The cloud providers can work with independent operators that run their cloud solutions in Europe. Does that exempt them from the CLOUD Act? If US companies have access to independent operators in Europe, presumably they can still be compelled to give that data to the US.
- eli 4y agoBut couldn't the NSA still spy on European cloud providers and domain registrars?
- rubito 4y agoThere is no tidal wave, Telekom partnered a long time ago with Microsoft for an EU only azure offering and it was sacked quickly because the demand from public procurements where too low since those largely require on-prem solutions.
- Lx1oG-AWb6h_ZG0 4y ago> It followed that company A's service qualified as an unlawful transfer of data to a third country because their parent company was located in the US, violating relevant data protection law (Article 44 GDPR). > The Chamber explained that a transfer in this context must also be assumed when data can be accessed from a third country, regardless of whether this actually takes place. The fact that the physical location of the server that provides such access was located in the EU was irrelevant. I think this is an interpretation of GDPR that most companies are not prepared for. You could write an implementation that restricts access to EU data, but if the parent company is not in EU, I guess the implementation could always be changed to allow access. Ergo, GDPR violation?
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- mgraczyk 4y agoSounds like blatant protectionism to me. If I'm reading the ruling correctly, the relevant legal standard applied here is completely bogus. They find that it is a violation of GDPR because the parent company could access the data, in principle if they wanted to. It doesn't matter if there are safeguards, technical, or institutional preventions in place. However, the exact same argument applies to any EU company with any internet connection, and directly applies to any EU company with infrastructure in the US. EU companies could, in principle, transfer data to the US intentionally or by accident. If technical, institutional, and legal prevention isn't good enough for US companies, why is it good enough for EU companies? Seems like GDPR has to also be construed to prevent EU companies from doing business in the US. If the counter argument is that US companies could be compelled by the US government to hand over data, while EU companies cannot be, that is factually untrue.
- testaccountfor 4y agoUS cloud companies can be forced by the US government to spy on European citizens. That's the reasoning behind this ruling. Are you not aware of the NSA spying programs?
- wins32767 4y agoI'm sure industrial policy and thus economics had no factor in those laws being written.
- testaccountfor 4y ago
- mgraczyk 4y agoRight, that's why I included my last paragraph. EU companies can also be forced by the US government to spy on European citizens. It happens all the time.
- xdennis 4y ago
- webmobdev 4y agoThank god at least some government has the sense to take steps to protect their country's sovereignty. All the US has to do to regain trust is to stop using BigTech for spying on other countries. To begin with, it can start by creating laws and regulations like the GDPR (or better) and move on to breaking up the monopolies of BigTech.
- lizardactivist 4y agoKeep rocking. I have no beef with US companies doing business here as such, but as long as they're supporting espionage and sabotage by handing crucial data to the NSA and CIA they should simply not be allowed to operate here.
- Gwypaas 4y agoSimply the CLOUD Act [1] which is incompatible with GDPR. No problem transferring to a third country [2] as long as you can uphold GDPR. [1]: https://en.wikipedia.org/wiki/CLOUD_Act https://en.wikipedia.org/wiki/CLOUD_Act [2]: https://www.imy.se/en/organisations/data-protection/this-applies-accordning-to-gdpr/transfer-of-data-to-a-third-country/ https://www.imy.se/en/organisations/data-protection/this-app...
- light_hue_1 4y agoThe US parent company was given access to the EU data. That's the problem here. > A included clauses in the offer that stated, among other things, that it will not access, use, or disclose customer data to any third party, except as necessary to maintain or provide the Services, or as necessary to comply with the law or a valid and binding order of a governmental body. Of course giving a US company control over EU data at a whim means that it's a transfer to the US. The court made the only reasonable decision.
- blocked_again 4y agoI think this kind of affirms the general opinion that Germany and many traditionally powerful European countries is doing poorly when it comes to modern tech. What went wrong with Germany and Europe? They used to be the front runners in tech once upon a time.
- johannes1234321 4y agoMaybe it's just, that the European law makers understand the risk of being are to transfer sensitive persona data into other legislations, and that a local registered company doesn't mean there are technical bounds.
- blocked_again 4y ago
- johannes1234321 4y agoI am not sure which exact incident you are after, but NSA, the largest operater of surveillance in Europe is American and GCHQ, the second alrgest, is British and also outside EU these days. But yes, there are some actions by European governments i condemn. However as a European citizen I have ways to counter actions by a European government. By voting, by legal means etc. Into the US I have now range and the US has very little responsibility towards me. Laws protecting Americans or actions in America don't protect me as a foreigner. That said: The court case here at hand was about the government being the (indirect) customer of that cloud. Thus it's their data amthey want to be protected from foreign governments.
- xdennis 4y agoIf you store data in your own country with non-American companies you're protected by your country's judicial system. If you use an American company or American-based company you're subject to illegal spying from the NSA or extra-judicial warrants from the CLOUD Act (which compels Americans to apply American law outside the US).
- throwaway4good 4y agoHey America - stop spying on our our citizens or we will stop buying your tech. Seriously. We talk about this cloud stuff like it is rocket science. It is not. It is a box in a basement. We are capable of doing that ourselves. And no. It ain’t cool for NSA to sniff around some German governmental software, even though you are the good guys and on our side.
- dang 4y agoPlease don't start nationalistic flamewars on HN. This one was particularly hellish and particularly dumb. It's not what this site is for, and it destroys what it is for. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- testaccountfor 4y agoCritcism of US spying is not "starting a flame war". Please refrain from interfering with healthy discussion.
- dang 4y agoWords cannot express how little we care what you or anyone else has to say about "US spying" as long as you/they do it within the site guidelines and the intended spirit of the site. From a moderation point of view, the issue is not "US spying", it's "violation of the site rules" - which was happening all over this thread. This was the extreme opposite of "healthy discussion". Btw, your account has been adding to this flamewar in just the way that we don't want here. I'm not going to ban you right now, but only because it doesn't feel sporting to ban an account that I only noticed when you replied to me. If you wouldn't mind reviewing https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html and sticking to the rules, though, we'd appreciate it.
- testaccountfor 4y agoThanks for proving my point. "Don't criticise US spying, and I'll threaten you with ban if you do." Not a single rule was violated in the post above. Looks like hackernews needs more responsible moderators.
- legalcorrection 4y ago
- bettysdiagnose 4y ago
- htkibar 4y agoPeople like being edgy in the end, I guess. They literally claim that "EU is an American protectorate". At this point, it is literally pointless to even have a dialogue, as they is far gone.
- bettysdiagnose 4y ago
- deleted 4y ago[deleted]
- dang 4y agoWe've banned this account for repeatedly breaking the site guidelines, not just in this thread but elsewhere. Please don't create accounts to do that with. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- mopsi 4y ago> they are too poor to afford ubiquitous air conditioning And I could say that americans are too poor to have heated bathroom floors, but that'd be ignorant. Europe is much further north and has significantly colder climate than the US: https://imgur.com/oIjh5eQ https://imgur.com/oIjh5eQ The main concern is insulation and heating, not cooling, hence much more expensive buildings overall compared to cheap wooden homes in the US.
- dang 4y agoWe've banned this account for repeatedly breaking the site guidelines, not just in this thread but elsewhere. Please don't create accounts to do that with. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- rad_gruchalski 4y agoFor public services, as in government public. From the page: The case concerns a decision by the Vergabekammer Baden-Württemberg ("Procurement chamber Baden-Wuerttemberg"), the administrative authority that reviews the public procurement procedures. On 3.11.2021, a public authority issued a Europe-wide invitation to tender for the procurement of software for digital management via an open procedure. The award criteria contained, among other things, requirements for data protection and IT security. The public authority received offers from company A and company B.
- blocked_again 4y agoSimple question. Who do you trust your data with? 1. A company in your own country which got marketshare mostly because of legal reasons and government interference. 2. A company which got marketshare by building products that people loved all over the world, has the smartest people working for them and have generated more value than the vast majority of the companies that existed previously in the world combined.
- Jensson 4y ago1. A foreign government with a tendency to imprison and torture foreign citizens without any process. 2. Your own government that is held accountable to local laws.
- htkibar 4y agoI'd agree with the implication here, if it weren't for the fact that the company on #2 would be _legally compelled to spy on me or my countrymen at the whim of 3 letter agencies_. That rubs some people, such as I, the wrong way. I wonder why :)
- deleted 4y ago[deleted]
- tzs 4y agoIt is not clear to me from that what the relationships are between company A, the EU subsidiary (which I'll call S), and the US cloud provider (which I'll call C). 1. Would A be dealing directly with S, or is A dealing with C which is using S to store A's data. 2. Is S incorporated in the EU? 3. Does C have access to data stored in S, other than data that C itself put there using the APIs that S makes available to all its storage customers?
- rubito 4y agoTelekom and Microsoft partnered together a long time ago to fix this problem but it turns out in european public comunal and state procurement projects that cloud offerings play a very insignificant role since its largely all on-prem IT projects and so that partnership was closed. I'm just writing this because a lot of comments are getting the wrong idea from this and causing some weird mix of hysteria and europhoby. In the grand scheme of things, there is no money lost for Azure and AWS, the potential of the once in a full moon cloud projects from public european institutions wouldn't even amount to something that would be described as pocket chance.
- dang 4y agoAll: the hellish and puerile flamewar that many of you stooped to in this thread is exactly what HN is not for. We ban accounts that post like this, so please don't post like this. What an embarrassment. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html I suppose I'd better add that this isn't about which side you're on. It's just about having an international forum that doesn't suck and doesn't destroy itself. All of you flaming each other in this thread have made HN suck (in this neighborhood) and contributed to destroying it. No more of this, please. You can make your substantive points without any of that. If you can't, please don't post until you can.
- alaricus 4y agoThere was no flame war in this thread. But there is clear evidence of abuse and harassment by a mod. I'm flagging dang's post in the hope that a real moderator will look at it. What an embarrassment indeed. Hackernews deserves better moderation.
- dang 4y agoCertainly, people can and do have different ideas of what counts as a flamewar. In that sense it's just a difference of opinion and that's fine. However, we're trying for HN to be a particular kind of web forum. The principles of what we're trying for are expressed at https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html. Many comments in this thread broke those principles quite badly.