Jump to content

Recommended Posts

Posted

I don't really think it's 'picking on Google'.. It's that Google is the most popular mail provider in the world AFAIK. Just like Hotmail was back-in-the-day. So it makes for the most relateable* example.

 

* Not a word.

Posted
All email is unsecured and always has been, even when we used RM Easy mail we had to have a disclaimer saying it was not a secure messaging service, funny how they always pick on Google.

 

No, not all email is unsecured.

Posted
Meanwhile I'm sat here wondering why the EU should be the one coming up with an alternative when the issue isn't with Safe Harbour, it's with the US Patriot Act and their silly secret tribunals and you're-not-allowed-to-say-no-or-tell-anybody data 'requests'.
Posted
Meanwhile I'm sat here wondering why the EU should be the one coming up with an alternative when the issue isn't with Safe Harbour, it's with the US Patriot Act and their silly secret tribunals and you're-not-allowed-to-say-no-or-tell-anybody data 'requests'.

 

Because the US Gov is happy with those laws, it's the rest of the world and the US businesses that are not. The EU and the US businesses affected need to push this through.

Posted
Because the US Gov is happy with those laws, it's the rest of the world and the US businesses that are not. The EU and the US businesses affected need to push this through.

 

The US government won't be happy if the EU says "it is illegal to export this data from the EU to the USA, due to XYZ laws in the USA". It'd kill of a great many US jobs and shutter billions of dollars worth of business. Realistically, the EU has the upper hand here!

Posted
The US government won't be happy if the EU says "it is illegal to export this data from the EU to the USA, due to XYZ laws in the USA". It'd kill of a great many US jobs and shutter billions of dollars worth of business. Realistically, the EU has the upper hand here!

 

Oh I know that, but they're not going to change anything until we push it.

Posted
The US government won't be happy if the EU says "it is illegal to export this data from the EU to the USA, due to XYZ laws in the USA". It'd kill of a great many US jobs and shutter billions of dollars worth of business. Realistically, the EU has the upper hand here!

 

That's precisely my point. The EU is in a position to say "No. We're not changing our laws. There is nothing wrong with Safe Harbour. The problem is the Patriot Act. Sort out your shadowy back-door snooping laws, or gee-tee-eff-off our data." but instead they're trying to solve the issue? It's not on us to solve, it's on the US. The US should be saying "Alright, well, we propose X" but that won't happen until companies lobby governments (as they're so fond of doing in the US..) for a change.. And that won't happen until the EU says "Righ' lads. Stop shippin' abroad." and their bottom line takes a nice punch.

Posted
That's precisely my point. The EU is in a position to say "No. We're not changing our laws. There is nothing wrong with Safe Harbour. The problem is the Patriot Act. Sort out your shadowy back-door snooping laws, or gee-tee-eff-off our data." but instead they're trying to solve the issue? It's not on us to solve, it's on the US. The US should be saying "Alright, well, we propose X" but that won't happen until companies lobby governments (as they're so fond of doing in the US..) for a change.. And that won't happen until the EU says "Righ' lads. Stop shippin' abroad." and their bottom line takes a nice punch.

 

i suspect there a fair few "military" contractors with "access to senators" that want the existing system snooping and all because they are making a killing doing it/selling kit etc so once again with american politics the will of the people be damned its whos lobbyists can buy the most votes

Posted
The US government won't be happy if the EU says "it is illegal to export this data from the EU to the USA, due to XYZ laws in the USA". It'd kill of a great many US jobs and shutter billions of dollars worth of business. Realistically, the EU has the upper hand here!

 

I thought that was essentially what had just happened although It's not illegal because of laws in the US per se, it is illegal because doing so cannot comply with laws in the EU which guarantee peoples rights with respect to their personal data and the processing that is able to be done with it.

Posted
I thought that was essentially what had just happened although It's not illegal because of laws in the US per se, it is illegal because doing so cannot comply with laws in the EU which guarantee peoples rights with respect to their personal data and the processing that is able to be done with it.

 

The ECJ has said that, but the European Commission hasn't - they are the ones that have to implement the ruling, and are the ones negotiating the new treaty. So, it'd be them who should be saying it.

Posted
The ECJ has said that, but the European Commission hasn't - they are the ones that have to implement the ruling, and are the ones negotiating the new treaty. So, it'd be them who should be saying it.

As I understand it, any case bought by a UK subject under Data Protection legislation could refer to the judgement as established precedent and the court would have to accept that, if relevant. There is no grace period in the judgement for people to get alternative arrangements in place. This is law right now.

 

From a schools perspective, this seems to call into question the use of any 'cloud' service where the operating company is subject to US law. We cannot say what processing will be done with data which is held by such companies because they might be subject to requests for the data under US law. This is different from (say) GCHQ intercepting data in telecoms pipes because engaging with US companies is entirely within our control. We choose to use them as service providers.

Posted

This ruling has nothing to do with any part of the US Judiciary requesting data held overseas.

 

This ruling as about the safety and security of data that has been transferred to, and then held in, the US.

 

Data cannot be transferred without consent (unless covered by transfer due to EU laws), which is one of the reasons there is a new pact for transfer of data between enforcement agencies (which covers the EU laws bit), and also why Microsoft are fighting the case tooth and nail.

 

Jokingly, one person said to me a few months back that it would make more sense for a number of US companies to move to EU, and then just play EU and US off against each other. Starting to think that is what is happening already.

 

This is politics at this point.

  • Thanks 1
Posted
This ruling has nothing to do with any part of the US Judiciary requesting data held overseas.

 

This ruling as about the safety and security of data that has been transferred to, and then held in, the US.

 

Thanks for confirming that for me.

 

I know with Office 365 Edu they say all data will only be replicated within the EU which is fine.

 

But Capita (not a Gov or Edu) uses Azure for hosting, is this likely to be replicated outside of the EU? (i know i'll need to ask them...)

Same with companies that also use Google or AWS.

Posted

But Capita (not a Gov or Edu) uses Azure for hosting, is this likely to be replicated outside of the EU? (i know i'll need to ask them...)

Same with companies that also use Google or AWS.

 

Google Compute Engine only stores data in the EU of you tell it to.

Posted
Thanks for confirming that for me.

 

I know with Office 365 Edu they say all data will only be replicated within the EU which is fine.

 

But Capita (not a Gov or Edu) uses Azure for hosting, is this likely to be replicated outside of the EU? (i know i'll need to ask them...)

Same with companies that also use Google or AWS.

 

You would need to check with Capita, but it is highly unlikely. When you set up Azure services, you are asked for a region, and then how you wish to replicate. It'd be very odd if Capita hadn't chosen West Europe as the region, and either local, zone or geo redundancy (geo redundancy for West Europe replicates to North Europe).

Posted
You would need to check with Capita, but it is highly unlikely. When you set up Azure services, you are asked for a region, and then how you wish to replicate. It'd be very odd if Capita hadn't chosen West Europe as the region, and either local, zone or geo redundancy (geo redundancy for West Europe replicates to North Europe).

 

AWS is the same, you pick the region and the data stays there unless you specifically set up cross region replication (which costs a huge amount)

Posted
Google Compute Engine only stores data in the EU of you tell it to.

 

Where in GAFE should I have set this? I don't think it's critical for us - our policy for cloud is to not put confidential data there, but given the option, I'd rather keep it in Europe.

 

On another note, the current set up seems to suit their politicians quite nicely. US intelligence agencies are quite restricted in what they can do to their own citizens, so are happy for GCHQ to do it for them. I presume it works the other way round as well. And even if you change the law, you have to trust people whose job it is to gather information covertly to desist from doing so. History would suggest that either they believe they'll never be found out or they don't care that they might be.

Posted
Where in GAFE should I have set this? I don't think it's critical for us - our policy for cloud is to not put confidential data there, but given the option, I'd rather keep it in Europe.

 

 

It's not currently available in GAFE, the conversation moved onto Google compute engine, Amazon web services and Azure.

  • Thanks 1
Posted

Ars has just posted an article about it all, quite interesting:

 

Fallout from EU-US Safe Harbor ruling will be dramatic and far-reaching | Ars Technica

 

In the wake of last week's dramatic judgement by the Court of Justice of the European Union (CJEU), which means that transatlantic data transfers made under the Safe Harbour agreement are likely to be ruled illegal across the EU, there has been no shortage of apocalyptic visions claiming that e-commerce—and even the Internet itself—was doomed. Companies are already finding alternative, if imperfect, ways to transfer personal data from the EU to the US, although a very recent data protection ruling in Germany suggests that one approach—using contracts—is unlikely to withstand legal scrutiny. But what's being overlooked are the much wider implications of the court's ruling, which reach far beyond e-commerce.
Posted
European Safe Harbor ruling update and Google Apps

 

Hello Apps Administrator,

 

Please note that the update below is relevant only if you process personal data and European Data Protection laws apply to that processing. This will often be the case if your business is based in the European Union. If you are unsure whether this applies to you, we suggest you seek advice from legal counsel.

 

On October 6, 2015, Europe’s highest court declared that the decision of the European Commission regarding the US-EU Safe Harbor framework―one of the legal mechanisms that enables the transfer of personal data from the EU to US companies―is invalid, on the basis that Safe Harbor doesn’t provide an adequate level of protection for personal data originating in the EU.

 

Through 2015, the European Commission and the US have been negotiating a revised Safe Harbor agreement that should address these concerns, but they were not able to finalize the agreement before the court issued its ruling. Both the Commission and the US have committed to finalizing the revised agreement as soon as possible.

 

In the meantime, we’d like to reassure you that we offer a compliance alternative to the Safe Harbor framework, and our records show that your organization has already adopted this option. Specifically, we offer a data processing amendment and model contract clauses as an additional means―beyond the Safe Harbor framework―of meeting the adequacy and security requirements of the EU Data Protection Directive. Model contract clauses were created specifically by the European Commission to permit the transfer of personal data from Europe.

 

We are committed to helping our customers address their regulatory compliance needs in this area, and we thank you for entrusting your data to Google.

 

If you have additional questions, please contact your Google representative or Google Apps Support.

 

Sincerely,

The Google Apps Team

 

 

https://www.google.com/work/apps/terms/dpa_terms.html

 

https://www.google.com/work/apps/terms/mcc_terms.html

  • Thanks 1
Posted (edited)

The specific part of the mentioned German court ruling regarding model contracts:

 

For Private Sector organisations, the Schleswig-Holstein Authority points to Clause 5(b) of the Model Clauses themselves. They require Data Controllers exporting data to consider this clause and to suspend transfers given the inability of US companies to meet their obligations under Clause 5(b). They go on to point out that, in order for the Model Clauses Decision to be interpreted consistently with the CJEU ruling in Schrems, transfers on the basis of Model Clauses are no longer permitted.

 

and

 

With regard to their Audit and investigation function, the Schleswig-Holstein Authority points out that Clause 4(a) of the Model Clauses require the Data Exporter to ensure that data processing will be carried out in compliance with the "relevant provisions of the applicable Data Protection Law". They highlight that it is not possible now for a Data Controller in the EU to meet the requirement of that clause, unless an exemption under Article 13 of the Directive can be applied to the processing. As such, the Controller needs to suspend their processing in accordance with Clause 5(b) of the Model Clauses.

 

https://castlebridge.ie/news/2015/10/14/schleswig-holstein-model-clauses-ist-kaput-update-1

Edited by pete
I can't spell.
  • Thanks 2
Posted

Hi All,

 

Received this in my inbox were 4 Primary and 1 Nursery school we all use GAFE. Do I need to change anything?

 

Thanks

 

 

European Safe Harbor ruling update and Google Apps

 

"Hello Apps Administrator,

 

Please note that the update below is relevant only if you process personal data and European Data Protection laws apply to that processing. This will often be the case if your business is based in the European Union. If you are unsure whether this applies to you, we suggest you seek advice from legal counsel.

 

On October 6, 2015, Europe’s highest court declared that the decision of the European Commission regarding the US-EU Safe Harbor framework―one of the legal mechanisms that enables the transfer of personal data from the EU to US companies―is invalid, on the basis that Safe Harbor doesn’t provide an adequate level of protection for personal data originating in the EU.

 

Through 2015, the European Commission and the US have been negotiating a revised Safe Harbor agreement that should address these concerns, but they were not able to finalize the agreement before the court issued its ruling. Both the Commission and the US have committed to finalizing the revised agreement as soon as possible.

 

In the meantime, we’d like to reassure you that we offer a compliance alternative to the Safe Harbor framework and have done so since 2012. Specifically, we offer a data processing amendment and model contract clauses as an additional means―beyond the Safe Harbor framework―of meeting the adequacy and security requirements of the EU Data Protection Directive. Model contract clauses were created specifically by the European Commission to permit the transfer of personal data from Europe.

 

Many Google Apps customers have already adopted the data processing amendment and model contract clauses. If you have not already done so, we’d like to remind our Google Apps customers to consider opting-in to the data-processing amendment and model contract clauses. Instructions are available in the Help Center.

 

We are committed to helping our customers address their regulatory compliance needs in this area, and we thank you for entrusting your data to Google.

 

If you have additional questions, please contact your Google representative or Google Apps Support.

 

Sincerely,

The Google Apps Team"

Posted
Hi All,

 

Received this in my inbox were 4 Primary and 1 Nursery school we all use GAFE. Do I need to change anything?

 

Depends who you speak to. We opted in years ago but others would say delete all of your data. You choose.

Posted
If the choice of hitting the DEL key was mine I would probably hit it. Though I have this nagging feeling they might stop my pay if i do!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...