Live data from Hacker News

German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

twitter.com

241–250 of 346 posts

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#241
post #160

Earlier quoted context omitted.

> I understand the hope is that companies will comply rather than forego the entire European market, but if they don't, the last consequence is ultimately on the consumer, not the company. Essentially you are asking „why should a government expect anyone to follow the law“

It's more "why should a government expect any foreign company to follow the law". Personally I run a small business, GDPR came out, our solution is to just violate it and not care. They have no legal jurisdiction over us so their laws do not matter. If we had to comply with every jurisdictions special laws on the entire planet we'd surely waste most of our time doing it.

Without making a judgment here if you do business somewhere the expectation typically is that you will comply with local laws. This is partially the reason why only big companies can handle truly international business.

Anecdotally, when GDPR came out, in the old country the, almost, first thing that happened is whole bunch of companies started bothering small businesses saying they are not complying and offering to bring them into compliance by adding cookie warning popup we love so much.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#242

Earlier quoted context omitted.

Getting the balance of this right to prevent a tragedy of the commons turns out to be hard. Element (who funds most of Matrix dev) has released almost everything we do as permissive-licensed FOSS open source. As a result, there's a huge ecosystem of folks building commercial solutions on Matrix. But surprisingly little $ actually gets back to Element (or the Matrix Foundation) from those commercial solutions, if any.

I don't have any proof but I'm certain Germany must have made some sort of funding for matrix https://matrix.org/blog/2021/07/21/germanys-national-healthc...

The messengerfor German armed forces is based on matrix

https://www.heise.de/newsticker/meldung/Bundeswehr-setzt-kue...

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#244

Earlier quoted context omitted.

I agree in principle, but not if it is applied to Microsoft 365 or GCP. If it’s my small business animal shelter, or my grocery store, or even just my little SaaS… leave me alone, please, from requirements like the Quebec translation law, or similar. Microsoft 365 is different. Odds are that there are dozens of businesses you interact with, who store their data in 365 without your knowledge. Microsoft 365 is a “in th…

Leave you alone to determine your own health code? To buy meat without proper paperwork? To hire children to work? Where is the border?

I think what parent is trying to say that at certain point over-regulation is not helpful and actually detrimental not just to the business, but the ecosystem as a whole. For a smaller business, onerous regulation could mean closing the doors. For a big business, the burden is also there, but it can more easily withstand it due to its size ( and it typically has some resources to throw at a given issue ).

I agree that there are some 'minimal functioning society' laws like the ones you listed, but I am not certain Canada law example in previous posts or GDPR falls in the same category.

As usual, the question is that of where the line is. And that should be determined by societies at large.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#245

Earlier quoted context omitted.

You can host it yourself on servers in the EU.

So self-hostable or on-prem software has the advantage, not specifically FOSS. But in many cases this transfers the gdpr compliance burden to the business that's running the software

The burden is on the owner of the data in any case. When using an external data processor like Microsoft they have to make sure that the external company complies, and this must be explicitly covered by the contract.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#246
post #143

Earlier quoted context omitted.

AFAIK Nextcloud does have some funding from the EU. I've got an instance for file storage and notes, but more advanced stuff is pretty buggy and unstable in my experience

I have had broadly the same use case - small scale file sync (text notes, some documents) If you want to save some cash, I can recommend Syncthing. You don't need to host a server for it unless you want to - it is peer-to-peer with all devices you want to be linked via their discovery servers (you can host your own as well). I used to host my own Nextcloud for about 3 years, moved to Syncthing a few weeks ago, pretty…

Thank you, I'll try it. I don't spend any money on my Nextcloud though, it's hosted on an "always free" (true so far) compute instance of Oracle OCI.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#247
post #129

Earlier quoted context omitted.

For the same reasons you're not allowed to sign particular contacts, such as enslaving yourself. Without restriction companies will do every illegal thing they can get away with via their collective power of size versus your weak individualism. In some cases it's rather trivial, in other cases its dependent on the survival of the nation state to enforce the rules on the corporation.

Hmm that is a good point. It is forbidden to sign contracts of enslavement in every country I know of, even if the potential contractee is making it free from duress. Therefore forbidding some types of contracts for everyone does have established precedent. However, there does not appear to be a limit to this. For example, can governments ban their residents from signing contracts to distribute or host porn, gambling…

> can governments ban their residents from signing contracts to distribute or host porn, gambling, etc.?

The question is always what do local laws say. Even in the US you have laws or court decisions that allow child marriage, non-revocable consent, upskirt photos, or regulate that men are allowed to show nipples but women aren't.

Other countries have equally outrageous (or reasonable, depending on your views) laws making something effectively (il)legal. So yes, governments can and do prohibit porn or gambling, or just the hosting and distribution. Laws and regulation can have a lot of purposes. They can protect you from abuse you may not even understand, or they can even protect the abusers.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#248

Earlier quoted context omitted.

How is that great news? The competition is literally decades behind. This is crippling Europe.

I genuinely don't understand why anyone would need MS products ever. I thought it was just hard lobbying that made it so our instituitions have to use that garbage.

And obviously your opinion is not at all biased by the fact that you are a software developer working on Linux.

This propensity of developers to reject the existence of everything that they cannot see through their own tiny lens is beyond laughable.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#250
post #222

Earlier quoted context omitted.

A websites using wordpress got fined for including google fonts. Not the organization that provides wordpress using google fonts by default. Likewise, a company using O365 to store customer or employee data will get in trouble, not Microsoft for offering that service.

That's not what's being discussed. My comment asserts with certainty that a small business will never be punished as leverage against the upstream big corp.

It's not Microsofts fault if customers use it to store GDPR relevant data. It's Microsofts customers using them as an external data processor. It's the companies that are using O356 for such data that will get fined.
Post reply on HN