Live data from Hacker News

German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

twitter.com

231–240 of 346 posts

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#231
post #220

Earlier quoted context omitted.

Investments in that area would be investment into European open source development as a whole and European IT in general. Businesses can spring up around such efforts, people can find employment, technology can be developed, and the European market could be strengthened.

Why haven’t Europeans been able to be successful in this area already? It’s not like there aren’t always European businesses working on this problem. It is striking that both the evil empire solution (Microsoft 365) and the underdog disruptive upstart (Google Docs, at least that’s what it was ~15 years ago) are both American companies. iWork is American, Zoho is Indian. Why aren’t Europeans producing competitive soft…

OpenOffice was German (Star Office).

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#232
post #220

Earlier quoted context omitted.

Investments in that area would be investment into European open source development as a whole and European IT in general. Businesses can spring up around such efforts, people can find employment, technology can be developed, and the European market could be strengthened.

Why haven’t Europeans been able to be successful in this area already? It’s not like there aren’t always European businesses working on this problem. It is striking that both the evil empire solution (Microsoft 365) and the underdog disruptive upstart (Google Docs, at least that’s what it was ~15 years ago) are both American companies. iWork is American, Zoho is Indian. Why aren’t Europeans producing competitive soft…

There’s a small market for it.

Back before Gmail ate the world there were a number of small “mail server with webmail” in a box setups - those mostly died off. Similar things happened with office suites.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#233
post #208

Earlier quoted context omitted.

Thank you, both. IMNHO the most likely outcome is that o365 will come to be GDPR compliant - and so business will be able to (continue to) deliver on government contracts building on o365.

It's hard to see how. MS would have to create an entity entirely separate from MS US... while providing the exact same services.

What’s hard about that? Every company has tons of shells for various reason.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#234

Earlier quoted context omitted.

What a depressing reality where hostile US corporate data privacy practices and hostile US surveillance law take de facto priority over the EU's own privacy legislation meant to protect its own residents. I wish the EU politicians and regulators were more willing to enforce their own rules, and that the ECJ were more willing to be explicit rather than implicit about the meaning of its Schrems rulings, all of which wo…

What a depressing reality where hostile US corporate data privacy practices and hostile US surveillance law take de facto priority over the EU's own privacy legislation meant to protect its own residents. The EU has provisions for very similar "hostile surveillance law" in its own member states. It just gave them a get out of jail free card in the GDPR. There is a considerable amount of hypocrisy about the EU's posit…

Yes, I'm not defending the EU hypocrisy or their own hostile surveillance laws. However, keep in mind that this report mentioned many issues about MS's own processing purposes, policies, and practices, and wasn't only about the problems posed by US surveillance law. It's those MS-specific issues for which the Dutch government got fixes applied to Dutch private sector use of MS 365; naturally they haven't changed US surveillance law.

And as bad as government surveillance is in both the EU and the US, it's awful when local companies send the data of the majority of their population into the jurisdiction of surveillance law whose political bosses the population can't even indirectly vote against.

This is rare in the US because US companies rarely send the data of US citizens to EU providers, which itself is because the big tech players are American. Whereas for exactly the same reason of where the big tech players are based, it's common for EU companies to send the data of EU citizens to US providers.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#235
post #129
post #124

I'm not European, and maybe this is why I struggle to understand this, but why do people want regulators to say, "This doesn't comply with our regulations, so you aren't allowed to use it ?" I understand the hope is that companies will comply rather than forego the entire European market, but if they don't, the last consequence is ultimately on the consumer, not the company. It seems like the same type of thing as wh…

For the same reasons you're not allowed to sign particular contacts, such as enslaving yourself. Without restriction companies will do every illegal thing they can get away with via their collective power of size versus your weak individualism. In some cases it's rather trivial, in other cases its dependent on the survival of the nation state to enforce the rules on the corporation.

Hmm that is a good point. It is forbidden to sign contracts of enslavement in every country I know of, even if the potential contractee is making it free from duress.

Therefore forbidding some types of contracts for everyone does have established precedent.

However, there does not appear to be a limit to this.

For example, can governments ban their residents from signing contracts to distribute or host porn, gambling, etc.?

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#236
post #194

Earlier quoted context omitted.

We also import goods from the US where prisoners do forced labour. At any rate; one bad thing does not cancel out another. We can fight both slave labor and strive for protecting citizen data.

True - but equating the US prison system to what is happening to them is an absurdity. It’s like if Nazi Germany said their camps weren’t that bad, after all, the US has prisons.

The Nazi camp counterpart for US would be Guantanamo: https://en.m.wikipedia.org/wiki/Guantanamo_Bay_detention_cam...

They just moved it to occupied foreign soil to technically not have a concentration camp in US soil. But then Germany had concentration camps in occupied soil as well, like Auschwitz in occupied Poland.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#237

Earlier quoted context omitted.

It's hard to see how. MS would have to create an entity entirely separate from MS US... while providing the exact same services.

What’s hard about that? Every company has tons of shells for various reason.

Shells are not separate from the parent company. The Cloud act still applies to them.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#238

Earlier quoted context omitted.

Which somewhat highlights the problem with "permissive" licences, as opposed to copyleft ones like AGPL.

But would AGPL have gotten traction in the first place? I guess we can’t say for sure, but my guess is no. I think it safe to say that at minimum it would be an additional barrier to entry.

Mastodon and peertube are both AGPL

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#239

Earlier quoted context omitted.

Not being a totalitarian country gives you the right to spy on people?

Not being totalitarian implies no to spy on your people. Spying on your people implies being totalitarian. Pretty sure US agencies have more rights to spy on not-their people, e.g., Microsoft EU customer data than Microsoft US customer data.

Let's be real, no Western country is banning Chinese products or services because China is spying on their own citizens or abusing Uyghurs. That's at best the "feel good" story sold in the media to get the people's support and distract from other issues. They're banning them for 2 reasons. One is that China will abuse them to spy and get a competitive advantage over those other countries. The second is that it's hard to compete in price so local alternatives are pushed out.

In the same vein the EU isn't blocking a US company from collecting data because the US is spying on its own citizens and abusing people of color. They're doing it for almost the same 2 reasons. Everyone knows (with evidence) that the US will abuse them to spy and get a competitive advantage. The second is that it's hard to compete in performance/features so local alternatives are pushed out.

The only reason to see a difference here is nationalistic bias. And that's fair enough, most people aren't educated enough (not talking just academic degrees) to be capable of critical thinking when their own principles or morals are under attack. They will just go to the first easy, "feel good" explanation when they do something to others, and the opposite when others do something to them.

My favorite illustration on the topic: https://pics.me.me/their-barbarous-wastes-our-blessed-homela...

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#240

Earlier quoted context omitted.

For some reason it's a big national security concern when Chinese companies collect data on US citizens, but when Europeans apply the same caution with American companies, people across the Atlantic see it purely from a business perspective. Why is that? This isn't TikTok and what people do on their private phones. This is a foreign company that has the capability to siphon off a lot of data about business decisions,…

> Why is that? because china is a totalitarian country and the us isn't

Sir, you must have grown up in front of a TV with strictly US American programming.
Post reply on HN