News: 1669969812

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

US commerce bosses view EU rules as threat to its clouds

(2022/12/02)


More than a dozen industry associations including the US Chamber of Commerce this week issued a joint statement warning the EU against adopting rules that would effectively exclude US cloud providers like Amazon, Google, and Microsoft from doing business in much of Europe.

The [1]statement filed by 13 industry associations, including the US Chamber of Commerce, Japan’s Association of New Economy, and the Latin American Internet Association, addresses proposed changes by the EU cybersecurity agency ENISA. The expected tweaks would change how governments and companies use cloud providers, and potentially which operators they could pick, according to documents [2]passed to Reuters.

The issue at hand are changes to the European Cybersecurity Certification Scheme for Cloud Services (EUCS) proposed in May that Reuters reports would require cloud services to be operated and maintained from the EU and require that customer data be stored and processed in the continent according to its rules.

[3]

"These EUCS requirements are seemingly designed to ensure that non-EU suppliers cannot access the EU market on an equal footing, thereby preventing European industries and governments from fully benefiting from the offerings of these global suppliers," the joint statement reads.

[4]

[5]

The letter also made the case that the provisions as drafted would not level the playing field and would instead considerably reduce the number of cloud offerings available in Europe, potentially resulting in higher costs for customers.

And there may be some truth to that according to John Dinsdale, chief analyst at Synergy Research Group, who [6]previously told The Register that most European cloud providers instead target niche markets, and don't come anywhere close to meeting the criteria require to complete with US cloud providers.

[7]

The Chamber appears to call out this fact in its statement, arguing that is the EU moves forward with these proposed changes, it could leave customers with existing cloud commitments in a lurch as they're forced to invest significant time and resources to migrate their workloads and data off of non-EU clouds and onto those ill-equipped to support them.

[8]Microsoft floats Cloud for Sovereignty

[9]Microsoft revises software licensing, cloud policies amid EU regulator scrutiny

[10]AWS, Microsoft, Google own 72% of Euro customer cloud spending

[11]Digital sovereignty gives European cloud a 'window of opportunity'

"If the European Commission suggests the EU wants '75 percent of Union enterprises' to take up 'cloud computing services, big data, and artificial intelligence,' it should seek to expand — not decrease — the availability of cloud technologies in Europe," the joint statement reads.

In response to questions, ENISA tells The Register that work on the EUCS is ongoing and no decision has been taken yet. A spokesperson for the agency said that many of the proposed changes are targeted at "use cases requiring the highest level of security," like those involving sensitive government data or involving critical infrastructure.

The spokesperson added that the scheme in question is also voluntary, "so the fact that a cloud service cannot be certified at a given assurance level does not prevent this service from being used, if this is not defined by national legislation."

The cloud battle for Europe

As The Register has previously reported, it's not as though US cloud providers are struggling to find customers in Europe. A Synergy Research Group report from earlier this year [12]found that Amazon Web Services (AWS), Google Cloud, and Microsoft Azure account for 72 percent of cloud spending in Europe and that top six providers are all based in the US.

American cloud dominance in Europe has been a point of contention for years now. Two of the more recent complaints filed with the European Commission come from French public cloud provider OVHCloud and Nextcloud, which have [13]called Microsoft's business practices anticompetitive. In may Microsoft offered a series of [14]concessions over its licensing policies in a bid to appease regulators investigating the case.

Similarly, we've seen US cloud providers scramble to stay in compliance with EU data sovereignty and General Data Protection Regulation (GDPR) requirements. Earlier this year the European Data Protection Board (EDPB) initiated a [15]probe into public sector use of the cloud to determine whether services complied with these requirements.

[16]

In the wake of the investigation every major cloud provider, including Google, Microsoft, Amazon, and Oracle, have rolled out sovereign cloud services. Broadly speaking, the [17]services are aimed at public sector customers subject to GDPR restrictions on data collection and processing.

Microsoft in particular has committed to [18]implementing a EU Data Boundary by the end of the year intended to ensure that EU customer data process all data within the EU. Meanwhile Google is being [19]forced to pursue similar measures to continue doing business with EU institutions. ®

Get our [20]Tech Resources



[1] https://www.uschamber.com/security/coalition-joint-industry-statement-on-european-cybersecurity-certification-scheme-for-cloud-services-eucs

[2] https://www.reuters.com/technology/us-chamber-commerce-warns-against-draft-eu-plan-exclude-non-eu-cloud-vendors-2022-12-01/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y4na08f7eY9qQSf0EZArEwAAAI0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y4na08f7eY9qQSf0EZArEwAAAI0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y4na08f7eY9qQSf0EZArEwAAAI0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2022/09/29/aws_microsoft_google_european_cloud_spend/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y4na08f7eY9qQSf0EZArEwAAAI0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2022/07/20/microsoft_cloud_for_sovereignty/

[9] https://www.theregister.com/2022/05/18/microsoft_cloud_concessions/

[10] https://www.theregister.com/2022/09/29/aws_microsoft_google_european_cloud_spend/

[11] https://www.theregister.com/2022/06/07/openinfra_sovereignty/

[12] https://www.theregister.com/2022/09/29/aws_microsoft_google_european_cloud_spend/

[13] https://www.theregister.com/2022/06/06/gaia_x_ovh_nextcloud_scaleway/

[14] https://www.theregister.com/2022/05/18/microsoft_cloud_concessions/

[15] https://www.theregister.com/2022/02/15/edpb_cloud/

[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y4na08f7eY9qQSf0EZArEwAAAI0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[17] https://www.theregister.com/2022/07/20/microsoft_cloud_for_sovereignty/

[18] https://blogs.microsoft.com/eupolicy/2021/12/16/eu-data-boundary-for-the-microsoft-cloud-a-progress-report/

[19] https://www.theregister.com/2022/07/20/microsoft_cloud_for_sovereignty/

[20] https://whitepapers.theregister.com/



"ensure that non-EU suppliers cannot access the EU market on an equal footing"

Pascal Monett

No, they are designed to ensure that EU data stays in the EU.

If you don't like it, tough. That's the way the ball is rolling now and you're not going to stop it.

Re: "ensure that non-EU suppliers cannot access the EU market on an equal footing"

Potemkine!

If those companies and governments stop messing with EU data and consider they can do whatever they want as these data were theirs, maybe things would be different. As it is not the case, it's good to see EU institutions are doing what is required to protect EU citizens and companies.

I hope these rules will be enforced, the sooner the better.

== Bring us Dabbsy back! ==

Re: "ensure that non-EU suppliers cannot access the EU market on an equal footing"

codejunky

@Pascal Monett

"No, they are designed to ensure that EU data stays in the EU.

If you don't like it, tough. That's the way the ball is rolling now and you're not going to stop it."

Roll on the new iron curtain. The EU cutting itself off from the world one bit at a time.

Re: "ensure that non-EU suppliers cannot access the EU market on an equal footing"

ThatOne

Cutting yourself off Facebook and Twitter might be a service to humanity.

Seriously, your argument is disingenuous at best. It's colonialism to say those countries should actually feel honored we bother stealing their resources, because of course we have a much better use for them than those primitive savages. (What better use can there be than to make me (myself) rich?...)

And yes, PI are resources, the proof is they're worth money.

(Didn't downvote you though.)

The power of the EU

Anonymous Coward

I doubt these companies would even notice if the UK this on it's own.

The US doesn't like the EU. It doesn't like the idea of the EU. But it has to respect it.

Tubz

In other words, USA cloud suppliers see a threat to profit margins and attempts to use vague words and threats.

Joe W

or "the EU is sick of the US applying their rules to the world - like forcing a company to send their data held in another jurisdiction (in the EU) to the US just because some TLA wants it, without proper oversight (like a warrant) or using the existing and proven methods (when you investigate a crime you can ask other countries to help), and without having proper data protection rules in place".

So, yeah, nah. I hope the politicians do grow a pair of hairy ones and tell them to just fork off. You can come and do business here when you play by our rules. Same thing when EU companies want to do business in the US, right?

msobkow

Note to Americans:

Your corporate entities DO NOT have the right to rape the entire planet for profits. Ferengi are only supposed to be fiction .

"potentially resulting in higher costs for customers"

Filippo

This is both true, and pointless. Any system that adheres to some certification will cost more than a similar uncertified system, and this is widely accepted. This is true even when the certification is meaningless, but is much more true when the certification - as is the case here - actually has a meaningful impact on what's going on. In this case, preventing foreign companies from monetizing data on EU citizens in an opaque fashion. It's not that we are unaware that this will lead to increased costs; we know, and we're fine with that.

At the individual level, I myself would be quite fine with a subscription service that guarantees privacy, in lieu of many "free" services that slurp everything they can. This goes ten times more if the data I'm handling is not my own. The fact that such an arrangement is typically not even an option is deeply problematic, and the market has had 10+ years to fix this problem, and hasn't. Regulation seems appropriate in this case.

Curious!

jmch

"These EUCS requirements are seemingly designed to ensure that non-EU suppliers cannot access the EU market on an equal footing, thereby preventing European industries and governments from fully benefiting from the offerings of these global suppliers,"

That's a curious statement, as it implies that EU industries and governments are somehow 'losing out' from excluding non-EU suppliers, while actually it is a benefit for them. As many people have repeatedly pointed out, "cloud" just means someone else's computer somewhere else. The EU is large enough that the "somewhere else" can be safely in some other part of the EU that respects EU data privacy and rules. If the "someone else" isn't willing to play by EU rules, fine, go sell your cloud services to people who don't mind all their data being subject to the whims of the US government. Or lobby your government to repeal the laws that make any US company's data subject to US government search even if the data is physically held outside the US.

US data colonialism on the rampage

Anonymous Coward

The US regards data localism as a form of data protectionism, with the Information Technology and Innovation Foundation making the argument that data localism is a covert form of authoritarianism to facilitate domestic surveillance (conveniently forgetting that many data localisation initiatives were driven by Snowden’s revelations about US surveillance of its own citizens in the first place). The US, through its co-option of GAIA-X, opposition to GDPR, the ENISA initiative and many others is fundamentally opposed to Europe achieving any form of digital autonomy or sovereignty. Who cares if the US is inconvenienced and put out of pocket by EU cloud users wishing to keep their workloads in the EU? The EU has the will to grow its own autonomous, sovereign digital capability - and the UK would do well to take heed.

Re: US data colonialism on the rampage

Peter2

Who cares if the US is inconvenienced and put out of pocket by EU cloud users wishing to keep their workloads in the EU?

American corporations and the American chamber of commerce, apparently.

My heart bleeds.

But then it's a bit odd to think that declaring something int could
actually slow down the program, if it ended up forcing more conversions
back to string.
-- Larry Wall in <199708040319.UAA16213@wall.org>