Hacker News new | past | comments | ask | show | jobs | submit login

Using a CDN service operated by a non-GDPR business such as Cloudflare, Google, Amazon, or Akamai could potentially be confirmed to be a violation of GDPR, yes, if the CDN-hosted resources are used without opt-in. I’m eagerly awaiting the first complaint on these grounds to be reviewed and judged, now that the GDPR treaty with the United States has lapsed. It doesn’t matter where the CDN’s servers are; without the US having signed a treaty into law, each of their businesses are subject to compulsion by various US authorities to dishonor their commitments to the GDPR.




There was a very recent case which, at least for some types of data, found Cloudflare is not adequate: https://edpb.europa.eu/news/national-news/2021/census-2021-p...

It looks like the court decided SCCs were not sufficient as Cloudflare is subject to US surveillance laws so they wouldn't be able to provide adequate guarantees.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: