What they probably mean is that European companies cannot use cloud services hosted in the US anymore.
This is still a generalisation, since they can -- as long as no PII or otherwise GDPR-protected data is sent overseas.
The most likely outcome is that Google will start offering EU-hosted GA as an opt-in. How much that will affect their global data collection and processing I don't know, but I suspect it will still be far less than if all EU services stopped using them altogether.
Edit: I may be wrong. See lmkg's response in the thread.
A recent ruling about Cookiebot and their use of Akamai indicates that even EU-located servers run by a US company run afoul of GDPR. The core issue is that the US CLOUD Act gives US law enforcement access to data on those servers.
Thanks. Do you know if this covers other kinds of services, such as global load balancers (Akamai, Google Load Balancer, etc), for instance? They do know about source IP (which is considered PII), destination hosts and in many instances (where they terminate TLS, or unencrypted connections) pretty much all the information being transmitted.
I don't know for sure, and this ruling is likely to get appealed so don't take it as final yet. But the Akamai service in question was a CDN. I have a hard time imagining an argument that would sanction CDNs but not apply to load balancers.
It was about the use of personal data specifically, not jus tin general a use of US services. From the linked article (which seems to draw some broader fear-mongering conclusions not evidenced by the case it discusses):
It held that the mere use of a U.S.-based provider to collect IP addresses and user key data was an unlawful “transfer” because:
Per the Court of Justice of the European Union, IP addresses are personal data (the court also considered Cookiebot’s “user key” to be personal data).
Under the Clarifying Lawful Overseas Use of Data Act, a U.S. cloud provider can be obligated to produce all data in its possession, custody, or control to U.S. agencies, irrespective of whether the data is stored in or outside the U.S.
This decision has a number of noteworthy implications. Among the more salient are:
The court never evaluated whether a “transfer” actually occurred. The decision assumes a “transfer” occurs even if data never leaves the EU, so long as the recipient of data may formally be subject to requests by non-EU authorities.
> What they probably mean is that European companies cannot use cloud services hosted in the US anymore.
Or more specifically: That companies who target EU citizens (whether that is private use or a person being employee of a company - it does not matter) cannot use cloud services hosted in the US, when saving PII to said service.
It really doesn't matter whether you are based in Europe or not. Sendgrid for instance is an American company, but still has to follow the GDPR.
Wait sorry what? How does that even work?