Live data from Hacker News

German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

twitter.com

311–320 of 346 posts

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#311

Earlier quoted context omitted.

What a depressing reality where hostile US corporate data privacy practices and hostile US surveillance law take de facto priority over the EU's own privacy legislation meant to protect its own residents. The EU has provisions for very similar "hostile surveillance law" in its own member states. It just gave them a get out of jail free card in the GDPR. There is a considerable amount of hypocrisy about the EU's posit…

Yes, I'm not defending the EU hypocrisy or their own hostile surveillance laws. However, keep in mind that this report mentioned many issues about MS's own processing purposes, policies, and practices, and wasn't only about the problems posed by US surveillance law. It's those MS-specific issues for which the Dutch government got fixes applied to Dutch private sector use of MS 365; naturally they haven't changed US s…

I think we probably agree on almost everything here. I'm not defending the corporate surveillance culture. On the contrary I think that should be the first target.

I'm only saying that in politics you have to pick your battles if you want to make real progress instead of earning a ten second sound bite on tonight's news. The EU politicians aren't so good at that sometimes and the result is legal positions like Schrems II that are so impractical that they are widely ridiculed and compliance is negligible.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#312
post #50

My personal favorite outcome of this would be a joint public and corporate funded leap in open source development. This would do much for the budget, privacy and probably also security of businesses and private users. A good example where this principle is already in use is the Matrix protocol.

Getting the balance of this right to prevent a tragedy of the commons turns out to be hard. Element (who funds most of Matrix dev) has released almost everything we do as permissive-licensed FOSS open source. As a result, there's a huge ecosystem of folks building commercial solutions on Matrix. But surprisingly little $ actually gets back to Element (or the Matrix Foundation) from those commercial solutions, if any.

Agreed. Ideally, the official policy should be introduced to either fund or contribute to FOSS used.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#313
post #162

Earlier quoted context omitted.

Forget the migration costs just to develop and standup the cost and infra would be a few billion euros just for one O365 app. I don't think people understand how much O365 apps are used. Nobody is filing github issues either with this, you need to do commercial and customer support, basically replace a core MS SaaS product but not with some shitty idealistic hack because the economic consequences are dire!

A few billion Euro? That's nothing even for a middle sized EU state. Considering the whole EU such costs would be a rounding error; even really hard to spot in the budget. But it would be an investment in domestic economy and a step towards independence form the empire. Should be a nobrainer therefore.

Let me put put it another way, that's just the start. You would effectively need the EU to operate a SaaS service and compete against MS. The money is hardly the issue, you can't just throw money at it or say the magic phrase "open source" it isn't for a lack of money that libreoffice is nowhere near excel for example, tech people would actually say it is pretty good without knowing how these apps are used.

It is the digital equivalent of replacing all cars of a certain make that everyone uses for critical business functions and replacing them with your own line of cars that will take a decade plus to even mature after you spent a ton of money and an army of devs and dev-support/mgrs.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#314

Earlier quoted context omitted.

Investments in that area would be investment into European open source development as a whole and European IT in general. Businesses can spring up around such efforts, people can find employment, technology can be developed, and the European market could be strengthened.

Are business allowed to use M365 if all of this open source investment fails to produce an equal-or-better solution? Or are businesses forced to operate with the result even if it’s terrible?

I’ll take the strawman. Of course, the software would not be forced upon businesses. Commercial solutions that protect people’s data properly should be perfectly fine to use. I’d even expect many proprietary solutions to come up that solve niche use cases or provide a more polished UX/UI.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#315
post #162

Earlier quoted context omitted.

Forget the migration costs just to develop and standup the cost and infra would be a few billion euros just for one O365 app. I don't think people understand how much O365 apps are used. Nobody is filing github issues either with this, you need to do commercial and customer support, basically replace a core MS SaaS product but not with some shitty idealistic hack because the economic consequences are dire!

Investments in that area would be investment into European open source development as a whole and European IT in general. Businesses can spring up around such efforts, people can find employment, technology can be developed, and the European market could be strengthened.

EU market would also weaken because they lose the competitive advantage of O365, even google workspace would be better. O365 (or its replacement) is as important as diesel and gasoline to the economy!

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#316
post #132

Statement from Microsoft https://news.microsoft.com/de-de/microsoft-erfuellt-und-uebe... [in German]

Is that before or after they send the content of you powerpoint file?

If you're referring to the article posted last week, you need to read more than just the headlines

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#317

Earlier quoted context omitted.

Leave you alone to determine your own health code? To buy meat without proper paperwork? To hire children to work? Where is the border?

I think what parent is trying to say that at certain point over-regulation is not helpful and actually detrimental not just to the business, but the ecosystem as a whole. For a smaller business, onerous regulation could mean closing the doors. For a big business, the burden is also there, but it can more easily withstand it due to its size ( and it typically has some resources to throw at a given issue ). I agree tha…

What parent forgot to mention is that (from what I managed to find out) law 96 doesn't apply to businesses with less than 25 employees. Down from less than 50 in the previous law (though I'm not certain what other changes might have been made).

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#318
post #97

Is it me or does Germany switches (back?) to open-source every few years? I remember being excited they were switching to Linux (or was it Munich?) years ago

You are more or less. LiMux started in 2004. Last two points on its long timeline[0]: * November 2017 - The city council decided that LiMux will be replaced by a Windows-based infrastructure by the end of 2020. The costs for the migration are estimated to be around 90 million Euros. * May 2020 - Newly elected politicians in Munich take a U-turn and implement a plan to go back to the original plan of migrating to LiMu…

You forgot the quite important

September 2016 - Microsoft moves its German headquarters to Munich

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#319
post #89

Earlier quoted context omitted.

> Problem as always is, its all talk and (almost) zero enforcement in Germany. I have the exact opposite impression. Even in small start-up, every new external supplier will be judged whether the is any customer data processing in the US. People are super afraid of Google analytics. If you use the Google Fonts on your website you will get an cease and desist letter in no time from scummy lawyers. You pratically need…

> You pratically need an external company to manage your cookie banner because it is a legal risk. Don't set cookies for visitors. Notify on signup for everyone else.

> Notify on signup for everyone else.

You don't need notifications for purely functional cookies. If you have a Nextcloud instance that only uses a cookie to remember your user identity throughout a login session, no notifications are required. If you also feed the value of the Nextcloud cookie into a tracking system, that's when a notification is required. And only then.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#320
post #21
post #14

Earlier quoted context omitted.

GDPR fines can be massive, look at the list here: https://www.enforcementtracker.com/ (sort by the fine amount)

So 3 enforcements in Germany in all of 2022, and the highest fine in Germany was 35mil. 35mil is how much for Microsoft? The yearly Office 365 fees of one of their DAX customers?

The big fish all have their EU branches incorporated in Ireland for tax reasons. Filter by Ireland and you'll see some larger fines and some more well-known company names. And even then, it's a well-known contention within the EU that the Irish data protection authority is dragging their feet on investigations and fines because of the "tax reasons" part.
Post reply on HN