Live data from Hacker News

German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

twitter.com

31–40 of 346 posts

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#31

Earlier quoted context omitted.

I wish I had ms office with its 90s UI/UX instead of whatever garbage it evolved into.

Office 95 works on Windows 11: https://www.youtube.com/watch?v=_jSfIroiFdA So you can buy a copy of your favourite old Office version on eBay or whatever and use that.

going from obscure binary to zipped xml was the one good improvement one would miss out on.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#32

Earlier quoted context omitted.

It would really depend on the situation to be decided, whether MS would have to pay up, or rather the company using MS products to handle customer data. One can imagine a way to use MS products that might not be illegal, e.g. never use it to process personal data, use anonymized accounts that are not bound to a real person, swap around accounts and computers to prevent association with a person, etc. Then, all it wou…

That’s a good point: The use of general-purpose tools like Excel is by essence non-GDPR compliant, since there is no way to mark a column as “person” and therefore attach it to that person’s rights. Therefore, all corporate tools must be specific for one purpose when managing PII, and no tool should allow free-text fields. Excel, Access, notepads shouldn’t exist in companies.

How is that different from a sheet of paper?

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#33

At this points, isn't it pretty safe to assume very few Silicon Valley services conform to GDPR? Another example was shared recently: Shopify is technically illegal in Germany [1] [1] https://news.ycombinator.com/item?id=33561222

At this point, virtually no digital service - or in fact in business - can be considered to be compliant with GDPR. The reason for this is an ECJ case ruling informally known as Schrems II (https://www.gdprsummary.com/schrems-ii/ ).

That ruling not only invalidated the Privacy Shield agreement, but in fact prohibits the transfer of any data to any company affiliated with a US-based company in any way (including subsidiaries or even mere suppliers or customers), which comprises pretty much every company out there - US-based or not - because in today's globalized economy you'd be hard-pressed to find a company that doesn't in some way at least transitively deal with US-based companies.

Technically, the reason for this is the US CLOUD Act (https://en.wikipedia.org/wiki/CLOUD_Act ), which requires US-based companies to hand over any data, regardless of where that data is stored geographically. This also means that the common naïve assumption that you're safe in terms of GDPR as long as your data is stored in EU-based data centres is false as well.

So, when following GDPR and this court ruling to the letter, we'd (as in "everyone") pretty much have to stop trading and doing business altogether. Since that's (hopefully) not going to happen, none of this is enforced, at least not consistently or according to the rule of law (which in a way is even worse because at that point law and law enforcement becomes arbitrary and fines will be imposed based on how eagerly local authorities pursue these matters rather than universal principle).

Now, it can be argued that the EU and GDPR really aren't to blame because it's the US CLOUD Act that created this issue, after all. That CLOUD Act indeed is hugely problematic, to say the least.

However, the problem remains and it's on the EU to negotiate an agreement with the US that allows companies to legally do business in the real world (as opposed to an ideal world according to GDPR) again.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#34

Earlier quoted context omitted.

It's available to download at libreoffice.org

Ms office is available to download 'at libreoffice.org'?

They're joking that LibreOffice looks like MS Office in the 90's

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#36

Earlier quoted context omitted.

It would really depend on the situation to be decided, whether MS would have to pay up, or rather the company using MS products to handle customer data. One can imagine a way to use MS products that might not be illegal, e.g. never use it to process personal data, use anonymized accounts that are not bound to a real person, swap around accounts and computers to prevent association with a person, etc. Then, all it wou…

That’s a good point: The use of general-purpose tools like Excel is by essence non-GDPR compliant, since there is no way to mark a column as “person” and therefore attach it to that person’s rights. Therefore, all corporate tools must be specific for one purpose when managing PII, and no tool should allow free-text fields. Excel, Access, notepads shouldn’t exist in companies.

The point isn't about the tool, it's about where and by whom the tool is run.

Office 365 is cloud based, that's what makes it potentially non-compliant. Having Excel in your company, on your computer, and the data never leaves that computer is a totally different scenario.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#37
post #7

Earlier quoted context omitted.

It could lead to billions in fines for Microsoft. Up to 4% global revenue - for each EU country.

It would really depend on the situation to be decided, whether MS would have to pay up, or rather the company using MS products to handle customer data. One can imagine a way to use MS products that might not be illegal, e.g. never use it to process personal data, use anonymized accounts that are not bound to a real person, swap around accounts and computers to prevent association with a person, etc. Then, all it wou…

Microsoft can already claim that you can use Excel legally by only ever using it as an expensive calculator or table layout generator.

A theoretical methodology to do so is not enough to make their spyware legal.

There are alternative products that can do almost everything Excel does in almost every real life company without consuming data like the Very Hungry Caterpillar. It's up to them to prove why they need all that data that others don't need, and in what specific ways this data is used for the good of the customer.

Microsoft will need to act and change to solve this problem.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#38

This will have absolutely zero impact. Everybody knows you must use Microsoft products and if those don't comply with regulations, the regulations will have to change...

And what would be the alternative? LibreOffice with its 90s UI/UX?

LibreOffice has a ribbon these days. There are several ways to run it in the cloud with simultaneous editing. I don't know what the default UI settings are like these days, but the UI design is quite comparable to Office.

I suppose Office went "everything is flat and coloured rectangles" but I don't think that's necessarily a good thing.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#39
post #7

This will have absolutely zero impact. Everybody knows you must use Microsoft products and if those don't comply with regulations, the regulations will have to change...

It could lead to billions in fines for Microsoft. Up to 4% global revenue - for each EU country.

When did it change to be each EU country rather than one member state's regulator taking the lead in the case?

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#40

These people keep acting like they're so clever for figuring this out, yet in reality all they're doing is giving death sentences to European companies by making them unable to use industry standard products.

People think this will hurt MS, but in reality it will also make doing business in Europe more expensive. Almost all big companies use M365.

It will keep these already slow organizations busy trying to find and implement alternatives. Instead they could focus on growing their businesses.

Good luck Europe.

Post reply on HN