The Register® — Biting the hand that feeds IT

Feeds

EU data guardians: search engines must obey our rules

Which we will issue very soon now

Ensure Ease of Recovery with Asigra’s Agentless Software

European gov data-privacy supremos have collectively said that search engines operating in their jurisdiction are governed by EU personal-data regs even if headquartered elsewhere.

The Article 29 Working Group, a committee of EU member state data protection chiefs, is expected to issue a full working paper on search engines "in the course of the next months".

However, after a meeting this week in Brussels, the group issued a short preliminary statement (pdf).

According to the assembled bureaucrats:

As the use of search engines becomes a daily routine for an ever growing number of citizens, the protection of the users’ privacy and the guaranteeing of their rights, such as the right to access to their data and the right to information as provided for by the applicable data protection regulations, remain the core issues of the ongoing debate.

Search engines fall under the EU Data Protection Directive 95/46/EC if there are controllers collecting users’ IP addresses or search history information, and therefore have to comply with relevant provisions. These provisions also apply to such controllers who have their headquarters outside the EU, but only an establishment in one of the EU Member States, or who use automated equipment based in one of the Member States for the purposes of processing personal data.

So essentially the only way for a search engine to avoid compliance with the EU regs is to have neither offices nor hardware in Europe. Most of the major search providers have at least some such footprint in EU territory.

IP addresses - particularly when times are logged - can be tied to locations and often to individuals, and as such can be viewed as personal information. Exact details of the compliance regime are expected to appear in the full report.

Google told AP that "we look forward to seeing [the Article 29 Group's] report". Microsoft apparently said that a way for companies to comply would be to remove IPs from stored data. ®

Cloud based data management

Latest Comments

re: Phorm getting users' traffic data from ISPs

I always though that, due to the US's unbelievebly lax data security laws, the UK law required a persons express permission before transferring any personal data to the US.

Amazon have fallen foul of this in the past, by automatically signing people up to Amazon.com when they sign up for Amazon.co.uk.

0
0

more than just search engines?

will this also apply to MyFaceSpaceBook?

0
0

re google.com and google.co.uk

I wrote:

"I imagine google.co.uk is an EU/UK subsidiary of google.com"

My imagination was getting away with me - google.co.uk is hosted in the US. Sorry.

0
0

More from The Register

SCO vs. IBM battle resumes over ownership of Unix
Zombie lawsuit back and wants to suck the brains out of Linux
 breaking news
 breaking news
Ecuador: All right, Julian, you CAN stay on our sofa - it's your human right
Minister and Wikileaker share cosy chat in tiny London flat
Google flings another £1m at online child sex abuse vid CRACKDOWN
See, see, we're trying, ad giant tells Daily Mail UK.gov
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
 breaking news
BBC lied to Parliament about doomed £100m IT monster, thunder MPs
Axed DMI ballooned and burst while watchdogs sang Kumbaya
NSA whistleblower to tech firms, Obama: 'Grow a pair!'
Ed Snowden: Email tracking grabs 'IPs, raw data, content, headers, attachments, everything'
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights