So which country's laws apply?

bekdik

Honorary Master
Joined
Dec 5, 2004
Messages
12,860
Reaction score
20
Location
I exist only in my own mind ...
From an article on ComputerWorld:

While providers of email, chat, social network and cloud services often claim -- even in their service agreements -- that the data they store is encrypted and private, most often they -- not you -- are the ones who hold the keys. That means a rogue employee or any government "legally" requesting encryption keys can decrypt and see your data.

So, for the sake of argument:

A South African company stores its data in a Google Cloud where the data centre is hosted in Ireland.

If a government demands access to the data, which of the 3 possible governments in the above scenario would have access/ownership to the data?
 
For the sake of argument:

A South African company stores its data in a Google Cloud where the data centre is hosted in Ireland.

If a government demands access to the data, which of the 3 possible governments in the above scenario would have access/ownership to the data?

Guessing it would be ireland, depending on their own laws. But you get data havens.
 
From an article on ComputerWorld:



So, for the sake of argument:

A South African company stores its data in a Google Cloud where the data centre is hosted in Ireland.

If a government demands access to the data, which of the 3 possible governments in the above scenario would have access/ownership to the data?

Ireland.
Then on Google's legal policy. If SA requests it from Google and they decide to comply, so be it.
Our laws can't force them to do anything.
 
I think you have to do with two jurisdictions namely where the agreement was closed and then the jurisdiction of where the data reside or is held.

Interesting question, will be keeping an eye on replies....
 
I wonder what SARS says? Can't they demand access to company data?

So I did some digging on SARS's site and found http://www.sars.gov.za/AllDocs/Lega...2-01 - Notice 787 GG 35733 1 October 2012.pdf

Unless I'm missing something, Section 4 seems to answer the question.

Location of records

‘Records’ retained in an electronic form must be kept and maintained at a place physically located in South Africa.
A senior SARS official may authorise a person to keep ‘records’ in an electronic form at a location outside South Africa if the official is satisfied that—
(a) the electronic system used by the person will be accessible from the
person's physical address in South Africa for the duration of the period that the person is obliged to keep and retain 'records’;
(b) the locality where the ‘records' are proposed to be kept will not affect
access to the electronic records;
(c) there is an international tax agreement for reciprocal assistance in the administration of taxes in place between South Africa and the country in which the person proposes to keep the electronic ‘records’;
(d) the form in which the ‘records’ are maintained satisfies all the requirements of these rules apart from the issue of physical locality of the storage; and
(e) the person will be able to provide an 'acceptable electronic form’ of the
'records’ to SARS on request within a reasonable period.​

But that then begs the next question, is the physical location of Cloud storage known to the entity storing the data?
 
Top
Sign up to the MyBroadband newsletter
X