Live data from Hacker News

German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

twitter.com

171–180 of 346 posts

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#171
post #124

I'm not European, and maybe this is why I struggle to understand this, but why do people want regulators to say, "This doesn't comply with our regulations, so you aren't allowed to use it ?" I understand the hope is that companies will comply rather than forego the entire European market, but if they don't, the last consequence is ultimately on the consumer, not the company. It seems like the same type of thing as wh…

For some reason it's a big national security concern when Chinese companies collect data on US citizens, but when Europeans apply the same caution with American companies, people across the Atlantic see it purely from a business perspective. Why is that? This isn't TikTok and what people do on their private phones. This is a foreign company that has the capability to siphon off a lot of data about business decisions,…

> Why is that?

because china is a totalitarian country and the us isn't

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#172

For the businesses who might want to switch to an alternative. A great one is Cryptpad: https://github.com/xwiki-labs/cryptpad There are hosted instances also if you're not interested in self hosting. P.S. I'm not affiliated in any way with the project.

I can second cryptpad.

It can do documents and „excel“ and „PowerPoint „ and a few other things.

No experience in an „industrial „ environment though so YMMV.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#174
I use onlyoffice[0] because MS Office doesn't run on Linux. It is open source and seems to have the best compatibility with MS Office. You can self host it and/or use it locally. It also integrates with e.g. nextcloud or seafile.

Some features are missing yes, but the usability (IMO) is better than Libre-/OpenOffice.

I don't know how good the collaboration is but they seem to advertise for it.

[0] https://www.onlyoffice.com/

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#175

At this points, isn't it pretty safe to assume very few Silicon Valley services conform to GDPR? Another example was shared recently: Shopify is technically illegal in Germany [1] [1] https://news.ycombinator.com/item?id=33561222

It's quite safe to assume that none does. Unless all your data (including metadata) is end-to-end encrypted outside of the US, the service is non-conforming. And the internet makes it quite hard to encrypt metadata.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#176
post #21
post #14

Earlier quoted context omitted.

GDPR fines can be massive, look at the list here: https://www.enforcementtracker.com/ (sort by the fine amount)

So 3 enforcements in Germany in all of 2022, and the highest fine in Germany was 35mil. 35mil is how much for Microsoft? The yearly Office 365 fees of one of their DAX customers?

The possible fine for Microsoft would be 4% of the sales revenue of the whole company, which would amount to 6.8 billion dollars (at 170 billion dollars revenue in 2021)

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#178
post #117

These people keep acting like they're so clever for figuring this out, yet in reality all they're doing is giving death sentences to European companies by making them unable to use industry standard products.

Monopoly is not the same as "industry standard". And specifically in the case of Microsoft Office / O365 there is very little actually benefit of using it over any of the more open (and even free) alternatives... rather than being an "industry standard" it's really just an "industry default", i.e. what most companies use because no IT manager ever got fired for deploying it.

You're a SRE, I'd argue that you have absolutely no idea about what is the industry standard when it comes to office productivity suites.

Having this discussion on HackerNews is useless, because people here are at best very light users of Office and at worst don't use it at all.

How many hours per week does your work involve Office software? Because for a lot of people it's 40, but those people are not on HN.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#179
post #89

Problem as always is, it's all talk and (almost) zero enforcement in Germany. Complaints to a data protection official take forever, are usually dismissed at first, even if counter to published opinions or decisions such as TFA. And only if you still care after a few years of waiting and at least one appeal you might get a decision, however usually a very cheap one for the perpetrator.

> Problem as always is, its all talk and (almost) zero enforcement in Germany. I have the exact opposite impression. Even in small start-up, every new external supplier will be judged whether the is any customer data processing in the US. People are super afraid of Google analytics. If you use the Google Fonts on your website you will get an cease and desist letter in no time from scummy lawyers. You pratically need…

The first example isn't enforcement, it is due diligence and compliance in companies. That does happen, of course, sometimes in a useful way, sometimes to just have some fig leaf to point at in case of a complaint.

Google analytics and Google fonts are regularly enforced, but not by data protection officials. "Enforcement" of those is, as you've said, done by scummy private lawyers, scanning websites and sending expensive letters ("Abmahnungen") en masse. Basically, due to a weird precedent, those lawyers are allowed to give you unasked advice on your wrongdoing and billing you for it. But that is, afaik, a specialty of German law, and mostly limited to stuff that can be fully automated. So while you can scan for a website using Google Fonts, you cannot as easily scan for someone using Office365. Although you might, maybe, get a hint by looking at the DNS MX records.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#180
post #21

Earlier quoted context omitted.

So 3 enforcements in Germany in all of 2022, and the highest fine in Germany was 35mil. 35mil is how much for Microsoft? The yearly Office 365 fees of one of their DAX customers?

It's nothing, but once one of their customers gets a 5 millioj euro fine for using Office365 for sensitive data, the impact will be significantly higher. Microsoft can take the hit but most of its customers can't. Microsoft's incompatibility with the GDPR puts some of its customers at risk. A fine or two and businesses might stop paying for those lucrative cloud subscriptions.

This will literally, not figuratively, but -literally- never happen. A smaller business will never be punished as a signal to Microsoft.
Post reply on HN