Feeds

EU data guardians: search engines must obey our rules

Which we will issue very soon now

Top 5 reasons to deploy VMware with Tegile

European gov data-privacy supremos have collectively said that search engines operating in their jurisdiction are governed by EU personal-data regs even if headquartered elsewhere.

The Article 29 Working Group, a committee of EU member state data protection chiefs, is expected to issue a full working paper on search engines "in the course of the next months".

However, after a meeting this week in Brussels, the group issued a short preliminary statement (pdf).

According to the assembled bureaucrats:

As the use of search engines becomes a daily routine for an ever growing number of citizens, the protection of the users’ privacy and the guaranteeing of their rights, such as the right to access to their data and the right to information as provided for by the applicable data protection regulations, remain the core issues of the ongoing debate.

Search engines fall under the EU Data Protection Directive 95/46/EC if there are controllers collecting users’ IP addresses or search history information, and therefore have to comply with relevant provisions. These provisions also apply to such controllers who have their headquarters outside the EU, but only an establishment in one of the EU Member States, or who use automated equipment based in one of the Member States for the purposes of processing personal data.

So essentially the only way for a search engine to avoid compliance with the EU regs is to have neither offices nor hardware in Europe. Most of the major search providers have at least some such footprint in EU territory.

IP addresses - particularly when times are logged - can be tied to locations and often to individuals, and as such can be viewed as personal information. Exact details of the compliance regime are expected to appear in the full report.

Google told AP that "we look forward to seeing [the Article 29 Group's] report". Microsoft apparently said that a way for companies to comply would be to remove IPs from stored data. ®

Remote control for virtualized desktops

More from The Register

next story
I'll be back (and forward): Hollywood's time travel tribulations
Quick, call the Time Cops to sort out this paradox!
Musicians sue UK.gov over 'zero pay' copyright fix
Everyone else in Europe compensates us - why can't you?
Megaupload overlord Kim Dotcom: The US HAS RADICALISED ME!
Now my lawyers have bailed 'cos I'm 'OFFICIALLY' BROKE
MI6 oversight report on Lee Rigby murder: US web giants offer 'safe haven for TERRORISM'
PM urged to 'prioritise issue' after Facebook hindsight find
BT said to have pulled patent-infringing boxes from DSL network
Take your license demand and stick it in your ASSIA
Right to be forgotten should apply to Google.com too: EU
And hey - no need to tell the website you've de-listed. That'll make it easier ...
prev story

Whitepapers

10 ways wire data helps conquer IT complexity
IT teams can automatically detect problems across the IT environment, spot data theft, select unique pieces of transaction payloads to send to a data source, and more.
Why CIOs should rethink endpoint data protection in the age of mobility
Assessing trends in data protection, specifically with respect to mobile devices, BYOD, and remote employees.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Mitigating web security risk with SSL certificates
Web-based systems are essential tools for running business processes and delivering services to customers.