Problem as always is, it's all talk and (almost) zero enforcement in Germany. Complaints to a data protection official take forever, are usually dismissed at first, even if counter to published opinions or decisions such as TFA. And only if you still care after a few years of waiting and at least one appeal you might get a decision, however usually a very cheap one for the perpetrator.
GDPR fines can be massive, look at the list here: https://www.enforcementtracker.com/ (sort by the fine amount)
German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR
121–130 of 346 posts
Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR
#122I'm not sure why there is such a doomer sentiment (mostly from the US community but also some EU) about stepping away from Office 365. There are already existing replacements which do comply with GDPR for all of their service (modulo any vendor lock that I can't think of right now). The ruling is mainly for Gvt and Edu sectors since those handle PII regularly through these services, so the main challenge will be pack…
Any examples? Finding mail and cloud storage alternatives is fairly easy, but as a business operator having this bundled into good identity management is what makes it hard to replace. OIDC provider support with mail and a secure way to store documents and I would be good. Then slack could be wired in via SAML or apis for account management etc. Right now its just a huge undertaking to replace the convenience of GSui…
It's very likely that (if this becomes a bigger issue within the EU), the EU itself will provide more convenient options.
[0]:https://helpcenter.onlyoffice.com/installation.aspx [1]: https://www.onlyoffice.com/blog/2018/06/how-onlyoffice-enter...
EDIT: I missed part of your comment for OIDC provider there is Ory[2] (but again not bundled)
[2]: https://www.ory.sh/
Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR
#123Earlier quoted context omitted.
Let me fix that for you: "industry standard products" -> "monopolist's products". Microsoft spent decades aggressively lobbying European governments and companies to use their stuff. Even if this finding has any short term impact (see the other comments about this point), I find it hard to believe Microsoft wouldn't swallow the pill and simply become compliant. If not - yeah, companies who are entrenched in Microsoft…
The main problem for them is that it's not in Microsoft's power to be compliant here, as the problems are created by the US CLOUD act, not Microsoft's own policies. The only way for Microsoft to become compliant is to carve out its European business into a separate organization (not even a subsidiary -- it could be that even a joint venture would not be enough to escape the reach of the CLOUD act).
Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR
#124I understand the hope is that companies will comply rather than forego the entire European market, but if they don't, the last consequence is ultimately on the consumer, not the company.
It seems like the same type of thing as when Quebec recently decided any service that serves customers in Quebec must offer a French version of all their services. Quebec is a much smaller market than Europe, so the effect was that companies just stopped offering services to people in Quebec, but it seems like these are the same kind of issue.
Government wants services to be provided in a certain way. Service provider declines. Consequences disproportionately impact the consumer, not the service provider.
Why should it be up to a governmental agency to tell you you are not permitted to use a service because they think the service is being provided in a way they don't like?
Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR
#125A great one is Cryptpad: https://github.com/xwiki-labs/cryptpad
There are hosted instances also if you're not interested in self hosting.
P.S. I'm not affiliated in any way with the project.
Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR
#126My personal favorite outcome of this would be a joint public and corporate funded leap in open source development. This would do much for the budget, privacy and probably also security of businesses and private users. A good example where this principle is already in use is the Matrix protocol.
How does FOSS make gdpr compliance easier?
What they mean is that FOSS is more likely to be developed with product quality and value in mind. Proprietary software need to satisfy corporate goals too. And these are often contradictory to the spirit behind GDPR.
Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR
#127Earlier quoted context omitted.
How is that great news? The competition is literally decades behind. This is crippling Europe.
Microsoft products haven't really changed in 20 years. What are you referring to? The fact that you can access them anywhere?
I'm assuming that 100% of people saying "it's fine we have LibreOffice" or "it's fine we have Office 2014 installed locally" don't use it beyond basic PowerPoints and the occasional resume update on Word.
Just as an example, the world pretty much runs on Excel, and each version brings valuable additions.
Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR
#128Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR
#129I'm not European, and maybe this is why I struggle to understand this, but why do people want regulators to say, "This doesn't comply with our regulations, so you aren't allowed to use it ?" I understand the hope is that companies will comply rather than forego the entire European market, but if they don't, the last consequence is ultimately on the consumer, not the company. It seems like the same type of thing as wh…
In some cases it's rather trivial, in other cases its dependent on the survival of the nation state to enforce the rules on the corporation.