Hey everybody, I'm back on this stage talking about something I've already talked about in a very new age. To give you a bit of an idea, we did have this whole discussion about using all the wonderful US cloud services we have, and when Trump got elected, our internal chat group had that wonderful give, because we talked about this whole data transfer situation we have with the US where we use every US cloud as a bit of this house of cards that the last couple of years got built and everybody hoped it somehow stays up.
But this give actually has, obviously, a dynamic element to it as well, which is kind of the orange cat. So I would just talk today a little bit about what happens now the next couple of months or next year or so if the orange cat is around in the White House and tells us how he's going to deal with all these wonderful legal things some of my lawyer colleagues have come up with.
Just to give you a couple of ideas, obviously, there's this whole idea of potentially having a US-EU trade war, so potentially a lot of these services will get a lot more costly because one of the little things that the EU has to tax in return would be a lot of these US cloud providers.
Since Trump got elected, I suddenly got shitloads of invitations to Copenhagen, to Denmark, because they realized that they have a discussion about Greenland, and one of the theories that could come up there, I'm not saying this is going to happen tomorrow, but it suddenly becomes part of the thinkable, is that there could be, for example, an embargo against a member state, an individual member state, like Denmark has 6 million people, doesn't really bother the US to put an embargo on them, but that would basically mean that all US providers would have to shut down services tomorrow, so basically that country would go largely offline and they couldn't even access their emails or cloud products or anything anymore.
That can happen overnight. The US does have embargoes like that for Cuba, Iran, North Korea, Sudan, Syria, something like that. But that can be rather quickly done, and the big shots would have to shut down one of the member states.
Again, nothing I think is going to happen tomorrow, but suddenly all of these things become at least theoretically thinkable. Let's probably stay at that point. What is probably more likely to happen is that a single executive order, we now realise that US presidents love to sign these little pieces of paper, one of these executive orders could really tank a lot of the data usage we have right now in the European Union.
To recap where does this whole discussion come from, if you look at the US side of surveillance, probably some people that have been here before have seen that slide before, we basically have two types of US government surveillance. One thing is called upstream, that is where on the backbone of the internet data is collected, but over the years this got properly encrypted, so you don't have that much information there anymore.
But by now we also know that there is prism, now it's called downstream, where basically this data is taken from the servers of the big tech companies, and there you have most of the data with the encryption keys, because typically they have access to that information to be able to process that information. A lot of these slides, as you can see, they're about 15 years old, so a lot more is probably happening than what Snowden told us back then, these are the good old Snowden slides.
But the legal structure still exists, and it just requires two things, it requires that there is an electronic communication service provider, so any one of these cloud providers, and that they must have what they call foreign intelligence information, so very, very broad terminology, and that includes for example any information that relates to the conduct of the foreign affairs of the United States. So kind of anything that's interesting from an espionage perspective, doesn't have to be personal data, can also be business data, government data, anything that is of interest.
There are certain limitations, but largely what these limitations do is that they separate the data stream into US data and non-US data, because the interesting thing is on both sides of the Atlantic we feel that this is unconstitutional.
The problem is that the fourth amendment to the US constitution only covers Americans, so the solution is to take a law that basically separates the data into two data streams, one of that is constitutionally protected because concerning Americans, and the other half is the rest of the world where there is no constitutional protections and you can do whatever the F you want to do. In the end you basically get a directive to a service provider that has to open up something like an API to actually get that data.
On the European side, maybe known to people in the room anyways, we do have a general data protection regulation that kind of says data transfers are generally prohibited, so since 1995 we have actually a data transfer prohibition with certain exemptions, so if you really need to send the data abroad you can do that, and you can also outsource processing, and usually for these situations we just basically have a contractual relationship where we send the data abroad and someone signs a contract to follow EU law in simple terms, and that generally works in countries like the US where there's no data protection law, where there's just a vacuum, you can fill that vacuum with a contract, the problem is that in the US you don't just have that vacuum, you also have the existing legislation, so what you have overall is a conflict between US surveillance law and European privacy law, and as a company you're kind of between these two chairs, because under US law you have to provide all that data and under European law you're not allowed to give it out, so you basically got to be in a twist there.
Court of Justice basically told us twice already that this is not doable, that this is illegal, and usually what they do in these tests is a proportionality test, so you basically ask for the public interest to kind of have access to that data and then the interest of the individual to not give that data out, and usually you end up somewhere in this green to red scale where you balance these two interests, so for example data retention, so this idea in Europe to keep all the phone records of everybody, was somewhere in the red area and was illegal.
The data transfers to the US even made the black area, which is where you don't even do proportionality tests anymore, which is a violation of the essence of your fundamental right, so the Court of Justice said it's so massive we don't even do a balancing test here anymore, and that's the current case law so to say. Now, what is the current state of the law however?
So after the Court of Justice told us twice that you can't do that, there was the idea of doing a third agreement, so the Court of Justice struck down two of these agreements between the EU and the US, but politics decided we're just going to do a third one and hope that it's going to be any different, and how they did that is that for one and a half years the lawyers sat together and tried to hammer out a deal and solve the problem somehow, and couldn't solve it, until these two wonderful presidents got together for an afternoon tea and then solved the problem with one PDF that had two headlines that basically said the US is going to be wonderful and there's going to be court, and that was the wonderful agreement, and I always joke that's the reason these guys were presidents and we probably weren't, because they are able to do these wonderful solutions.
Now, if you look into that solution, what they basically did is they threw a shitload of paper at us, and usually I'm mostly talking at legal conferences with a lot of lawyers in the room that do consultancy for companies and tell companies how wonderful all of this can be solved, and I usually ask people how many people advised their clients on data transfers and all hands are up, and I ask people how many people actually read all the paper and then all the hands are down because we're giving legal advice to things that we've never read, but that's basically how these data transfer systems work, is that it was just a bombardment of text that no-one really read.
That being said, I obviously can't go through it, and you probably all don't want me to go through this, but I can give you a couple of highlights where you can probably see how all of that is a bit of a card player's trickery to kind of try to get all of this up and running. Now, this new executive order was basically one of these executive orders signed by Biden, and for the Europeans especially in the audience, we probably have to explain what an executive order is.
Basically, the US has normal laws like we know it, but since 20, 30 years, it's very hard to pass any laws anymore, because no majority for anything, they can't even pass their budget partly, so we need to get to something else to regulate, and one option was to do executive orders. Executive orders are basically an order by the top of the executive branch to anybody below them to do or not do something.
It's a bit like your boss telling you to jump or not jump, or sell or not, or have to hire a lower price, some internal order that you just have to follow because there is a superior, but it's not a law in that sense. For example, if you have a client and you're told to please sell this for, I don't know, 100 bucks less and you don't, your client can sue you over it because you didn't follow your boss's order. It's not an external effect. That's exactly what an executive order is. And the US tried to use that more to kind of wiggle around with the legal framework it already has.
So, under the surveillance law that we have in the US, which is called Pfizer 702, the one that I tried to explain a bit before, what they did is to basically do an executive order on top of it to kind of limit the surveillance law somehow, to say, oh, you do have this whole area, the green area that you can as public employee use, but my executive order tells me to not use all these options that you actually have. That's the idea to kind of limit US surveillance that way.
The really interesting thing is this is basically what the European Commission relied on to say, oh, we can still continue sending all the data to the US cloud because we now have this limitation through the executive order. What they did not say is that this executive order, it's 14086, is not new. The same thing already existed in an Obama executive order that was called PPT28. You don't need to know the details. But basically, they just reissued the same executive order, and the old one was already told by the court of justice to not be sufficient.
So, they basically ran out to the public stage and said, look at our new shiny executive order without telling anybody that that's basically the old shiny executive order that was already trashed by the court of justice. If we look into these two things, again, they're very lengthy and very complicated. It's interesting because they didn't just copy it. What they did is they took the text, put in a little confetti pieces, and reassembled the pieces.
So, basically, you now have the same elements just all over the place in a different text. So, just to not make it easy to compare. But I can give you a couple of examples.
Mostly, they have the same limitations. They have slightly clearer language.
So, partly, they're a bit more direct on things. One thing that they're quite direct on, for example, is that these executive orders can be changed in secret.
So, you do have an official law that basically tells you there's a limitation. But the U.S. president could limit or change that in a secret other executive order. And therefore, you don't even know if that thing you're reading is actually currently the law that's on the books.
Now, obviously, the European Commission said, oh, we have clearer language. But I'm not sure if that clearer language helps anybody because it just confirms the problems that we already knew. There's even four reasons of mass surveillance. We used to have six grounds for mass surveillance. And they now added two. One of them was, for example, a health crisis or climate change.
So, we now can have mass surveillance of everything that is in the U.S. cloud to combat climate change.
I mean, maybe they really combat climate change that way. I don't know. That would be an upside of this whole exercise. But otherwise, there are now these options to kind of have mass surveillance as well. But the big thing that the European Commission usually points its finger at to say this is the big new change and big new development is that I mentioned before there's this proportionality test.
So, this red to green test. That they added that to U.S. law. And that would be huge. Because the court of justice said this is not proportionate. You have to stop that type of surveillance.
So, basically, on the European scale, what they're doing is somewhere in the black area, as I mentioned before. And if this proportionality test is now part of U.S.
law, that would be huge. Would be great. The problem is that the U.S. says what they're doing, they're just going to continue that. But they also are going to say it's proportionate.
Now, these three things cannot logically exist at the same time. It cannot be not proportionate under court of justice rulings, proportionate under the new system, and still be the same thing. The solution that they came up with is that they had an American definition of proportionality. Which is just moved and has a different meaning.
So, we now have an American meaning of proportionality, which means it's possible. And the European definition. And therefore, we're all happy.
Now, this is the current state of law. If it ever hits the court of justice, to be frank, I just am so done with this discussion that we didn't have the energy to bring that back there a third time around. But this graph is fundamentally what all U.S. big tech is relying on, this argument here. When they say, oh, just put everything in our cloud, it's great.
Now, let's assume this all is great. And actually working at the court of justice, for whatever reason, finds this a wonderful argument. There is another problem. There is a new president. And as much as you can have that executive order with one signature of Biden, you can have one signature of Trump to undo the whole thing again.
So, this is kind of the basis of this whole layers and layers of law is basically one signature by Trump. And it's quite interesting, because the data transfer agreement relies 100% on this executive order. And theoretically, as I said, it can be overturned confidentially.
So, we don't even know if it is. But in reality, what that meant is I was sitting there the first night when Trump got elected until I think one third in the morning getting totally drunk at the office. Because I had to listen to all this shit for one or two hours. Because he said he's going to sign an executive order undoing all the Biden executive orders. That was the headline.
Reload, reload, reload. Watching this crazy thing bottle of wine. And at one third in the morning, I finally he finally signed this executive order and actually killed half of the Biden executive orders, but not this one.
So, the one with the number above and below, he killed, but not this one. I think no one in Europe realized that when there would have been another number on this thing, usage of any U.S. cloud tomorrow would have been basically a violation of EU law in that second. But they also said they're going to review all the national security ones within 45 days.
So, that's almost two months ago by now. What's also kind of an indicator where we're going is there is this project 2025, like their hostile conservative takeover of the government idea, and it has a full fucking page on this executive order that the Europeans have forced on the U.S. and that should be killed.
So, it's kind of on their agenda to kill this. We don't know if they're going to do it or not. As with all of this, it's all very much in flux. But it's quite interesting that the consequence of this one signature would be that most of these cloud providers you wouldn't be able to use because all of them rely on this whole stack of legal arguments. But also a lot of the software as a services providers that we have in Europe also rely on the same thing.
So, it's quite interesting that this is kind of the infrastructure we're running on right now. Now, typically the argument was, oh, we had all of this before and we had these data transfer discussions before. How about enforcement?
I mean, Europe has all these wonderful laws, but no consequences. The interesting thing is the authorities, the data protection authorities are likely continue to just be inactive and not do much. But we just recently had a case at the general court of the EU, like the lower EU court, where one guy asked for damages because his IP address was sent to the U.S. actually by the European commission without a legal basis. And that dude got 400 euros just for his IP address being sent to the U.S. without a legal basis.
Now, we also now have collective redress in Europe, so class sections, since last summer. There isn't any privacy class section yet, but they're cooking. If you think about the 400 euros multiplied by the user base you have, I wonder how many companies will go bankrupt over a class section like that. There would be a good amount of people that probably wouldn't be able to finance that.
Obviously, the other issue that for most companies is more relevant is just the cost for experts, lawyers, the whole compliance circus. And so I just wanted to flag this here, that potentially you want to look out for this whole discussion. The EU-U.S. transfers will go back probably to the European commission. It may be that if they change more in the U.S., they've already changed certain elements of this whole stack.
So, for example, the FTC got demolished. The P-Club, which is an oversight board, got removed. So it could be that the European commission has to kind of kill this data transfer deal on its own side already. We may also end up at the court of justice. There's a case coming up by a French lawmaker that's at the lower court right now that may go up to the court of justice and invalidate the whole deal another time around. So right now, that's kind of the threat model, so to say. There is the option to host with EU providers.
That may, for a lot of situations, be quite useful. Be aware, however, that there's a lot of issues with official EU subsidiaries. So we see that more and more argue, oh, we do have an EU subsidiary. The big question for U.S. law is if there is what they call possession custody control. So these U.S. surveillance laws are actually global. They are not limited to servers in the U.S. As long as there is access from the U.S., you would still have the problem that these laws apply.
There is options that, and some providers start doing that, is that they really seal it off and say there's no physical access. So you can't actually use a U.S. provider where there's really no physical access. We have discussions, for example, with Microsoft with their EU boundary thing that were quite interesting. In Austria, we went through that with the Austrian schools. And in short, there is not really anything that limits the access from the U.S. We also looked into the options to really audit that, to really look into it.
So in reality, there's a lot of, let's say, PR fluff that is flowing around, and you should probably take a closer look at what they really do. Just to give you a math problem here as well, we have about 1 million school kids in Austria that are all on board to that due to 400 Euros there and think what the Austrian government would have to pay in damages for all of that.
Now, obviously, you try to end keynotes on a positive note, which in this topic is kind of a trick or like really hard to do. But what we could really think about is long-term proper solutions, probably after Trump.
I mean, I don't think there's going to be much useful stuff happening in the next couple of years. But the simplest and cheapest option would be to just add a couple of judges in the U.S. Like if you would basically have 20 judges saying yes and no on access to data, that would fulfill the EU test easily, and we would all be happy and it would probably be the cheapest option to kind of get done with this whole discussion. Not likely to happen anytime soon, but that would be the easiest one right now.
I think in the meantime, we also have to discuss like your global solutions on access by governments on how we can regulate that throughout kind of at least the democratic countries in a way that your data can flow freely. Last bit that I want to throw out there is also think about we can probably get a solution in the democratic countries, but this is the democracy index currently of the world. So you may also want to think about where your data is flowing otherwise, where such solutions also in 10 years may not really be available.
So I hope that's somehow useful for you guys, and thank you for your attention. Before in the green room, Max and I were talking about the 20-minute slots and how difficult it was to cover these complex topics. I think you did an exceedingly good job of covering a very complex topic. You also made it extremely entertaining. I had to smile to myself where Max was explaining to an ostensibly European audience what an executive order was. For hundreds of years, we had executive orders. We just called them the order of the king.
Anyway, moving swiftly on. One thing I want to ask you is should companies be preparing for more localization of data processing, and if so, how do you recommend balancing that with global service delivery? To be frank, I'm a globalist first of all, so politically I'm usually on the side of let's do everything global and everything is wonderful. But the reality is we have certain differences in laws, and it's very hard to operate in two laws if they go opposite directions. If they just don't go as far in one direction, fair enough. But if they go opposite directions, you're somehow in a twist.
And I think to a certain extent, it may be easier to manage as well. It depends extremely on the business model. But there may be situations where it's easier to manage two, so to say, systems that just run under a certain regulation than trying to do everything globally at the same time. Because if you zoom out, we have more and more laws, digital laws, and we have more and more enforcement of them. And in the US, you have just different political opinions on stuff. Or in China, obviously, you have different rules. And it's going to be hard to deal with all of them at the same time.
So there may be, not just for privacy, but also for freedom of speech or for other topics, just certain differences in the rules. And depending on your exposure and where you are and so on, you may want to take that into account and say it's easier to have a system A and a system B in place, at least a European one where something's rather consistent usually, than trying to do like A, B, C, D, E, F, G all in one. Because that was the original intent and it's just going to be harder, especially in a time where we're now deglobalizing to a certain extent.
I think the thinking always came from, oh, we're going to globalize more and it's going to be easier. Unfortunately, the direction goes a bit the opposite direction right now. So I think it depends on what you do. But there may be situations where it's easier to just say, okay, we're done with this. We're just having the local one. We hear it more and more from companies that they also offer that because customers want it.
Oh, that's great. Certainly a challenge. Here's one question that came on fairly early in your presentation. It's why don't we just use confidential computing on cloud providers, infrastructure, so everything is encrypted during processing? Then we'd have no problems. So on the technical side, I'm not going to raise my I'm a lawyer flag here. But in the second case we had at the court of justice, we brought that up and said, you know, if there's a technical solution, we don't have to have that debate.
If there is what they call possession custody to control, if that doesn't exist, if let's say Google and Microsoft can legitimately say we can ourselves not access that information, then they can also tell the NSA to fuck off. Even under US law. But so far what we saw was mostly like a, you know, pretending that we have some kind of encryption and in reality we still have access to the keys. You have to know that under US law they have to make everything possible to allow the acquisition.
So just saying, for example, oh, we take the key only in the moment where we process data and give it back, that would probably the reaction from US law enforcement side would be like, yeah, then copy the keys in the moment you get it. So I think these we need to if there are solid technical solutions, that's great. And that's also what we would advocate for. If there are these half assed solutions, probably not going to get you very far.
Yeah, well, you've got you've got a very rich language there. I haven't had an indication that our next guests are behind stage. So we'll just carry on with a couple more questions. What structural reforms to GDPR enforcement do you see as essential to withstand political volatility in the US?
So I mean, on the European side, when it comes to enforcement, it's extremely political. The data protection authorities are officially independent, but in many jurisdictions, very much politicized. And that goes both ways, sometimes over enforcement, sometimes under enforcement, but hardly like just factual enforcement, and depends on the country. Some do a good job as well. But overall, we have a problem there.
I think what I mentioned before with the class sections is something where a lot of that may move to so far at the legal conferences, they're usually like, there's a, you know, never a fine, no consequence ever. Right now, we have 1.3% of GDPR procedures in Europe ever see a fine in the end, that includes a 500 euro fine. So the risk model, the risk here is almost zero. When we move on to the class section discussion, if you have a lot of customers, or also to a certain extent, a lot of like staff that could itself legitimately bring a claim, you suddenly end up in a totally different ballpark.
And to be frank, we looked at first cases as a qualified entity, we fall under this whole system, and we can bring cases like that, because as a nonprofit organization, you have to get qualified for all of this. And to be frank, the biggest problem we have right now is that most companies that we could sue with this would go bankrupt. Like you have companies like data brokers, like the really like guys that just do nothing but you know, selling data for a couple of cents that they never had any legal basis for. They don't make a lot of money.
They are oftentimes 20 people and just sell the data of 100 million people. And if 100 million people sued a 20, then you know, there's not much left of them. So one of the biggest problems in litigation is you end up paying the bills because you know, the other side is just going to go bankrupt over this. And that is a totally different situation. That's the total opposite of what we had before with like, oh, there is almost no risk. Right now the risk is extreme. If you have that exposure depends extremely on the company.
If you're you know, a typical consumer company, and suddenly that's really a topic. In other cases, maybe not so much.
Okay, great. Insightful, entertaining as usual. Thank you very much, Max Schrens.