Safe Harbor Just Sank and Nobody Told the Small Sites

Safe Harbor Just Sank and Nobody Told the Small Sites

Tech News eu-data-law privacy safe-harbor side-projects

So I was catching up on RSS feeds Tuesday night (yes, I still use an RSS reader, no I will not be taking further questions on this) and saw the headline that the European Court of Justice tossed out Safe Harbor. My first reaction was "great, more EU regulatory stuff that doesn't apply to me." My second reaction, about four minutes later after actually reading past the headline, was "oh no, this might apply to me."

Quick background for anyone who wasn't following: Safe Harbor was this arrangement from 2000 that let US companies say "yep, we handle European users' data responsibly" by self-certifying with the Commerce Department, and that self-certification was enough to legally move EU citizens' personal data over to US servers. A guy named Max Schrems, an Austrian law student, sued Facebook over it back after the Snowden leaks, basically arguing that "we pinky promise to protect your data" doesn't mean much when the NSA can apparently just help itself to it anyway. The court agreed with him on October 6th and struck the whole framework down. Fifteen years of legal plumbing, gone in one ruling.

Here's why I care beyond the general principle of the thing. I run a tiny side project, a newsletter for a local hiking group, nothing fancy, maybe 340 subscribers at this point. It sits on a $5 DigitalOcean droplet in a New York data center and I use it to send out trail condition updates and the occasional "the parking lot at Bear Mountain is full again" warning. A decent chunk of those subscribers signed up through a link I posted on a German hiking forum a couple years back, because apparently German hikers found my incredibly amateur trail notes useful. So legally, right now, today, I have no real idea whether storing their email addresses on a server in New York is fine or a problem. Nobody does. That's the actual story here, not the ruling itself but the fact that it dropped like a bomb and nobody has cleaned up the wreckage yet.

Companies like Facebook and Microsoft have armies of lawyers who'll spend the next few months figuring out workarounds, probably model contract clauses or binding corporate rules, the same tools that were always technically available but that Safe Harbor let everyone ignore because self-certifying was so much cheaper. Some tiny operation like mine doesn't have that option. I don't have a lawyer. I have a Squarespace-adjacent understanding of GDPR-before-it-was-GDPR compliance and a strong desire to just keep sending trail updates without getting an angry letter from some regulator in Brussels I've never heard of.

What bugs me most isn't even the legal uncertainty, it's the timing. This ruling didn't come out of nowhere, everyone in the privacy world has known since 2013 that Safe Harbor was on shaky ground post-Snowden, and yet the transition plan from "old system" to "new system" appears to be roughly zero pages long. The court just said the old thing is invalid, effective immediately, go figure it out. That's a very European way to regulate things, I'm told, but as someone running side projects on nights and weekends it's a little maddening. I'd take a boring six-month grace period over a dramatic court decision any day of the week.

I'm not going to pretend I know what happens next. Maybe nothing happens to small operators like me because enforcement resources go toward Facebook and Google first, which honestly seems likely. Maybe some new framework gets negotiated by next year that quietly fixes all of this. Maybe I just move that droplet to a Frankfurt data center out of an abundance of caution and call it a day, which is probably the actual sane move and would cost me almost nothing extra a month. I keep meaning to just do that this weekend and keep not doing it, mostly because migrating a Postgres database over SSH on a Saturday afternoon sounds like a special kind of misery.

Anyway. If you run anything, even something small and dumb like a hiking newsletter, and you've got European signups sitting on American servers, this is worth five minutes of your attention even if the headlines made it sound like a Facebook problem. It isn't just a Facebook problem. It's everybody's problem now, we just don't all realize it yet.