SlideShare a Scribd company logo
1 of 55
Data Export after the Google Analytics decision
How to ensure
Safe Data Export
After the Google
Analytics decision
11 February 2021
Data Export after the Google Analytics decision
Legal game changers with a passion for
technology, media and IT
VLAIO Partner for Cybersecurity projects
Contributors to the “ICLG to Cybersecurity”
DPO-Trainer at Data Protection Institute
Guest lecturers at Universities across Belgium & regular authors
Legal Partner of leading associations in marketing, web building, e-commerce and IT
Member of the Board at Smart Cities Law Firms
Chairman IT & Data Protection Practice Group at Consulegis Law Network
Data Export after the Google Analytics decision
Useful downloads
● 5 copies of our ICLG Cyber Security Guide
● The actual Google Analytics decision (in German)
● EDPB Guidelines on supplementary measures for data export (01/2020)
● EDPB Guidelines on what constitutes international data transfer (05/2021)
● EDPS Guidelines on data transfers to Russia, China and India
● Sirius Legal data export vendor assessment form
● Sirius Legal coordinated and split version(s) of new SCC’s
● Sirius Legal webinar recording on international data transfers
Data Export after the Google Analytics decision
On our menu today
▪ What happened?
▪ What is data export?
▪ Why all the fuzz?
▪ Data export after Schrems II
A bit of
background
▪ Now, really, what happened?
▪ GA as the canary in the coal mine
▪ But Google must have an answer to this,
right?
▪ Lessons (to be) learned
The Google
Analytics bomb
▪ DTIA’s & Vendor Assessments
▪ Encryption and pseudonymisation
▪ Looking for “safer” alternatives
▪ Key takeaways from all of this
Practical
“how to” tools
Data Export after the Google Analytics decision
What happened?
Austrian DSB decision 22/12/21
Data Export after the Google Analytics decision
What happened?
Well, to cut the story short…
80% of European online businesses use Google Analytics
Cookie based web analytics tool
Creates unique ID that is tracked over time
Shares data with Google servers in the US
One Austrian user decided to be the smart guy
IP addresses and Google ID are PII
PII export outside EU without prior consent
PII export outside EU without proper data security
This impacts almost Every non-EU cloud service
Data Export after the Google Analytics decision
A new and complex legal reality…
Or a witch hunt, according to some
7
Data Export after the Google Analytics decision
“Data export”...?
Data Export after the Google Analytics decision
MS O365,
Facebook, LinkedIn,
Mailchimp, Hotjar,
Cloudflare, Google,
Hubspot,...
The list is endless
Offshore call
centers
outside EU
(Cloud)
Server
hosting
outside EU
Any cross
border data
movement
outside
EU/EEA
Data Export after the Google Analytics decision
Why all the fuzz?
Data Export after the Google Analytics decision
Title Title
Until that day
(more or less) free flow
of data between EU and
US under Privacy Shield
“US can never offer
data privacy”
New Privacy Shield will
not come any time soon
Schrems II
terminated Privacy
Shield with
immediate effect
Reason?
US security laws
FISA
CLOUD Act
ECJ decision
on Schrems II
16 July 2020
Data Export after the Google Analytics decision
Data export after Schrems II
Data Export after the Google Analytics decision
Title Title
End of Privacy Shield is
not the end of EU-US
data flow
Compliance is your
responsibility
Not the cloud providers
Find a new and
appropriate legal
basis
In addition to that, always
case by case DTIA
Additional measures to
ensure data privacy
ECJ decision
on Schrems II
16 July 2020
Data Export after the Google Analytics decision
Adequate country
Very short list…
Switzerland
UK + Islands
Canada
Israel
Japan
South Korea
New Zealand
Argentina
Uruguay
Faroër & Andorra
Appropriate
safeguards
SCC
BCR
+
Always DTIA and
additional measures
+
Careful with new SCC’s
Alternative legal
grounds
DIY contract
Opt-in
Contractual necessity
…
But really, don’t…
Legitimate interest?
Theoretically possible
But almost impossible
to justify
…
So really, don’t…
Data Export after the Google Analytics decision
Looking for a practical
SCC template?
Data Export after the Google Analytics decision
Now really, what happened?
Data Export after the Google Analytics decision
Now really, what happened?
Google Analytics and the inevitable logic of GDPR
Most (all) cloud services require you to share PII
Many are not EU based ⇒ export data
Google offers EU servers, SCC and “additional measures”
Google Analytics allows for partially anonymised IP
Google does not allow you to add PII to GA accounts
But that was not sufficient
Google Analytics exports PII outside the EU
Without proper data privacy (FISA!)
Violation of GDPR by the website (no decision on Google)
Data Export after the Google Analytics decision
Google Analytics as the canary in the
coal mine…
Data Export after the Google Analytics decision
And many others...
Data Export after the Google Analytics decision
Austrian DSK
Finds company in
breach for using
GA
Dutch AP warns on
it’s website the next
day that “GA may
no longer be legal”
Norwegian Datatilsynet
announces 2 ongoing cases
and advises to look for
alternative to Google
Analytics
German DSK
expert opinion on
FISA: “it’s broader
than we think”
EDPS fines
European
Parliament over
Google Analytics
and Stripe cookies
on website
German court decision
sanctions Google Fonts
(and by extension
Google Recaptcha,
Google Tag Manager, …
It’s not just the one
decision.
Since beginning of 2022,
here’s what happened…
City of Stockholm
says no to further
use of O365
Data Export after the Google Analytics decision
It’s not just the one
decision.
And just yesterday this…
Data Export after the Google Analytics decision
CNIL
Feb 2021
MS Azure
Bavaria
March 2021
Mailchimp
Hamburg
June 2021
Zoom “On demand”
Portugal
April 2021
Cloudflare
Germany
June 2021
Facebook company page
EU Commission
January 2022
“New Privacy
Shield not for
tomorrow”
And that just
confirms what we
already knew
2021 was no different
from 2022
Data Export after the Google Analytics decision
But Google must have an
answer to this, right…?
Data Export after the Google Analytics decision
“We ask people not to enter PII in
their Google Analytics account”
“You can partially anonymise IP
addresses in Google Analytics”
“We have never had a
Google Analytics access
request before”
“We have taken
supplementary measures,
as requested by Schrems II”
“The EU should replace the
Privacy Shield with a new privacy
shield (or we’re leaving…)”
What Google says
Data Export after the Google Analytics decision
What Google said
earlier this week
“We are working to add additional
controls that will allow customers to
further customize the analytics data they
collect, thereby enabling them to
continue to use Google Analytics in a
manner that is consistent with their
compliance objectives”
No idea what that exactly means…
This does not say that Google Analytics
will be GDPR compliant in the near
future
Further anonymisation?
EU data residence?
Additional encryption possibilities?
When?
How?
Data Export after the Google Analytics decision
In Google’s
defence
Data Export after the Google Analytics decision
Microsoft
remains
vague
And Azure
(also MS)
remains a big
question
mark...
Data Export after the Google Analytics decision
Amazon Web
Services
(AWS) does
not mention
any additional
safeguards in
place...
Data Export after the Google Analytics decision
“We’re moving all EU citizen data
to EU servers exclusively”
“We will begin making changes
that allow for third party “zero
access” encryption on your data”
“We will no longer use GA
data for Google Ad
purposes”
“We will disable all non-
essential data sharing (cfr.
IP in Google Fonts”)
“The US should adapt it’s
surveillance laws to allow for proper
data privacy (or we’re leaving…)
What Google should
actually be saying
Data Export after the Google Analytics decision
Lessons (to be) learned...
Data Export after the Google Analytics decision
European
SME’s are
paying the
price
Google, FB,
e.g. are
playing high
stakes
gambling
It’s almost
impossible to
avoid data
transfers
through cloud
services
This problem
is not going
away by itself
Data Export after the Google Analytics decision
Data Transfer Impact Assessments &
vendor assessment
Data Export after the Google Analytics decision
So this is important?
Wait a moment while I write this down...
ALWAYS run a prior DTIA
Incorporate data residence and security
in Vendor assessment procedures
Also, run a full scale post factum DTIA
on current services without delay
If possible, choose EU based providers
Vendor assessments under GDPR
Data Export after the Google Analytics decision
Data Export after the Google Analytics decision
Data Export after the Google Analytics decision
Destination country
political assessment
Prior behaviour of
local authorities
Data sensitivity
Purpose of the
processing
Economic sector
Duration and
volume of data
export
Number of
actors involved
Transmission
channels
Storage
location
Intended
onward
transfers
How to DTIA?
Contractual
safeguards
put in place?
TOM’s put in
place?
High Risk?
Additional
Safeguards
possible?
If not?
Alternative
options
If not?
Stop the
partnership
Data Export after the Google Analytics decision
37
Data Export after the Google Analytics decision
38
Data Export after the Google Analytics decision
39
Data Export after the Google Analytics decision
Looking for help?
Data Export after the Google Analytics decision
Encryption & Pseudonymisation
Data Export after the Google Analytics decision
Series of specific
examples of
sufficient TOM’s
Series of examples
of insufficient
TOM’s
EU based “zero access” encryption
“State of the art technology”
EU based “zero
access”
Pseudonimisation
(beware of re-ID risks
through different data
sets)
Supplier based
technology will never
suffice
“standard” measures
(staff training,
password protection,
2FA, … will never
suffice
Supplementary
measures?
EDPB guidelines 01/2020
Austrian DSK
+ others
Data Export after the Google Analytics decision
A few useable encryption tools
(For what it’s worth)
Boxcryptor
EU based
Works seamlessly with Google
Workspace
Full end-to end encryption
Cryptomator
Full end-to-end encryption
Add-on to Google Drive, Dropbox,
ect…
Veracrypt
Third party alternative to MS’s
Bitlocker
Interesting extra features for
enhanced security (a.o.
steganography)
Bitlocker?
MS, so perhaps not the best solution…
Apple Filevault?
Same problem…
Data Export after the Google Analytics decision
Looking for “safer” alternatives...
Data Export after the Google Analytics decision
Alternatives to Google Analytics
(For what it’s worth)
Matomo
EU based
Privacy centric
€ 19/month - € 35/month for 30 sites and 30 users
Extensive options
Rather costly in full service
Used by governments, banks, …
Piwik Pro
EU based
Privacy centric
Free up to 10 sites and 500.000 PV/month
Extesive options
Same origin as Matomo
Simple Analytics
EU based
Like the name says… simple
€ 19/month entry level - € 59/month business
1 mio page views - 10 users
May not suffice for full commercial analytics
Plausible Analytics
EU based
€ 9/month basic up to € 49/month for 1 mio PV’s
Open source
Cookieless (but that is no guarantee for compliance)
May not suffice for full commercial analytics
Fathom
Canadian
But with “EU Isolation” feature
Guarantees data residency in EU
Rather complete options
€ 14/month - € 44/month for 50 sites and
500.000 PV’s
Data Export after the Google Analytics decision
Alternatives to Mailchimp
(Again, for what it’s worth)
Flexmail
Belgian based
Privacy centric
Good Mailchimp alternative
Extensive options
ActiveCampaign (?)
Maybe…
US based
But with EU data processing guarantee
What else?
We’re still looking for any other reliable
alternatives, to be honest…
Emaillabs.io
(?)
EU based
But mainly focused on e-mail tracking
As far as we see not a full replacement for
Mailchimp
Data Export after the Google Analytics decision
Alternatives to O365 en MS Teams
(Again, for what it’s worth)
Nextcloud
EU based
Open source (free)
Host-it-yourself solution
Cloud storage + office tools + comm tools
Cryptpad
French based
Full office productivity suite
End-to-end encryption
Crypt.ee
Document storage + editing
End-to-end encryption
O365 itself?
Compliance should theoretically be possible
With full ”zero access” encryption
Google
Workspace?
Already offers
Strong Google based encryption
EU server location and back-up
With additional “zero access” encryption, compliance seems possible
Third party encryption tool for Workspace: Boxcryptor
Data Export after the Google Analytics decision
Key takeaways
Data Export after the Google Analytics decision
Title Title
There is a major issue with
all data transfers outside
the EU, including yours
You should:
List
Assess
Document
Secure
or Replace
This is part of a
fundamentally different
view on privacy between
the EU and the US, China,
Russia, …
You are liable for all data
export by cloud services,
online tools, apps, … within
your organisation.
So get and stay in control!
Key takeaways
from all of this
Data Export after the Google Analytics decision
Why?
Business
continuity
disturbance
Reputational
damage
Liability ico
data breach
High fines &
actual
enforcement
Data Export after the Google Analytics decision
And if needed, we can help…
Data Export after the Google Analytics decision
Want to know more?
Data Export after the Google Analytics decision
Looking for help?
Data Export after the Google Analytics decision
Our recent work in data protection...
Data Export after the Google Analytics decision
Any remaining questions?
www.siriuslegal.be
bart@siriuslegal.be
+32 486 901 931
+32 485 586 208
linkedin.com/company/sirius-legal-law-firm

More Related Content

What's hot

Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyMicrosoft Österreich
 
Building Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR ManagementBuilding Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR ManagementTrustArc
 
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...TrustArc
 
Getting Started with GDPR Compliance
Getting Started with GDPR ComplianceGetting Started with GDPR Compliance
Getting Started with GDPR ComplianceDATAVERSITY
 
BigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar SlidesBigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar SlidesDimitri Sirota
 
GDPR - Australian perspective - the challenge, the opportunity and your duty
GDPR - Australian perspective - the challenge, the opportunity and your duty GDPR - Australian perspective - the challenge, the opportunity and your duty
GDPR - Australian perspective - the challenge, the opportunity and your duty Jakub Otrząsek
 
Data Privacy: What you need to know about privacy, from compliance to ethics
Data Privacy: What you need to know about privacy, from compliance to ethicsData Privacy: What you need to know about privacy, from compliance to ethics
Data Privacy: What you need to know about privacy, from compliance to ethicsAT Internet
 
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]TrustArc
 
12th July GDPR event slides
12th July GDPR event slides12th July GDPR event slides
12th July GDPR event slidesExponential_e
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesTech Trust
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsUlf Mattsson
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Ulf Mattsson
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationGhostery, Inc.
 
A Comparison of Analytics and Tag Management Suites by Piwik PRO and Google
A Comparison of Analytics and Tag Management Suites by Piwik PRO and GoogleA Comparison of Analytics and Tag Management Suites by Piwik PRO and Google
A Comparison of Analytics and Tag Management Suites by Piwik PRO and GooglePiwik PRO
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slidesNaomi Holmes
 
IoT Guildford Meetup#26: GDPR, IoT and Transparency
IoT Guildford Meetup#26: GDPR, IoT and TransparencyIoT Guildford Meetup#26: GDPR, IoT and Transparency
IoT Guildford Meetup#26: GDPR, IoT and TransparencyMicheleNati
 

What's hot (20)

Beginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) JourneyBeginning your General Data Protection Regulation (GDPR) Journey
Beginning your General Data Protection Regulation (GDPR) Journey
 
Building Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR ManagementBuilding Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR Management
 
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
 
Getting Started with GDPR Compliance
Getting Started with GDPR ComplianceGetting Started with GDPR Compliance
Getting Started with GDPR Compliance
 
BigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar SlidesBigID GDPR Compliance Automation Webinar Slides
BigID GDPR Compliance Automation Webinar Slides
 
GDPR
GDPRGDPR
GDPR
 
GDPR - Australian perspective - the challenge, the opportunity and your duty
GDPR - Australian perspective - the challenge, the opportunity and your duty GDPR - Australian perspective - the challenge, the opportunity and your duty
GDPR - Australian perspective - the challenge, the opportunity and your duty
 
Data Privacy: What you need to know about privacy, from compliance to ethics
Data Privacy: What you need to know about privacy, from compliance to ethicsData Privacy: What you need to know about privacy, from compliance to ethics
Data Privacy: What you need to know about privacy, from compliance to ethics
 
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]
Marketing under the GDPR: What You Can and Cannot Do [Webinar Slides]
 
12th July GDPR event slides
12th July GDPR event slides12th July GDPR event slides
12th July GDPR event slides
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
 
GDPR and evolving international privacy regulations
GDPR and evolving international privacy regulationsGDPR and evolving international privacy regulations
GDPR and evolving international privacy regulations
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
GDPR - 5 Months On!
GDPR - 5 Months On!GDPR - 5 Months On!
GDPR - 5 Months On!
 
Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?Do You Have a Roadmap for EU GDPR Compliance?
Do You Have a Roadmap for EU GDPR Compliance?
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
 
A Comparison of Analytics and Tag Management Suites by Piwik PRO and Google
A Comparison of Analytics and Tag Management Suites by Piwik PRO and GoogleA Comparison of Analytics and Tag Management Suites by Piwik PRO and Google
A Comparison of Analytics and Tag Management Suites by Piwik PRO and Google
 
GDPR
GDPRGDPR
GDPR
 
GDPR Presentation slides
GDPR Presentation slidesGDPR Presentation slides
GDPR Presentation slides
 
IoT Guildford Meetup#26: GDPR, IoT and Transparency
IoT Guildford Meetup#26: GDPR, IoT and TransparencyIoT Guildford Meetup#26: GDPR, IoT and Transparency
IoT Guildford Meetup#26: GDPR, IoT and Transparency
 

Similar to 20220211 Data export after the Google Analytics decision

G Suite Data Protection: 3 steps to compliance
G Suite Data Protection: 3 steps to complianceG Suite Data Protection: 3 steps to compliance
G Suite Data Protection: 3 steps to complianceJames Farha
 
Web Marketing Wednesday Ottawa Oct 12th 2011
Web Marketing Wednesday Ottawa Oct 12th 2011Web Marketing Wednesday Ottawa Oct 12th 2011
Web Marketing Wednesday Ottawa Oct 12th 2011Antoine Gay
 
Central NJ Web Developers Meetup - Google Analytics 4.pdf
Central NJ Web Developers Meetup - Google Analytics 4.pdfCentral NJ Web Developers Meetup - Google Analytics 4.pdf
Central NJ Web Developers Meetup - Google Analytics 4.pdfDesignHammer
 
Bi social vet_ga_day_1
Bi social vet_ga_day_1Bi social vet_ga_day_1
Bi social vet_ga_day_1BeyondIndigo
 
eMarketing Techniques Conference_Google Tools May2 Goebel
eMarketing Techniques Conference_Google Tools May2 GoebeleMarketing Techniques Conference_Google Tools May2 Goebel
eMarketing Techniques Conference_Google Tools May2 GoebelCorporate College
 
Why care about GDPR and avoid over $20 million fines, even outside EU ?
Why care about GDPR and avoid over $20 million fines, even outside EU ?Why care about GDPR and avoid over $20 million fines, even outside EU ?
Why care about GDPR and avoid over $20 million fines, even outside EU ?FactoVia
 
Blackhat Analytics 2 @ Superweek
Blackhat Analytics 2  @ SuperweekBlackhat Analytics 2  @ Superweek
Blackhat Analytics 2 @ SuperweekPhil Pearce
 
Blackhat Analytics 3 @ superweek - Do be evil: Force awakens
Blackhat Analytics 3 @  superweek - Do be evil: Force awakensBlackhat Analytics 3 @  superweek - Do be evil: Force awakens
Blackhat Analytics 3 @ superweek - Do be evil: Force awakensPhil Pearce
 
Google Analytics location data visualised with CARTO & BigQuery
Google Analytics location data visualised with CARTO & BigQueryGoogle Analytics location data visualised with CARTO & BigQuery
Google Analytics location data visualised with CARTO & BigQueryCARTO
 
The competitive landscape of IoT - Global IoT Day Conference Vienna 9 April 2015
The competitive landscape of IoT - Global IoT Day Conference Vienna 9 April 2015The competitive landscape of IoT - Global IoT Day Conference Vienna 9 April 2015
The competitive landscape of IoT - Global IoT Day Conference Vienna 9 April 2015Knud Lasse Lueth
 
The competitive landscape of the Internet of Things
The competitive landscape of the Internet of ThingsThe competitive landscape of the Internet of Things
The competitive landscape of the Internet of ThingsIoTAnalytics
 
A Pratical Guide to GDPR - F.Coin
A Pratical Guide to GDPR - F.CoinA Pratical Guide to GDPR - F.Coin
A Pratical Guide to GDPR - F.CoinFranco Coin
 
Data Beats Emotions – How DATEV Generates Business Value with Data-driven Dec...
Data Beats Emotions – How DATEV Generates Business Value with Data-driven Dec...Data Beats Emotions – How DATEV Generates Business Value with Data-driven Dec...
Data Beats Emotions – How DATEV Generates Business Value with Data-driven Dec...DataWorks Summit
 
Big data minute privacy
Big data minute privacyBig data minute privacy
Big data minute privacyGuyVanderSande
 
Globant Wearable And Internet of Things Studio Presentation TMAG
Globant Wearable And Internet of Things Studio Presentation TMAGGlobant Wearable And Internet of Things Studio Presentation TMAG
Globant Wearable And Internet of Things Studio Presentation TMAGPablo Vittori
 
EMFcamp2022 - What if apps logged into you, instead of you logging into apps?
EMFcamp2022 - What if apps logged into you, instead of you logging into apps?EMFcamp2022 - What if apps logged into you, instead of you logging into apps?
EMFcamp2022 - What if apps logged into you, instead of you logging into apps?Chris Swan
 
Becoming Data Driven
Becoming Data DrivenBecoming Data Driven
Becoming Data DrivenTimo Josten
 
GDPR Scotland 2017
GDPR Scotland 2017GDPR Scotland 2017
GDPR Scotland 2017Ray Bugg
 
IMGS 2015 - Ordnance Survey Ireland - Hugh Mangan
IMGS 2015 - Ordnance Survey Ireland - Hugh ManganIMGS 2015 - Ordnance Survey Ireland - Hugh Mangan
IMGS 2015 - Ordnance Survey Ireland - Hugh ManganIMGS
 

Similar to 20220211 Data export after the Google Analytics decision (20)

GDPR- The Buck Stops Here
GDPR-  The Buck Stops HereGDPR-  The Buck Stops Here
GDPR- The Buck Stops Here
 
G Suite Data Protection: 3 steps to compliance
G Suite Data Protection: 3 steps to complianceG Suite Data Protection: 3 steps to compliance
G Suite Data Protection: 3 steps to compliance
 
Web Marketing Wednesday Ottawa Oct 12th 2011
Web Marketing Wednesday Ottawa Oct 12th 2011Web Marketing Wednesday Ottawa Oct 12th 2011
Web Marketing Wednesday Ottawa Oct 12th 2011
 
Central NJ Web Developers Meetup - Google Analytics 4.pdf
Central NJ Web Developers Meetup - Google Analytics 4.pdfCentral NJ Web Developers Meetup - Google Analytics 4.pdf
Central NJ Web Developers Meetup - Google Analytics 4.pdf
 
Bi social vet_ga_day_1
Bi social vet_ga_day_1Bi social vet_ga_day_1
Bi social vet_ga_day_1
 
eMarketing Techniques Conference_Google Tools May2 Goebel
eMarketing Techniques Conference_Google Tools May2 GoebeleMarketing Techniques Conference_Google Tools May2 Goebel
eMarketing Techniques Conference_Google Tools May2 Goebel
 
Why care about GDPR and avoid over $20 million fines, even outside EU ?
Why care about GDPR and avoid over $20 million fines, even outside EU ?Why care about GDPR and avoid over $20 million fines, even outside EU ?
Why care about GDPR and avoid over $20 million fines, even outside EU ?
 
Blackhat Analytics 2 @ Superweek
Blackhat Analytics 2  @ SuperweekBlackhat Analytics 2  @ Superweek
Blackhat Analytics 2 @ Superweek
 
Blackhat Analytics 3 @ superweek - Do be evil: Force awakens
Blackhat Analytics 3 @  superweek - Do be evil: Force awakensBlackhat Analytics 3 @  superweek - Do be evil: Force awakens
Blackhat Analytics 3 @ superweek - Do be evil: Force awakens
 
Google Analytics location data visualised with CARTO & BigQuery
Google Analytics location data visualised with CARTO & BigQueryGoogle Analytics location data visualised with CARTO & BigQuery
Google Analytics location data visualised with CARTO & BigQuery
 
The competitive landscape of IoT - Global IoT Day Conference Vienna 9 April 2015
The competitive landscape of IoT - Global IoT Day Conference Vienna 9 April 2015The competitive landscape of IoT - Global IoT Day Conference Vienna 9 April 2015
The competitive landscape of IoT - Global IoT Day Conference Vienna 9 April 2015
 
The competitive landscape of the Internet of Things
The competitive landscape of the Internet of ThingsThe competitive landscape of the Internet of Things
The competitive landscape of the Internet of Things
 
A Pratical Guide to GDPR - F.Coin
A Pratical Guide to GDPR - F.CoinA Pratical Guide to GDPR - F.Coin
A Pratical Guide to GDPR - F.Coin
 
Data Beats Emotions – How DATEV Generates Business Value with Data-driven Dec...
Data Beats Emotions – How DATEV Generates Business Value with Data-driven Dec...Data Beats Emotions – How DATEV Generates Business Value with Data-driven Dec...
Data Beats Emotions – How DATEV Generates Business Value with Data-driven Dec...
 
Big data minute privacy
Big data minute privacyBig data minute privacy
Big data minute privacy
 
Globant Wearable And Internet of Things Studio Presentation TMAG
Globant Wearable And Internet of Things Studio Presentation TMAGGlobant Wearable And Internet of Things Studio Presentation TMAG
Globant Wearable And Internet of Things Studio Presentation TMAG
 
EMFcamp2022 - What if apps logged into you, instead of you logging into apps?
EMFcamp2022 - What if apps logged into you, instead of you logging into apps?EMFcamp2022 - What if apps logged into you, instead of you logging into apps?
EMFcamp2022 - What if apps logged into you, instead of you logging into apps?
 
Becoming Data Driven
Becoming Data DrivenBecoming Data Driven
Becoming Data Driven
 
GDPR Scotland 2017
GDPR Scotland 2017GDPR Scotland 2017
GDPR Scotland 2017
 
IMGS 2015 - Ordnance Survey Ireland - Hugh Mangan
IMGS 2015 - Ordnance Survey Ireland - Hugh ManganIMGS 2015 - Ordnance Survey Ireland - Hugh Mangan
IMGS 2015 - Ordnance Survey Ireland - Hugh Mangan
 

More from Bart Van Den Brande

Start2AIM Legal focus points for AI in Marketing
Start2AIM Legal focus points for AI in Marketing Start2AIM Legal focus points for AI in Marketing
Start2AIM Legal focus points for AI in Marketing Bart Van Den Brande
 
20211116 gastles UCLL Hogeschool: Legal compliant websites
20211116 gastles UCLL Hogeschool: Legal compliant websites20211116 gastles UCLL Hogeschool: Legal compliant websites
20211116 gastles UCLL Hogeschool: Legal compliant websitesBart Van Den Brande
 
SafeShops wijzigingen in intracommunautaire btw vanaf 1 juli 2021
SafeShops wijzigingen in intracommunautaire btw vanaf 1 juli 2021SafeShops wijzigingen in intracommunautaire btw vanaf 1 juli 2021
SafeShops wijzigingen in intracommunautaire btw vanaf 1 juli 2021Bart Van Den Brande
 
20210526 cybersafety first! Sirius Legal webinar for Comeos
20210526 cybersafety first! Sirius Legal webinar for Comeos20210526 cybersafety first! Sirius Legal webinar for Comeos
20210526 cybersafety first! Sirius Legal webinar for ComeosBart Van Den Brande
 
Sirius Legal presentatie voor Voka: 10 praktische tips om correct om te gaan ...
Sirius Legal presentatie voor Voka: 10 praktische tips om correct om te gaan ...Sirius Legal presentatie voor Voka: 10 praktische tips om correct om te gaan ...
Sirius Legal presentatie voor Voka: 10 praktische tips om correct om te gaan ...Bart Van Den Brande
 
20201214 schrems II webinar politeia
20201214 schrems II webinar politeia20201214 schrems II webinar politeia
20201214 schrems II webinar politeiaBart Van Den Brande
 
Wedstrijden en social media. Gastles Odisee Hogeschool 17/11/2020
Wedstrijden en social media. Gastles Odisee Hogeschool 17/11/2020Wedstrijden en social media. Gastles Odisee Hogeschool 17/11/2020
Wedstrijden en social media. Gastles Odisee Hogeschool 17/11/2020Bart Van Den Brande
 
Direct marketing and data protection in fundraising
Direct marketing and data protection in fundraisingDirect marketing and data protection in fundraising
Direct marketing and data protection in fundraisingBart Van Den Brande
 
Sirius Legal Gastles aan Thomas More Hogeschool: e commerce en gdpr (1)
Sirius Legal Gastles aan Thomas More Hogeschool: e commerce en gdpr (1)Sirius Legal Gastles aan Thomas More Hogeschool: e commerce en gdpr (1)
Sirius Legal Gastles aan Thomas More Hogeschool: e commerce en gdpr (1)Bart Van Den Brande
 
fvb 10 praktische tips om correct om te gaan met klantendata (1)
fvb 10 praktische tips om correct om te gaan met klantendata (1)fvb 10 praktische tips om correct om te gaan met klantendata (1)
fvb 10 praktische tips om correct om te gaan met klantendata (1)Bart Van Den Brande
 
The somewhat awkward marriage between digital marketing and data protection (...
The somewhat awkward marriage between digital marketing and data protection (...The somewhat awkward marriage between digital marketing and data protection (...
The somewhat awkward marriage between digital marketing and data protection (...Bart Van Den Brande
 
Omgaan met data in e-commerce na de komst van GDPR en ePrivacy
Omgaan met data in e-commerce na de komst van GDPR en ePrivacyOmgaan met data in e-commerce na de komst van GDPR en ePrivacy
Omgaan met data in e-commerce na de komst van GDPR en ePrivacyBart Van Den Brande
 
Omgaan met data in tijden van GDPR en Privacy
Omgaan met data in tijden van GDPR en PrivacyOmgaan met data in tijden van GDPR en Privacy
Omgaan met data in tijden van GDPR en PrivacyBart Van Den Brande
 
Sirius Friday seminarie "1 jaar gdpr"
Sirius Friday seminarie "1 jaar gdpr"Sirius Friday seminarie "1 jaar gdpr"
Sirius Friday seminarie "1 jaar gdpr"Bart Van Den Brande
 
20190326 Safeshops eLegal Day 2019
20190326 Safeshops eLegal Day 201920190326 Safeshops eLegal Day 2019
20190326 Safeshops eLegal Day 2019Bart Van Den Brande
 
20190319 gdpr en consumentenbescherming in de autocarsector
20190319 gdpr en consumentenbescherming in de autocarsector20190319 gdpr en consumentenbescherming in de autocarsector
20190319 gdpr en consumentenbescherming in de autocarsectorBart Van Den Brande
 
20181209 gastles HoGent digital marketing
20181209 gastles HoGent digital marketing20181209 gastles HoGent digital marketing
20181209 gastles HoGent digital marketingBart Van Den Brande
 

More from Bart Van Den Brande (20)

Start2AIM Legal focus points for AI in Marketing
Start2AIM Legal focus points for AI in Marketing Start2AIM Legal focus points for AI in Marketing
Start2AIM Legal focus points for AI in Marketing
 
20211116 gastles UCLL Hogeschool: Legal compliant websites
20211116 gastles UCLL Hogeschool: Legal compliant websites20211116 gastles UCLL Hogeschool: Legal compliant websites
20211116 gastles UCLL Hogeschool: Legal compliant websites
 
SafeShops wijzigingen in intracommunautaire btw vanaf 1 juli 2021
SafeShops wijzigingen in intracommunautaire btw vanaf 1 juli 2021SafeShops wijzigingen in intracommunautaire btw vanaf 1 juli 2021
SafeShops wijzigingen in intracommunautaire btw vanaf 1 juli 2021
 
20210526 cybersafety first! Sirius Legal webinar for Comeos
20210526 cybersafety first! Sirius Legal webinar for Comeos20210526 cybersafety first! Sirius Legal webinar for Comeos
20210526 cybersafety first! Sirius Legal webinar for Comeos
 
Sirius Legal presentatie voor Voka: 10 praktische tips om correct om te gaan ...
Sirius Legal presentatie voor Voka: 10 praktische tips om correct om te gaan ...Sirius Legal presentatie voor Voka: 10 praktische tips om correct om te gaan ...
Sirius Legal presentatie voor Voka: 10 praktische tips om correct om te gaan ...
 
20201211 DPIA webinar
20201211 DPIA webinar20201211 DPIA webinar
20201211 DPIA webinar
 
20201214 schrems II webinar politeia
20201214 schrems II webinar politeia20201214 schrems II webinar politeia
20201214 schrems II webinar politeia
 
Wedstrijden en social media. Gastles Odisee Hogeschool 17/11/2020
Wedstrijden en social media. Gastles Odisee Hogeschool 17/11/2020Wedstrijden en social media. Gastles Odisee Hogeschool 17/11/2020
Wedstrijden en social media. Gastles Odisee Hogeschool 17/11/2020
 
Schrems II, wat nu?
Schrems II, wat nu?Schrems II, wat nu?
Schrems II, wat nu?
 
Direct marketing and data protection in fundraising
Direct marketing and data protection in fundraisingDirect marketing and data protection in fundraising
Direct marketing and data protection in fundraising
 
Sirius Legal Gastles aan Thomas More Hogeschool: e commerce en gdpr (1)
Sirius Legal Gastles aan Thomas More Hogeschool: e commerce en gdpr (1)Sirius Legal Gastles aan Thomas More Hogeschool: e commerce en gdpr (1)
Sirius Legal Gastles aan Thomas More Hogeschool: e commerce en gdpr (1)
 
fvb 10 praktische tips om correct om te gaan met klantendata (1)
fvb 10 praktische tips om correct om te gaan met klantendata (1)fvb 10 praktische tips om correct om te gaan met klantendata (1)
fvb 10 praktische tips om correct om te gaan met klantendata (1)
 
Sirius Friday Corona Webinar
Sirius Friday Corona WebinarSirius Friday Corona Webinar
Sirius Friday Corona Webinar
 
The somewhat awkward marriage between digital marketing and data protection (...
The somewhat awkward marriage between digital marketing and data protection (...The somewhat awkward marriage between digital marketing and data protection (...
The somewhat awkward marriage between digital marketing and data protection (...
 
Omgaan met data in e-commerce na de komst van GDPR en ePrivacy
Omgaan met data in e-commerce na de komst van GDPR en ePrivacyOmgaan met data in e-commerce na de komst van GDPR en ePrivacy
Omgaan met data in e-commerce na de komst van GDPR en ePrivacy
 
Omgaan met data in tijden van GDPR en Privacy
Omgaan met data in tijden van GDPR en PrivacyOmgaan met data in tijden van GDPR en Privacy
Omgaan met data in tijden van GDPR en Privacy
 
Sirius Friday seminarie "1 jaar gdpr"
Sirius Friday seminarie "1 jaar gdpr"Sirius Friday seminarie "1 jaar gdpr"
Sirius Friday seminarie "1 jaar gdpr"
 
20190326 Safeshops eLegal Day 2019
20190326 Safeshops eLegal Day 201920190326 Safeshops eLegal Day 2019
20190326 Safeshops eLegal Day 2019
 
20190319 gdpr en consumentenbescherming in de autocarsector
20190319 gdpr en consumentenbescherming in de autocarsector20190319 gdpr en consumentenbescherming in de autocarsector
20190319 gdpr en consumentenbescherming in de autocarsector
 
20181209 gastles HoGent digital marketing
20181209 gastles HoGent digital marketing20181209 gastles HoGent digital marketing
20181209 gastles HoGent digital marketing
 

Recently uploaded

一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书E LSS
 
Essentials of a Valid Transfer.pptxmmmmmm
Essentials of a Valid Transfer.pptxmmmmmmEssentials of a Valid Transfer.pptxmmmmmm
Essentials of a Valid Transfer.pptxmmmmmm2020000445musaib
 
Mediation ppt for study materials. notes
Mediation ppt for study materials. notesMediation ppt for study materials. notes
Mediation ppt for study materials. notesPRATIKNAYAK31
 
如何办理佛蒙特大学毕业证学位证书
 如何办理佛蒙特大学毕业证学位证书 如何办理佛蒙特大学毕业证学位证书
如何办理佛蒙特大学毕业证学位证书Fir sss
 
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书FS LS
 
How You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad VisaHow You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad VisaBridgeWest.eu
 
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书Sir Lt
 
The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...James Watkins, III JD CFP®
 
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书Fir L
 
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 如何办理威斯康星大学密尔沃基分校毕业证学位证书 如何办理威斯康星大学密尔沃基分校毕业证学位证书
如何办理威斯康星大学密尔沃基分校毕业证学位证书Fir sss
 
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》o8wvnojp
 
A Short-ppt on new gst laws in india.pptx
A Short-ppt on new gst laws in india.pptxA Short-ppt on new gst laws in india.pptx
A Short-ppt on new gst laws in india.pptxPKrishna18
 
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书Fir L
 
Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126Oishi8
 
Cleades Robinson's Commitment to Service
Cleades Robinson's Commitment to ServiceCleades Robinson's Commitment to Service
Cleades Robinson's Commitment to ServiceCleades Robinson
 
Arbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaArbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaNafiaNazim
 
Introduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusionIntroduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusionAnuragMishra811030
 
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueAndrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueSkyLaw Professional Corporation
 

Recently uploaded (20)

一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书
 
Essentials of a Valid Transfer.pptxmmmmmm
Essentials of a Valid Transfer.pptxmmmmmmEssentials of a Valid Transfer.pptxmmmmmm
Essentials of a Valid Transfer.pptxmmmmmm
 
Mediation ppt for study materials. notes
Mediation ppt for study materials. notesMediation ppt for study materials. notes
Mediation ppt for study materials. notes
 
如何办理佛蒙特大学毕业证学位证书
 如何办理佛蒙特大学毕业证学位证书 如何办理佛蒙特大学毕业证学位证书
如何办理佛蒙特大学毕业证学位证书
 
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
如何办理密德萨斯大学毕业证(本硕)Middlesex学位证书
 
How You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad VisaHow You Can Get a Turkish Digital Nomad Visa
How You Can Get a Turkish Digital Nomad Visa
 
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 
The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...The Active Management Value Ratio: The New Science of Benchmarking Investment...
The Active Management Value Ratio: The New Science of Benchmarking Investment...
 
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
 
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 如何办理威斯康星大学密尔沃基分校毕业证学位证书 如何办理威斯康星大学密尔沃基分校毕业证学位证书
如何办理威斯康星大学密尔沃基分校毕业证学位证书
 
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
 
A Short-ppt on new gst laws in india.pptx
A Short-ppt on new gst laws in india.pptxA Short-ppt on new gst laws in india.pptx
A Short-ppt on new gst laws in india.pptx
 
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
如何办理普利茅斯大学毕业证(本硕)Plymouth学位证书
 
Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126Indemnity Guarantee Section 124 125 and 126
Indemnity Guarantee Section 124 125 and 126
 
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
 
Cleades Robinson's Commitment to Service
Cleades Robinson's Commitment to ServiceCleades Robinson's Commitment to Service
Cleades Robinson's Commitment to Service
 
Russian Call Girls Rohini Sector 6 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
Russian Call Girls Rohini Sector 6 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...Russian Call Girls Rohini Sector 6 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
Russian Call Girls Rohini Sector 6 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
 
Arbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaArbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in India
 
Introduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusionIntroduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusion
 
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueAndrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
 

20220211 Data export after the Google Analytics decision

  • 1. Data Export after the Google Analytics decision How to ensure Safe Data Export After the Google Analytics decision 11 February 2021
  • 2. Data Export after the Google Analytics decision Legal game changers with a passion for technology, media and IT VLAIO Partner for Cybersecurity projects Contributors to the “ICLG to Cybersecurity” DPO-Trainer at Data Protection Institute Guest lecturers at Universities across Belgium & regular authors Legal Partner of leading associations in marketing, web building, e-commerce and IT Member of the Board at Smart Cities Law Firms Chairman IT & Data Protection Practice Group at Consulegis Law Network
  • 3. Data Export after the Google Analytics decision Useful downloads ● 5 copies of our ICLG Cyber Security Guide ● The actual Google Analytics decision (in German) ● EDPB Guidelines on supplementary measures for data export (01/2020) ● EDPB Guidelines on what constitutes international data transfer (05/2021) ● EDPS Guidelines on data transfers to Russia, China and India ● Sirius Legal data export vendor assessment form ● Sirius Legal coordinated and split version(s) of new SCC’s ● Sirius Legal webinar recording on international data transfers
  • 4. Data Export after the Google Analytics decision On our menu today ▪ What happened? ▪ What is data export? ▪ Why all the fuzz? ▪ Data export after Schrems II A bit of background ▪ Now, really, what happened? ▪ GA as the canary in the coal mine ▪ But Google must have an answer to this, right? ▪ Lessons (to be) learned The Google Analytics bomb ▪ DTIA’s & Vendor Assessments ▪ Encryption and pseudonymisation ▪ Looking for “safer” alternatives ▪ Key takeaways from all of this Practical “how to” tools
  • 5. Data Export after the Google Analytics decision What happened? Austrian DSB decision 22/12/21
  • 6. Data Export after the Google Analytics decision What happened? Well, to cut the story short… 80% of European online businesses use Google Analytics Cookie based web analytics tool Creates unique ID that is tracked over time Shares data with Google servers in the US One Austrian user decided to be the smart guy IP addresses and Google ID are PII PII export outside EU without prior consent PII export outside EU without proper data security This impacts almost Every non-EU cloud service
  • 7. Data Export after the Google Analytics decision A new and complex legal reality… Or a witch hunt, according to some 7
  • 8. Data Export after the Google Analytics decision “Data export”...?
  • 9. Data Export after the Google Analytics decision MS O365, Facebook, LinkedIn, Mailchimp, Hotjar, Cloudflare, Google, Hubspot,... The list is endless Offshore call centers outside EU (Cloud) Server hosting outside EU Any cross border data movement outside EU/EEA
  • 10. Data Export after the Google Analytics decision Why all the fuzz?
  • 11. Data Export after the Google Analytics decision Title Title Until that day (more or less) free flow of data between EU and US under Privacy Shield “US can never offer data privacy” New Privacy Shield will not come any time soon Schrems II terminated Privacy Shield with immediate effect Reason? US security laws FISA CLOUD Act ECJ decision on Schrems II 16 July 2020
  • 12. Data Export after the Google Analytics decision Data export after Schrems II
  • 13. Data Export after the Google Analytics decision Title Title End of Privacy Shield is not the end of EU-US data flow Compliance is your responsibility Not the cloud providers Find a new and appropriate legal basis In addition to that, always case by case DTIA Additional measures to ensure data privacy ECJ decision on Schrems II 16 July 2020
  • 14. Data Export after the Google Analytics decision Adequate country Very short list… Switzerland UK + Islands Canada Israel Japan South Korea New Zealand Argentina Uruguay Faroër & Andorra Appropriate safeguards SCC BCR + Always DTIA and additional measures + Careful with new SCC’s Alternative legal grounds DIY contract Opt-in Contractual necessity … But really, don’t… Legitimate interest? Theoretically possible But almost impossible to justify … So really, don’t…
  • 15. Data Export after the Google Analytics decision Looking for a practical SCC template?
  • 16. Data Export after the Google Analytics decision Now really, what happened?
  • 17. Data Export after the Google Analytics decision Now really, what happened? Google Analytics and the inevitable logic of GDPR Most (all) cloud services require you to share PII Many are not EU based ⇒ export data Google offers EU servers, SCC and “additional measures” Google Analytics allows for partially anonymised IP Google does not allow you to add PII to GA accounts But that was not sufficient Google Analytics exports PII outside the EU Without proper data privacy (FISA!) Violation of GDPR by the website (no decision on Google)
  • 18. Data Export after the Google Analytics decision Google Analytics as the canary in the coal mine…
  • 19. Data Export after the Google Analytics decision And many others...
  • 20. Data Export after the Google Analytics decision Austrian DSK Finds company in breach for using GA Dutch AP warns on it’s website the next day that “GA may no longer be legal” Norwegian Datatilsynet announces 2 ongoing cases and advises to look for alternative to Google Analytics German DSK expert opinion on FISA: “it’s broader than we think” EDPS fines European Parliament over Google Analytics and Stripe cookies on website German court decision sanctions Google Fonts (and by extension Google Recaptcha, Google Tag Manager, … It’s not just the one decision. Since beginning of 2022, here’s what happened… City of Stockholm says no to further use of O365
  • 21. Data Export after the Google Analytics decision It’s not just the one decision. And just yesterday this…
  • 22. Data Export after the Google Analytics decision CNIL Feb 2021 MS Azure Bavaria March 2021 Mailchimp Hamburg June 2021 Zoom “On demand” Portugal April 2021 Cloudflare Germany June 2021 Facebook company page EU Commission January 2022 “New Privacy Shield not for tomorrow” And that just confirms what we already knew 2021 was no different from 2022
  • 23. Data Export after the Google Analytics decision But Google must have an answer to this, right…?
  • 24. Data Export after the Google Analytics decision “We ask people not to enter PII in their Google Analytics account” “You can partially anonymise IP addresses in Google Analytics” “We have never had a Google Analytics access request before” “We have taken supplementary measures, as requested by Schrems II” “The EU should replace the Privacy Shield with a new privacy shield (or we’re leaving…)” What Google says
  • 25. Data Export after the Google Analytics decision What Google said earlier this week “We are working to add additional controls that will allow customers to further customize the analytics data they collect, thereby enabling them to continue to use Google Analytics in a manner that is consistent with their compliance objectives” No idea what that exactly means… This does not say that Google Analytics will be GDPR compliant in the near future Further anonymisation? EU data residence? Additional encryption possibilities? When? How?
  • 26. Data Export after the Google Analytics decision In Google’s defence
  • 27. Data Export after the Google Analytics decision Microsoft remains vague And Azure (also MS) remains a big question mark...
  • 28. Data Export after the Google Analytics decision Amazon Web Services (AWS) does not mention any additional safeguards in place...
  • 29. Data Export after the Google Analytics decision “We’re moving all EU citizen data to EU servers exclusively” “We will begin making changes that allow for third party “zero access” encryption on your data” “We will no longer use GA data for Google Ad purposes” “We will disable all non- essential data sharing (cfr. IP in Google Fonts”) “The US should adapt it’s surveillance laws to allow for proper data privacy (or we’re leaving…) What Google should actually be saying
  • 30. Data Export after the Google Analytics decision Lessons (to be) learned...
  • 31. Data Export after the Google Analytics decision European SME’s are paying the price Google, FB, e.g. are playing high stakes gambling It’s almost impossible to avoid data transfers through cloud services This problem is not going away by itself
  • 32. Data Export after the Google Analytics decision Data Transfer Impact Assessments & vendor assessment
  • 33. Data Export after the Google Analytics decision So this is important? Wait a moment while I write this down... ALWAYS run a prior DTIA Incorporate data residence and security in Vendor assessment procedures Also, run a full scale post factum DTIA on current services without delay If possible, choose EU based providers Vendor assessments under GDPR
  • 34. Data Export after the Google Analytics decision
  • 35. Data Export after the Google Analytics decision
  • 36. Data Export after the Google Analytics decision Destination country political assessment Prior behaviour of local authorities Data sensitivity Purpose of the processing Economic sector Duration and volume of data export Number of actors involved Transmission channels Storage location Intended onward transfers How to DTIA? Contractual safeguards put in place? TOM’s put in place? High Risk? Additional Safeguards possible? If not? Alternative options If not? Stop the partnership
  • 37. Data Export after the Google Analytics decision 37
  • 38. Data Export after the Google Analytics decision 38
  • 39. Data Export after the Google Analytics decision 39
  • 40. Data Export after the Google Analytics decision Looking for help?
  • 41. Data Export after the Google Analytics decision Encryption & Pseudonymisation
  • 42. Data Export after the Google Analytics decision Series of specific examples of sufficient TOM’s Series of examples of insufficient TOM’s EU based “zero access” encryption “State of the art technology” EU based “zero access” Pseudonimisation (beware of re-ID risks through different data sets) Supplier based technology will never suffice “standard” measures (staff training, password protection, 2FA, … will never suffice Supplementary measures? EDPB guidelines 01/2020 Austrian DSK + others
  • 43. Data Export after the Google Analytics decision A few useable encryption tools (For what it’s worth) Boxcryptor EU based Works seamlessly with Google Workspace Full end-to end encryption Cryptomator Full end-to-end encryption Add-on to Google Drive, Dropbox, ect… Veracrypt Third party alternative to MS’s Bitlocker Interesting extra features for enhanced security (a.o. steganography) Bitlocker? MS, so perhaps not the best solution… Apple Filevault? Same problem…
  • 44. Data Export after the Google Analytics decision Looking for “safer” alternatives...
  • 45. Data Export after the Google Analytics decision Alternatives to Google Analytics (For what it’s worth) Matomo EU based Privacy centric € 19/month - € 35/month for 30 sites and 30 users Extensive options Rather costly in full service Used by governments, banks, … Piwik Pro EU based Privacy centric Free up to 10 sites and 500.000 PV/month Extesive options Same origin as Matomo Simple Analytics EU based Like the name says… simple € 19/month entry level - € 59/month business 1 mio page views - 10 users May not suffice for full commercial analytics Plausible Analytics EU based € 9/month basic up to € 49/month for 1 mio PV’s Open source Cookieless (but that is no guarantee for compliance) May not suffice for full commercial analytics Fathom Canadian But with “EU Isolation” feature Guarantees data residency in EU Rather complete options € 14/month - € 44/month for 50 sites and 500.000 PV’s
  • 46. Data Export after the Google Analytics decision Alternatives to Mailchimp (Again, for what it’s worth) Flexmail Belgian based Privacy centric Good Mailchimp alternative Extensive options ActiveCampaign (?) Maybe… US based But with EU data processing guarantee What else? We’re still looking for any other reliable alternatives, to be honest… Emaillabs.io (?) EU based But mainly focused on e-mail tracking As far as we see not a full replacement for Mailchimp
  • 47. Data Export after the Google Analytics decision Alternatives to O365 en MS Teams (Again, for what it’s worth) Nextcloud EU based Open source (free) Host-it-yourself solution Cloud storage + office tools + comm tools Cryptpad French based Full office productivity suite End-to-end encryption Crypt.ee Document storage + editing End-to-end encryption O365 itself? Compliance should theoretically be possible With full ”zero access” encryption Google Workspace? Already offers Strong Google based encryption EU server location and back-up With additional “zero access” encryption, compliance seems possible Third party encryption tool for Workspace: Boxcryptor
  • 48. Data Export after the Google Analytics decision Key takeaways
  • 49. Data Export after the Google Analytics decision Title Title There is a major issue with all data transfers outside the EU, including yours You should: List Assess Document Secure or Replace This is part of a fundamentally different view on privacy between the EU and the US, China, Russia, … You are liable for all data export by cloud services, online tools, apps, … within your organisation. So get and stay in control! Key takeaways from all of this
  • 50. Data Export after the Google Analytics decision Why? Business continuity disturbance Reputational damage Liability ico data breach High fines & actual enforcement
  • 51. Data Export after the Google Analytics decision And if needed, we can help…
  • 52. Data Export after the Google Analytics decision Want to know more?
  • 53. Data Export after the Google Analytics decision Looking for help?
  • 54. Data Export after the Google Analytics decision Our recent work in data protection...
  • 55. Data Export after the Google Analytics decision Any remaining questions? www.siriuslegal.be bart@siriuslegal.be +32 486 901 931 +32 485 586 208 linkedin.com/company/sirius-legal-law-firm

Editor's Notes

  1. Bart neemt over
  2. Thomas neemt over
  3. Thomas neemt over
  4. Bart neemt over