Live data from Hacker News

German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

twitter.com

191–200 of 346 posts

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#191
post #68

Earlier quoted context omitted.

At this point, virtually no digital service - or in fact in business - can be considered to be compliant with GDPR. The reason for this is an ECJ case ruling informally known as Schrems II ( https://www.gdprsummary.com/schrems-ii/ ). That ruling not only invalidated the Privacy Shield agreement, but in fact prohibits the transfer of any data to any company affiliated with a US-based company in any way (including subs…

it's on the EU to negotiate an agreement with the US Wouldn't it be equally on the US to negotiate an agreement with the EU to maintain the global dominance their tech sector currently enjoys? I don't see a categoric reason why the EU should blink first.

The EU's relevance and clout is notoriously overestimated, particularly when it comes to the digital economy. There's this pipe dream that GDPR would somehow jumpstart a privacy-focused digital economy with viable alternatives to US-based services, cloud providers in particular. By and large, these ideas so far have proven to be unrealistic, delusional even.

Let's consider the possibly ways this might play out:

1. The US maintains its position and the CLOUD Act, specifically. The EU maintains its position and GDPR and the Schrems II ruling, but doesn't strictly enforce those.

So, pretty much the status quo as it is today. In that scenario, the EU and local authorities will keep pestering EU-based businesses here and there, but overall prove they're a paper tiger with lofty ideals but no power or will to back those up with action.

From a US perspective, that's an not only an acceptable but even a desirable outcome, because a relevant international party decided to deliberately hamper themselves and their economy with no repercussions for the US. So, no need for the US to blink first, or at all, as a matter of fact.

2. The US maintains its position. The EU maintains its position, too, but contrary to the first scenario does suddenly decide to strictly enforce GDPR and crack down on any business that doesn't comply.

Since, as outlined above, this would mean pretty much every business under EU jurisdiction, the entire economy of the EU would come to a grinding halt within weeks, which in turn would probably lead to major insurrections and the EU ceasing to exist within a matter of weeks as well.

This of course would entail major turmoil and crisis for the world economy as a whole as well, but the EU and EU countries what suffer the most.

So, not exactly a desirable outcome for the US. However, there'd be no need for the US to blink first in this scenario either. If a player decides to commit economic suicide, why should the other player indulge them?

3. The US maintains its position. Again, the EU maintains its position, too, but contrary to scenario #1 and #2 not only decides to strictly enforce GDPR, but first entirely extricates itself from the US economy (i.e. mercantilism 2.0) by not only requiring businesses under EU jurisdiction to cut all ties to the US but by managing to provide viable alternatives to US-based services first.

As pointed out above, so far this hasn't been happening and there's no obvious reason why that would change all of a sudden.

Still, even if such a scenario were realistic, the economic consequences probably would be more severe for the EU than for the US, too.

So, again, no need for the US to blink first.

Hence, in any possible scenario - however likely or unlikely - the US can simply wait it out and it's on the EU to make the first move.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#192
post #162
post #50

My personal favorite outcome of this would be a joint public and corporate funded leap in open source development. This would do much for the budget, privacy and probably also security of businesses and private users. A good example where this principle is already in use is the Matrix protocol.

Forget the migration costs just to develop and standup the cost and infra would be a few billion euros just for one O365 app. I don't think people understand how much O365 apps are used. Nobody is filing github issues either with this, you need to do commercial and customer support, basically replace a core MS SaaS product but not with some shitty idealistic hack because the economic consequences are dire!

Investments in that area would be investment into European open source development as a whole and European IT in general. Businesses can spring up around such efforts, people can find employment, technology can be developed, and the European market could be strengthened.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#193
post #68

Earlier quoted context omitted.

it's on the EU to negotiate an agreement with the US Wouldn't it be equally on the US to negotiate an agreement with the EU to maintain the global dominance their tech sector currently enjoys? I don't see a categoric reason why the EU should blink first.

The EU's relevance and clout is notoriously overestimated, particularly when it comes to the digital economy. There's this pipe dream that GDPR would somehow jumpstart a privacy-focused digital economy with viable alternatives to US-based services, cloud providers in particular. By and large, these ideas so far have proven to be unrealistic, delusional even. Let's consider the possibly ways this might play out: 1. Th…

>. There's this pipe dream that GDPR would somehow jumpstart a privacy-focused digital economy with viable alternatives to US-based services

I would like to see this, but given the extremely shitty track record of European software projects (400 million Euro wasted on a search engine, just as an example), I can only agree that this is very unrealistic.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#194

Earlier quoted context omitted.

Leave you alone to determine your own health code? To buy meat without proper paperwork? To hire children to work? Where is the border?

Speaking from the US perspective, Europe still imports from Xinjiang region of China, where over 2 million Muslims do forced labor. The US banned imports already. Not only that, according to SCMP, they more than doubled in just August. Straighten out the obvious before adding another yoke on small businesses.

We also import goods from the US where prisoners do forced labour.

At any rate; one bad thing does not cancel out another. We can fight both slave labor and strive for protecting citizen data.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#196

I don't really understand the GDPR, maybe because I'm not a lawyer. For example, the GDPR states: >An establishment's failure to designate an EU Representative is considered ignorance of the regulation and relevant obligations, which itself is a violation of the GDPR subject to fines of up to €10 million or up to 2% of the annual worldwide turnover of the preceding financial year in case of an enterprise, whichever i…

From your own profile bio: "Only a fool would take anything posted here as fact."

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#197

Earlier quoted context omitted.

Getting the balance of this right to prevent a tragedy of the commons turns out to be hard. Element (who funds most of Matrix dev) has released almost everything we do as permissive-licensed FOSS open source. As a result, there's a huge ecosystem of folks building commercial solutions on Matrix. But surprisingly little $ actually gets back to Element (or the Matrix Foundation) from those commercial solutions, if any.

Which somewhat highlights the problem with "permissive" licences, as opposed to copyleft ones like AGPL.

But would AGPL have gotten traction in the first place? I guess we can’t say for sure, but my guess is no. I think it safe to say that at minimum it would be an additional barrier to entry.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#198
post #143
post #50

My personal favorite outcome of this would be a joint public and corporate funded leap in open source development. This would do much for the budget, privacy and probably also security of businesses and private users. A good example where this principle is already in use is the Matrix protocol.

AFAIK Nextcloud does have some funding from the EU. I've got an instance for file storage and notes, but more advanced stuff is pretty buggy and unstable in my experience

I have had broadly the same use case - small scale file sync (text notes, some documents)

If you want to save some cash, I can recommend Syncthing. You don't need to host a server for it unless you want to - it is peer-to-peer with all devices you want to be linked via their discovery servers (you can host your own as well).

I used to host my own Nextcloud for about 3 years, moved to Syncthing a few weeks ago, pretty happy so far.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#199
post #194

Earlier quoted context omitted.

Speaking from the US perspective, Europe still imports from Xinjiang region of China, where over 2 million Muslims do forced labor. The US banned imports already. Not only that, according to SCMP, they more than doubled in just August. Straighten out the obvious before adding another yoke on small businesses.

We also import goods from the US where prisoners do forced labour. At any rate; one bad thing does not cancel out another. We can fight both slave labor and strive for protecting citizen data.

[deleted]

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#200

Problem as always is, it's all talk and (almost) zero enforcement in Germany. Complaints to a data protection official take forever, are usually dismissed at first, even if counter to published opinions or decisions such as TFA. And only if you still care after a few years of waiting and at least one appeal you might get a decision, however usually a very cheap one for the perpetrator.

Enforcement is a major issue for most countries. I once asked for a data export from GitHub and GitHub said becuase I couldn't prove 2fa I couldn't prove I owned the account. The account was in my name with my profile picture, I can prove who I am via Passport. I'm legally entitled to know what personal data they have of me and to get an export. The Netherlands were very wishywashy and basically too lazy to do anything about it, probably because they were overworked.

GDPR, mostly seems like an annoyance to developers while providing little actual benefit to users since countries aren't willing to enforce it and even if you do take it to court yourself the courts aren't doing much. In once case, a German court found that a company breached GDPR by using Mailchimp but because they stopped using Mailchimp they didn't fine them, for the breach. That is realistically a complete joke of a judgement. And honestly, there are lots of judgements that are basically similar.

Post reply on HN