Live data from Hacker News

German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

twitter.com

331–340 of 346 posts

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#331
post #301

Earlier quoted context omitted.

How does FOSS make gdpr compliance easier?

It is not the main point I am trying to make, but FOSS may be hosted in the same country by an entity whose business is integration and support. The main point I am trying to make, though, is that investing in software that can be used and improved by anyone is (IMO) the appropriate allocation of tax money. Right now, the money is used on licenses (and, of course, support). What if it was used on development (and sup…

Your suggestion boils down to developing a business based on deploying and supporting a software product they can neither control nor own. 'Improved by anyone' tends to mean improved by no one who has a real stake in the product.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#332
post #140

Earlier quoted context omitted.

You could look into NextCloud and their NextCloud Office if you haven't heard of it yet. If you have are there any point that speak against it in your opinion? It's open source so you can even self host. Should be more than enough for most comapnies. Not sure how difficult the set-up process for an enterprise environment is, I only used the docker version before. But should be viable and if a company has Money for Mi…

I think you underestimate how many industries have software that integrates with office and cannot be easily replaced, if at all.

> industries have software that integrates with office and cannot be easily replaced, if at all.

It's just a question of money.

Having the US spy on Europeans is also very costly.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#333
post #132

Earlier quoted context omitted.

Is that before or after they send the content of you powerpoint file?

If you're referring to the article posted last week, you need to read more than just the headlines

Care to elaborate, instead of providing 'headline'?

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#334
post #14

Problem as always is, it's all talk and (almost) zero enforcement in Germany. Complaints to a data protection official take forever, are usually dismissed at first, even if counter to published opinions or decisions such as TFA. And only if you still care after a few years of waiting and at least one appeal you might get a decision, however usually a very cheap one for the perpetrator.

GDPR fines can be massive, look at the list here: https://www.enforcementtracker.com/ (sort by the fine amount)

It's not massive at all when you compare the fines to the profits of this companies.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#335
post #333

Earlier quoted context omitted.

If you're referring to the article posted last week, you need to read more than just the headlines

Care to elaborate, instead of providing 'headline'?

Microsoft is phoning home the content of PowerPoint slides: https://news.ycombinator.com/item?id=33506576

I suppose I should've said 'read the comments' considering that the particular post is very short.

https://news.ycombinator.com/item?id=33506844

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#336

Earlier quoted context omitted.

Microsoft products haven't really changed in 20 years. What are you referring to? The fact that you can access them anywhere?

Can you clarify your usage of Office products? I'm assuming that 100% of people saying "it's fine we have LibreOffice" or "it's fine we have Office 2014 installed locally" don't use it beyond basic PowerPoints and the occasional resume update on Word. Just as an example, the world pretty much runs on Excel, and each version brings valuable additions.

Good guess! I use PowerPoint and word. I occasionally use excel for a quick spreadsheet but for data storage we have databases and for visualisation we have grafana. The only time I use the live edit feature of excel is when we are coordinating pizza orders.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#337

Earlier quoted context omitted.

I've found these cloud editing solutions great for working with your colleagues but terrible for collaborating externally. You can't share a doc with their company for policy reasons and likewise they can't share with you. I've resorted to sending docx back and forward instead.

> I've found these cloud editing solutions great for working with your colleagues but terrible for collaborating externally. You can blame this on your O365 admins rather than Microsoft. For admins who want to generally restrict external sharing, it can even be limited to select Document Libraries. https://learn.microsoft.com/en-us/microsoft-365/solutions/co...

It is admins that are to blame, but not making easy for an end user to get permission to share something is on Microsoft.

Also not just Microsoft is at fault. Using Google docs to share with a company that doesn't have Google docs is just as painful.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#338
post #8

Earlier quoted context omitted.

We regularly discuss GDPR matters in our German company because there's a lot of FUD concerning the various cloud platforms and we have to cater to sensitive customers with our own hosting. One extreme is that you can't use AWS at all because of Schrems and it's a US compancy etc. On the other hand there's some hearsay about Microsoft (Azure) being tolerated because there's no way around it.

Imho, the "FUD" is largely right and most cloud platforms are indeed illegal. However, due to enforcement being absent or taking ages, there are too few legal decisions and big expensive enforcement actions that one can point to. Currently everything is really still fear, uncertainty and doubt, the hammer hasn't come down yet. I'm not sure if it ever will, at least not before EU institutions or other member states su…

It's a bit tedious to work in that climate of uncertainty. Every time we want to use some AWS service it prompts endless discussions.

On the other hand it made us research and use European alternatives such as Hetzner (they have a cloud too, although with less SaaS offerings), OVH or Scaleway.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#339
post #97

Is it me or does Germany switches (back?) to open-source every few years? I remember being excited they were switching to Linux (or was it Munich?) years ago

It was Munich - and it only happened once.

I shared the excitement, but as so often it was only executed half-way. In essence, instead of recreating processes from the ground up to fit the new reality, they tried to make everything as beforehand. Unsurprisingly, that was a huge uphill battle - in the end they spend more money than beforehand and had a lot of trouble in maintenance etc.

(Regarding the 2020 public announcement; nothing has happened since then IIRC so I would not count that in - just talk no actions)

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#340
post #253

Earlier quoted context omitted.

I don't have any proof but I'm certain Germany must have made some sort of funding for matrix https://matrix.org/blog/2021/07/21/germanys-national-healthc...

It's disappointing that Germany decided to go their own way rather than joining DirectTrust and working on the Trusted Instant Messaging Plus open industry standard. It's specifically designed for healthcare. https://directtrust.org/standards/tim-plus

Looks like it's based on the established and mature standard XMPP. Not disappointing to me.
Post reply on HN