<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Jurisdiction &amp; Cyber-Law on ARPOKRAT</title>
    <link>https://arpokrat.com/blog/jurisdiction/</link>
    <description>Recent content in Jurisdiction &amp; Cyber-Law on ARPOKRAT</description>
    <generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Fri, 19 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://arpokrat.com/blog/jurisdiction/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Data Act vs CLOUD Act: who really controls your data in the cloud?</title>
      <link>https://arpokrat.com/blog/data-act-vs-cloud-act-digital-sovereignty/</link>
      <pubDate>Fri, 19 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/data-act-vs-cloud-act-digital-sovereignty/</guid>
      <description>&lt;p&gt;For years, the world operated on a simple assumption: data has a physical place of residence. If it was stored on a server in Dublin, it fell under Irish and European law. That assumption collapsed in 2018, when the United States enacted the CLOUD Act — a law that grants American authorities access to data controlled by US companies, regardless of where that data is physically stored in the world. Several years later, Brussels responded with its own protective framework: the Data Act, now fully applicable, which attempts to limit the extraterritorial access of third-country authorities to data held within the European Union.&lt;/p&gt;
&lt;p&gt;Here is what these two texts actually provide, where they collide, and why the only truly robust protection against this conflict remains technical impossibility of access.&lt;/p&gt;
&lt;h2 id=&#34;the-american-cloud-act-access-based-on-control-not-location&#34;&gt;The American CLOUD Act: access based on control, not location&lt;/h2&gt;
&lt;p&gt;The &lt;strong&gt;CLOUD Act&lt;/strong&gt; (&lt;em&gt;Clarifying Lawful Overseas Use of Data Act&lt;/em&gt;), enacted in March 2018, amended US law by adding &lt;strong&gt;18 U.S. Code § 2713&lt;/strong&gt;. This provision requires any provider of electronic communication services or remote computing services to preserve, back up, or disclose the contents of a communication or any record pertaining to it, whenever that data is in the provider&amp;rsquo;s possession, custody, or control, &lt;strong&gt;regardless of whether the data is located inside or outside the United States&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;It is precisely this final clause that changes everything. The criterion is no longer the physical location of the server, but the control exercised by the parent company over its subsidiaries. A US company operating data centres in Europe therefore remains subject to American legal demands, even for data stored entirely on European soil.&lt;/p&gt;
&lt;h2 id=&#34;the-european-data-act-a-legal-barrier-to-extraterritorial-access&#34;&gt;The European Data Act: a legal barrier to extraterritorial access&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Regulation (EU) 2023/2854&lt;/strong&gt;, known as the Data Act, entered into force on 11 January 2024 and has been fully applicable since 12 September 2025, with certain provisions phased in through 2026 and 2027. Its &lt;strong&gt;Article 32&lt;/strong&gt; directly addresses the question of international governmental access to data.&lt;/p&gt;
&lt;p&gt;The text establishes a clear rule: any decision or judgment of a court or administrative authority of a third country requiring a data processing service provider to transfer or give access to non-personal data held in the European Union &lt;strong&gt;is recognised and enforceable only if it is based on an international agreement&lt;/strong&gt;, such as a mutual legal assistance treaty (MLAT), in force between the requesting country and the Union, or between that country and the relevant Member State.&lt;/p&gt;
&lt;p&gt;In the absence of such an agreement, Article 32 provides a second avenue, but one that is strictly circumscribed: the foreign decision may only be enforced if the legal system of the third country requires that the request be reasoned, proportionate, and sufficiently specific — for example, by establishing a clear link to specific individuals or offences — and if the recipient&amp;rsquo;s reasoned objection can be submitted to the review of a competent court in that third country.&lt;/p&gt;
&lt;h2 id=&#34;a-direct-legal-collision&#34;&gt;A direct legal collision&lt;/h2&gt;
&lt;p&gt;The problem is immediate: the CLOUD Act requires disclosure based on the control exercised by the parent company, without a proportionality requirement comparable to that demanded by European law. The Data Act, conversely, conditions recognition of such a request on the existence of an international agreement or specific procedural safeguards. A US company operating in Europe, ordered by an American authority to hand over data hosted within the Union, thus finds itself caught between two contradictory legal obligations: comply with the American mandate and violate Union law, or respect the Data Act and face the consequences of refusal in the United States.&lt;/p&gt;
&lt;p&gt;This tension is not theoretical. It has already been documented by the Court of Justice of the European Union (CJEU) in two landmark rulings, &lt;strong&gt;Schrems I&lt;/strong&gt; (2015) and &lt;strong&gt;Schrems II&lt;/strong&gt; (2020). In the Schrems II judgment, the CJEU held that American surveillance conducted under &lt;strong&gt;Section 702 of FISA&lt;/strong&gt; (&lt;em&gt;Foreign Intelligence Surveillance Act&lt;/em&gt;) and &lt;strong&gt;Executive Order 12333&lt;/strong&gt; does not respect the minimum safeguards required by Union law under the principle of proportionality, and therefore cannot be regarded as limited to what is strictly necessary. The Court also noted the absence of an effective judicial remedy for Union data subjects, in violation of Article 47 of the Charter of Fundamental Rights. This ruling invalidated the Privacy Shield framework, which had until then governed data transfers between the EU and the United States.&lt;/p&gt;
&lt;h2 id=&#34;the-structural-risk-harvest-now-decrypt-later&#34;&gt;The structural risk: Harvest Now, Decrypt Later&lt;/h2&gt;
&lt;p&gt;Beyond the jurisdictional conflict, a more insidious threat looms over data hosted in infrastructures subject to US law: the so-called &lt;a href=&#34;https://arpokrat.com/blog/harvest-now-decrypt-later-hndl-zero-knowledge/&#34;&gt;&lt;strong&gt;Harvest Now, Decrypt Later&lt;/strong&gt;&lt;/a&gt;
 (HNDL) strategy. The principle involves an intelligence service or hostile state actor intercepting and storing encrypted data today, in anticipation of sufficient quantum computing capabilities to decrypt it in the future.&lt;/p&gt;
&lt;p&gt;This strategy transforms any prolonged dependence on American cloud infrastructure into a deferred security liability: what is confidential today may become readable in ten or fifteen years, without any further action required on the part of the attacker — only time and patience.&lt;/p&gt;
&lt;h2 id=&#34;why-only-technical-impossibility-constitutes-a-genuine-guarantee&#34;&gt;Why only technical impossibility constitutes a genuine guarantee&lt;/h2&gt;
&lt;p&gt;Legal analysis converges on a finding shared by many compliance experts: however solid the Data Act&amp;rsquo;s legal framework may be, it remains a text that geopolitical power dynamics and diplomatic pressures can circumvent, delay, or reinterpret. The only protection that depends on no future negotiation is &lt;strong&gt;technical impossibility of enforcement&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;A &lt;strong&gt;zero knowledge&lt;/strong&gt; architecture, in which the service provider never holds possession or custody of the decryption keys, renders a legal demand materially inoperable. One cannot be compelled to hand over what one never possesses.&lt;/p&gt;
&lt;p&gt;This is the logic that underpins ecosystems such as &lt;strong&gt;Arpokrat&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Jurisdictional neutralisation&lt;/strong&gt;: the infrastructure is hosted in Switzerland, under the Swiss Federal Act on Data Protection (FADP/LPD), outside the direct scope of the CLOUD Act&amp;rsquo;s extraterritoriality&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No custody&lt;/strong&gt;: the zero knowledge architecture deprives the service provider of any ability to hand over keys or content it never holds&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reduced identity footprint&lt;/strong&gt;: by eliminating the requirement to register with a phone number or email address — identifiers that FISA Section 702-based surveillance can easily track — the user ceases to be an identifiable subscriber and becomes an anonymous cryptographic key&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;the-chain-of-custody-does-not-stop-at-message-encryption&#34;&gt;The chain of custody does not stop at message encryption&lt;/h2&gt;
&lt;p&gt;A point often underestimated in compliance analyses: encrypting the content of a communication is not enough if the underlying operating system — whether Android or iOS — continues to capture metadata or kernel-level telemetry destined for servers under US jurisdiction. Protecting confidentiality requires a complete closure of the chain of custody, from content all the way down to the hardware infrastructure itself.&lt;/p&gt;
&lt;p&gt;This is why digital sovereignty also requires reflection on the operating system in use, not just on messaging applications. De-Googled systems, in which modules such as Bluetooth or GNSS geolocation can be disabled directly at the kernel level, eliminate physical attack vectors that no application-layer encryption can compensate for.&lt;/p&gt;
&lt;h2 id=&#34;post-quantum-cryptography-an-already-engaged-horizon&#34;&gt;Post-quantum cryptography: an already-engaged horizon&lt;/h2&gt;
&lt;p&gt;In the face of the threat posed by the HNDL strategy, adopting post-quantum cryptography (PQC) standards becomes a necessity for anyone wishing to guarantee the confidentiality of sensitive data over the long term — whether that involves trade secrets, professional correspondence, or health data. Encryption considered robust today under classical standards does not guarantee that it will withstand the quantum computing capabilities expected within the next fifteen years.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;The conflict between the Data Act and the CLOUD Act illustrates a broader reality: digital sovereignty can no longer be built on legislation alone, however solid that legislation may be. It requires closing the chain of custody at every level — from the encryption protocol to the hosting jurisdiction, and including the operating system itself. It is this layered approach, rather than trust placed in a single regulatory framework, that defines genuine digital sovereignty by design today.&lt;/p&gt;
</description>
    </item>
    <item>
      <title>Monero and Zcash Banned in Europe from 2027: What AMLR Changes</title>
      <link>https://arpokrat.com/blog/monero-zcash-banned-eu-amlr-2027/</link>
      <pubDate>Thu, 18 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/monero-zcash-banned-eu-amlr-2027/</guid>
      <description>&lt;p&gt;Monero and Zcash banned in Europe: it is now settled. From July 2027, the European Union will close institutional access to privacy-enhanced cryptocurrencies through a new anti-money laundering regulation called &lt;strong&gt;AMLR&lt;/strong&gt;. Here is what the text concretely provides for, the role of the new European authority &lt;strong&gt;AMLA&lt;/strong&gt; tasked with enforcing it, and what this truly means for anyone holding privacy coins.&lt;/p&gt;
&lt;h2 id=&#34;amlr-and-amla-two-different-texts-not-to-be-confused&#34;&gt;AMLR and AMLA: Two Different Texts, Not to Be Confused&lt;/h2&gt;
&lt;p&gt;Before going into detail, a clarification is in order — these two acronyms refer to two distinct things, often confused in the specialist press:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;AMLR&lt;/strong&gt; (&lt;em&gt;Anti-Money Laundering Regulation&lt;/em&gt;) is &lt;strong&gt;the law itself&lt;/strong&gt;: Regulation (EU) 2024/1624, which defines the rules — anonymous accounts prohibited, verification thresholds, treatment of privacy coins. It is the &amp;ldquo;what.&amp;rdquo;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AMLA&lt;/strong&gt; (&lt;em&gt;Anti-Money Laundering Authority&lt;/em&gt;) is &lt;strong&gt;the new European supervisory authority&lt;/strong&gt;, created by a separate regulation adopted on the same day, Regulation (EU) 2024/1620. Its role is to directly supervise the application of the AMLR, particularly with respect to the largest crypto-asset service providers (CASPs) operating across multiple Member States. It is the &amp;ldquo;who enforces it.&amp;rdquo;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In short: AMLR sets the rules, AMLA ensures they are followed. Both texts form a single European legislative package against money laundering and the financing of terrorism.&lt;/p&gt;
&lt;h2 id=&#34;what-the-amlr-regulation-actually-says&#34;&gt;What the AMLR Regulation Actually Says&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Regulation (EU) 2024/1624&lt;/strong&gt; was adopted by the European Parliament and the Council on 31 May 2024, then published in the Official Journal of the European Union on 19 June 2024. Its &lt;strong&gt;Chapter VIII (Articles 79–80)&lt;/strong&gt;, entitled &lt;em&gt;&amp;ldquo;Measures to mitigate risks associated with anonymous instruments&amp;rdquo;&lt;/em&gt;, and more specifically its &lt;strong&gt;Article 79&lt;/strong&gt; (&amp;ldquo;Anonymous accounts, bearer shares and bearer warrants&amp;rdquo;), establishes that credit institutions, financial institutions, and &lt;strong&gt;crypto-asset service providers (CASPs)&lt;/strong&gt; are now prohibited from maintaining anonymous accounts or offering products that enable the anonymisation of transactions.&lt;/p&gt;
&lt;p&gt;The text explicitly targets two distinct but related categories:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Anonymous accounts&lt;/strong&gt; — whether banking, payment, or crypto. The rule aligns the crypto sector with restrictions that already existed for anonymous bank accounts, bearer securities accounts, and anonymous safe-deposit boxes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;ldquo;Anonymity-enhancing coins&amp;rdquo;&lt;/strong&gt; — the generic term used by the regulation to refer to assets that use advanced cryptographic techniques making transaction flows untraceable. &lt;strong&gt;Important clarification&lt;/strong&gt;: the legal text does not name any token by name. It is the widely shared interpretation of compliance firms and the industry — notably the &lt;em&gt;AML Handbook&lt;/em&gt; published by the European Crypto Initiative (EUCI) — that identifies Monero (XMR), Zcash (ZEC), and Dash (DASH) as falling within this category. This is a reading consistent with the regulation&amp;rsquo;s definition, but it is a sectoral interpretation, not a nominative list written into the law.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The regulation is part of a broader framework, alongside &lt;strong&gt;MiCA&lt;/strong&gt; (&lt;em&gt;Markets in Crypto-Assets&lt;/em&gt;), already in force since 2024–2025 and which has already led many platforms (Kraken as early as October 2024, followed by dozens of others) to delist Monero from their European markets in anticipation.&lt;/p&gt;
&lt;h2 id=&#34;the-key-date-july-2027&#34;&gt;The Key Date: July 2027&lt;/h2&gt;
&lt;p&gt;The AMLR has a firm application date. The majority of specialist sources, including French-language ones, converge on &lt;strong&gt;10 July 2027&lt;/strong&gt; as the deadline for full application. From that date, crypto-asset exchanges and custodial services will no longer be able to deal with either anonymous accounts or privacy coins.&lt;/p&gt;
&lt;p&gt;Before that deadline, the regulation already imposes enhanced obligations:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Mandatory identity verification&lt;/strong&gt; for any occasional crypto transaction exceeding 1,000 euros — a threshold significantly lower than the current practices of many platforms&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enhanced controls&lt;/strong&gt; on self-hosted wallets (&lt;em&gt;self-custody&lt;/em&gt;): when a user transfers funds between a regulated platform and a personal wallet, the CASP will be required to collect information on the origin and destination of the funds, and at minimum verify the identity of the holder of the external wallet&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Elimination of anonymous cash payments&lt;/strong&gt; above 3,000 euros, following the same logic of extending identity controls to all anonymous financial instruments&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;why-brussels-is-banning-monero-and-zcash-on-regulated-platforms&#34;&gt;Why Brussels Is Banning Monero and Zcash on Regulated Platforms&lt;/h2&gt;
&lt;p&gt;In its &lt;em&gt;AML Handbook&lt;/em&gt;, the EUCI summarises the logic underpinning the text: the anonymity of crypto-assets presents significant risks of misuse for criminal purposes, by preventing transaction traceability and complicating the detection of suspicious activity.&lt;/p&gt;
&lt;p&gt;This is precisely the same reasoning that has already led Japan, South Korea, and &lt;a href=&#34;https://arpokrat.com/blog/philippines-bans-privacy-coins-monero-zcash/&#34;&gt;more recently the Philippines&lt;/a&gt;
 to exclude privacy coins from their regulated platforms — a progressive alignment of developed jurisdictions with FATF (Financial Action Task Force) standards. By formalising this prohibition in a regulation directly applicable across all 27 Member States, the European Union gives this trend a legal weight and a pull effect (the &amp;ldquo;Brussels Effect&amp;rdquo;) considerably greater than that of isolated national decisions.&lt;/p&gt;
&lt;h2 id=&#34;what-is-not-prohibited--the-nuance-that-matters&#34;&gt;What Is NOT Prohibited — The Nuance That Matters&lt;/h2&gt;
&lt;p&gt;Several legal analyses converge on a central point: &lt;strong&gt;the AMLR does not criminalise individual ownership of privacy coins, nor peer-to-peer transfers outside regulated platforms.&lt;/strong&gt; Self-hosted wallets are not prohibited as such — they are subject to enhanced controls only when they interact with a platform subject to regulation.&lt;/p&gt;
&lt;p&gt;What the AMLR closes off are the &lt;strong&gt;institutional on-ramps&lt;/strong&gt;: the purchase, sale, deposit, and withdrawal of privacy coins through a regulated CASP within the European Union. Private ownership and decentralised exchanges remain, at this stage, outside the direct scope of the prohibition — a pattern identical to that already observed in the Philippines.&lt;/p&gt;
&lt;h2 id=&#34;what-this-concretely-means-for-xmr-and-zec-holders&#34;&gt;What This Concretely Means for XMR and ZEC Holders&lt;/h2&gt;
&lt;p&gt;If you currently hold privacy coins on a regulated exchange within the European Union:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;By July 2027&lt;/strong&gt;, these platforms will have had to remove support for these assets or ceased accepting new deposits related to them&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Transfers to personal wallets&lt;/strong&gt; from those same platforms will be subject to enhanced identity verification, even before the final deadline&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Any crypto transaction above 1,000 euros&lt;/strong&gt;, privacy coin or not, will require full identification&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Critics of the text, even within the crypto industry itself, point to a structural risk: by closing off regulated circuits without technically prohibiting the assets themselves, the regulation mechanically pushes privacy coin holders toward less transparent markets and unregulated platforms — the exact opposite of the traceability objective Brussels has declared.&lt;/p&gt;
&lt;h2 id=&#34;getting-organised-before-the-2027-deadline&#34;&gt;Getting Organised Before the 2027 Deadline&lt;/h2&gt;
&lt;p&gt;With a horizon set at 2027, the transition is not immediate — but it is already underway. Platforms are already adjusting their offerings in anticipation of compliance, and the window to exchange or consolidate privacy coin positions without depending on infrastructure subject to this jurisdiction narrows every month.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://arpokrat.com/swap&#34;&gt;Arpokrat Swap&lt;/a&gt;
 allows you to exchange Monero, Zcash, and all privacy-enhanced cryptocurrencies with no sign-up, no collection of identity data, and no dependency on a regulated CASP subject to the AMLR. The platform is accessible on the clearnet as well as via our .onion address, ensuring that your ability to exchange these assets does not depend on any jurisdiction that might close its on-ramps overnight.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;The AMLR confirms a trajectory that is now beyond doubt: regulated crypto markets and financial privacy are becoming, jurisdiction by jurisdiction, structurally incompatible. The question is no longer whether this trend will extend across all developed economies, but how much time will remain, after 2027, to exchange private assets outside circuits that will no longer have the right to touch them.&lt;/p&gt;
</description>
    </item>
    <item>
      <title>The Philippines Bans Monero and Zcash on Regulated Platforms: The Signal of a Global Trend</title>
      <link>https://arpokrat.com/blog/philippines-bans-privacy-coins-monero-zcash/</link>
      <pubDate>Wed, 17 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/philippines-bans-privacy-coins-monero-zcash/</guid>
      <description>&lt;p&gt;The central bank of the Philippines has just dealt a severe blow to privacy-enhanced cryptocurrencies. Under the guise of compliance with international anti-money laundering standards, the decision illustrates a regulatory dynamic that extends well beyond this single country — and should alert anyone who holds or uses assets like Monero or Zcash.&lt;/p&gt;
&lt;h2 id=&#34;what-the-memorandum-says&#34;&gt;What the Memorandum Says&lt;/h2&gt;
&lt;p&gt;The &lt;strong&gt;Bangko Sentral ng Pilipinas&lt;/strong&gt; (BSP), the country&amp;rsquo;s central bank, has approved &lt;strong&gt;Memorandum M-2026-023&lt;/strong&gt;, signed by Deputy Governor Lyn Javier. The text orders all licensed virtual asset service providers (VASPs) to stop listing and supporting &amp;ldquo;anonymity-enhancing virtual assets.&amp;rdquo; The memorandum does not name any token specifically, but the targeted category unambiguously covers Monero, Zcash, and Dash — cryptocurrencies designed to make transaction tracing difficult or impossible.&lt;/p&gt;
&lt;p&gt;The measure took effect &lt;strong&gt;immediately&lt;/strong&gt;, with no transition period. Beyond simply delisting these assets from platforms, VASPs must now evaluate each listed token against six compliance pillars: issuer credibility, market maturity, use case, transparency and security, liquidity and reserves, and legal compliance. They must also define internal thresholds that automatically trigger a delisting when an asset no longer satisfies these criteria.&lt;/p&gt;
&lt;h2 id=&#34;what-this-concretely-changes&#34;&gt;What This Concretely Changes&lt;/h2&gt;
&lt;p&gt;The memorandum does not criminalize the private holding of Monero or Zcash, nor peer-to-peer transfers conducted outside regulated platforms. What disappears is institutional access: regulated on- and off-ramps (buying, selling, depositing, withdrawing on a licensed platform) will no longer be able to handle these assets.&lt;/p&gt;
&lt;p&gt;In practical terms, if you held privacy coins on a Philippine platform subject to a BSP license — including Coins.ph/Betur, Maya Philippines, PDAX, GoTyme Bank, or UnionBank — you must transfer them to a personal wallet or convert them before the platform is forced to delist them.&lt;/p&gt;
&lt;p&gt;With over 16 million cryptocurrency users in the country, the impact will be felt on a large scale in the domestic market, even if the effect on the global price of XMR or ZEC should remain limited — the Philippines representing only a marginal fraction of the global liquidity of these assets.&lt;/p&gt;
&lt;h2 id=&#34;fatf-alignment-the-universal-justification&#34;&gt;FATF Alignment, the Universal Justification&lt;/h2&gt;
&lt;p&gt;The BSP justifies its decision through explicit alignment with the standards of the &lt;strong&gt;FATF (Financial Action Task Force)&lt;/strong&gt;, the international body that sets the rules for combating money laundering and terrorist financing. Staying on good terms with the FATF is not optional for most central banks — a poor rating can affect an entire country&amp;rsquo;s access to international financial circuits.&lt;/p&gt;
&lt;p&gt;This is exactly the same justification that has already led the European Union, Japan, and South Korea to progressively exclude privacy coins from their regulated platforms over recent years. The Philippine decision is therefore not an isolated case: it is the confirmation of a de facto standard that is becoming widespread — if a jurisdiction wants to operate an internationally recognized crypto market, privacy-enhanced assets no longer have a place in it.&lt;/p&gt;
&lt;h2 id=&#34;a-tension-that-nobody-truly-resolves&#34;&gt;A Tension That Nobody Truly Resolves&lt;/h2&gt;
&lt;p&gt;It is telling that even actors who support the decision acknowledge the legitimacy of the use case it seeks to restrict. The crypto head at GCash, one of the country&amp;rsquo;s largest fintechs, explicitly acknowledged that Monero and Zcash &amp;ldquo;exist for legitimate reasons&amp;rdquo; and that privacy constitutes &amp;ldquo;a founding value of crypto: the ability to transact without surveillance.&amp;rdquo; He nonetheless supported the measure, arguing that the Philippines — a country heavily dependent on remittance flows — could not position itself as a trusted financial infrastructure while allowing the free circulation of anonymizing assets.&lt;/p&gt;
&lt;p&gt;This tension is not resolved; it is simply decided in favor of the regulatory perspective: remittance volumes and international credibility weigh heavier than the legitimate privacy argument, every time the trade-off arises.&lt;/p&gt;
&lt;h2 id=&#34;the-logical-next-step-migration-toward-self-custody&#34;&gt;The Logical Next Step: Migration Toward Self-Custody&lt;/h2&gt;
&lt;p&gt;The pattern repeating itself from one jurisdiction to another is now clearly readable. The pattern is almost always identical: financial privacy remains legal at the individual level, but gradually becomes impossible to exercise through institutional channels. Self-custody is not yet targeted — but each new jurisdiction that follows this model further reduces the space in which these assets can circulate without regulatory lock-in.&lt;/p&gt;
&lt;p&gt;We detailed in depth the technical workings of these blockchains and the reasons why they have become a prime target for regulators in our &lt;a href=&#34;https://arpokrat.com/blog/anonymous-blockchains-privacy-coins-explained/&#34;&gt;comprehensive guide on anonymous blockchains&lt;/a&gt;
 — ring signatures, zk-SNARKs, and the real limitations of these technologies.&lt;/p&gt;
&lt;h2 id=&#34;exchanging-outside-the-closing-circuits&#34;&gt;Exchanging Outside the Closing Circuits&lt;/h2&gt;
&lt;p&gt;As regulated platforms withdraw from the privacy coin market one after another, the role of non-custodial, data-collection-free infrastructure becomes central for anyone wishing to continue using these assets without depending on a VASP subject to a jurisdiction that could change its policy overnight.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://arpokrat.com/swap&#34;&gt;Arpokrat Swap&lt;/a&gt;
 allows you to exchange Monero, Zcash, and all privacy-enhanced cryptocurrencies without registration, without IP log collection, and without cookies — whether you access the platform via clearnet or through our .onion address. No jurisdiction can remove what we never collect.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;This Philippine decision is probably not the last of its kind this year. The question is no longer whether other countries will follow the same path — recent history suggests they will — but how much time remains before institutional access to privacy coins becomes the exception rather than the norm.&lt;/p&gt;
</description>
    </item>
    <item>
      <title>The End of Privacy? Backdoors, the Online Safety Act, and the Response of Sovereign Ecosystems</title>
      <link>https://arpokrat.com/blog/ipa-osa-backdoors/</link>
      <pubDate>Wed, 10 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/ipa-osa-backdoors/</guid>
      <description>&lt;p&gt;London has become the epicenter of a global battle for the future of digital privacy. With the adoption of the &lt;em&gt;Online Safety Act&lt;/em&gt; 2023 (OSA) and recent proposals to revise the &lt;em&gt;Investigatory Powers Act&lt;/em&gt; (IPA) — dubbed the &amp;ldquo;Snoopers&amp;rsquo; Charter&amp;rdquo; by its critics —, the British government is claiming the right to impose surveillance obligations at the very heart of private communications. The breaking point is the power granted to the regulator OFCOM to require platforms to deploy &amp;ldquo;accredited technology&amp;rdquo; to detect child sexual exploitation and abuse (CSEA) material or terrorism, including within &lt;a href=&#34;https://arpokrat.com/messenger&#34;&gt;end-to-end encrypted communications&lt;/a&gt;
.&lt;/p&gt;
&lt;p&gt;For major digital platforms, Westminster&amp;rsquo;s message is unambiguous: either they facilitate state access to their infrastructures, or they face fines of up to 10% of their global revenue. The response was immediate: services like Signal and WhatsApp publicly threatened to withdraw from the UK market, refusing to compromise the security of their users to satisfy a single jurisdiction. The technical argument is hard to dispute: there is no master key reserved solely for legitimate actors. An open door for law enforcement is, by design, an open door for cybercriminals and foreign intelligence services.&lt;/p&gt;
&lt;h2 id=&#34;the-business-model-of-major-platforms-a-structural-obstacle-to-zero-knowledge&#34;&gt;The business model of major platforms: a structural obstacle to Zero-Knowledge&lt;/h2&gt;
&lt;p&gt;The resistance of major platforms to adopting Zero-Knowledge encryption is not explained by technical inability, but by a fundamental economic incompatibility. Companies like Alphabet and Meta rely on monetization models based on the systematic collection of behavioral data. This model is, incidentally, implicitly recognized by the European Union&amp;rsquo;s Digital Markets Act (DMA), which classifies these &amp;ldquo;gatekeepers&amp;rdquo; as entities whose dominant position is precisely fueled by the accumulation of data on an unparalleled scale. For these actors, adopting a Zero-Knowledge architecture would mean depriving their advertising systems of the continuous identification of users that constitutes its fuel. It is therefore not a technical choice, but a trade-off between user privacy and the viability of their business model.&lt;/p&gt;
&lt;h2 id=&#34;the-strategic-risk-the-harvest-now-decrypt-later-threat&#34;&gt;The strategic risk: the &amp;ldquo;Harvest Now, Decrypt Later&amp;rdquo; threat&lt;/h2&gt;
&lt;p&gt;Beyond the debate on privacy, the weakening of encryption raises a national security issue of a completely different scope. The strategy known as &lt;a href=&#34;https://arpokrat.com/blog/harvest-now-decrypt-later-hndl-zero-knowledge/&#34;&gt;&lt;em&gt;Harvest Now, Decrypt Later&lt;/em&gt; (HNDL)&lt;/a&gt;
 involves state adversaries intercepting and storing massive volumes of encrypted communications today, in anticipation of future quantum decryption capabilities. By weakening current encryption standards, the British legislative framework objectively facilitates this type of operations against government, diplomatic, or industrial communications.&lt;/p&gt;
&lt;p&gt;It is precisely in this context of a trust deficit that ecosystems like Arpokrat&amp;rsquo;s acquire operational relevance. By operating under the regime of the Swiss Federal Act on Data Protection (FADP), with an architecture that collects no civil identifiers, Arpokrat offers a technical break from infrastructures subject to British jurisdiction — guaranteeing that the system remains deaf to the injunctions foreseen by the OSA.&lt;/p&gt;
&lt;h2 id=&#34;the-conflict-of-norms-osa-and-ipa-against-european-law&#34;&gt;The conflict of norms: OSA and IPA against European law&lt;/h2&gt;
&lt;p&gt;The legal analysis of the new British state prerogatives reveals a direct collision with the foundations of European law regarding data protection and the confidentiality of communications.&lt;/p&gt;
&lt;h3 id=&#34;osa-against-the-prohibition-of-generalized-surveillance&#34;&gt;OSA against the prohibition of generalized surveillance&lt;/h3&gt;
&lt;p&gt;Article 121 of the OSA introduces the possibility for OFCOM to issue notices forcing platforms to implement client-side scanning. This measure directly contravenes the principle, derived from European law and included in the jurisprudence of the CJEU, prohibiting general surveillance obligations. By imposing a &amp;ldquo;vulnerability by design&amp;rdquo;, it also places companies in a double bind situation: by weakening their security to comply with a state mandate, they fail in their obligation to guarantee a level of security appropriate to the processing, as enshrined in Article 32 of the GDPR.&lt;/p&gt;
&lt;h3 id=&#34;the-eprivacy-directive-and-the-confidentiality-of-communications&#34;&gt;The ePrivacy Directive and the confidentiality of communications&lt;/h3&gt;
&lt;p&gt;The scanning of private messages is in direct contradiction with Article 5, paragraph 1, of Directive 2002/58/EC (&lt;em&gt;ePrivacy&lt;/em&gt;), which obliges Member States to guarantee the confidentiality of electronic communications and prohibits any form of interception or surveillance without the explicit consent of the users concerned.&lt;/p&gt;
&lt;h3 id=&#34;technical-capability-notices-and-blocking-security-updates&#34;&gt;&lt;em&gt;Technical Capability Notices&lt;/em&gt; and blocking security updates&lt;/h3&gt;
&lt;p&gt;Under the IPA 2016 regime, the British government now intends to use &lt;em&gt;Technical Capability Notices&lt;/em&gt; (TCN) to block security updates before they are deployed. This mechanism creates an unsolvable conflict with the obligation, set by Article 32 of the GDPR, to ensure the continuous security of processing systems — an obligation that precisely requires the ability to apply patches without delay or external interference.&lt;/p&gt;
&lt;h2 id=&#34;compliance-risks-for-companies-operating-in-europe&#34;&gt;Compliance risks for companies operating in Europe&lt;/h2&gt;
&lt;p&gt;The revisions to the IPA aim to force companies to notify the British government of any technical modification affecting security, prior to its implementation, thereby granting it a veto right over product development. This interference creates considerable legal insecurity for suppliers operating in the European market: British adequacy to European law — already fragile — could be called into question if the UK no longer guarantees protection substantially equivalent to that of the GDPR. Data transfers to the UK under this new framework would therefore likely expose companies to sanctions under the GDPR.&lt;/p&gt;
&lt;h2 id=&#34;defense-through-technical-impossibility-the-zero-knowledge-principle-as-a-legal-shield&#34;&gt;Defense through technical impossibility: the Zero-Knowledge principle as a legal shield&lt;/h2&gt;
&lt;p&gt;International jurisprudence, consolidated by the &lt;em&gt;Schrems I&lt;/em&gt; and &lt;em&gt;Schrems II&lt;/em&gt; rulings of the CJEU, has established a defining principle: the only robust safeguard against disproportionate surveillance is the technical impossibility of accessing it. Zero-Knowledge architectures apply this principle in three layers of protection:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Absence of custody:&lt;/strong&gt; since the platform does not hold the decryption keys, any injunction to scan messages is technically inoperative;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Sovereignty of the operating system:&lt;/strong&gt; the control of &lt;a href=&#34;https://arpokrat.com/os&#34;&gt;ArpokratOS&lt;/a&gt;
 eliminates telemetry that feeds intelligence collection at the device level;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Swiss jurisdictional anchoring:&lt;/strong&gt; by hosting its infrastructure in Switzerland, Arpokrat operates under a legal regime requiring individualized and reasoned mutual legal assistance requests, neutralizing the automated execution of mass scans foreseen by the OSA.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;The provisions of the OSA and the revisions of the IPA are not only a threat to the privacy of individuals: they represent a breach of legal certainty for all European data passing through infrastructures subject to British jurisdiction. By legitimizing the weakening of encryption in the name of public safety, London paradoxically exposes its allies and trading partners to risks of industrial and state espionage that Zero-Knowledge architectures are precisely designed to prevent.&lt;/p&gt;
&lt;p&gt;The integrity of professional and institutional communications now requires a structural response: the migration towards decentralized ecosystems guaranteeing digital sovereignty, from the code level up to the jurisdictional anchoring.&lt;/p&gt;
</description>
    </item>
    <item>
      <title>The Shouting Silence: What is a Warrant Canary and Why Its Disappearance Should Worry You</title>
      <link>https://arpokrat.com/blog/canary-warrant-explained/</link>
      <pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/canary-warrant-explained/</guid>
      <description>&lt;p&gt;Deep in the coal mines of the 19th century, miners carried caged canaries with them. These small birds, extremely sensitive to toxic gases like carbon monoxide, succumbed long before the miners perceived the danger. They served as a silent, but highly effective early warning system.&lt;/p&gt;
&lt;p&gt;In our modern digital world, this bird has come back to life in the form of the &lt;strong&gt;&amp;ldquo;Warrant Canary&amp;rdquo;&lt;/strong&gt;.&lt;/p&gt;
&lt;h2 id=&#34;what-is-a-warrant-canary&#34;&gt;What is a Warrant Canary?&lt;/h2&gt;
&lt;p&gt;It is a public statement, published and updated regularly by a service provider (messaging app, VPN, host), stating that, up to that exact date, it has not received any secret legal request forcing it to compromise its users&amp;rsquo; data — such as an American &lt;em&gt;National Security Letter (NSL)&lt;/em&gt; or an order issued by a FISA court.&lt;/p&gt;
&lt;p&gt;The subtlety — and the gravity — of the canary lies in what happens when it disappears.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;If a service that displayed the statement &lt;em&gt;&amp;ldquo;We have received no secret orders&amp;rdquo;&lt;/em&gt; every month suddenly stops updating it, the informed user deduces the obvious: &lt;strong&gt;the canary is dead&lt;/strong&gt;.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The company has been targeted by a surveillance measure accompanied by a &lt;strong&gt;gag order&lt;/strong&gt;, legally forbidding it from revealing the existence of this request. Unable to say that they have been compromised, they simply stop saying that they haven&amp;rsquo;t been.&lt;/p&gt;
&lt;h2 id=&#34;the-era-of-invisible-surveillance-and-bypassing-silence&#34;&gt;The Era of Invisible Surveillance and Bypassing Silence&lt;/h2&gt;
&lt;p&gt;At a time when extraterritorial legislations like the &lt;strong&gt;CLOUD Act&lt;/strong&gt; and &lt;strong&gt;FISA&lt;/strong&gt; (Foreign Intelligence Surveillance Act) allow the U.S. government to access data hosted by companies without ever informing the targets, the Warrant Canary constitutes one of the few mechanisms to bypass this forced silence.&lt;/p&gt;
&lt;p&gt;With the CLOUD Act, the geographical barrier no longer exists: if data is under the &amp;ldquo;control&amp;rdquo; of an American company, the United States government claims the right to access it, even if these servers are physically located in Europe. The canary then becomes the last warning signal before a user&amp;rsquo;s digital sovereignty is silently sacrificed.&lt;/p&gt;
&lt;p&gt;This is why major actors in the &lt;em&gt;Privacy&lt;/em&gt; sphere have adopted this tool as a standard of transparency:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://proton.me/legal/transparency&#34;&gt;Proton&lt;/a&gt;
&lt;/strong&gt;: The Swiss messaging and email service publishes a transparency report including a strict Warrant Canary.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://riseup.net/en/canary&#34;&gt;Riseup&lt;/a&gt;
&lt;/strong&gt;: The secure communication collective for activists maintains one of the most famous and monitored canaries on the web.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://arpokrat.com/canary&#34;&gt;Arpokrat&lt;/a&gt;
&lt;/strong&gt;: Our own ecosystem maintains a public Warrant Canary, cryptographically updated, to guarantee absolute transparency to our community.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;legal-analysis-the-right-not-to-lie&#34;&gt;Legal Analysis: The Right Not to Lie&lt;/h2&gt;
&lt;p&gt;The very existence of the Warrant Canary rests on one of the most fascinating pillars of constitutional law: the doctrine of &lt;em&gt;compelled speech&lt;/em&gt; and its collision with judicial secrecy.&lt;/p&gt;
&lt;p&gt;The legal basis rests on a simple principle: &lt;strong&gt;if the State has the power to impose silence on you (via a gag order), it does not have the constitutional power to force you to lie.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Under the First Amendment of the United States Constitution (and analogous principles in Europe), the government cannot force a company to produce a factually false statement. Thus, when a company removes its canary, it does not violate the silence order — since it does not explicitly announce having received a warrant. It simply exercises its fundamental right to stop making a statement that is no longer true.&lt;/p&gt;
&lt;h3 id=&#34;the-conflict-with-european-law&#34;&gt;The Conflict with European Law&lt;/h3&gt;
&lt;p&gt;The relevance of the canary is today reinforced by &lt;strong&gt;Article 32 of the Data Act (EU Regulation 2023/2854)&lt;/strong&gt;. This provision requires providers to implement technical and legal measures to prevent data access by authorities of third countries when this contradicts European law. The death of a canary immediately signals this conflict of laws: the provider is likely being forced to bypass European guarantees to satisfy a foreign mandate.&lt;/p&gt;
&lt;h2 id=&#34;the-arpokrat-approach-sovereignty-by-design&#34;&gt;The Arpokrat Approach: Sovereignty by Design&lt;/h2&gt;
&lt;p&gt;In the &lt;strong&gt;Arpokrat&lt;/strong&gt; ecosystem, operating under the jurisdiction of the Swiss FADP (Federal Act on Data Protection - RS 235.1), the canary takes on an even more powerful dimension. It is part of a holistic approach to digital sovereignty: &lt;em&gt;Zero-Knowledge&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;The architecture is designed in such a way that the company creates a &lt;strong&gt;technical and mathematical impossibility&lt;/strong&gt; to obey a mandate. The State or an intelligence agency can issue all the orders it wants, the answer will remain the same: there are no private keys, no identities (Zero-ID), and no centralized metadata to hand over.&lt;/p&gt;
&lt;p&gt;In this context, the canary is no longer just a warning of compromise; it is the continuous public proof that the infrastructure has remained technically inviolable and faithful to its principles.&lt;/p&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;Ultimately, the Warrant Canary is the piece of &lt;strong&gt;legal agility&lt;/strong&gt; that complements the cryptographic agility necessary to face the horizon of modern threats (such as post-quantum computing). In an infrastructure where data is sovereign by design, the canary is not just a simple bird in a mine: it is the silent guardian of your digital fortress.&lt;/p&gt;
</description>
    </item>
    <item>
      <title>Utiq: The new telecom &#39;Super-Cookie&#39; threatening your privacy</title>
      <link>https://arpokrat.com/blog/utiq-supercookie-telecom-privacy/</link>
      <pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/utiq-supercookie-telecom-privacy/</guid>
      <description>&lt;p&gt;The scheduled end of third-party cookies on web browsers has triggered a true arms race in the targeted advertising industry. While Google is trying to impose its own standards (like the Privacy Sandbox), another unexpected player has decided to grab a piece of the pie: &lt;strong&gt;your Internet Service Provider (ISP)&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Thus was born &lt;strong&gt;Utiq&lt;/strong&gt; (formerly known as project &lt;em&gt;TrustPid&lt;/em&gt;), a joint venture founded by European telecommunications giants. Sold to the general public as a &amp;ldquo;transparent and respectful&amp;rdquo; solution, Utiq is actually what cybersecurity experts fear most: a &amp;ldquo;supercookie&amp;rdquo; operating at the network level.&lt;/p&gt;
&lt;h2 id=&#34;what-is-utiq-and-how-does-it-work&#34;&gt;What is Utiq and how does it work?&lt;/h2&gt;
&lt;p&gt;Traditionally, advertising tracking (cookies) is managed by your web browser (&lt;a href=&#34;https://www.google.com/chrome/&#34;&gt;Chrome&lt;/a&gt;
, &lt;a href=&#34;https://www.mozilla.org/firefox/&#34;&gt;Firefox&lt;/a&gt;
, &lt;a href=&#34;https://www.apple.com/safari/&#34;&gt;Safari&lt;/a&gt;
). You could block it using extensions (like &lt;a href=&#34;https://ublockorigin.com/&#34;&gt;uBlock Origin&lt;/a&gt;
) or a privacy-oriented browser (like &lt;a href=&#34;https://brave.com/&#34;&gt;Brave&lt;/a&gt;
).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Utiq shifts the problem one step back: to the level of your network connection.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Here is how the trap springs:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Network interception:&lt;/strong&gt; When you browse the internet via your mobile connection (4G/5G) or your fiber box, Utiq uses your IP address and your telecom subscription data to identify you.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Consent (the false choice):&lt;/strong&gt; Upon arriving at a partner site, a pop-up window asks you to accept Utiq. Due to the fatigue associated with cookie banners (&lt;em&gt;Consent Fatigue&lt;/em&gt;), millions of users click &amp;ldquo;Accept&amp;rdquo; without reading.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The &amp;ldquo;Network Signal&amp;rdquo;:&lt;/strong&gt; Once consent is given, Utiq directly contacts your telecom operator. The latter generates a unique, pseudonymized identification token (the network signal) which it transmits to advertisers.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;You are now trackable from site to site, not by a file stored on your computer, but by &lt;strong&gt;the very infrastructure that provides you with the internet&lt;/strong&gt;.&lt;/p&gt;
&lt;h2 id=&#34;why-utiq-is-a-privacy-nightmare-opsec&#34;&gt;Why Utiq is a privacy nightmare (OPSEC)&lt;/h2&gt;
&lt;p&gt;The initiative raises serious problems for digital sovereignty and the confidentiality of your data:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Tracking at the source:&lt;/strong&gt; Unlike classic cookies, you cannot simply &amp;ldquo;clear your history&amp;rdquo; or &amp;ldquo;empty your cache&amp;rdquo; to get rid of Utiq. The identification token is generated by your ISP.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The centralization of profiles:&lt;/strong&gt; Telecom operators already know your name, physical address, banking details, and location in real-time. By linking your web browsing history via Utiq to this, they create behavioral profiling of daunting precision.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The flaw of pseudonymization:&lt;/strong&gt; Utiq defends itself by not sharing your name in plain text, claiming to use &amp;ldquo;encrypted&amp;rdquo; tokens. However, in the cybersecurity world, it is proven that pseudonymization is reversible. Cross-referencing these tokens with other databases allows individuals to be easily re-identified.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;which-operators-use-utiq&#34;&gt;Which operators use Utiq?&lt;/h2&gt;
&lt;p&gt;Utiq was founded by an alliance of the four largest European operators. If you are a customer of one of them (or one of their low-cost subsidiaries), your connection is potentially already &amp;ldquo;compatible&amp;rdquo; with this tracking.&lt;/p&gt;
&lt;p&gt;Here are the founders and links to their respective privacy policies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://www.orange.fr/portail/politique-de-confidentialite&#34;&gt;Orange&lt;/a&gt;
&lt;/strong&gt; (France, Spain, Poland, etc.)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://www.vodafone.com/privacy-center&#34;&gt;Vodafone&lt;/a&gt;
&lt;/strong&gt; (Germany, Spain, UK, etc.)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://www.telefonica.com/en/privacy-policy/&#34;&gt;Telefónica / O2 / Movistar&lt;/a&gt;
&lt;/strong&gt; (Spain, Germany, etc.)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://www.telekom.com/en/company/data-privacy-and-security&#34;&gt;Deutsche Telekom&lt;/a&gt;
&lt;/strong&gt; (Germany, Central Europe)&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The OPSEC tip:&lt;/strong&gt; Although Utiq offers a centralized consent management portal (&lt;a href=&#34;https://consenthub.utiq.com/&#34;&gt;consenthub.utiq.com&lt;/a&gt;
) to revoke access, the best defense remains technological.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&#34;the-zero-trust-approach-to-counter-utiq&#34;&gt;The Zero-Trust approach to counter Utiq&lt;/h2&gt;
&lt;p&gt;The philosophy of digital sovereignty, driven by ecosystems like &lt;strong&gt;Arpokrat&lt;/strong&gt;, relies on a simple principle: never trust the network infrastructure.&lt;/p&gt;
&lt;p&gt;To technically neutralize systems like Utiq, the solution is to hide your traffic from your own internet service provider:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Using a sovereign VPN:&lt;/strong&gt; By encrypting your traffic as soon as it leaves your device, your ISP only sees an unreadable stream of data directed towards a VPN server. It can no longer inject or read Utiq tokens.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The Tor network (&lt;a href=&#34;https://orbot.app/&#34;&gt;Orbot&lt;/a&gt;
):&lt;/strong&gt; Onion routing prevents any end-to-end identification.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;DNS Encryption (DoH/DoT):&lt;/strong&gt; Prevents your operator from knowing which websites you request to visit.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;In summary, Utiq is proof that internet service providers are no longer content with being mere &amp;ldquo;pipes&amp;rdquo;; they want to become data brokers. More than ever, encrypting your traffic is no longer a security option, but an absolute necessity to preserve your digital silence.&lt;/p&gt;
</description>
    </item>
    <item>
      <title>The Illusion of Sovereignty: The Olvid Case and the CLOUD Act Trap</title>
      <link>https://arpokrat.com/blog/illusion-of-sovereignty-cloud-act-fisa/</link>
      <pubDate>Thu, 21 May 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/illusion-of-sovereignty-cloud-act-fisa/</guid>
      <description>&lt;p&gt;The announcement sounded like a true &amp;ldquo;cry of independence&amp;rdquo; in the corridors of Paris: the Prime Minister ordered the government to abandon WhatsApp and Signal in favor of Olvid, a messaging app presented as &amp;ldquo;native.&amp;rdquo; The stated goal was clear: protect state secrets from the long reach of foreign intelligence agencies.&lt;/p&gt;
&lt;p&gt;However, a bitter irony quickly emerged: Olvid&amp;rsquo;s core — its server infrastructure — beats within Amazon Web Services (AWS), an American giant.&lt;/p&gt;
&lt;p&gt;For the general public, this seems like a simple technical hosting issue. But for &lt;a href=&#34;https://arpokrat.com/infrastructure&#34;&gt;architects of sovereign cybersecurity&lt;/a&gt;
 and those tracking data geopolitics, it is a primary political vulnerability.&lt;/p&gt;
&lt;h2 id=&#34;extraterritoriality-and-conflict-of-sovereignties&#34;&gt;Extraterritoriality and Conflict of Sovereignties&lt;/h2&gt;
&lt;p&gt;By relying on Amazon&amp;rsquo;s infrastructure, Olvid automatically enters the orbit of the US &lt;a href=&#34;https://wikipedia.org/wiki/CLOUD_Act&#34;&gt;CLOUD Act&lt;/a&gt;
.&lt;/p&gt;
&lt;p&gt;The legal analysis of this case reveals a scenario of jurisdictional insecurity that simply adopting a national &amp;ldquo;app&amp;rdquo; does not resolve. The tipping point lies in the concept of &amp;ldquo;control&amp;rdquo; versus &amp;ldquo;localization.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;The CLOUD Act radically changed the legal paradigm by stipulating that the physical location of the server does not matter. The service provider&amp;rsquo;s (here, AWS) obligation to cooperate stems solely from its jurisdictional tie to the US. Thus, Washington can demand data from companies under its jurisdiction, even when that data is physically stored on European soil.&lt;/p&gt;
&lt;p&gt;Legally, this creates a frontal conflict with the General Data Protection Regulation (GDPR). The Court of Justice of the European Union (through the famous &lt;a href=&#34;https://wikipedia.org/wiki/Max_Schrems&#34;&gt;Schrems I and II rulings&lt;/a&gt;
) has already established that US surveillance laws do not offer a level of protection equivalent to Europe&amp;rsquo;s, as they are not limited to what is &amp;ldquo;strictly necessary.&amp;rdquo;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Digital sovereignty is not an attribute of software, but a property of the integrity of the chain of custody.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&#34;the-spectre-of-fisa-and-the-false-promise-of-encryption&#34;&gt;The Spectre of FISA and the False Promise of Encryption&lt;/h2&gt;
&lt;p&gt;Worse still, this dependence on American infrastructure places this data under the shadow of the &lt;a href=&#34;https://wikipedia.org/wiki/Foreign_Intelligence_Surveillance_Act&#34;&gt;Foreign Intelligence Surveillance Act (FISA)&lt;/a&gt;
, which authorizes electronic surveillance for &amp;ldquo;foreign intelligence&amp;rdquo; purposes targeting individuals located outside the US.&lt;/p&gt;
&lt;p&gt;Faced with these threats, Olvid asserts that its end-to-end encryption constitutes a sufficient shield. From a privacy engineering perspective, this defense is dangerously partial.&lt;/p&gt;
&lt;p&gt;The recent rejection of backdoors by the French National Assembly shows legislative resistance to vulnerability by design. Yet, even if the content of a message is encrypted, AWS&amp;rsquo;s centralized infrastructure exposes &lt;strong&gt;metadata&lt;/strong&gt;. Knowing &lt;em&gt;who&lt;/em&gt; is talking to &lt;em&gt;whom&lt;/em&gt;, &lt;em&gt;when&lt;/em&gt;, &lt;em&gt;how often&lt;/em&gt;, and &lt;em&gt;from where&lt;/em&gt; is often much more valuable to foreign intelligence than the message content itself.&lt;/p&gt;
&lt;p&gt;Encryption protects the text, but the centralized server betrays the network of contacts.&lt;/p&gt;
&lt;h2 id=&#34;the-real-danger-is-yet-to-come&#34;&gt;The Real Danger Is Yet to Come&lt;/h2&gt;
&lt;p&gt;As long as European infrastructure relies on entities subject to extraterritorial statutes, the legal security of our communications will remain purely temporary and illusory.&lt;/p&gt;
&lt;p&gt;National security in the 21st century requires much more than good legislative intentions or superficial software shields: it demands &lt;a href=&#34;https://arpokrat.com/os&#34;&gt;total infrastructure and hardware independence&lt;/a&gt;
. Because while intercepting this metadata and encrypted packets seems harmless today, it actually feeds the most devastating threat of the next decade: the strategy of &lt;em&gt;&amp;ldquo;Harvest now, decrypt later&amp;rdquo;&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;A state secret intercepted today is nothing but a mathematical time bomb.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;(Read the rest of our analysis in Part 2: &lt;a href=&#34;https://arpokrat.com/blog/harvest-now-decrypt-later-hndl-zero-knowledge/&#34;&gt;The Time Bomb and the Zero-Knowledge Imperative&lt;/a&gt;
)&lt;/em&gt;&lt;/p&gt;
</description>
    </item>
  </channel>
</rss>