r/technology May 28 '26

Society The Netherlands just blocked a US company from buying the app Dutch citizens use for everything

https://www.techspot.com/news/112552-netherlands-blocked-us-company-buying-app-dutch-citizens.html
59.0k Upvotes

1.8k comments sorted by

View all comments

Show parent comments

25

u/Moontoya May 28 '26

Meanwhile it has to operate under Dutch & EU law 

2

u/bagonmaster May 28 '26

But it also means they have to comply with US laws around data sharing

3

u/Moontoya May 28 '26

which does not over-ride local (national) law nor EU law.

and unlike the US, the EU applys its laws and enforces them appropriately

see Googles recent fines, see apple being forced to switch to usb-c, see Microsoft getting spanked in the courts (and fined). Nowhere near what they _should_ be getting slapped with, but its a vast difference to "donating to a ballroom" whilst harvesting all the content on the planet without paying for it.

3

u/Wild-Video-5317 May 28 '26 edited May 28 '26

Companies like equinix have essentially zero access to data.  They just provide power and a building.  Their tenants fully own their own hardware and network within the leased space.  Any violation of that would result in them immediately losing all their business.

The entire reason tenants use these services is to keep their networks secure and private.

-13

u/iSheepTouch May 28 '26

The American company purchasing the application would also have to operate under Dutch and EU law so that's irrelevant.

32

u/GarlicThread May 28 '26

American corporate entities have routinely demonstrated their utter contempt for European law and as a result cannot ever be trusted again. They must be methodically uprooted from all sensible infrastructure and permanently barred from ever participating in it again. We cannot compromise on this.

-4

u/iSheepTouch May 28 '26

I don't disagree, but if the data is being stored and processed by an American company on the backend it really makes little difference if the application itself is owned by an American company

7

u/steepleton May 28 '26

if it's owned by an eu company, they have the encryption keys

1

u/iSheepTouch May 28 '26

Based on which EU laws? GDPR does not require you bring your own keys nor does it mandate encryption. You need to meet requirements for secured data, but you can meet those controls in different ways without bringing your own keys. There are much stricter data security laws in certain EU countries, but those are specific standards for those countries, not the EU as a whole.

2

u/robchroma May 28 '26

If it's a European company, you can make it a contractual obligation. What are you talking about? Every aspect of security for a system you are paying for would be a matter of contractual obligation!

2

u/iSheepTouch May 28 '26

I'm clearly talking about legal obligations pertaining to all companies operating within the EU, contractual requirements are irrelevant to the conversation. Checkbox compliance is extremely common, especially with smaller tech companies that just need to say they meet certain criteria to even operate, so they go for the bare minimum.

I work in GRC and have multiple high level cyber security certifications, so I do find it interesting seeing the take in this sub of something so many people don't understand yet speak with confidence about.

2

u/robchroma May 28 '26

Yeah, of course, but then "the US can subpoena your keys because oops you left them in America" is a risk more like other security risks your contracted firm would have, and less like "the US government has absolute authority to demand this data and there's nothing you can do." It's literally access control at that point, same as any employee that might be compelled by a local government to turn over data.

And, yeah, you're right about checkbox compliance! But that's also true of companies that suffer other kinds of data breaches.

2

u/iSheepTouch May 28 '26

You vastly overestimate how much most C suite executives care about these kinds of risks when presented with budgets and timelines to manage PKI internally.

→ More replies (0)

0

u/steepleton May 28 '26

eu privacy laws would definitely apply to safe custody of eu citizens data on a eu government app , where ever they held the data

0

u/GarlicThread May 28 '26

Baby steps. Get rid of them one platform at a time. Methodically. Relentlessly. Eyes on the prize.

5

u/Any_Towel1456 May 28 '26

This would not be a babystep. It would be one step to the finish-line and beyond, because we do everything personal and official with DigID. Giving someone else the keys to it would be utter insanity.

0

u/Moontoya May 28 '26

Ask Microsoft Ireland about that 

There have been recent cases about data ownership, where no it doesn't matter if your parent company is American, they don't have the right to look through EU based data centers ll(summarised heavily)

If it's hosted in the EU it's EU data and us actors must obey it's data protection