Danish Data Protection Agency bans Google Workspace for Municipalities(blog.simpleanalytics.com) |
Danish Data Protection Agency bans Google Workspace for Municipalities(blog.simpleanalytics.com) |
But the law is the law.
https://noyb.eu/en/project/eu-us-transfers
> At its core, this case is about a conflict of law between US surveillance laws which demand surveillance and EU data protection laws that require privacy.
A cue to other countries. Follow Denmark's lead and safeguard your data, your systems, and the privacy and security of everyone working in your municipalities.
> the Central Intelligence Agency (CIA), the Bureau of Intelligence and Research (INR) and the United States European Command (USEUCOM) already spied on France in their 2012 elections. Targets have been all parties and their leaders. [..] All targets were infiltrated both by human (”HUMINT”) and electronic (”SIGINT”) CIA spies. Specific tasks have been selected for all targets individually. [1,2]
Associated Press, on the other hand, did everything they could to downplay the degree of espionage and infiltration:
> American spies wanted an insider’s take on the race, including details of party funding, internal rivalries and future attitudes toward the United States. Although WikiLeaks’ publication of a purportedly secret CIA document was striking, the orders seemed to represent standard intelligence-gathering. [3]
I wonder if they would have described Russian infiltration of US parties as "standard", and not striking.
[1] https://www.huffpost.com/entry/cia-spied-french-elections_b_...
[2] https://wikileaks.org/cia-france-elections-2012/
[3] https://apnews.com/article/8e5094a33ad84837a7faa31c426ca909
There are no EU only alternatives to GCP, Azure or AWS, I mean there’s always Alicloud but well…
Alternatives will not be developed in time for these rulings to have a devastating impact on EU companies and in fact any company that works in the EU that processes data covered by GDPR even if they host purely within the EU simply because the parent company is in the US.
And even if my some miracle a real European cloud competitor would arise they wouldn’t limit their market to the EU, and the moment they have a substantial US presence and a US legal entity they can fall under similar circumstances as US originated companies.
This also means that potentially using solutions such as customer supplied or managed keys to encrypt data outside of the direct control of cloud providers is no longer sufficient to protect yourself from data transfer risk.
The data that municipalities store is not super sensitive, at worst it contains information about the number of sick days and salary. If the NSA cares about this data at all, it will probably have other means to obtain it.
On the other hand, the municipalities might now have to spend a lot more taxpayer money to support a worse system that might reduce their efficiency, increasing wait times and frustrations for citizens.
I would l rather see resources spent towards the defense against Russian aggression, instead of major IT projects with really unclear privacy impact.
The idea that all but the most dangerous military information should not be public in real time flies in the face of the concept of an informed citizenry, and is far more dangerous and pernicious than its access by hostile powers.
If some information should not be public, it simply should not be accessible by the state.
I can see there being some argument for eliminating the whole idea of "classified information", but that is absolutely not what is being discussed here. This is about the private data of the people of Denmark, and keeping it private.
And given that this is in Denmark—which, while certainly within a zone of some concern, is hardly in any imminent danger from Russia—it seems to me that focusing on defending against Russian aggression, at the expense of effectively everything else, would be quite unproductive.
Or is it just that you don't think spending on maintaining privacy is worthwhile no matter what, and the Russia situation is a convenient distraction you can point to?
But I truly think that Russia is a bigger threat to the average danish citizen than the NSA.
For example: https://cphpost.dk/?p=131412
And yes, money gets moved between governments pots all the time.