Yeah make sense, AWS is crap I agree.
small not for clarity, AWS has around 30%, Azure 20%, Google 10% of market share
Yeah 90% is a stupid figure, dunno where it came from, sorry
This topic won’t hold up my work, as it is limited to the PDS and it would be on operators of PDS and Apps to deal with GDPR requests and encryption if their hosting provider does not handle it for them.
I think we are violently agreeing on this one.
The nature of the system does make for cases I have not heard before w.r.t. GDPR
That’s an interesting statement. It would be beneficial to understand the implications this proposal would have with respect to current law requirements, e.g., https://g.co/gemini/share/99c3beb15004 , and provide guidelines for Private Data-enabled PDS/AppViews operators. I will be happy to propose a legal analysis within the Eurosky team, once we have a final draft (and if we manage to secure the necessary funding).
e.g. According to Gemini, PDS operators might need to get users to sign ToS:
The PDS operator must have a legally binding contract with the user (or the entity representing the user) that sets out the subject matter, duration, nature, and purpose of the processing. (Article 28(3))
If the PDS uses another service (e.g., a cloud storage provider) to handle the user’s data, it must obtain the Controller’s (user’s) prior written authorization for that third party (sub-processor).
BTW, just FYI, GDPR doesn’t end with data removal requests and encryption.
As I mentioned above, there is data minimisation Principle (c): Data minimisation | ICO and a few more requirements.
The British GDPR-equivalent agency, the ICO, has a well-designed website that can be skimmed through in a few hours: UK GDPR guidance and resources | ICO
I went through it some years ago and haven’t had to navigate GDPR-related data for a couple of years now, luckily. There is probably plenty of stuff that I’m not connecting ATM.
Again, I want to reiterate, I’m not trying to bash your proposal. I saw your presentation in the WG, it makes sense, and we need to start from somewhere. I’m just trying to contribute with my experience. Also, I never said GPDR to be a blocker, but only made an initial observation that with E2EE we would avoid a few headaches. We can sort them out.