Live data from Hacker News

German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

twitter.com

251–260 of 346 posts

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#251

Problem as always is, it's all talk and (almost) zero enforcement in Germany. Complaints to a data protection official take forever, are usually dismissed at first, even if counter to published opinions or decisions such as TFA. And only if you still care after a few years of waiting and at least one appeal you might get a decision, however usually a very cheap one for the perpetrator.

Er..no. I mean, yes, that's what it used to be, pre-GDPR. With GDPR, the data protection agencies have grown teeth. And fangs. And claws and talons. GDPR enforcement is young, and the goal is compliance, not maximum fines. So depending on the offence and the offender, they start with a warning or a small fine. This will ratchet up and the maximum is € 10 million or 2% of the previous year's annual revenue (not profit…

This.

There were plenty of EU countries with privacy laws. The laws were all ignored by all but the largest companies in the country. Getting FAANG to take note of local law was basically impossible.

On paper, the GDPR is weaker than what it replaced in my country. I lost some privacy rights with the GDPR, and gained some bureacratics if I want my rights enforced. In practice, the GDPR gets some following, even outside the EU. It has teeth.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#252
post #124

I'm not European, and maybe this is why I struggle to understand this, but why do people want regulators to say, "This doesn't comply with our regulations, so you aren't allowed to use it ?" I understand the hope is that companies will comply rather than forego the entire European market, but if they don't, the last consequence is ultimately on the consumer, not the company. It seems like the same type of thing as wh…

Because individuals rarely have the choice here in the US. Our schools here require the use of Google accounts in a manner which is almost certainly illegal, but isn't enforced anyways. My kids privacy is mandatorily violated because of a decision of the school district. So I have to hope regulators here will wise up and start to force schools to abandon harmful products.

So what you think of as freedom of choice often isn't for students, employees, and consumers. It's why we need drastically more business regulation to guarantee individual rights.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#253

Earlier quoted context omitted.

Getting the balance of this right to prevent a tragedy of the commons turns out to be hard. Element (who funds most of Matrix dev) has released almost everything we do as permissive-licensed FOSS open source. As a result, there's a huge ecosystem of folks building commercial solutions on Matrix. But surprisingly little $ actually gets back to Element (or the Matrix Foundation) from those commercial solutions, if any.

I don't have any proof but I'm certain Germany must have made some sort of funding for matrix https://matrix.org/blog/2021/07/21/germanys-national-healthc...

It's disappointing that Germany decided to go their own way rather than joining DirectTrust and working on the Trusted Instant Messaging Plus open industry standard. It's specifically designed for healthcare.

https://directtrust.org/standards/tim-plus

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#254
post #68

Earlier quoted context omitted.

it's on the EU to negotiate an agreement with the US Wouldn't it be equally on the US to negotiate an agreement with the EU to maintain the global dominance their tech sector currently enjoys? I don't see a categoric reason why the EU should blink first.

The EU's relevance and clout is notoriously overestimated, particularly when it comes to the digital economy. There's this pipe dream that GDPR would somehow jumpstart a privacy-focused digital economy with viable alternatives to US-based services, cloud providers in particular. By and large, these ideas so far have proven to be unrealistic, delusional even. Let's consider the possibly ways this might play out: 1. Th…

You may have a better insight into this, but could you elaborate a little further? Is entirety of EU running everything on AWS the way US seems to be and thus making it a vulnerable monoculture of sorts? For example, I can see some heavily digitized countries suffer( Germany, Estonia ), but not all of them seem that independent of paper documentation.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#255
post #129

Earlier quoted context omitted.

For the same reasons you're not allowed to sign particular contacts, such as enslaving yourself. Without restriction companies will do every illegal thing they can get away with via their collective power of size versus your weak individualism. In some cases it's rather trivial, in other cases its dependent on the survival of the nation state to enforce the rules on the corporation.

Hmm that is a good point. It is forbidden to sign contracts of enslavement in every country I know of, even if the potential contractee is making it free from duress. Therefore forbidding some types of contracts for everyone does have established precedent. However, there does not appear to be a limit to this. For example, can governments ban their residents from signing contracts to distribute or host porn, gambling…

They could, but at the risk of losing public mandate, leading to a change of government and/or losing in the next elections.

In somewhat functional representative democracies, that is.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#256

Statement from Microsoft https://news.microsoft.com/de-de/microsoft-erfuellt-und-uebe... [in German]

English version (PDF): https://news.microsoft.com/wp-content/uploads/prod/sites/40/...

> "For greater transparency, we would welcome the publication of the detailed DSK report, with appropriate redaction, alongside the detailed responses Microsoft had provided the DSK."

Redactions? How should the data owners be able to verify Microsofts processes if some of the information is redacted?

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#257

Earlier quoted context omitted.

A few billion is no problem. Simply collect the GDPR defined maximum fine of 4% of total global revenue from Microsoft, and use that to build the alternative. Provide that solution for self-hosting, so the cost of the infrastructure is payed for by the user organizations.

Why would Microsoft (or Google, or anyone) continue to operate in Europe in that model? Seems like a recipe to go from an imperfect tech solution to none at all.

No post body was provided.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#258
post #163
post #100

Earlier quoted context omitted.

Right? European policy makers should look to determine what incentives they encourage that generates this fairly common attitude.

Maybe they just cater to their electorate. Democracy etc.

Did the electorate vote on gdpr directly?

If so, I stand corrected.

If not, it was performed by representatives whose incentives are not aligned to the electorate (see Arrows impossibility theorem).

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#259

Earlier quoted context omitted.

And what would be the alternative? LibreOffice with its 90s UI/UX?

I wish I had ms office with its 90s UI/UX instead of whatever garbage it evolved into.

I prefer LibreOffice Calc to Excel thanks to the sane 90s UI/UX as well.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#260

Earlier quoted context omitted.

For some reason it's a big national security concern when Chinese companies collect data on US citizens, but when Europeans apply the same caution with American companies, people across the Atlantic see it purely from a business perspective. Why is that? This isn't TikTok and what people do on their private phones. This is a foreign company that has the capability to siphon off a lot of data about business decisions,…

> Why is that? because china is a totalitarian country and the us isn't

From many European capitals perspective, the USA is one wrong election away from fascism.
Post reply on HN