Jump to content

Recommended Posts

Posted
Except under GDPR, that data has to be stored as if it's in the country of origin, so the US would have to go to the country's court to get access.

Under US law, that's not correct. The company that has had data requested from it could object on that basis, and take it to a US court. But, GDPR is not a US law, so as much as it applies to US companies and their subsidiaries, the US government is not bound by it. SafeHarbor provides a little bit of defense that can be used.

 

An example situation - the famous case where the FBI wanted data from Microsoft that was on their Ireland servers. They took it to the courts, to prevent it because it would be a problem with Irish law. When CLOUD Act came in, the FBI dropped the entire thing, filed their warrant in accordance with CLOUD and Microsoft had to comply.

Posted (edited)
Under US law, that's not correct. The company that has had data requested from it could object on that basis, and take it to a US court. But, GDPR is not a US law, so as much as it applies to US companies and their subsidiaries, the US government is not bound by it. SafeHarbor provides a little bit of defense that can be used.

Interesting. Just re-reading it now.

GDPR states that data cannot be transferred out of the EEA without the appropriate safeguards being put in place.

So that would be the EU-US Privacy Shield framework, which Google are signed up to, so would be considered adequate under GDPR.

 

The Privacy Shield places requirements on US companies certified by the scheme to protect personal data and provides for redress mechanisms for individuals. US Government departments such as the Department of Commerce oversee certification under the scheme.

 

And of course, we're all forgetting Five Eyes, so the US, UK, Canada, Australia and New Zealand are all continually spying on their own citizens anyway, and sharing that data between the five of them, so ultimately all of this is pure lip service. :eyebrows:

https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/international-transfers/

 

https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active

Edited by paulkerton

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...