• Treczoks@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 month ago

    They have to give s shit, because they are ultimately responsible for the handling (and abuse, if it comes to that) of the data, and as European companies they are in easy reach of the European law.

    • Zos_Kia@lemmynsfw.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      Nah, as long as the actual servers are hosted in Europe, you’re compliant with GDPR and European law. The European company is not liable if the US government violates the EU-US framework.

      • biofaust@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        The Processor is not, but the Controller is still required to guarantee appropriate security for personal data. Appropriate means running a risk assessment and deciding accordingly.

        The problem is when in the EU we take as security responsible for healthcare people who handled IAM for Jira tops.

        • Zos_Kia@lemmynsfw.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 month ago

          Appropriate means running a risk assessment and deciding accordingly

          The risk assessment doesn’t require the company to assess the reliability of international diplomatic relationships. Having your data on EU soil (even under the care of a US company) is enough for compliance.

          • biofaust@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 month ago

            I assure you that is not true. Even in my “mild” domain of marketing analytics, vendors exist that are EU companies with EU storage also run by EU companies or they offer on-premise deployment. And serious companies with users that may signal personal details through behavioral data seek such solutions.