back
204 comments
We need to wake the fuck up in the EU and start aggressively building European-based competitors to US tech companies that actually respect user privacy. A good area to start would be in the data storage industry, and perhaps social media too. Obviously, non Silicon Valley based startups face certain challenges[1], but we should at least try. It would arguably benefit US consumers also, if they could choose products that are designed to compete on privacy, a good example being Switzerland-based ProtonMail[2] (ok, non-EU but still).

I wasn't aware of Privacy Shield before now, but after reading a little bit about it[3], it reads like something that only gives a fig leaf of protection to EU citizens.

[1] http://paulgraham.com/america.html

[2] https://protonmail.com/

[3] http://ec.europa.eu/justice/data-protection/document/citizen...

100% agree. Funny how when I was 16 my dream was to leave EU as soon as I can to go work at Google, FB, etc... and live the 'American dream'. USA represented progress and innovation to me.

Now with Snowden revelations, Obama's expansion of mass surveillance, etc... USA has become the exact opposite to me, they embody a future I don't want to live in.

The worst part is that some EU countries start to become like them because they still think like when I was 16, "USA is progress" => "so we have to do like them" and that's how for eg France adopted "Loi sur le renseignement" which allows gov to do like what NSA's doing.

Now all that I want is finish my CS master and start working for Protonmail,Signal,Tor,Mozilla,Linux,... or whatever company/app/foundation that is trying to protect us.

The thing I'm afraid of is that EU will keep getting weaker in terms of privacy & rights like France because of the "terrorists will kill your children if you don't give us your data" propaganda.

I hope EU will understand that even outside the ethical & moral issues having strong laws on privacy is the only way we can compete with USA tech because it's the only thing we have they don't

I'm a bit of a special case--I'm an American military brat. I was born in the US but lived overseas before I could form a memory until I was a teenager.

I, too, had dreams of America being a beacon of progress and freedom. It was my nominal homeland but one I'd never experienced. I was proud of it and loved that other nations looked up to us.

But now that dream is dead. We're perfecting the surveillance state I was told would be impossible.

Now I look at Europe, and while I disagree with a great deal of its economic policies, I wonder if the grass just might be greener on the other side.

Semi-similar: when I was younger, I really wanted to move to the states and work in SV or similar.

Sadly, I hadn't researched labour-laws in the US (or healthcare, or... well, many things). Seems like a bad deal, now - though a few of my friends have moved out there, I don't particularly envy them.

I find myself experiencing similar frustrations from the other side.

I'm an American and I find it troublesome and tiresome when people want to adopt the EU's way of doing things, just because that's how it's done over there.

I like that things are done differently in different places. It gives all of us a chance to see what things work and what things don't. The EU's privacy protections are something that I happen to think work much better than ours.

I'd love to see a "Silicon Valley of Europe" emerge as a competitor. We could see how things play out under the different ways of doing things.

My hope - perhaps naïvely so - is that President Trump will be the kick in our complacency that we so desperately need. Even if for all the wrong reasons. Both in the US and the EU.
You're too much of an optimist.

What you call "complacency" is actually years of progress in international trade and cooperation going down the drain.

Yes, people eventually wake up, but sometimes it takes a war to do it. Indeed, everybody woke up after WWII.

Well, scientists already seem about 1000% more motivated to innovate with new ways of publishing & sharing data.
I .. feel the same. Which conflicts me a lot because he's despicable in many dimensions. But he'll act as the wall(sic) we'll hit to react. He's driven and polarizing, even in the worst sense of the term.. that's still "coherent energy".

ps: that said, I can't wait for the U.S to kick him out.. he seems unfit to do anything.

> We need to wake the fuck up in the EU

...and stop trying to dismantle it from the inside because money and too much regulation. it's in chinese, russian and US interests for the EU countries to negotiate independently, but certainly not in europe's interest at large.

I'm privacy-conscious, but know of a lot of people outside the tech industry who aren't. I'd welcome products which respect my privacy but I don't think this would be enough a difference to make people or companies choose them over established players.

Having strong privacy regulations in the EU could create a market for this kind of products.

> A good area to start would be in the data storage industry, and perhaps social media too. Obviously, non Silicon Valley based startups face certain challenges[1], but we should at least try.

I'm an outsider looking in, but at least in regards to data storage and other provider services, I get to work with tons of independent providers across the EU every day. My experience is that there seems to be far more acceptance for all sorts of cloud and storage providers within the EU than I do with my North American clients, who tend to be seeking support primarily for their infrastructure that just supports their company, as opposed to providing a service to others.

I think there's a lot of good happening in this space and where such services can compete with the big three (Google, Amazon, Microsoft) is with having accessible and knowledgable engineers available. They're never going to compete on price, but service will just overall float most of these companies to the top of the list for customers looking for a place to rest their data.

So I think the will and the infrastructure is there - more than any point in modern history is it possible for an earnest start up to get a solid clientele, and having local options are important for reasons just like this - rapidly changing political climates shouldn't be able to have a strong impact on your users like this. There has to be some ability for a failover when the stroke of a pen suddenly makes holding data at one GPS coordinate illegal.

>We need to wake the fuck up in the EU and start aggressively building European-based competitors

Good luck with that. Europe doesn't provide the environment (neither culturally nor financially) needed for these types of companies to arise.

And if you want 'state planned' tech companies: What happened to the EU funded Google-killer again?

If Europe doesn't reform itself and makes it less punishing for people to start, grow, fail, start again businesses then Europe will be left behind.

And tbh. I don't believe Europe can reform. Because the problems are so deeply entrenched in European societies that it would take a herculean effort to change things. Something no one is willing to do.

So all we have left is old money industry. But that won't keep up as alive for ever...

But EC's recent unpridictable behaviour[1] only gives negative hopes.

[1] https://www.itic.org/news-events/techwonk-blog/arguing-again...

There are many good tech startups and industries in the U.K. that would be able to do such things but with us leaving the EU it seems we might be heading down the same path and be banned from storing EU data. The Snoopers Charter when we leave the EU already makes us incompatible with EU law and is already considered illegal too.

Its no wonder that the 1984 novel is flying of the shelves now.

;-P

That, and/or open source decentralized solutions, where possible.
Just chiming in to point at the fact that Bulgaria is out of the picture. The police here are very used to just casually walk in (even without an uniform) in your office and just say "let's have a look at your servers". If you resist, they might violently force you. You might eventually win in court but by that time your servers will be somebody's cousin gaming machines for 2 years at least.

It seems the only way to win around here is to emphasize the economical benefits of independent and strong privacy-oriented commercial organizations. That however would probably involve bribing politicians to "agree" with you.

Yeah, I know. I let desperation creep inside of me but when you see everybody around you being OK with outrageous violations of basic human rights, that tends to happen. :(

Then we need to change the way people are able to raise money on ideas only. We dont have a Google/Facebook etc. because no one is willing to upfront the costs.

That's why we dont have a Silicon Valley in the EU.

Its a mentality problem inside the investor space to only put money into "safer" bets not moon-shots.

> We need to wake the fuck up in the EU and start aggressively building European-based competitors to US tech companies that actually respect user privacy. A good area to start would be in the data storage industry

We are US based, but provably private cloud storage is the thesis of our company. All data is encrypted on the client machine, the keys stay on the client machine, and then the encrypted data is remotely stored across about 50 providers (using erasure coding, the actual redundancy overhead is relatively small) to minimize the impact that any single provider or even any single continent of providers can have on your data's accessibility or uptime.

It's also 100% open source.

https://github.com/NebulousLabs/Sia

Privacy in data storage might end up requiring owning your hardware in the long run, regardless of your location. One company doing interesting work in this field is protonet, founded in Germany - https://protonet.com/company/about-us/.

I'm not sure why it seems harder for companies to take off in the EU. It does seem like funding is harder to come by here, but to be honest it seems like it ought to be _easier_ to start here than in the US. If I fail in most EU countries, I'm not worried about dying in a gutter like I am if I fail in the US.

But the EU has much less qualms about restricting and violating the freedom of their citizens. We have no free speech like the US. Massive data collection laws are passed without any large backlash regularly. I still support aggressive competition from the EU simply because the EU needs to stand on its own legs but don't pretend that it's for privacy of its citizens. I guess maybe if you explain it in a roundabout way, it is for our privacy.. privacy from US institutions, well that counts for something too, sure.
Full Ack. Not only do we need privacy respecting data storage and social media, but a EU privacy friendly search engine will be a step in the right direction as well.
EU porn tech does beat US porn tech in many metrics. I have always wondered why, when the rest of their tech sector is way behind.
> start aggressively building European-based competitors to US tech companies that actually respect user privacy

Won't happen when all of Europe keeps raising taxes and the US lowers theirs.

Most creators like to keep their rewards and distribute it at their discretion, not have over half of it stolen from them by force.

My fear is that this gives the EU commision a justified target (US tech companies) when they look for something to bargain with once Trump fires first shots at EU (German) car companies (which he will).

A EU directive could look something like:

* EU citizen data must not leave the EU to the US since EU citizen privacy is not respected there

* If US tech companies are not able to segregate data (difficult for small tech companies and e.g. Facebook) they will be blocked

And there we have it. The balkanization of the (western world) Internet.

This doesn't seem like a bad thing to me. I think countries in the EU are being incredibly stupid by allowing a foreign nation to maintain databases of pretty much all of their citizens movements, conversations, plans, history and relationships.
Yup, Trump keeps forgetting the fact that trade blocks work both ways. Or perhaps he doesn't care.
It's not really a very strong bargaining chip for the EU commission, because ECJ and ECHR can independently rule certain decisions to share data as unconstitutional or as violations of the human rights of European citizens. So the commission cannot simply agree to set up particularly lax data sharing standards that the US would like to have, for instance.

It's already dubious enough whether the Privacy Shield would withstand additional legal scrutiny by ECJ, and this also depends on actions of the current US government to conform with it.

I am actually the Lead Developer at a medical device company making software that manages patient data from EU citizens. Our answer to this is really easy: Do not host anything in the US. We intend to use AWS. Frankfurt will do just fine, even if it is a bit more expensive.
You may want to research requirements for patient data by country.

I am pretty sure you can't store medical data in AWS in France. (if your data actually qualify as medical data according the law, it's hard to know without knowing the details, the exact term is "données de santé à caractère médical" which translates to health data of medical nature)

There, you have to choose from a list of certified providers (thanksfully, OVH is now in the list [1]).

It will probably be different for every country, though you should be able to fly under the radar until you get some traction.

[1] Full list [FR] : http://esante.gouv.fr/services/referentiels/securite/heberge...

Medical data and AWS? Urks. If you host with an US-company, your data is no more secure then if they were physically in the US. Not if preventions of overreach like Privacy Shield (which was mostly a joke anyway) are dismantled.

Get a EU data-provider!

Relevant case: the DOJ attempted to gain access to Hotmail data residing on a server based in Ireland: https://www.theguardian.com/technology/2015/sep/09/microsoft...

Any US connection is worrying from a privacy POV.

Actually, in Germany there is a law that prohibits storing any user data somewhere else then Germany.
I think it needs a country by country solution. Doesn't France make it illegal to move transmit data on patients to outside France?
At this point I can't take any Trump news seriously. Everything is "could" or "might". I can't even tell what's real and who's just working their Trump derangement out.
I do understand to a point: Sometimes I can't actually tell the difference between a piece of actual trump news and satire - and this isn't a new thing. I get the feeling Trump is playing the country like he'd play an audience for a drama, complete with cliffhangers and reveals and plot twists.

Not to mention it all seems so very surreal.

And the truth is that I find this frightening. I don't want government to mimic entertainment.

Some of the stuff should be verifiable at this point: If he's signing executive orders, surely there are copies. Not that we'd be able to see all of them, since I'm sure some are classified. This article seems to be speculation and worries based on something somewhat verifiable. And it is stuff like this that somewhat helps me keep some sort of grasp on things, as much as possible.

The EC has already gone on record saying that this EO does not apply to the Privacy Shield.

https://www.theregister.co.uk/2017/01/26/trump_blows_up_tran...

One of the provisions for the EU to agree to the Shield was that the Privacy Act would be extended to citizens of the EU plus certain non-EU European countries. The Shield and the Privacy Act extension goes into effect Feb 1.

That said, I don't think this executive order will alleviate the concerns of ordinary European consumers giving American internet companies

The original TechCrunch article was wrong, and they updated it with the statement from the EU Commission that tells them it was wrong.

There's a law now called the Judicial Redress Act, and it passed as a compromise made to the EU before enabling the Privacy Shield data-sharing deal between the EU and the US.

I still don't think it goes far enough, because I don't think the US Privacy Act gives "essentially the same protections" as the EU privacy laws do (per CJEU requirement), but at least it gives non-U.S. citizens the same protections Americans have.

So this executive order means nothing. The administration may act as if it does, but if sued, it can be ruled unconstitutional/invalid.

I guess this could be a problem if Trump continues to sign multiple unconstitutional executive orders every day for the rest of his term. There are only so many lawsuits people can start against his administration, so many of the unconstitutional executive orders may get ignored.

The problem lies in tossing new demands out every day, how is any agency even supposed to understand how they apply to their policies? Mass confusion might be great in campaigns but it isn't very useful for governing a country. When it may or may not affect interactions with foreign countries, lots of mistakes will happen, and often those lead to wars, both economic and otherwise.
The article has been updated:

The spokeswoman has now sent us a statement in which the EC asserts that Privacy Shield “does not rely on the protections under the U.S. Privacy Act”.

Since the impetus for this article was an executive order[0] regarding the Privacy Act, it seems that there's no immediate need for concern.

[0] Privacy Act. Agencies shall, to the extent consistent with applicable law, ensure that their privacy policies exclude persons who are not United States citizens or lawful permanent residents from the protections of the Privacy Act regarding personally identifiable information.

>Except in many ways the EU was conceived by US planners to eliminate popular control and provide a negotiating partner for the US that could be dealt with as a whole.

Not exactly true. The EU was logical evolution of the common European trading bloc. One of the conditions of the Marshall Plan was that European nations had to xome together to receive aid and xould not deal with the US on a nation by nation basis... in order to foster cooperation and not repeat the horror of constant warfare that plagued the European continent for 1000+ years

The so called "Privacy Shield" was from the start just a renaming of the previous existing contract between the US and the EU. Thus it did not protect anything more than it was protected before.

Until the EU stops to make such "show politics" for the masses, nothing will change and we will get such contracts that essentially have no effect at all.

Is there any good alternatives to Gmail? Self hosted or hosted is EU, both works
What will happen with non-EU citizens? I'm from south america. How does this affect me?

Thanks!

Based on the European Commission's guide to Privacy Shield document, it does not appear that Trump's order affects it.

Privacy Shield sets requirements for how US companies must deal with personal data that they transfer from the EU to the US. These requirements are:

1. The company must inform you about:

- the types of personal data it processes,

- the reasons is processes personal data,

- if it intends to transfer your data to another company and why,

- your right to ask for access to your personal data,

- your opt-out right to having the data used in a way "materially different" or disclosed to another company,

- how to contact the company if you have a complaint about the use of your data,

- the dispute resolution body in the EU or US where you can bring a complaint,

- the US government agency that is responsible for investigating and enforcing these obligations,

- the possibility that the company may have to respond to lawful requests from US public authorities to disclose information about you.

2. If the company wants to use your personal data for a different purpose than the one for which it was originally collected or has been subsequently authorized by you:

- this is not allowed if the new purpose is incompatible with the original purpose,

- if the new purpose is different but related to the original, they may only do so if you do not object (but in the case of "sensitive data" you have to actually consent).

- if the new different purpose is close enough to not be considered "materially different" the use is permitted.

3. They should only receive and process personal data to the extend that is relevant for the purpose of processing, and only keep it as long as necessary for this, with some exceptions allowing longer keeping for the public interest, journalism, literature and art, scientific or historical research, or statistical analysis.

4. The company must secure the data.

5. Protect the data if transferred to another company.

6. Provide you with access to your data and a way to request corrections.

Trump's order says that agencies, which means Federal government agencies, have to exclude from their privacy policies people who are not US citizens and not lawful permanent residents.

These agency privacy policies were not covered under Privacy Shield, and so this change to them appears to be irrelevant to Privacy Shield. It doesn't change the obligations of companies under Privacy Shield.

Note that I'm basing this analysis on a document written by the EU to explain Privacy Shield to ordinary citizens. It is possible that there are subtleties or complexities that they left out of that document that may be relevant.

I'm not sure how accurate that is that it doesn't affect agencies at all. The whole reason the old Safe Harbor deal fell at the CJEU was because of Snowden's documents and accusations that US is indiscriminately accessing European's data through companies.
I'm seeing a lot of talk from Europeans about how they need European competitors to US companies to protect their data.

The question I have to ask is:

What makes you think your European competitor company won't start doing the data-harvesting and privacy-invading methods that their US counterparts do ?

Your answer might be: European laws and regulation

But then, just like in the US with GooFace, your European competitor will setup their lobby groups and get their preferred candidates into Europe-governance

They (lobbyist) will obviously try, if they will succeed is up to the people of the EU countries, nothing is a given. So far the right to privacy is strong is several countries, others less so. But lobbyists appear to have a somewhat hard time to influence the entirety of EU, maybe with the exception of agriculture.