Live data from Hacker News

German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

twitter.com

121–130 of 346 posts

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#121
post #14

Problem as always is, it's all talk and (almost) zero enforcement in Germany. Complaints to a data protection official take forever, are usually dismissed at first, even if counter to published opinions or decisions such as TFA. And only if you still care after a few years of waiting and at least one appeal you might get a decision, however usually a very cheap one for the perpetrator.

GDPR fines can be massive, look at the list here: https://www.enforcementtracker.com/ (sort by the fine amount)

even with all it's flaws, I love the EU. 746 million euro fine on Amazon for not respecting data privacy principles

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#122
post #96

I'm not sure why there is such a doomer sentiment (mostly from the US community but also some EU) about stepping away from Office 365. There are already existing replacements which do comply with GDPR for all of their service (modulo any vendor lock that I can't think of right now). The ruling is mainly for Gvt and Edu sectors since those handle PII regularly through these services, so the main challenge will be pack…

Any examples? Finding mail and cloud storage alternatives is fairly easy, but as a business operator having this bundled into good identity management is what makes it hard to replace. OIDC provider support with mail and a secure way to store documents and I would be good. Then slack could be wired in via SAML or apis for account management etc. Right now its just a huge undertaking to replace the convenience of GSui…

Maybe in your case self-hosted/on-premise OnlyOffice is an option[0][1], but as I implied earlier the main issue currently isn't that there aren't alternatives for each individual service but that often a combined package is not there yet.

It's very likely that (if this becomes a bigger issue within the EU), the EU itself will provide more convenient options.

[0]:https://helpcenter.onlyoffice.com/installation.aspx [1]: https://www.onlyoffice.com/blog/2018/06/how-onlyoffice-enter...

EDIT: I missed part of your comment for OIDC provider there is Ory[2] (but again not bundled)

[2]: https://www.ory.sh/

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#123
post #74
post #66

Earlier quoted context omitted.

Let me fix that for you: "industry standard products" -> "monopolist's products". Microsoft spent decades aggressively lobbying European governments and companies to use their stuff. Even if this finding has any short term impact (see the other comments about this point), I find it hard to believe Microsoft wouldn't swallow the pill and simply become compliant. If not - yeah, companies who are entrenched in Microsoft…

The main problem for them is that it's not in Microsoft's power to be compliant here, as the problems are created by the US CLOUD act, not Microsoft's own policies. The only way for Microsoft to become compliant is to carve out its European business into a separate organization (not even a subsidiary -- it could be that even a joint venture would not be enough to escape the reach of the CLOUD act).

If they can do a double Irish with a Dutch sandwich to pay fewer taxes in Europe, I doubt they couldn't find a creative way to deal with this. They only have to be compliant enough for the fines and repercussions to be lower than their profits.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#124
I'm not European, and maybe this is why I struggle to understand this, but why do people want regulators to say, "This doesn't comply with our regulations, so you aren't allowed to use it?"

I understand the hope is that companies will comply rather than forego the entire European market, but if they don't, the last consequence is ultimately on the consumer, not the company.

It seems like the same type of thing as when Quebec recently decided any service that serves customers in Quebec must offer a French version of all their services. Quebec is a much smaller market than Europe, so the effect was that companies just stopped offering services to people in Quebec, but it seems like these are the same kind of issue.

Government wants services to be provided in a certain way. Service provider declines. Consequences disproportionately impact the consumer, not the service provider.

Why should it be up to a governmental agency to tell you you are not permitted to use a service because they think the service is being provided in a way they don't like?

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#125
For the businesses who might want to switch to an alternative.

A great one is Cryptpad: https://github.com/xwiki-labs/cryptpad

There are hosted instances also if you're not interested in self hosting.

P.S. I'm not affiliated in any way with the project.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#126
post #50

My personal favorite outcome of this would be a joint public and corporate funded leap in open source development. This would do much for the budget, privacy and probably also security of businesses and private users. A good example where this principle is already in use is the Matrix protocol.

How does FOSS make gdpr compliance easier?

Not in a direct way.

What they mean is that FOSS is more likely to be developed with product quality and value in mind. Proprietary software need to satisfy corporate goals too. And these are often contradictory to the spirit behind GDPR.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#127

Earlier quoted context omitted.

How is that great news? The competition is literally decades behind. This is crippling Europe.

Microsoft products haven't really changed in 20 years. What are you referring to? The fact that you can access them anywhere?

Can you clarify your usage of Office products?

I'm assuming that 100% of people saying "it's fine we have LibreOffice" or "it's fine we have Office 2014 installed locally" don't use it beyond basic PowerPoints and the occasional resume update on Word.

Just as an example, the world pretty much runs on Excel, and each version brings valuable additions.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#129
post #124

I'm not European, and maybe this is why I struggle to understand this, but why do people want regulators to say, "This doesn't comply with our regulations, so you aren't allowed to use it ?" I understand the hope is that companies will comply rather than forego the entire European market, but if they don't, the last consequence is ultimately on the consumer, not the company. It seems like the same type of thing as wh…

For the same reasons you're not allowed to sign particular contacts, such as enslaving yourself. Without restriction companies will do every illegal thing they can get away with via their collective power of size versus your weak individualism.

In some cases it's rather trivial, in other cases its dependent on the survival of the nation state to enforce the rules on the corporation.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#130
post #114
post #49

Earlier quoted context omitted.

I’m also European. Thanks for the insight. I don’t agree with you. So think about that next time you say “most Europeans”.

Just because you disagree doesn't contradict "most Europeans". Or how many are you?

That was exactly my point.
Post reply on HN