Live data from Hacker News

German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

twitter.com

221–230 of 346 posts

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#221

Earlier quoted context omitted.

Leave you alone to determine your own health code? To buy meat without proper paperwork? To hire children to work? Where is the border?

Speaking from the US perspective, Europe still imports from Xinjiang region of China, where over 2 million Muslims do forced labor. The US banned imports already. Not only that, according to SCMP, they more than doubled in just August. Straighten out the obvious before adding another yoke on small businesses.

That does not answer my question at all

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#222
post #180

Earlier quoted context omitted.

This will literally, not figuratively, but -literally- never happen. A smaller business will never be punished as a signal to Microsoft.

A websites using wordpress got fined for including google fonts. Not the organization that provides wordpress using google fonts by default. Likewise, a company using O365 to store customer or employee data will get in trouble, not Microsoft for offering that service.

That's not what's being discussed. My comment asserts with certainty that a small business will never be punished as leverage against the upstream big corp.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#223

Problem as always is, it's all talk and (almost) zero enforcement in Germany. Complaints to a data protection official take forever, are usually dismissed at first, even if counter to published opinions or decisions such as TFA. And only if you still care after a few years of waiting and at least one appeal you might get a decision, however usually a very cheap one for the perpetrator.

Er..no.

I mean, yes, that's what it used to be, pre-GDPR.

With GDPR, the data protection agencies have grown teeth. And fangs. And claws and talons.

GDPR enforcement is young, and the goal is compliance, not maximum fines. So depending on the offence and the offender, they start with a warning or a small fine. This will ratchet up and the maximum is € 10 million or 2% of the previous year's annual revenue (not profit), whichever is greater!

Microsoft's annual revenue for FY 2022 (I guess they are early) was almost $200 Billion. So the fine for them could be $4 billion. Yes, that's noticeable and not something you want to explain to your shareholders.

And of course this seems to apply to their customers, for whom margins tend to be tighter, and for whom IT is not their main business, but an operating expense in the first place. For example, Volkswaken has an operating profit of around 6-7%. So 2% of revenue is around a third of their profit. And also around a third of their entire R&D budget. Yeah, compliance is the cheaper option by far.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#224
post #89

Earlier quoted context omitted.

> Problem as always is, its all talk and (almost) zero enforcement in Germany. I have the exact opposite impression. Even in small start-up, every new external supplier will be judged whether the is any customer data processing in the US. People are super afraid of Google analytics. If you use the Google Fonts on your website you will get an cease and desist letter in no time from scummy lawyers. You pratically need…

The first example isn't enforcement, it is due diligence and compliance in companies. That does happen, of course, sometimes in a useful way, sometimes to just have some fig leaf to point at in case of a complaint. Google analytics and Google fonts are regularly enforced, but not by data protection officials. "Enforcement" of those is, as you've said, done by scummy private lawyers, scanning websites and sending expe…

What needs to be true about me and my website to possibly be subject to Abmahnungen? Does my website need to be hosted I'm Germany? Do I need to reside in Germany?

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#225
post #50

My personal favorite outcome of this would be a joint public and corporate funded leap in open source development. This would do much for the budget, privacy and probably also security of businesses and private users. A good example where this principle is already in use is the Matrix protocol.

Kolab was originally an open source alternative to Exchange developed by BSI (Bundesamt für Sicherheit in der Informationstechnik) and different companies. I don’t think it has been very successful though.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#226
Aren't CDNs against GDPR in some cases? Seems like an overly broad regulation that is enforced by often dismissed in judgement. Changing nothing, adding headache, and preventing meaningful regulation from taking its place...

And when you request data from companies, you don't even get what you want a lot of the time because it is often aggregated.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#227
post #124

I'm not European, and maybe this is why I struggle to understand this, but why do people want regulators to say, "This doesn't comply with our regulations, so you aren't allowed to use it ?" I understand the hope is that companies will comply rather than forego the entire European market, but if they don't, the last consequence is ultimately on the consumer, not the company. It seems like the same type of thing as wh…

[deleted]

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#228
post #48

finally, this is really great news for anyone european, I hope it won't take long to determine there are a whole lot of other MS products that should also be illegal

How is that great news? The competition is literally decades behind. This is crippling Europe.

I genuinely don't understand why anyone would need MS products ever. I thought it was just hard lobbying that made it so our instituitions have to use that garbage.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#230

Earlier quoted context omitted.

The first example isn't enforcement, it is due diligence and compliance in companies. That does happen, of course, sometimes in a useful way, sometimes to just have some fig leaf to point at in case of a complaint. Google analytics and Google fonts are regularly enforced, but not by data protection officials. "Enforcement" of those is, as you've said, done by scummy private lawyers, scanning websites and sending expe…

What needs to be true about me and my website to possibly be subject to Abmahnungen? Does my website need to be hosted I'm Germany? Do I need to reside in Germany?

Probably a german address in the imprint. I can't imagine they'd bother with anyone abroad. They're just after easy money after all.
Post reply on HN