Live data from Hacker News

German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

twitter.com

151–160 of 346 posts

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#151
post #50

My personal favorite outcome of this would be a joint public and corporate funded leap in open source development. This would do much for the budget, privacy and probably also security of businesses and private users. A good example where this principle is already in use is the Matrix protocol.

Getting the balance of this right to prevent a tragedy of the commons turns out to be hard. Element (who funds most of Matrix dev) has released almost everything we do as permissive-licensed FOSS open source. As a result, there's a huge ecosystem of folks building commercial solutions on Matrix. But surprisingly little $ actually gets back to Element (or the Matrix Foundation) from those commercial solutions, if any.

Which somewhat highlights the problem with "permissive" licences, as opposed to copyleft ones like AGPL.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#152
post #124

I'm not European, and maybe this is why I struggle to understand this, but why do people want regulators to say, "This doesn't comply with our regulations, so you aren't allowed to use it ?" I understand the hope is that companies will comply rather than forego the entire European market, but if they don't, the last consequence is ultimately on the consumer, not the company. It seems like the same type of thing as wh…

> I'm not European, and maybe this is why I struggle to understand this

Put it another way.

Most sensible Americans would rather have European employment law and healthcare provisions.

Well, the same goes for privacy legislation....

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#153
post #55

Earlier quoted context omitted.

I don't disagree that finding alternatives will be expensive, but I think this is the same harmful thinking we have in the US where people disagree with regulation that adds necessary protection at the cost of business. So we have a "regulation is bad" mindset. Most prominently I wish we could convince companies here to believe handling/retaining unnecessary data is like handling something radioactive. Until we convi…

I am not even sure where to start. What are we afraid of? What can happen with the data? In Sweden all tax filings are public. No one cares.

So let me ask, are you OK sharing all your work documents with China or Russia?

The US commonly uses corporate data in geopolitical moves. Buy using Microsoft cloud products you're sharing all your data with us.gov

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#154

Earlier quoted context omitted.

I agree in principle, but not if it is applied to Microsoft 365 or GCP. If it’s my small business animal shelter, or my grocery store, or even just my little SaaS… leave me alone, please, from requirements like the Quebec translation law, or similar. Microsoft 365 is different. Odds are that there are dozens of businesses you interact with, who store their data in 365 without your knowledge. Microsoft 365 is a “in th…

Leave you alone to determine your own health code? To buy meat without proper paperwork? To hire children to work? Where is the border?

Speaking from the US perspective, Europe still imports from Xinjiang region of China, where over 2 million Muslims do forced labor. The US banned imports already. Not only that, according to SCMP, they more than doubled in just August.

Straighten out the obvious before adding another yoke on small businesses.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#155
post #14

Earlier quoted context omitted.

GDPR fines can be massive, look at the list here: https://www.enforcementtracker.com/ (sort by the fine amount)

Yes. But there is too few of them, and usually in situations where other companies can still wait and see. "We aren't Facebook", "We are too small to be noticed" and "but we had them sign a waiver" are still prevalent in most companies. For things to change, there would really need to be something like: - data protection fines the whole of the customer list of Amazon/Google/MS cloud - data protection fines a high-pro…

There's nothing wrong with persecuting the large perpetrators first, and only going into the smaller ones once the large get under control. In fact, it's the cost-effective way of doing it.

Besides, the GDPR is not extremely clear, so setting the boundaries in a very public way is a good thing.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#156
post #124

I'm not European, and maybe this is why I struggle to understand this, but why do people want regulators to say, "This doesn't comply with our regulations, so you aren't allowed to use it ?" I understand the hope is that companies will comply rather than forego the entire European market, but if they don't, the last consequence is ultimately on the consumer, not the company. It seems like the same type of thing as wh…

The EU has a population of nearly 450M. That's a sizeable market. You might imagine that Microsoft would like a piece of that and would be prepared to ensure that their products meet the standards required to earn it. They already go to some lengths to adapt their products to various locales and languages in order to compete in certain markets. Adapting Office365 to comply with EU law and gain access to that market would seem to be just the cost of doing business.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#157
post #124

I'm not European, and maybe this is why I struggle to understand this, but why do people want regulators to say, "This doesn't comply with our regulations, so you aren't allowed to use it ?" I understand the hope is that companies will comply rather than forego the entire European market, but if they don't, the last consequence is ultimately on the consumer, not the company. It seems like the same type of thing as wh…

[deleted]

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#158
post #124

I'm not European, and maybe this is why I struggle to understand this, but why do people want regulators to say, "This doesn't comply with our regulations, so you aren't allowed to use it ?" I understand the hope is that companies will comply rather than forego the entire European market, but if they don't, the last consequence is ultimately on the consumer, not the company. It seems like the same type of thing as wh…

You make a general point about government regulation, and the answer is that choices made by individual consumers can affect other people too. Should people be given the choice of using leaded gas?

Then we can discuss if the GDPR protects important rights or not , but that's a different discussion.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#159

These people keep acting like they're so clever for figuring this out, yet in reality all they're doing is giving death sentences to European companies by making them unable to use industry standard products.

You mean MS Office?

Yeah, right. Plenty of companies will fail if they are forced to use some of the almost perfectly equal alternatives.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#160
post #124

I'm not European, and maybe this is why I struggle to understand this, but why do people want regulators to say, "This doesn't comply with our regulations, so you aren't allowed to use it ?" I understand the hope is that companies will comply rather than forego the entire European market, but if they don't, the last consequence is ultimately on the consumer, not the company. It seems like the same type of thing as wh…

> I understand the hope is that companies will comply rather than forego the entire European market, but if they don't, the last consequence is ultimately on the consumer, not the company. Essentially you are asking „why should a government expect anyone to follow the law“

It's more "why should a government expect any foreign company to follow the law".

Personally I run a small business, GDPR came out, our solution is to just violate it and not care. They have no legal jurisdiction over us so their laws do not matter.

If we had to comply with every jurisdictions special laws on the entire planet we'd surely waste most of our time doing it.

Post reply on HN