Live data from Hacker News

German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

twitter.com

211–220 of 346 posts

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#211

Earlier quoted context omitted.

How does FOSS make gdpr compliance easier?

Not in a direct way. What they mean is that FOSS is more likely to be developed with product quality and value in mind. Proprietary software need to satisfy corporate goals too. And these are often contradictory to the spirit behind GDPR.

Most companies are going to be well-aligned with not being sued out of existence for gdpr violations

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#212

This will have absolutely zero impact. Everybody knows you must use Microsoft products and if those don't comply with regulations, the regulations will have to change...

It already has an impact according to Microsoft - see this thread: https://news.ycombinator.com/item?id=33752687

It might imply that o365 sevices in the EU/EEC will increase in price - but I'm quite certain the data privacy will be better.

Remember that this has implications for all businesses that deliver on government contracts in the EU - they would all have to move away, for example not hosting email with o365 because government won't communicate details involving GDPR protected data over untrusted services (even with encryption enabled).

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#213

Earlier quoted context omitted.

How does FOSS make gdpr compliance easier?

You can host it yourself on servers in the EU.

So self-hostable or on-prem software has the advantage, not specifically FOSS. But in many cases this transfers the gdpr compliance burden to the business that's running the software

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#214
post #180

Earlier quoted context omitted.

It's nothing, but once one of their customers gets a 5 millioj euro fine for using Office365 for sensitive data, the impact will be significantly higher. Microsoft can take the hit but most of its customers can't. Microsoft's incompatibility with the GDPR puts some of its customers at risk. A fine or two and businesses might stop paying for those lucrative cloud subscriptions.

This will literally, not figuratively, but -literally- never happen. A smaller business will never be punished as a signal to Microsoft.

A websites using wordpress got fined for including google fonts. Not the organization that provides wordpress using google fonts by default.

Likewise, a company using O365 to store customer or employee data will get in trouble, not Microsoft for offering that service.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#215
post #55

Earlier quoted context omitted.

I don't disagree that finding alternatives will be expensive, but I think this is the same harmful thinking we have in the US where people disagree with regulation that adds necessary protection at the cost of business. So we have a "regulation is bad" mindset. Most prominently I wish we could convince companies here to believe handling/retaining unnecessary data is like handling something radioactive. Until we convi…

I am not even sure where to start. What are we afraid of? What can happen with the data? In Sweden all tax filings are public. No one cares.

Have you been paying attention to all the TikTok scare in the US? Lot of people care.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#216

Earlier quoted context omitted.

For some reason it's a big national security concern when Chinese companies collect data on US citizens, but when Europeans apply the same caution with American companies, people across the Atlantic see it purely from a business perspective. Why is that? This isn't TikTok and what people do on their private phones. This is a foreign company that has the capability to siphon off a lot of data about business decisions,…

> Why is that? because china is a totalitarian country and the us isn't

Tell that to Assange. Or Snowden.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#217

Earlier quoted context omitted.

> Why is that? because china is a totalitarian country and the us isn't

Not being a totalitarian country gives you the right to spy on people?

Not being totalitarian implies no to spy on your people. Spying on your people implies being totalitarian.

Pretty sure US agencies have more rights to spy on not-their people, e.g., Microsoft EU customer data than Microsoft US customer data.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#218
post #124

I'm not European, and maybe this is why I struggle to understand this, but why do people want regulators to say, "This doesn't comply with our regulations, so you aren't allowed to use it ?" I understand the hope is that companies will comply rather than forego the entire European market, but if they don't, the last consequence is ultimately on the consumer, not the company. It seems like the same type of thing as wh…

The reasoning is that your personal data doesn't belong to you. It belongs to your government. A user's personal data is a vector for attack for a foreign agent. You can argue up to which degree this is correct or not, but the EU instance on this matter is of paranoia.

What utter drivel.

The EU stance is this: "a person's data belongs to the person, and you can't obtain, collect, sell, or transfer this data in any way, shape, or form without an explicit consent from the person".

The US on the other hand: all your data belongs to the US government regardless of where you are on the globe: https://en.wikipedia.org/wiki/CLOUD_Act?wprov=sfti1 And this is on top of all the large scale data collection already performed by companies.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#219
post #208

Earlier quoted context omitted.

English version (PDF): https://news.microsoft.com/wp-content/uploads/prod/sites/40/...

Thank you, both. IMNHO the most likely outcome is that o365 will come to be GDPR compliant - and so business will be able to (continue to) deliver on government contracts building on o365.

It's hard to see how. MS would have to create an entity entirely separate from MS US... while providing the exact same services.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#220
post #162

Earlier quoted context omitted.

Forget the migration costs just to develop and standup the cost and infra would be a few billion euros just for one O365 app. I don't think people understand how much O365 apps are used. Nobody is filing github issues either with this, you need to do commercial and customer support, basically replace a core MS SaaS product but not with some shitty idealistic hack because the economic consequences are dire!

Investments in that area would be investment into European open source development as a whole and European IT in general. Businesses can spring up around such efforts, people can find employment, technology can be developed, and the European market could be strengthened.

Why haven’t Europeans been able to be successful in this area already? It’s not like there aren’t always European businesses working on this problem.

It is striking that both the evil empire solution (Microsoft 365) and the underdog disruptive upstart (Google Docs, at least that’s what it was ~15 years ago) are both American companies. iWork is American, Zoho is Indian.

Why aren’t Europeans producing competitive software?

Post reply on HN