Embed this noticekaia (kaia@brotka.st)'s status on Monday, 01-Sep-2025 18:49:44 JST
kaiaIn Germany, when you have a photo for passport or ID card taken, your image gets uploaded to AWS. the photo gets submitted to German authorities with QR code they use to download from said US cloud services. this is not optional; without complying you cannot get a new passport or ID card.
@cell@kaia AWS is gdpr compliant and can store data on european servers only. data transfer between EU and US is an absolute nightmare for any company that tries to be compliant.
They're claiming to be GDPR compliant while in fact not even the European Commission believes that. The attempts to tape over this legally are a cheap way of hiding the fact, and it only "works" because everybody in power wants this to magically be compliant when actually it simply isn't.
Since US companies are bound by US law, even *if* it were to "also" be "GDPR compliant" does not mean that they don't have full access, and are harvesting the data for their (US) national purposes. I personally remember a large university project that was involved in improving bulk image scanning across AWS, in the early 2000s. See also Snowden leaks etc. They're not relying on data security, but on looking away and pretending.
@kaia Source? Sure, that's one way it can be done, and that's apparently how it is done when you go to dm. Doesn't mean that it has to be done this way.
Okay, this puts your claim into perspective. It's not as extreme ("without complying you cannot get a new passport or ID card") - there is an alternative.
Specifically: "Die Übermittlung des Lichtbilds an die Personalausweisbehörde von einem zertifizierten Lichtbildaufnahmegerät eines Dienstleisters, das unmittelbar an das Behördennetz einer Personalausweisbehörde angeschlossen ist."
This is the option I used to take my photo last time I had to get my ID in Bonn.
@kaia Furthermore, a very important detail: The image is stored *encrypted* on AWS. It can - using current technical capabilities - only be accessed using the key, which along with the URL is stored in the QR code.
So all in all, given that there usually is an acceptable alternative (on-site photo booths) that avoids cloud uploads altogether, and that images are stored encrypted on AWS servers, I see no big reason for panic here.