Live data from Hacker News

German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

twitter.com

281–290 of 346 posts

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#281
post #50

My personal favorite outcome of this would be a joint public and corporate funded leap in open source development. This would do much for the budget, privacy and probably also security of businesses and private users. A good example where this principle is already in use is the Matrix protocol.

OpenOffice has been good enough for a while, but we're still here. I'm not sure what's missing for governments to adopt it, but the solution isn't just "more open source development." Something else is wrong.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#282

At this points, isn't it pretty safe to assume very few Silicon Valley services conform to GDPR? Another example was shared recently: Shopify is technically illegal in Germany [1] [1] https://news.ycombinator.com/item?id=33561222

From what I've seen at a few places I've worked (you'd know the names), regulatory compliance is good enough to make the auditor happy, but that's about it.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#283
post #253

Earlier quoted context omitted.

I don't have any proof but I'm certain Germany must have made some sort of funding for matrix https://matrix.org/blog/2021/07/21/germanys-national-healthc...

It's disappointing that Germany decided to go their own way rather than joining DirectTrust and working on the Trusted Instant Messaging Plus open industry standard. It's specifically designed for healthcare. https://directtrust.org/standards/tim-plus

It’s definitely unfortunate that there’s a schism between e2ee matrix and e2ee xmpp there.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#284
post #210

Earlier quoted context omitted.

I don't have any proof but I'm certain Germany must have made some sort of funding for matrix https://matrix.org/blog/2021/07/21/germanys-national-healthc...

> TI-Messenger is gematik’s technical specification for an interoperable secure instant messaging standard. The healthcare industry will be able to build a wide range of apps based on TI-Messenger specifications knowing that, being built on Matrix, all those apps will interoperate. The ones getting most of the money will probably be third-party developers integrating Matrix into their gematik-certified healthcare pro…

Ironically very little of the $ seems to be propagating back to Matrix itself…

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#285

Earlier quoted context omitted.

You can host it yourself on servers in the EU.

But most companies don't actually want to host things themselves. If they did, 'cloud computing' wouldn't be so popular.

Sure, but smaller EU-resident providers could do hosting for companies.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#286

Earlier quoted context omitted.

Getting the balance of this right to prevent a tragedy of the commons turns out to be hard. Element (who funds most of Matrix dev) has released almost everything we do as permissive-licensed FOSS open source. As a result, there's a huge ecosystem of folks building commercial solutions on Matrix. But surprisingly little $ actually gets back to Element (or the Matrix Foundation) from those commercial solutions, if any.

Which somewhat highlights the problem with "permissive" licences, as opposed to copyleft ones like AGPL.

the problem of AGPL for Matrix is that it would have likely impeded uptake significantly. But yes, it’s something we’ve considered.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#287
post #182

Tech will end up exactly the same way finance is (if it isn’t already there). Employees will work for the regulatory enforcement agency for around five years on shit pay learning how the system works from the inside and making contacts in the industry before leaving and being ushered into a tech firm with a nice six figure salary. Meanwhile, no regulations will really get enforced apart from the odd token case agains…

I've never seen such a cynical comment like this one here. On what basis are you theorizing this?

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#288

365 is the cloud base suite of Microsoft Office, you can still use the Microsoft Office 2021 Professional or older versions. 365 is a nice way of collaborate at work, if you are a small business is a nice product, for the big companies this is just going to be more headache for their I.T department, so now instead of relying in the Microsoft servers to allocate and store the documents, they will use any other server…

I've found these cloud editing solutions great for working with your colleagues but terrible for collaborating externally. You can't share a doc with their company for policy reasons and likewise they can't share with you. I've resorted to sending docx back and forward instead.

> I've found these cloud editing solutions great for working with your colleagues but terrible for collaborating externally.

You can blame this on your O365 admins rather than Microsoft. For admins who want to generally restrict external sharing, it can even be limited to select Document Libraries. https://learn.microsoft.com/en-us/microsoft-365/solutions/co...

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#289

Earlier quoted context omitted.

Microsoft 365 is extremely widespread in companies in the EU. Not because they love Microsoft but because this is a relatively simple setup. Like Google (US) or Zoho (Indian). I do not know European companies providing a cloud solution easy to deploy (I wild truly be glad to know one).

You could look into NextCloud and their NextCloud Office if you haven't heard of it yet. If you have are there any point that speak against it in your opinion? It's open source so you can even self host. Should be more than enough for most comapnies. Not sure how difficult the set-up process for an enterprise environment is, I only used the docker version before. But should be viable and if a company has Money for Mi…

I know NextCloud, for having self-hosted it for years, alongside many other similar software and having reviewed its code. I am a strong proponent of open source, both as a user and a developper - and managed IT for very large companies (thi si to bring some context to my comments).

While something like NextCloud or Seafile it is fine for personal use or for small teams it is no way close to something like Microsoft 365 with the extensive backend it provides out of the box. Not to mention email integration.

Again, this is from the perspective of someone who uses and develops open source software and hots a lot of services for personal/family ise, but also from someone who knows the complexity and shitbat crazy wrchitectures you find in large, distributed companies.

If we managed to have in Europe something similar to Zoho, driven by European laws, that would be fantastic. We do not, and this is a real shame.

> But should be viable and if a company has Money for Microsoft365 they should have money to pay to someone to set it up manage for them.

Microsoft 365 is expensive, but the expense of running a home-made solution for a large company is not only the pure management, but also the ability to have hope if there is a problem. I have raised issues for Nextcloud (some of them quite impacting from a security monitoring perspective) and the community replies were horrible. If NextCloud does not monitor the community forum when someone raises such issues then I cannot have any trust that they will fix it for a paying user.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#290

Earlier quoted context omitted.

The EU's relevance and clout is notoriously overestimated, particularly when it comes to the digital economy. There's this pipe dream that GDPR would somehow jumpstart a privacy-focused digital economy with viable alternatives to US-based services, cloud providers in particular. By and large, these ideas so far have proven to be unrealistic, delusional even. Let's consider the possibly ways this might play out: 1. Th…

You may have a better insight into this, but could you elaborate a little further? Is entirety of EU running everything on AWS the way US seems to be and thus making it a vulnerable monoculture of sorts? For example, I can see some heavily digitized countries suffer( Germany, Estonia ), but not all of them seem that independent of paper documentation.

As outlined above, simply having a US-based supplier or customer might be enough for a business to be in violation of GDPR.

Even if your entire business is offline and all your processes are still paper-based (which today would be highly unusual, even in less digitized countries such as Germany, where quite a few businesses actually still rely on paper and - indeed - fax for at least some of their processes), that might still be the case.

More realistically, any run-of-the-mill SMB will use at least some digital tools, e.g., for accounting or for running their website. Relying on EU-based suppliers and EU data centres exclusively or even going all the way and storing everything on-premises doesn't necessarily mean you're compliant with GDPR.

If only one of those EU-based suppliers has any dealings whatsoever with just one US-based company you're technically in violation of GDPR again.

Post reply on HN