European Autonomy Directives, Sovereign Cloud Mandates & Big Tech Platform Accountability

EU: URSULA VAN DER LEYEN HIGHLIGHTS EUROPEAN AUTONOMY

Speaking in Paris at the MEDEF meeting (the French enterprise chiefs), the President of the EU Commission, after having referred to Mario Draghi’s report, has insisted on six key projects. Among which: investing in key technologies and raw materials to avoid being too dependent, make sure companies can scale up while staying European thanks to the “Union of savings and investments” (does this mean Capital markets Union ?), setting up the “28th regime” for European companies, “EU Inc”, a more strategic use of public procurement and public aid.

ECA comment : we could not say better. Now let’s move from words to acts !

SOVEREIGN CLOUD: FRANCE TAKES ACTION

SecNumCloud 3.2 officially changed status a few days ago. So far, it was just a recommendation, today, after a decision by the Prime Minister, it’s a legal requirement for the State, its operators, and public interest groups. Government agencies will no longer have a choice: to host their most sensitive data in a private cloud, ANSSI – the National Cybersecurity Agency (or its European equivalent) qualification becomes essential. SecNumCloud is the equivalent of EUCS High end, the European certification for cloud services which would have included an obligation of immunity against extraterritorial jurisdictions attempting to control European data. At EU scale, such a system has finally been replaced by a “rating” of cloud services where the upper layer includes the said immunity.

DATA CENTERS REGULATION IN SPAIN

Spain wants to get a handle on the influx of data center projects in the country. To do this, the government has just put a draft royal decree up for public consultation, targeting facilities with a network access power of 1 MW or more. The goal: to favor projects that are the most responsible in terms of energy and environmental impact, as well as resilience and sovereignty. Regarding energy, a quota of sustainable energy will be mandatory, and water saving will be pushed. But the most striking is the will to give precedence to sovereign systems.

META REACHES AN AGREEMENT TO STOP LEGAL ACTION

(Tribute to ZDNet for its excellent article on this subject)

Further to the legal action launched against META and the coming trials, where the group is sued for abusing youngsters and pushing them into addictive behavior, META has finally moved back and sought an agreement.

The friendly settlement approved by the Oakland federal court ends huge legal pressure for Meta. To put an end to lawsuits over the impact of its apps on teens’ mental health, the company has agreed to pay up to $18 billion, in installments stretched out until 2035.

Previously, META tried to hide behind “self-regulation”. But the data presented during the hearings show the ineffectiveness of self-regulation measures:

Only 1.1% to 2% of minors spontaneously used the pause or screen time limit features.

Of the 51% of teenagers reporting having had a harmful experience on social media, only 0.02% of the offending content was actually removed by moderation.The algorithm guidance aimed to increase time spent on Meta’s services, targeting an average of 46 minutes per user each day.

The agreement also forces Meta to roll out operational changes within six months for all users aged 13 to 17 in the 46 U.S. states that were part of the lawsuit. To limit exposure for younger users, the text requires default reconfigurations of teen accounts:

Automatic blocking of Instagram and Facebook features from midnight to 6 a.m., except for messaging services.  

Capping total usage time at two hours per day across both apps.  

Hiding like counters and banning filters that alter users’ physical appearance.

Beyond the case of META, this case mainly marks a shift in the case law of the digital ecosystem in the United States. Historically sheltered by Section 230 of the Communications Decency Act, hosting platforms were not liable for content posted by third parties.  

But American courts are now targeting the functional design of their services, like infinite scrolling, autoplay, and targeted notifications.  Through their own UX, the responsibility of platforms is therefore directly involved, beyond the nature of the data they host.

UBER FINED AT 825 M€ LEVEL FOR LETTING ITS ALGORITHMS DECIDE THE FATE OF DRIVERS 

The AP, the Dutch equivalent of the CNIL, slapped Uber with an €825 million fine. Between 2018 and 2022, the platform allowed automated systems to suspend or deactivate drivers, especially if there were suspicions of fraud or low ratings, without real human intervention. A practice that goes against GDPR, according to the regulator.

 

Share:

More Posts