Live data from Hacker News

German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

twitter.com

271–280 of 346 posts

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#271
post #231
post #220

Earlier quoted context omitted.

Why haven’t Europeans been able to be successful in this area already? It’s not like there aren’t always European businesses working on this problem. It is striking that both the evil empire solution (Microsoft 365) and the underdog disruptive upstart (Google Docs, at least that’s what it was ~15 years ago) are both American companies. iWork is American, Zoho is Indian. Why aren’t Europeans producing competitive soft…

OpenOffice was German (Star Office).

And now the document foundation, which is behind LibreOffice (the active fork of the dead OpenOffice) is also german based. And they put a lot of work into it, also the modernisation. But to be honest, I am not sure, if they could ever become a serious competition. I think they would have to do a fresh UI start and be 100 microsoft office compatible. Then they would have a chance. With more official backing, this is maybe remotely possible, but I do not count on it. Rather political pressure for a slight modification for Microsofts operations for germany.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#272
post #89

Problem as always is, it's all talk and (almost) zero enforcement in Germany. Complaints to a data protection official take forever, are usually dismissed at first, even if counter to published opinions or decisions such as TFA. And only if you still care after a few years of waiting and at least one appeal you might get a decision, however usually a very cheap one for the perpetrator.

> Problem as always is, its all talk and (almost) zero enforcement in Germany. I have the exact opposite impression. Even in small start-up, every new external supplier will be judged whether the is any customer data processing in the US. People are super afraid of Google analytics. If you use the Google Fonts on your website you will get an cease and desist letter in no time from scummy lawyers. You pratically need…

> You pratically need an external company to manage your cookie banner because it is a legal risk.

Don't set cookies for visitors. Notify on signup for everyone else.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#273
post #180

Earlier quoted context omitted.

It's nothing, but once one of their customers gets a 5 millioj euro fine for using Office365 for sensitive data, the impact will be significantly higher. Microsoft can take the hit but most of its customers can't. Microsoft's incompatibility with the GDPR puts some of its customers at risk. A fine or two and businesses might stop paying for those lucrative cloud subscriptions.

This will literally, not figuratively, but -literally- never happen. A smaller business will never be punished as a signal to Microsoft.

The fine is not to send a signal to Microsoft. The fine is a punishment for letting Microsoft process personal information when it's know that they do so in a way that violates the GDPR.

The €100 fine to that one website that included Google Fonts wasn't an attempt to get Google to put Google Fonts in a European holding or whatever. That was never going to happen. It was to punish that website for breaking the law.

Before anything like this will hit the news, there would first be a massive lawsuit that will probably take months or years. I wouldn't be surprised if Microsoft would throw lawyer money to the company involved just to make sure the lawsuit doesn't end setting a precedent against their product.

Never underestimate German courts and their willingness to uphold privacy laws when they get challenged.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#274

Earlier quoted context omitted.

Why would Microsoft (or Google, or anyone) continue to operate in Europe in that model? Seems like a recipe to go from an imperfect tech solution to none at all.

Because there is a market in Europe they can service. Microsoft and Google are not shoestring budget bootstrapped startups - they can afford to run multiple products, or multiple variants of the same product adjusted for market need, and they will do it, as long as it's net profitable for them. Sure, it's nicer to earn X than X/2 or X/10, but as long as it's a positive amount, it's still worth doing. That is, as long…

The calculus changes when you’re being fined tens of billions of dollars that will be used to develop a competitor to your core product.

It’s not (X/2), it’s (X/2) - (NPV of future profits from giving X/2 to develop competition).

Your model would work for just an adaptation to a compliant product, but not to the proposed “just seize 4% of their global revenue and use that to fund a competitor” model that I was replying to.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#275

Earlier quoted context omitted.

Not being totalitarian implies no to spy on your people. Spying on your people implies being totalitarian. Pretty sure US agencies have more rights to spy on not-their people, e.g., Microsoft EU customer data than Microsoft US customer data.

Let's be real, no Western country is banning Chinese products or services because China is spying on their own citizens or abusing Uyghurs. That's at best the "feel good" story sold in the media to get the people's support and distract from other issues. They're banning them for 2 reasons. One is that China will abuse them to spy and get a competitive advantage over those other countries. The second is that it's hard…

You make it sound as if the GDPR is specifically targeted at US companies, which is not the case. It applies to domestic companies too.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#276
post #124

I'm not European, and maybe this is why I struggle to understand this, but why do people want regulators to say, "This doesn't comply with our regulations, so you aren't allowed to use it ?" I understand the hope is that companies will comply rather than forego the entire European market, but if they don't, the last consequence is ultimately on the consumer, not the company. It seems like the same type of thing as wh…

The EU has a population of nearly 450M. That's a sizeable market. You might imagine that Microsoft would like a piece of that and would be prepared to ensure that their products meet the standards required to earn it. They already go to some lengths to adapt their products to various locales and languages in order to compete in certain markets. Adapting Office365 to comply with EU law and gain access to that market w…

[deleted]

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#277

Earlier quoted context omitted.

"reject the existence"? What are you on about? I had to use MS office all my life and it has always been a very poor user experience, I wished I wasn't forced to use it and now maybe people won't be.

> I had to use MS office all my life Ah, so actually it wasn't true when you were saying "I genuinely don't understand why anyone would need MS products ever"?

Both are true, I was forced to use subpar solutions because MS paid a lot of money to become the default. I have no idea why anyone given the freedom to do so would choose MS products over alternatives.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#278
post #149
post #50

My personal favorite outcome of this would be a joint public and corporate funded leap in open source development. This would do much for the budget, privacy and probably also security of businesses and private users. A good example where this principle is already in use is the Matrix protocol.

There is already some work in progress to replace Office 365 with an free software stack for governments: https://www.phoenix-werkstatt.de

Ayayay, the list of partners does not really inspire confidence that this will be the fast success we'd need:

https://www.phoenix-werkstatt.de/#c2669

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#279
post #230

Earlier quoted context omitted.

What needs to be true about me and my website to possibly be subject to Abmahnungen? Does my website need to be hosted I'm Germany? Do I need to reside in Germany?

Probably a german address in the imprint. I can't imagine they'd bother with anyone abroad. They're just after easy money after all.

"Probably a german address in the imprint."

Just any adress. Their point is, it needs to be an physical adress - so in case someone wants to sue the website, they have somewhere to send the physical letters to.

In other words, many people got expensive physical letters, to make it in general easier for other people to send them expensive phyical letters.

But yes, as far as I know, this only affects germans. But once we control the EU, who knows.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#280

Earlier quoted context omitted.

How does FOSS make gdpr compliance easier?

You can host it yourself on servers in the EU.

But most companies don't actually want to host things themselves. If they did, 'cloud computing' wouldn't be so popular.
Post reply on HN