Live data from Hacker News

German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

twitter.com

81–90 of 346 posts

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#81
post #44

Earlier quoted context omitted.

Or it will force the European market to innovate instead of directly sending cash to US Megacorps.

Works very well for Cuba and North Korea

Both China and Russia eschewed US tech and they have much, much healthier tech industries than Europe.

The US also doesn't really believe in foreign competition ("Buy American", recent huge industrial subsidies as part of the IRA), so I don't really know if Europe should kowtow to the US here. If the US gave up on the CLOUD act none of this would be a problem anyway.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#82
I would argue it's basically impossible to have an internet connected app that does not run afoul of GDPR in one way or another. It's really just a question of how much of GDPR can you comply with at a reasonable cost or a better strategy is to do your best to comply with the spirit of GDPR, if not the letter.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#83

Earlier quoted context omitted.

Yes. But there is too few of them, and usually in situations where other companies can still wait and see. "We aren't Facebook", "We are too small to be noticed" and "but we had them sign a waiver" are still prevalent in most companies. For things to change, there would really need to be something like: - data protection fines the whole of the customer list of Amazon/Google/MS cloud - data protection fines a high-pro…

> - a court forces a public institution to cease using Office365 (no fines possible there) AFAIK, in Norway, most fines have been directed at public institutions.

Don't know about Norway. But whether fines apply to public institutions is up to the member states, and most member states, including Germany, have decided not to fine their public institutions for GDPR violations.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#84
post #50

My personal favorite outcome of this would be a joint public and corporate funded leap in open source development. This would do much for the budget, privacy and probably also security of businesses and private users. A good example where this principle is already in use is the Matrix protocol.

Getting the balance of this right to prevent a tragedy of the commons turns out to be hard. Element (who funds most of Matrix dev) has released almost everything we do as permissive-licensed FOSS open source. As a result, there's a huge ecosystem of folks building commercial solutions on Matrix. But surprisingly little $ actually gets back to Element (or the Matrix Foundation) from those commercial solutions, if any.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#85
post #44

Earlier quoted context omitted.

Or it will force the European market to innovate instead of directly sending cash to US Megacorps.

I totally agree with you. I think the EU should innovate more, than just relying on the usual tech giants.

Everyone in Europe would like Europe to innovate more. Unfortunately every time European governments add more regulation they usually also make it harder to do that.

You need to find the sweet spot. Too little regulation is harmful. Too much regulation is also harmful. The EU and US are near opposite ends of the spectrum at the moment and neither is an ideal place to be. The US produces many more financially successful big tech businesses but those businesses do a lot of things we don't like. The EU doesn't produce many successful big tech businesses in the first place.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#86
post #65
post #49

Earlier quoted context omitted.

I’m also European. Thanks for the insight. I don’t agree with you. So think about that next time you say “most Europeans”.

What's funny is that many Europeans I have spoken with from across the continent have the attitude that you come to the US when you are young to make money then retire to Europe to take advantage of the social safety net. Perhaps not yoir personal opinion, but definitely one that is anecdotally common among white collar workers.

That’s very unsustainable for Europe and great for the US since the latter gets the most productive years.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#87
post #50

My personal favorite outcome of this would be a joint public and corporate funded leap in open source development. This would do much for the budget, privacy and probably also security of businesses and private users. A good example where this principle is already in use is the Matrix protocol.

How does FOSS make gdpr compliance easier?

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#88
I don't really understand the GDPR, maybe because I'm not a lawyer.

For example, the GDPR states:

>An establishment's failure to designate an EU Representative is considered ignorance of the regulation and relevant obligations, which itself is a violation of the GDPR subject to fines of up to €10 million or up to 2% of the annual worldwide turnover of the preceding financial year in case of an enterprise, whichever is greater. The intentional or negligent (willful blindness) character of the infringement (failure to designate an EU Representative) may rather constitute aggravating factors.... Businesses must report data breaches to national supervisory authorities within 72 hours if they have an adverse effect on user privacy. In some cases, violators of the GDPR may be fined up to €20 million or up to 4% of the annual worldwide turnover of the preceding financial year in case of an enterprise, whichever is greater...

Why have neither of these been done? Speaking as an American who has spent his entire adult life advocating on these issues, it personally offends me when I basically get myself punted out of so called civil society trying to get a law like this enacted, and then our so called "allies" across the pond refuse to utilize it.

Here in "The States", folks used to joke "I'll believe corporations are people when they execute one in Texas"... given the EU's views on the death penalty, maybe some of these companies should be given what the Chinese would call "death with a suspended sentence"[1] -- fine them the full two to four percent, and use that money to fund things like universal health care, pensions, and the rebuilding of critical infrastructure instead of... well, based on my last trip to Tim Hortons[2], it looks like the new hotness is building a buncha condos that sit empty and drive up the rents -- but it's been a while, so I'll let any Canadians who want to wander in below and give their thoughts the floor.

The above is what I like to call "venture socialism". It is not communism, it is not even really socialism, more just... republicanism. But I can understand why even that feels violent and oppressive to... some people.

[1] https://en.wikipedia.org/wiki/Death_sentence_with_reprieve [2] Fun fact: for many Americans, the cost of a passport, let alone an international vacation is out of bounds -- once you understand this, a lot of the past four to forty years begins to make sense.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#89

Problem as always is, it's all talk and (almost) zero enforcement in Germany. Complaints to a data protection official take forever, are usually dismissed at first, even if counter to published opinions or decisions such as TFA. And only if you still care after a few years of waiting and at least one appeal you might get a decision, however usually a very cheap one for the perpetrator.

> Problem as always is, its all talk and (almost) zero enforcement in Germany.

I have the exact opposite impression. Even in small start-up, every new external supplier will be judged whether the is any customer data processing in the US. People are super afraid of Google analytics. If you use the Google Fonts on your website you will get an cease and desist letter in no time from scummy lawyers. You pratically need an external company to manage your cookie banner because it is a legal risk.

Re: German privacy watchdogs conclude that Microsoft 365 is incompatible with GDPR

#90
post #50

My personal favorite outcome of this would be a joint public and corporate funded leap in open source development. This would do much for the budget, privacy and probably also security of businesses and private users. A good example where this principle is already in use is the Matrix protocol.

More likely, someone will figure out a corporate structure that makes the EU subsidiaries out of reach from the US government. It's obvious that eventually all US-based services will be declared in breach of the GDPR given the US stance on global surveillance.
Post reply on HN