Live data from Hacker News

German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

twitter.com

321–330 of 346 posts

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#321

Earlier quoted context omitted.

Everyone in Europe would like Europe to innovate more. Unfortunately every time European governments add more regulation they usually also make it harder to do that. You need to find the sweet spot. Too little regulation is harmful. Too much regulation is also harmful. The EU and US are near opposite ends of the spectrum at the moment and neither is an ideal place to be. The US produces many more financially successf…

I don't agree with everyone in Europe wanting to innovate more. I'm a Bulgarian citizen and from my PoV a small group of people only want to innovate. One good thing that I've noticed is that the snowball here is slowly spinning up - we have a good university trying to be on a IVY league level as much as it can (for Bulgarian levels it's good, for EU maybe just about average) which teaches people tech or whatever the…

Is it bad that companies don't innovate on the power outlets any more ?

(BTW, USB standards are up to 240W already, it would be a decent power cable itself alone if not for the fire / power loss / safety / cable size issues that DC causes...)

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#322
post #230

Earlier quoted context omitted.

What needs to be true about me and my website to possibly be subject to Abmahnungen? Does my website need to be hosted I'm Germany? Do I need to reside in Germany?

Probably a german address in the imprint. I can't imagine they'd bother with anyone abroad. They're just after easy money after all.

But if I have no imprint which is a common cause of the Abmahnungen? I am curious because I am a German citizen, but haven't lived there in a long time. Right now I just ignore all of that legal German stuff. What would need to change for me to worry? Moving residence to Germany? The server being there?

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#323

At this points, isn't it pretty safe to assume very few Silicon Valley services conform to GDPR? Another example was shared recently: Shopify is technically illegal in Germany [1] [1] https://news.ycombinator.com/item?id=33561222

At this point, virtually no digital service - or in fact in business - can be considered to be compliant with GDPR. The reason for this is an ECJ case ruling informally known as Schrems II ( https://www.gdprsummary.com/schrems-ii/ ). That ruling not only invalidated the Privacy Shield agreement, but in fact prohibits the transfer of any data to any company affiliated with a US-based company in any way (including subs…

The issue is older than that :

it dates back at least to the warrantless wiretapping authorized by Bush with the 2001 Patriot Act and legalized with the 2008 update of the US Foreign Intelligence Surveillance Act,

being incompatible with the 2000-2010 Charter of Fundamental Rights of the European Union,

making the 1998-2000 Safe Harbor agreements between the US and the EU null and void,

as first judged by the Court of Justice of the European Union in 2015 (Schrems I).

GDPR (2016-2018) and the CLOUD Act (2018) are basically just the EU and the US digging deeper into their respective positions.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#324

Earlier quoted context omitted.

Yes, I'm not defending the EU hypocrisy or their own hostile surveillance laws. However, keep in mind that this report mentioned many issues about MS's own processing purposes, policies, and practices, and wasn't only about the problems posed by US surveillance law. It's those MS-specific issues for which the Dutch government got fixes applied to Dutch private sector use of MS 365; naturally they haven't changed US s…

I think we probably agree on almost everything here. I'm not defending the corporate surveillance culture. On the contrary I think that should be the first target. I'm only saying that in politics you have to pick your battles if you want to make real progress instead of earning a ten second sound bite on tonight's news. The EU politicians aren't so good at that sometimes and the result is legal positions like Schrem…

Yeah, well the reason the Schrems II ruling is widely ridiculed with negligible compliance is not because of the ECJ ruling - it's the natural result of the legal status quo on both sides of the Atlantic and was predicted accurately by plenty of lawyers who weren't forced by their financial incentives to ignore the obvious.

It's ridiculed and ignored primarily because enforcement is irrelevantly rare and small in financial impact, just like enforcement of the rules around cookie consent and many other aspects of the GDPR. Companies calculate that true compliance costs more than pretending to comply plus occasional fines for not doing so. Therefore they don't implement the parts of true compliance under their own control, and don't feel a need to lobby politicians on either side of the Atlantic to fix the incompatibility between US surveillance law on the GDPR. Similarly, the politicians and regulators are okay pretending that new EU-US agreements with no real legal substance can solve the problem, such that nobody has to comply and the ECJ and Max Schrems stay busy spinning their wheels.

If this were different and the EU were actually enforcing the rules, either companies in the EU would have to stop using American providers - helping build a home-grown EU software industry without being crowded out by American providers - or US companies like MS would have to change what internal practices they can and lobby the US government to make the necessary legislative changes for them to fully comply with the GDPR.

To be honest, I don't think the EU politicians/regulators are bad at what they're trying to do. It's simply that what they're trying to do is to look tough on privacy while actually not pissing off the deep-pocketed megacorps and the politicians they can/do fund on either side of the Atlantic. Which is different than what I'd like them to do, of course.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#325

Earlier quoted context omitted.

For some reason it's a big national security concern when Chinese companies collect data on US citizens, but when Europeans apply the same caution with American companies, people across the Atlantic see it purely from a business perspective. Why is that? This isn't TikTok and what people do on their private phones. This is a foreign company that has the capability to siphon off a lot of data about business decisions,…

> Why is that? because china is a totalitarian country and the us isn't

From the point of view of the EU it is, since it violates basic (EU) rights of (at least) non-US citizens since 2001 :

https://news.ycombinator.com/item?id=33751805#33757090

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#326
post #196

I don't really understand the GDPR, maybe because I'm not a lawyer. For example, the GDPR states: >An establishment's failure to designate an EU Representative is considered ignorance of the regulation and relevant obligations, which itself is a violation of the GDPR subject to fines of up to €10 million or up to 2% of the annual worldwide turnover of the preceding financial year in case of an enterprise, whichever i…

From your own profile bio: "Only a fool would take anything posted here as fact."

I can change the bio to a quote more literary in a bit if that'll help you address my ideas instead of my reputation.

Folks seem to pick and choose when to take me seriously in the hacker scene, which is amusing considering rumor has it "Chapo Trap House" is a reference to what the portmanteau of DNS requests coming out of my college house share looked like to the local FBI field office during the Pittsburgh G20.

Spoiler alert: One guy was playing a lot of illegal poker, one guy was really into certain types of... free expression... and one was discovering the joys of democratic socialism as he did experiments on undergrads like Bill Murray at the beginning of Ghostbusters as he pirated everything on the IMDB Top 250. Guess which one was me, and you win a special prize.

(Also... don't do cocaine.)

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#327
post #196

I don't really understand the GDPR, maybe because I'm not a lawyer. For example, the GDPR states: >An establishment's failure to designate an EU Representative is considered ignorance of the regulation and relevant obligations, which itself is a violation of the GDPR subject to fines of up to €10 million or up to 2% of the annual worldwide turnover of the preceding financial year in case of an enterprise, whichever i…

From your own profile bio: "Only a fool would take anything posted here as fact."

I can change the bio to a quote more literary in a bit if that'll help you address my ideas instead of my reputation.

Folks seem to pick and choose when to take me seriously in the hacker scene, which is amusing considering rumor has it "Chapo Trap House" is a reference to what the portmanteau of DNS requests coming out of my college house share looked like to the local FBI field office.

(Spoiler alert: One guy was playing a lot of illegal poker, one guy was really into certain types of pornography, and one was discovering the joys of democratic socialism as he did experiments on undergrads like Bill Murray at the beginning of Ghostbusters... guess which one was me, and you win a special prize.)

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#328
post #313

Earlier quoted context omitted.

A few billion Euro? That's nothing even for a middle sized EU state. Considering the whole EU such costs would be a rounding error; even really hard to spot in the budget. But it would be an investment in domestic economy and a step towards independence form the empire. Should be a nobrainer therefore.

Let me put put it another way, that's just the start. You would effectively need the EU to operate a SaaS service and compete against MS. The money is hardly the issue, you can't just throw money at it or say the magic phrase "open source" it isn't for a lack of money that libreoffice is nowhere near excel for example, tech people would actually say it is pretty good without knowing how these apps are used. It is the…

> libreoffice is nowhere near excel

Really?

What does it lack (besides cloud lock-in, and compatibility with formats that are made in a way that it's impossible to be fully compatible).

> […] that will take a decade plus to even mature after you spent a ton of money and an army of devs and dev-support/mgrs.

You need to start somewhere.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#329
post #293

Earlier quoted context omitted.

Thanks! Macroexpanded: German state of Hesse has banned the use of Microsoft 365 in its schools - https://news.ycombinator.com/item?id=33741537 - Nov 2022 (115 comments) Germany Forces a Microsoft 365 Ban Due to Privacy Concerns - https://news.ycombinator.com/item?id=33741300 - Nov 2022 (11 comments) France bans Office 365 and Google Docs from schools and public administration - https://news.ycombinator.com/item?id=3…

The first one is a partial copy of the full article (and of a much bigger discussion) : German state of Hesse has banned the use of Microsoft 365 in its schools (techgenix.com) - https://news.ycombinator.com/item?id=33741537 - Nov 2022 (115 comments)

Thanks! I've added that one to the list.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#330
post #50

My personal favorite outcome of this would be a joint public and corporate funded leap in open source development. This would do much for the budget, privacy and probably also security of businesses and private users. A good example where this principle is already in use is the Matrix protocol.

OpenOffice has been good enough for a while, but we're still here. I'm not sure what's missing for governments to adopt it, but the solution isn't just "more open source development." Something else is wrong.

Who host it for the organization?

Who supports it when something goes wrong?

Who ensures there are a wide base of users trained to use it?

How good are the transition resources?

How much will it really cost to transition to the "free" option...

Post reply on HN