Bonum Certa Men Certa

EPO and Microsoft Collude to Break the Law -- Part VII: Lipstick on a Pig…

Previous parts:



Safe Harbour pig
The Privacy Shield was derided by its critics as "lipstick on a pig"



Summary: The Schrems II judgment has significant implications for "cloud computing" services

As we saw in the last part, following the invalidation of the Safe Harbour by the CJEU in its "Schrems I" judgment a revised framework for regulating transatlantic exchanges of personal data was pulled out of the hat in the form of the Privacy Shield.



From its very inception the robustness of this arrangement was questioned and it was derided by its critics as "lipstick on a pig".

The hurried manner in which the Privacy Shield was cobbled together meant that it always smacked of being a flaky and legally unsound last minute political compromise between the EU and the Obama Administration.

In the eyes of its critics it was nothing more than a comfort blanket to calm post-NSA revelations nerves among non-US cloud services buyers, rather than a legally sound framework to protect data from intrusive examination by American intelligence services.

"The hurried manner in which the Privacy Shield was cobbled together meant that it always smacked of being a flaky and legally unsound last minute political compromise between the EU and the Obama Administration."The first signs that the revised arrangement might not last very long came in January 2017 during the early days of the Trump Administration when the incoming POTUS signed off on a new Executive Order on "Enhancing Public Safety in the Interior of the U.S."

Among other elements, this Executive Order directed US government agencies to “ensure that their privacy policies exclude persons who are not United States citizens or lawful permanent residents from the protections of the Privacy Act regarding personally identifiable information".

This prompted certain commentators, such as MEP Jan-Philipp Albrecht, to express concerns about the tenability of the Privacy Shield and to call for its suspension pending clarification of the legal implications of Trump's Executive Order.

The European Commission was quick to dismiss these concerns.

Others who remained sceptical about the tenability of the Privacy Shield arrangement confidently - and accurately - predicted that its days were numbered.

"The Schrems II judgment has significant implications for "cloud computing" services."The final nail in the coffin came in 16 July 2020 when the CJEU delivered its judgment in the case of Facebook Ireland Ltd. v. Maximillian Schrems – known as "Schrems II" – which not only invalidated the Privacy Shield agreement but also put other data transfer mechanisms into significant doubt.

The CJEU found that due to the possibility of access to personal data of EU citizens by US authorities, the Privacy Shield infringed EU data protection regulations because it did not provide adequate GDPR‑compliant protection of personal data.

Privacy Shield
The Schrems II judgment has significant implications for "cloud computing" services



The Schrems II judgment has significant implications for "cloud computing" services.

Private companies and public sector bodies have increasingly started to make use of cloud services in recent years and this trend is likely to continue in future. The majority of cloud services are provided by vendors located in the US. The servers for the purchased services are partly located in the US, partly in Europe.

And this is where it gets interesting.

Even if a server is located in the EU, US authorities may access the stored data. This access is possible because of the FISA (Foreign Intelligence Surveillance Act) 702 and the EO (Executive Order) 12.333 which apply to all Electronic Communication Service Providers headquartered in the US.

"The majority of cloud services are provided by vendors located in the US. The servers for the purchased services are partly located in the US, partly in Europe."Merely relocating the data to an EU-based region in these clouds is not sufficient, because the problem is not geographical in nature.

The decisive issue here is that US-owned cloud vendors are subject to US jurisdiction and US legislation can be used to them to hand out customer data to the US government, even if the servers storing that data happen to be located on foreign soil.

USA spying on EU
Even if a server is located in the EU, US authorities may access the stored data via FISA (Foreign Intelligence Surveillance Act) 702 and the EO (Executive Order) 12.333 which apply to all Electronic Communication Service Providers headquartered in the US.



In essence, the Schrems II judgment means that US-based cloud providers such as Google, Amazon Web Services (AWS), and Microsoft Azure cannot be used to store data about European citizens in a GDPR-compliant manner.

In December 2020 it was reported that the Swedish data protection authority had imposed the first GDPR-based fine for lack of adequate protection of sensitive data stored in a US‑based cloud platform after the Schrems II decision.

"In December 2020 it was reported that the Swedish data protection authority had imposed the first GDPR-based fine for lack of adequate protection of sensitive data stored in a US‑based cloud platform after the Schrems II decision."In that case the UmeÃ¥ University in Sweden was fined SEK 550,000 (approx. € 54,000) because it was found to have processed special categories of personal data concerning sexual life and health using storage in a cloud service of a US-based provider, without sufficiently protecting the relevant data.

The Swedish data protection authority referred to the Schrems II judgment and took the stance that per se a data transfer to the US triggers a high risk for personal data because data subjects are limited in protecting and enforcing their privacy rights.

In the next part we take a further look at the fallout from Schrems II in Europe and how the judgment has given new impetus to the discussion about European "data sovereignty".

Recent Techrights' Posts

SLAPP Censorship - Part 43 Out of 200: Garrett and Graveley Particulars of Claims Almost Identical and 5RB Needs to Investigate Its Barristers (Its Reputation is at Stake)
Scrolling up and down in social control media
The Central Staff Committee of the EPO Explains Late March Meetings Coinciding With Commencement of the Non-Stop Strikes at Europe's Second-Largest Institution
The fifth meeting report and sixth meeting report show some of the concerns leading up to the mass strikes
 
When Cruelty is the Point (American SLAPPs in London, the United Kingdom, Europe)
Consider the following
Resistance to SLAPPs in the UK: Coalition Growing
thankfully awareness of SLAPPs in the UK is improving
Links 12/04/2026: Mass Rebellion Against Slop, UK Crackdown on Nudification by Slop
Links for the day
Gemini Links 12/04/2026: "Objective Truth" and Flutter
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, April 11, 2026
IRC logs for Saturday, April 11, 2026
Red Hat: We Kill People, But Please Obey the CoC or We'll Banish You
From Red Hat's own site
Gemini Links 11/04/2026: Floppy Disks on Linux and Junix
Links for the day
statCounter: Microsoft Windows Falls to All-Time Low This Month in France
French government agencies are ordered to move to GNU/Linux
Disgruntled IBMers Explain Why IBM is Circling Down a Death Spiral, Gerstner (Recently Deceased) Destroyed IBM in April 1993, and IBM Now Weaponises PIPs to Attack Its Own
We've just checked if anyone has covered mass layoffs at IBM Red Hat. Nope.
Gemini Links 11/04/2026: Critique of Delta Chat and Why Trying to Emulate Centralised, Addictive "Facebook" is Misguided
Links for the day
Links 11/04/2026: Scam Altman’s Trust Issues at OpenAI and EFF Quitting Twitter
Links for the day
Links 11/04/2026: Twitter Presence Considered Harmful to News Sites, "The Future of Everything is Lies"
Links for the day
thenextweb.com (TNW) Appears to Have Become a Slopfarm, Fake Articles About France and GNU/Linux Flood the Web
If you're not against slop, you're part of the problem
Almost 3 Days Later, Still Zero Press Coverage (Except One Publisher) About Mass Layoffs at Red Hat, Almost 500 People Laid Off (Over 400 for Sure)
"A document posted by FOSS advocacy site Techrights appears to be that memo and explains that Red Hat has devised a location strategy under which it has identified key sites for prioritized hiring and strategic workforce investment."
The Register MS, About 6 Million Pounds in Debt, Helps Promote Microsoft's Gartner Group and Prop Up the Ponzi Scheme of Slop Plagiarism, Fake Article Mentions "AI" About 20 Times
What was now known as The Register UK not only works against the interests of the UK; it works for charlatans and frauds
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, April 10, 2026
IRC logs for Friday, April 10, 2026
Three Years Ago We Disconnected From the United States, Now France Does the Same
Maybe in the coming months France will recruit loads of UNIX/Linux specialists
While Thousands of EPO Workers Are on Strike the President of the EPO, Who Bribes His Voters, Gives Himself Millions of Euros and 5,000 Euros Per Month in Housing Allowance
Campinos is immune, inherently corrupt, and habitual briber of his 'voters'
IBM and Red Hat Whistleblowers Versus a Dying Fourth Estate (Journalism Seems to Have Died as Silently as IBM RAs Go)
What a crazy world we live in!
Slopfarms We Forget About Because They Silently Die
The hard reality (for slobs and sloppers) is, slopfarms have no future
Gemini Links 10/04/2026: Flexiveganism, What Happened to Twitter, and Algorithm Fetishes
Links for the day
Links 10/04/2026: Indonesia's Social Control Media Bans Extend to Google YouTube, "I.M.F. Says Iran War Will Drag Global Growth Lower"
Links for the day
Media Blackout Regarding Mass Layoffs at Red Hat
To be very clear, what happened is certainly real
IBM 'Value' Fell 20%, The Executives Took Bonuses and Bonus Hikes
IBM is paying more and more money to the executives
SLAPP Censorship - Part 42 Out of 200: Getting the Very Basic Technical Concepts Very Wrong, or Where Miscomprehension Begets "Plausible Deniability"
It's difficult to argue with people over things that they do not even understand
This Coming Weekend and Next Week We'll Cover EPO Scandals a Lot, There Are Still Perpetual Strikes That the Media Intentionally Avoids Covering
Expect our focus on EPO corruption to grow again
More Information on IBM Red Hat Layoffs in April 2026, Hundreds of Skilled GNU/Linux Engineers Laid Off (300+ Simultaneously)
How long can the corporate media ignore IBM layoffs for?
Raw: Extensive Evidence of Red Hat's Mass Layoffs in China (IBM Meets Geopolitics)
This has nothing to do with workers' performance
We'll Never Ever Do Social Control Media, Nate Silver's Article Helps Explain Why
If you want to research and publish, stay away from it
SLAPP Censorship - Part 41 Out of 200: More Misuse of UK-GDPR (for US Citizens), More Copy-Pasting for Garrett and Graveley, Alleging That Publishing Unflattering Information is a 'Privacy' Issue
No wonder his own colleagues thought poorly of him (the junior barrister)
Links 10/04/2026: Pseudoscience and "Amazon Pulls Support for Perfectly Fine Older Kindles" and More Attacks on American Journalism
Links for the day
Dr. Andy Farnell Blasts Misuse of the Term "AI" to Describe Plagiarism, Plunder, and Misinformation
Dr. Stallman wrote about it back in the early 1980s
A Sign of Progress?
We'll solve war hunger and colonise Mars soon, according to men who never graduated from College
The Slop Delusion: This Morning We Broke Story on Red Hat Layoffs in Two Posts, Google is Already Plagiarising Them With Slop and Getting the Basic Facts Wrong
Google does not have "AI"; it has slop, which means it scrapes other people's work, then imitates it poorly
"IBM is Constantly Laying Off People" (Not Just in Red Hat)
IBM as a company is collapsing
Many Layoffs at IBM Red Hat, as the Rumours Said
Red Hat mass layoffs [...] "this was a difficult decision to make."
Microsoft, Drowning in Net Debt, Will Make Many More Cuts
The company is a net negative to society
April 15: Richard Stallman to Speak at the University of Texas in Austin, Texas
Next Wednesday in the afternoon Dr. Stallman will speak in a US college for the second time this year and for the second time in nearly 8 years
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, April 09, 2026
IRC logs for Thursday, April 09, 2026
Gemini Links 10/04/2026: Cycling, Slop, and Software to Keep Photos Organised
Links for the day