Apple and Other Tech Companies Tangle with U.S. Over Data Access(nytimes.com)
nytimes.com
Apple and Other Tech Companies Tangle with U.S. Over Data Access
http://www.nytimes.com/2015/09/08/us/politics/apple-and-other-tech-companies-tangle-with-us-over-access-to-data.html
17 comments
> It is standard practise for companies in Europe (e.g. the bank I'm consulting for right now) to ensure that, when they subscribe to cloud services, their data is held stored and processed in datacentres within the EU, so that it is subject to EU legislation and, hence, the EU's data protection laws.
Absolutely. EU Data Protection Laws are so enshrined, I would argue that they are part of the culture. In the UK it's part of the educational syllabus to learn about the Data Protection Act.
If American companies cannot adhere to the act, companies will walk away from those services. I see a lucrative market opening up for "private clouds" whereby the requirement is, is the data "safe" is it vulnerable to American jurisdiction?
Is there a business opportunity here to brag about 100% none American? I don't see that being conducive to a free, open, global economy. Least of all between two of the largest economies.
There is rule-of-law in the EU and warrants do get issued and executed. The rabid pursuit of this by the US can only be counter productive in my mind. For everyone.
Absolutely. EU Data Protection Laws are so enshrined, I would argue that they are part of the culture. In the UK it's part of the educational syllabus to learn about the Data Protection Act.
If American companies cannot adhere to the act, companies will walk away from those services. I see a lucrative market opening up for "private clouds" whereby the requirement is, is the data "safe" is it vulnerable to American jurisdiction?
Is there a business opportunity here to brag about 100% none American? I don't see that being conducive to a free, open, global economy. Least of all between two of the largest economies.
There is rule-of-law in the EU and warrants do get issued and executed. The rabid pursuit of this by the US can only be counter productive in my mind. For everyone.
Health services moving to digital working pay money to have software and services that respect privacy and that don't send data everywhere.
Oh come on. As if governments all over the EU weren't monitoring their people as best they can, just like the US does.
In theory, they might bicker a bit behind the scenes over who gets access to what data etc, but it's also in their self-interest to co-operate in their spying activities.
It's all about maintaining their rule over the masses, after all, and that's a goal they all share.
In theory, they might bicker a bit behind the scenes over who gets access to what data etc, but it's also in their self-interest to co-operate in their spying activities.
It's all about maintaining their rule over the masses, after all, and that's a goal they all share.
Absolutely.
And I'd like to strengthen the point you made even further. It's not just standard practice alone - it's the law. For example, from principle 8 of the data protection act:
Personal data shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.
In my experience (with retail and banks), this means either hosting the data in a place where the law is the same (the EEA or acceptable countries), putting data under contract (EU Model contract), or using an acceptable scheme (such as US safe harbour).
At the moment, companies get around it as you said, by putting into the contract that the hosting has to be in the EU. However, if the US government win this court case, a lot of UK businesses will legally have to reconsider their use of US cloud companies at all.
And I'd like to strengthen the point you made even further. It's not just standard practice alone - it's the law. For example, from principle 8 of the data protection act:
Personal data shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.
In my experience (with retail and banks), this means either hosting the data in a place where the law is the same (the EEA or acceptable countries), putting data under contract (EU Model contract), or using an acceptable scheme (such as US safe harbour).
At the moment, companies get around it as you said, by putting into the contract that the hosting has to be in the EU. However, if the US government win this court case, a lot of UK businesses will legally have to reconsider their use of US cloud companies at all.
How does this work for data that has nothing to do with people in the EU?
For instance, suppose I only have US customers, and I have my data primarily in Amazon's cloud in the US West region. I want to have a backup someplace far away from US West.
Does the data protection act mean that I cannot use EU Ireland or EU Frankfurt for my backup, because if I ever had to restore from that backup I would be transferring it to a country or territory outside the EEA that does not ensure adequate protection?
For instance, suppose I only have US customers, and I have my data primarily in Amazon's cloud in the US West region. I want to have a backup someplace far away from US West.
Does the data protection act mean that I cannot use EU Ireland or EU Frankfurt for my backup, because if I ever had to restore from that backup I would be transferring it to a country or territory outside the EEA that does not ensure adequate protection?
> The feds are being hoisted on their own petard somewhat here, having long argued that a foreign person's data held on a US server is subject to US jurisdiction. The logical corrollary to that argument is that data held on an Irish server is subject to Irish jurisdiction.
Things can be subject to multiple jurisdictions simultaneously. That's one of the things that makes international commerce interesting.
Things can be subject to multiple jurisdictions simultaneously. That's one of the things that makes international commerce interesting.
While I would like to see the outcome as you describe it (both US business and government could use a splash of cold water from the EU data protection laws), I'm not so sure that's how it will play out. A common fallacy is to assume that the law and its implementation by government is logical, when in reality is full of contradictions, often on purpose.
The US has been throwing its weight around for a while now, so it wouldn't surprise me if it demands "special" treatment, even when it contradicts its past arguments. Without more evidence, I wouldn't rule out any possible outcome.
This whole revival of the Crypto Wars smells strange.
The US has been throwing its weight around for a while now, so it wouldn't surprise me if it demands "special" treatment, even when it contradicts its past arguments. Without more evidence, I wouldn't rule out any possible outcome.
This whole revival of the Crypto Wars smells strange.
Any time I read this type of article, I keep recalling what irritated the hell out of me with the Snowden leaks and responses of US citizens. To paraphrase: "It's terrible they're spying on US citizens (but everyone else is fair game, geez, whack a splicer in that fibre channel asap)".
The US has reinvented the concept of borderlines on the Internet with what the NSA/TLAs have been up to. I'd say that's a distinct step backwards.
The US has reinvented the concept of borderlines on the Internet with what the NSA/TLAs have been up to. I'd say that's a distinct step backwards.
The response of most US citizens has been, "Snowden?"
But then there are plenty of people on HN who should know better who are outraged, OUTRAGED to discover the US is spying on people, but seem to have no issues with their own and other governments spying on them. So it's ignorance and hypocrisy all-round.
But then there are plenty of people on HN who should know better who are outraged, OUTRAGED to discover the US is spying on people, but seem to have no issues with their own and other governments spying on them. So it's ignorance and hypocrisy all-round.
Well, all of the Five Eyes are complicit, no argument there. Certainly a top-heavy weighting from the US though, with basically control of the net, and a stellar budget. The peons just follow the marching orders.
“Only Congress has the institutional competence and constitutional authority to balance law enforcement needs against our nation’s sovereignty, the privacy of its citizens and the competitiveness of its industry.”
What competence?
What competence?
How do these things work in the case of physical goods and documents?
For instance, suppose you and I are both US residents, residing in the US. You loan me some item. I fail to return it and you sue me. The court orders me to return the item to you.
If I had that item in a storage locker in Los Angeles, there is no question that the court would have the authority to order me to retrieve that item and turn it over to you or to the court.
Suppose, however, I have taken the item to Mexico and have it in a storage locker there? Can I now get away with telling the court that since the item is in Mexico, the court does not authority to order me to retrieve it (or to order me to instruct the storage facility to retrieve it and ship it to me)?
Similar question for physical documents. For instance, if GM set up a documents storage facility a few miles away from its headquarters, across the border in Canada, and kept all documents not actively in use at the Canadian facility, would they then be able to fend off document subpoenas from US safety investigators this way?
For instance, suppose you and I are both US residents, residing in the US. You loan me some item. I fail to return it and you sue me. The court orders me to return the item to you.
If I had that item in a storage locker in Los Angeles, there is no question that the court would have the authority to order me to retrieve that item and turn it over to you or to the court.
Suppose, however, I have taken the item to Mexico and have it in a storage locker there? Can I now get away with telling the court that since the item is in Mexico, the court does not authority to order me to retrieve it (or to order me to instruct the storage facility to retrieve it and ship it to me)?
Similar question for physical documents. For instance, if GM set up a documents storage facility a few miles away from its headquarters, across the border in Canada, and kept all documents not actively in use at the Canadian facility, would they then be able to fend off document subpoenas from US safety investigators this way?
There are two entities in question: you and the object.
You are within the jurisdiction of the U.S. And can be held in contempt, charged (even in absentia), etc.
The object is now within the jurisdiction of Mexico so it gets complicated. A Mexican court can be petitioned to require the entity that (unwittingly or not) possesses it to turn it over, etc.
The difference with data Ina server is that a company has the power to turn it over regardless of where it's stored and the U.S. Government is having their hat on that.
By physically locating servers in other jurisdictions you have to comply with their laws too and that gets complicated. You can end up Ina situation where one government doesn't recognize the authority of the other and you're damned if you do, damned if you don't.
Personally I find the constant overreach of the U.S. Government to be appalling and entirely short term I it's thinking.
You are within the jurisdiction of the U.S. And can be held in contempt, charged (even in absentia), etc.
The object is now within the jurisdiction of Mexico so it gets complicated. A Mexican court can be petitioned to require the entity that (unwittingly or not) possesses it to turn it over, etc.
The difference with data Ina server is that a company has the power to turn it over regardless of where it's stored and the U.S. Government is having their hat on that.
By physically locating servers in other jurisdictions you have to comply with their laws too and that gets complicated. You can end up Ina situation where one government doesn't recognize the authority of the other and you're damned if you do, damned if you don't.
Personally I find the constant overreach of the U.S. Government to be appalling and entirely short term I it's thinking.
The problem in this case is that the data does not belong to the US government, but to a private person. If the law in Mexico says that you're not allowed to give someone else's object to the US government, obeying US law might require breaking Mexican law.
What if you stored it on a cloud server, but you encrypted it with strong keys and a password?
In practical terms how much will this set back the U.S. Govt? Won't they get rapid support from European countries and just make the process streamlined?
The feds are being hoisted on their own petard somewhat here, having long argued that a foreign person's data held on a US server is subject to US jurisdiction. The logical corrollary to that argument is that data held on an Irish server is subject to Irish jurisdiction.
It is standard practise for companies in Europe (e.g. the bank I'm consulting for right now) to ensure that, when they subscribe to cloud services, their data is held stored and processed in datacentres within the EU, so that it is subject to EU legislation and, hence, the EU's data protection laws.