TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Austrian DSB: EU-US Data Transfers to Google Analytics Illegal

254 点作者 sarnowski超过 3 年前

17 条评论

ckastner超过 3 年前
Max Schrems is just incredible. Just look at his Wikipedia page [1] and see how many EU-US data transfers he&#x27;s challenged successfully.<p>[1] <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Max_Schrems" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Max_Schrems</a><p>At this point, I wonder why the EU doesn&#x27;t consult him personally prior to enacting some law. It&#x27;s not as if they don&#x27;t consult with others as well.
评论 #29919386 未加载
评论 #29919187 未加载
评论 #29919647 未加载
boshomi超过 3 年前
»Max Schrems: &quot;In the long run we either need proper protections in the US, or we will end up with separate products for the US and the EU. I would personally prefer better protections in the US, but this is up to the US legislator - not to anyone in Europe.&quot;«<p>That&#x27;s the point: we need real data protection in US law for non-US citizens as well. Currently, US lawmakers treat EU citizens&#x27; data as US state property. Obviously, that&#x27;s unfair.
评论 #29920289 未加载
评论 #29920557 未加载
评论 #29922179 未加载
评论 #29923175 未加载
评论 #29920559 未加载
usr1106超过 3 年前
The deeper background is of course Google&#x27;s business model of data and privacy prostitution: Users give their private life to Google and they get web search, email, and videos back.<p>In a more reasonable world users would pay money for the services they want to use.<p>Of course it needs to be noted that most users don&#x27;t even understand that they are selling themselves. And of the few who do most still think it&#x27;s better than paying money.<p>This ruling, should Google comply in the end, will not change anything. Google will store the data in the EU and that&#x27;s it. I don&#x27;t think they share user data with the advertiser when they show an ad. So they could still show ads of US companies. And that&#x27;s a niche business only anyway because when Europeans do business with Amazon, Disney, and the like they deal with the respective European subsidiaries already.
评论 #29920238 未加载
评论 #29933304 未加载
评论 #29922435 未加载
评论 #29928236 未加载
sebsebsn超过 3 年前
It looks like this makes Fathom Analytics the only provider for website analytics that you can use if you don&#x27;t want to maintain a locally hosted version if an open source product – which blows my mind. A small company is the only service that is able to comply with the rules while huge ones simply fail.<p>I assume that this regulation is also coming to other services soon and analytics isn&#x27;t the only service that needs to be replaced when a business is in the EU and can&#x27;t ignore these rules without risking fines. The team at Fathom wrote about alternatives for lots of services here: <a href="https:&#x2F;&#x2F;usefathom.com&#x2F;blog&#x2F;degoogle" rel="nofollow">https:&#x2F;&#x2F;usefathom.com&#x2F;blog&#x2F;degoogle</a>
评论 #29921076 未加载
评论 #29921411 未加载
YetAnotherNick超过 3 年前
I really don&#x27;t understand why countries are so persistent about storing data in their country. It&#x27;s not like the enforcers could walk into the datacenter and plug in the usb drive and get the data. And it&#x27;s even hard to see what all constitutes user data. Does logging constitute user data. Does that mean that to get logs for the error the developer need to travel to every country and remember the log messages in his head.<p>And companies could easily copy their data in a click if they need to. A much saner approach should be limiting what the company is allowed to do with the data.
评论 #29920150 未加载
评论 #29920509 未加载
评论 #29920999 未加载
评论 #29920119 未加载
评论 #29920287 未加载
评论 #29920630 未加载
评论 #29920069 未加载
timgl超过 3 年前
Relevant thread on open source alternatives to Google Analytics from earlier today: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=29888599" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=29888599</a>
评论 #29919693 未加载
phoronixrly超过 3 年前
The key points in the article for me:<p>&gt; Max Schrems, honorary chair of noyb.eu: &quot;Instead of actually adapting services to be GDPR compliant, US companies have tried to simply add some text to their privacy policies and ignore the Court of Justice. Many EU companies have followed the lead instead of switching to legal options.&quot;<p>&gt; In the long run, there seem to be two options: Either the US adapts baseline protections for foreigners to support their tech industry, or US providers will have to host foreign data outside of the United States.<p>&gt; No penalty (yet). The decision is not dealing with a potential penalty, as this is seen as a &quot;public&quot; enforcement procedure, where the complainant is not heard. There is no information if a penalty was issued or if the DSB is planning to also issue a penalty.<p>We need more trials related to GDPR breaches. While having the legislation is a huge achievement, it needs to be backed with enforcement.<p>If there is no enforcement, a third long-term solution arises -- just ignoring the law until you manage to get the necessary amendments to it in order to keep operating as before without fear of penalty.
评论 #29919398 未加载
评论 #29919586 未加载
评论 #29919577 未加载
davidgerard超过 3 年前
Nothing about GDPR is hard ... unless your business model is to abuse your customers&#x27; personal data. Then it might be hard.<p>I <i>routinely</i> see the loudest complainers about the onerous nature of GDPR compliance suddenly get vague or stop posting when you ask for details of precisely what bit is so hard for them in particular. Note lack of those details in this present discussion, for example.<p>So far, it seems a safe assumption that the excuse makers are abusing personal data, and they know they&#x27;re abusing personal data.<p>Perhaps one day a clear exception will show up.<p>I wrote up a thing here a few years ago with my actual on the ground experience of getting us compliant: <a href="https:&#x2F;&#x2F;reddragdiva.dreamwidth.org&#x2F;606812.html" rel="nofollow">https:&#x2F;&#x2F;reddragdiva.dreamwidth.org&#x2F;606812.html</a><p>tl;dr anything that might vaguely constitute personal data, down to Apache logs, must either be in a writable database for redactability, or deleted.<p>Since then, our legal team - who are not <i>your</i> legal team! - has advised:<p>* 30 days for operational purposes is fine actually.<p>* Go feral on anything over 30 days. You need a named person responsible for GDPR redactions.<p>* If you want to do analytics on those Apache logs, do them quickly and into a form that doesn&#x27;t contain personal data.<p>I&#x27;m in the UK, which is no longer in the EU, but the GDPR laws still hold here.
评论 #29920412 未加载
评论 #29920349 未加载
评论 #29924161 未加载
评论 #29920348 未加载
fideloper超过 3 年前
To my knowledge, Fathom Analytics is the only analytics app that has bothered to hire actual lawyers and navigate EU isolation.<p>They wrote about it here: <a href="https:&#x2F;&#x2F;usefathom.com&#x2F;features&#x2F;eu-isolation" rel="nofollow">https:&#x2F;&#x2F;usefathom.com&#x2F;features&#x2F;eu-isolation</a>
snowwolf超过 3 年前
Has Google Analytics now adopted the latest European Commission approved SCCs (<a href="https:&#x2F;&#x2F;ec.europa.eu&#x2F;info&#x2F;law&#x2F;law-topic&#x2F;data-protection&#x2F;international-dimension-data-protection&#x2F;standard-contractual-clauses-scc_en" rel="nofollow">https:&#x2F;&#x2F;ec.europa.eu&#x2F;info&#x2F;law&#x2F;law-topic&#x2F;data-protection&#x2F;inte...</a>) and does that mean using GA with those SCC&#x27;s is now compliant going forwards. Or does this cases verdict that &quot;SCCs and &quot;TOMs&quot; not enough&quot; now mean those EC approved SCCs are now useless?
评论 #29921364 未加载
pieter_mj超过 3 年前
Great victory. I bet firebase crashlytics is illegal as well in EU.<p>The reason I uninstalled the hacker news app &#x27;Materialistic&#x27; is because it regularly crashed and was probably unvoluntarily siphoning off pii data through the crashlytics module.
评论 #29998428 未加载
etothepii超过 3 年前
In other news, king orders tide out.
jbrooksuk超过 3 年前
And that&#x27;s why, as a responsible developer, I exclusively use Fathom for my own projects. As far as I know, they are the <i>only</i> analytics company who are correctly following the law here <i>AND</i> they always try to do more.<p>They completely isolate EU analytics from their US databases, which you can read more about at <a href="https:&#x2F;&#x2F;usefathom.com&#x2F;features&#x2F;eu-isolation" rel="nofollow">https:&#x2F;&#x2F;usefathom.com&#x2F;features&#x2F;eu-isolation</a><p>Aside from this, unlike other startup analytic solutions, they&#x27;ve actually spoken to lawyers to read through the fine lines of the law and ensure their solution is legal. Go get it!
评论 #29921046 未加载
aspenmayer超过 3 年前
This is due to GDPR. Amazing ruling for privacy for all of EU.<p>Detailed analysis:<p><a href="https:&#x2F;&#x2F;gdprhub.eu&#x2F;index.php?title=DSB_(Austria)_-_2021-0.586.257_(D155.027)" rel="nofollow">https:&#x2F;&#x2F;gdprhub.eu&#x2F;index.php?title=DSB_(Austria)_-_2021-0.58...</a>
评论 #29919154 未加载
ur-whale超过 3 年前
The EU regulating itself out from the market.<p>Not for the first time, mind you.
评论 #29920174 未加载
rehamelbasha超过 3 年前
There are alternatives like snowplow.<p>My former company and current one decided to move out from GA to snowplow as you have much more control on your data and do not so much depend on Google to be gdpr compliant.
评论 #29919335 未加载
tjansen超过 3 年前
That stuff scares me. More than US government surveillance could ever scare me. The most likely outcome is that smaller companies just don&#x27;t do business in the EU. At least before they are large enough to deal with GDPR.<p>I am located in Germany, but if I would start a SAAS site today, I wouldn&#x27;t try to sell to the EU. Just isn&#x27;t worth the trouble.<p>Over time, many people in the EU will start using VPNs to get access to the latest web sites without GDPR restrictions. Even today I have to use a VPN to access some websites (mostly news sites), but I suspect it will be much worse if noyb succeeds.
评论 #29920346 未加载
评论 #29920013 未加载
评论 #29919771 未加载
评论 #29920011 未加载
评论 #29923406 未加载
评论 #29919649 未加载
评论 #29919707 未加载
评论 #29919718 未加载