Problem as always is, it's all talk and (almost) zero enforcement in Germany. Complaints to a data protection official take forever, are usually dismissed at first, even if counter to published opinions or decisions such as TFA. And only if you still care after a few years of waiting and at least one appeal you might get a decision, however usually a very cheap one for the perpetrator.
GDPR fines can be massive, look at the list here: https://www.enforcementtracker.com/ (sort by the fine amount)
German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR
21–30 of 346 posts
Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR
#22Problem as always is, it's all talk and (almost) zero enforcement in Germany. Complaints to a data protection official take forever, are usually dismissed at first, even if counter to published opinions or decisions such as TFA. And only if you still care after a few years of waiting and at least one appeal you might get a decision, however usually a very cheap one for the perpetrator.
GDPR fines can be massive, look at the list here: https://www.enforcementtracker.com/ (sort by the fine amount)
For things to change, there would really need to be something like:
- data protection fines the whole of the customer list of Amazon/Google/MS cloud
- data protection fines a high-profile company a lot of money for using Office365
- a court forces a public institution to cease using Office365 (no fines possible there)
- enforcement accelerates to a point where, from complaint to fine, things take only a few weeks, instead of a few years, so that lots of medium and smaller businesses are hit. Currently enforcement seems to be starting with the big cases, and being bogged down in the complexity of those.
Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR
#23This will have absolutely zero impact. Everybody knows you must use Microsoft products and if those don't comply with regulations, the regulations will have to change...
It could lead to billions in fines for Microsoft. Up to 4% global revenue - for each EU country.
Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR
#24Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR
#25Earlier quoted context omitted.
It could lead to billions in fines for Microsoft. Up to 4% global revenue - for each EU country.
It's just the cost of doing business for them, implementing and complaining with EU laws might cost even more than the fine
Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR
#26Earlier quoted context omitted.
We regularly discuss GDPR matters in our German company because there's a lot of FUD concerning the various cloud platforms and we have to cater to sensitive customers with our own hosting. One extreme is that you can't use AWS at all because of Schrems and it's a US compancy etc. On the other hand there's some hearsay about Microsoft (Azure) being tolerated because there's no way around it.
Imho, the "FUD" is largely right and most cloud platforms are indeed illegal. However, due to enforcement being absent or taking ages, there are too few legal decisions and big expensive enforcement actions that one can point to. Currently everything is really still fear, uncertainty and doubt, the hammer hasn't come down yet. I'm not sure if it ever will, at least not before EU institutions or other member states su…
Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR
#27This will have absolutely zero impact. Everybody knows you must use Microsoft products and if those don't comply with regulations, the regulations will have to change...
Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR
#28Earlier quoted context omitted.
It could lead to billions in fines for Microsoft. Up to 4% global revenue - for each EU country.
It would really depend on the situation to be decided, whether MS would have to pay up, or rather the company using MS products to handle customer data. One can imagine a way to use MS products that might not be illegal, e.g. never use it to process personal data, use anonymized accounts that are not bound to a real person, swap around accounts and computers to prevent association with a person, etc. Then, all it wou…
Therefore, all corporate tools must be specific for one purpose when managing PII, and no tool should allow free-text fields. Excel, Access, notepads shouldn’t exist in companies.
Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR
#29Earlier quoted context omitted.
And what would be the alternative? LibreOffice with its 90s UI/UX?
I wish I had ms office with its 90s UI/UX instead of whatever garbage it evolved into.
So you can buy a copy of your favourite old Office version on eBay or whatever and use that.
Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR
#30This will have absolutely zero impact. Everybody knows you must use Microsoft products and if those don't comply with regulations, the regulations will have to change...
Basically separation of encryption and decryption key in a location other then azure for example.
Nobody cared, nothing happened. People still store both in azure.
As long no one gets fined ( here companies) nothing will happen