Which wouldn't matter where the data is located, so I don't think that this is the reason Fastmail is doing it, because a savvy enough company would know that the problem is that the company is US based.
Which wouldn't matter where the data is located, so I don't think that this is the reason Fastmail is doing it, because a savvy enough company would know that the problem is that the company is US based.
They're Australian
Australian companies are also subject to the USA Cloud Act. As is the UK, with Canada coming on board soon too.
Even the entire EU is in the process of negotiating the same agreement.
https://www.justice.gov/archives/opa/pr/united-states-and-ca...
https://www.justice.gov/archives/opa/pr/justice-department-a...
That is plain wrong, and on top of that, the CLOUD act doesn't really solve anything because if the order to obtain data is legal for the US arm but illegal for the EU arm, releasing the data from say Ireland to the US would immediately lead to steep monetary and legal penalties for the EU arm.
It is not wrong...
You can read the text right here:
https://www.justice.gov/criminal/criminal-oia/cloud-act-agre...
The same agreement is in place with the UK. Canada and EU are currently in the process of negotiating it.
Your linked information doesn't indicate anywhere that Australia or any other foreign government is subject to US law. The latter states that negotiation with the EU on this topic was suspended in 2019.
Things have changed. With Chinese law in regards to data within Chinese jurisdiction a long-standing thing and an unfriendly American government potentially in power for an extended period, other countries are realizing the importance of data sovereignty.
https://www.justice.gov/criminal/criminal-oia/cloud-act-agre...
> The latter states that negotiation with the EU on this topic was suspended in 2019.
Dated 2023:
> Justice Department and European Commission Announces Resumption of U.S. and EU Negotiations on Electronic Evidence in Criminal Investigations
The negotiations are still ongoing. Canada is further along than the EU.
That’s not going to help anyone.
The Five Eyes is an Anglosphere intelligence alliance comprising Australia, Canada, New Zealand, the United Kingdom, and the United States. These countries are party to the multilateral UKUSA Agreement, a treaty for joint cooperation in signals intelligence.
https://en.wikipedia.org/wiki/Five_Eyes
Even being stored in EU doesn't preclude your data from being targeted by signals intelligence. Which is different than requiring US based companies to provide non-US data to American government.
Does fastmail have a US presence? If no - then they're not bound at all by US jurisdiction.
Meanwhile, in realPolitik, they are Australian, they are subject to AU government pressure, and the AU government is deeply intertwined with and compliant to US government wishes, AUKUS, Pine Gap, Harold Holt Sub communications, Over the horizon radar on China, etc.
See: https://roncobb.net/img/cartoons/aus/k5092-on-Tucker_Box-cuu...
The question isn’t whether a service has a presence in the sense of employees or regional office, or headquarters.
The question is: do they office services to residents of said country / state.
If so they may well be subject to certain laws that, if broken, could result in penalties up to an including extradition of the responsible officers.
isn't there this five eyes thingy?