Live data from Hacker News

German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

twitter.com

261–270 of 346 posts

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#261

Earlier quoted context omitted.

Don't know about Norway. But whether fines apply to public institutions is up to the member states, and most member states, including Germany, have decided not to fine their public institutions for GDPR violations.

> have decided not to fine their public institutions for GDPR violations Because they’re too Byzantine to make enforcement practicable, or because they’re not seen as a privacy risk (the government in Germany should know lots about you), or something else?

The official argument is that fining public institutions is a game of taking from the right pocket to put in the left pocket. It's the state fining itself. Also, officially, public servants are thought to obey the law as a matter of cause. A certain interpretation of the law can just be made an official order to all subordinate government agencies, and any civil servant disobeying that interpretation is at fault for not performing their duties and treated accordingly.

However, that all leads to the obvious workarounds: the official interpretation is usually the most lenient possible, compliance is put off to some time next century due to lack of personell/budget/willpower. And if something is found to be amiss, the data protection officer may order a government agency to fix whatever is wrong, but can neither fine nor discipline a civil servant. Because disciplining is up to the direct disciplinary superior, which cannot be (due to them being independent) the data protection officer.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#262
post #50

My personal favorite outcome of this would be a joint public and corporate funded leap in open source development. This would do much for the budget, privacy and probably also security of businesses and private users. A good example where this principle is already in use is the Matrix protocol.

This is a pipe dream not based in reality. Open source isn't all upside with no down and that is why co.mercial software still dominates and will unless someone decides to take the hit and carry the load for those downsides. Besides, in terms of MS365 there is the added problem that there is no good alternative. There are some reasonable alternatives for individual instances but not for the delivers of using 365.

No post body was provided.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#263
post #76

Earlier quoted context omitted.

I don't disagree that finding alternatives will be expensive, but I think this is the same harmful thinking we have in the US where people disagree with regulation that adds necessary protection at the cost of business. So we have a "regulation is bad" mindset. Most prominently I wish we could convince companies here to believe handling/retaining unnecessary data is like handling something radioactive. Until we convi…

Absolutes are often bad (i.e., zero tolerance). And many regulations are absolutes. It isn't enough to comply with the law as written, you have to comply with the strictest interpretation that a judge may come up with. And that may not be enough, because some court may be even more creative in their interpretation. Also often times business like regulation, as it forces all their competitors to play on the same playi…

Yes. Without careful stewardship, the compliance becomes a very weird dance, where regulators might focus on things that actually undermine the original intent of the law. For different example, lets look at the BSA front in US banking system, where SARs as a system was developed primarily to assist LEOs, but due to overzealous enforcement by various regulators, banks effectively threw their hands in the air and collectively said "Fine, we will report everything." ( look up defensive SAR filing if you are curious about the details). And now we are in a weird situation where LEOs have to sometimes say things like "If you file it, make it stand out and tell us why it matters so that we can use it"(paraphrased).

Unintended consequences of good intentions.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#264

Earlier quoted context omitted.

I genuinely don't understand why anyone would need MS products ever. I thought it was just hard lobbying that made it so our instituitions have to use that garbage.

And obviously your opinion is not at all biased by the fact that you are a software developer working on Linux. This propensity of developers to reject the existence of everything that they cannot see through their own tiny lens is beyond laughable.

"reject the existence"? What are you on about? I had to use MS office all my life and it has always been a very poor user experience, I wished I wasn't forced to use it and now maybe people won't be.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#265

Earlier quoted context omitted.

And obviously your opinion is not at all biased by the fact that you are a software developer working on Linux. This propensity of developers to reject the existence of everything that they cannot see through their own tiny lens is beyond laughable.

"reject the existence"? What are you on about? I had to use MS office all my life and it has always been a very poor user experience, I wished I wasn't forced to use it and now maybe people won't be.

> I had to use MS office all my life

Ah, so actually it wasn't true when you were saying "I genuinely don't understand why anyone would need MS products ever"?

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#266
post #140

Earlier quoted context omitted.

You could look into NextCloud and their NextCloud Office if you haven't heard of it yet. If you have are there any point that speak against it in your opinion? It's open source so you can even self host. Should be more than enough for most comapnies. Not sure how difficult the set-up process for an enterprise environment is, I only used the docker version before. But should be viable and if a company has Money for Mi…

I think you underestimate how many industries have software that integrates with office and cannot be easily replaced, if at all.

With Office or Office 365?

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#267

Earlier quoted context omitted.

A few billion is no problem. Simply collect the GDPR defined maximum fine of 4% of total global revenue from Microsoft, and use that to build the alternative. Provide that solution for self-hosting, so the cost of the infrastructure is payed for by the user organizations.

Why would Microsoft (or Google, or anyone) continue to operate in Europe in that model? Seems like a recipe to go from an imperfect tech solution to none at all.

Because there is a market in Europe they can service.

Microsoft and Google are not shoestring budget bootstrapped startups - they can afford to run multiple products, or multiple variants of the same product adjusted for market need, and they will do it, as long as it's net profitable for them. Sure, it's nicer to earn X than X/2 or X/10, but as long as it's a positive amount, it's still worth doing.

That is, as long as it's more profitable to do it by the books than what a lot of industry players did so far, which is to spend money on malicious compliance and sabotaging GDPR.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#268
post #258
post #163

Earlier quoted context omitted.

Maybe they just cater to their electorate. Democracy etc.

Did the electorate vote on gdpr directly? If so, I stand corrected. If not, it was performed by representatives whose incentives are not aligned to the electorate (see Arrows impossibility theorem).

More direct democracy would be nice.

However, as a citizen of EU member, I’d say GDPR pretty well aligns with the general notion of the people.

Sometimes people ain’t happy when government uses GDPR as a scapegoat to keep iffy data private. E.g. hiding final beneficiaries of companies. But I don’t see people unhappy that GDPR prevents crappy software practices.

Same deal as credit cards. Here in Europe cards processing fees are capped. Thus we don’t have US-style kickbacks or points programmes. Which probably limits credit card issuers innovations and business models. But I don’t see people complaining about that.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#270

Earlier quoted context omitted.

For some reason it's a big national security concern when Chinese companies collect data on US citizens, but when Europeans apply the same caution with American companies, people across the Atlantic see it purely from a business perspective. Why is that? This isn't TikTok and what people do on their private phones. This is a foreign company that has the capability to siphon off a lot of data about business decisions,…

> Why is that? because china is a totalitarian country and the us isn't

Imagine things would move towards every electronic document in American companies going through the servers of a European country, say in France. Do you really believe, there wouldn't be an outcry in Washington? Do you really believe, Congress would just watch? Do you really believe, US security agencies would just sit idly by? I don't.

This has nothing to do with totalitarian countries. Regardless of the political system, this is about a loss of control. About industrial espionage. Ask anyone who's work concerns US national security how much they trust foreign democries, like for instance France.

Post reply on HN