Everybody knows you must use Microsoft products and if those don't comply with regulations, the regulations will have to change...
Everybody knows you must use Microsoft products and if those don't comply with regulations, the regulations will have to change...
Therefore, all corporate tools must be specific for one purpose when managing PII, and no tool should allow free-text fields. Excel, Access, notepads shouldn’t exist in companies.
Office 365 is cloud based, that's what makes it potentially non-compliant. Having Excel in your company, on your computer, and the data never leaves that computer is a totally different scenario.
A theoretical methodology to do so is not enough to make their spyware legal.
There are alternative products that can do almost everything Excel does in almost every real life company without consuming data like the Very Hungry Caterpillar. It's up to them to prove why they need all that data that others don't need, and in what specific ways this data is used for the good of the customer.
Microsoft will need to act and change to solve this problem.
I doubt the EU can prevent MS365 from being used, and MS can say "we aren't paying a fine here. Ever. Good luck with it."
Who will succeed? No idea.
TBH, i used to work at a bank (and now at an energy company), and anecdotal evidence i have is that no big business use M365 cloud services(2 for 2 now). At least not in the IT departement, even where we have people using access to mash .xlsx together and get actionnable data from it.
[edit] I must add that the bank used azure (as an AWS backup mostly), and still, we had no M365 product installed on our microsoft computer.
I'm not a hater or anything, i do have a FOSS bias, but i try to stick to the facts here.
So you can buy a copy of your favourite old Office version on eBay or whatever and use that.
I suppose Office went "everything is flat and coloured rectangles" but I don't think that's necessarily a good thing.
Basically separation of encryption and decryption key in a location other then azure for example.
Nobody cared, nothing happened. People still store both in azure.
As long no one gets fined ( here companies) nothing will happen
They have more power over MS than they think if they're willing to exercise it, but they're mostly not willing. (Examples like the Dutch public sector do exist, where they were able to get different terms from MS that are more compliant with the GDPR, including effective audit rights that have successfully verified compliance with these terms.)
The EU has provisions for very similar "hostile surveillance law" in its own member states. It just gave them a get out of jail free card in the GDPR. There is a considerable amount of hypocrisy about the EU's positions on privacy and data protection.
The trouble with this whole subject is that you get grandstanding politicians trying to make big statements that go so far that it becomes unrealistic to enforce them because you'd cause catastrophic economic and/or social damage. If you really want to improve things what you need is steady, incremental progress towards restricting unwanted invasions of privacy. You can start with the most invasive commercial spyware. After a while you have moved the Overton window so that the worst excesses of governments' own surveillance programmes start to become viable candidates for reform as well. Ideally you eventually move societies away from the politics of fear that motivates those kinds of mass surveillance laws but that doesn't seem likely any time soon.
And as bad as government surveillance is in both the EU and the US, it's awful when local companies send the data of the majority of their population into the jurisdiction of surveillance law whose political bosses the population can't even indirectly vote against.
This is rare in the US because US companies rarely send the data of US citizens to EU providers, which itself is because the big tech players are American. Whereas for exactly the same reason of where the big tech players are based, it's common for EU companies to send the data of EU citizens to US providers.
I'm only saying that in politics you have to pick your battles if you want to make real progress instead of earning a ten second sound bite on tonight's news. The EU politicians aren't so good at that sometimes and the result is legal positions like Schrems II that are so impractical that they are widely ridiculed and compliance is negligible.
It's ridiculed and ignored primarily because enforcement is irrelevantly rare and small in financial impact, just like enforcement of the rules around cookie consent and many other aspects of the GDPR. Companies calculate that true compliance costs more than pretending to comply plus occasional fines for not doing so. Therefore they don't implement the parts of true compliance under their own control, and don't feel a need to lobby politicians on either side of the Atlantic to fix the incompatibility between US surveillance law on the GDPR. Similarly, the politicians and regulators are okay pretending that new EU-US agreements with no real legal substance can solve the problem, such that nobody has to comply and the ECJ and Max Schrems stay busy spinning their wheels.
If this were different and the EU were actually enforcing the rules, either companies in the EU would have to stop using American providers - helping build a home-grown EU software industry without being crowded out by American providers - or US companies like MS would have to change what internal practices they can and lobby the US government to make the necessary legislative changes for them to fully comply with the GDPR.
To be honest, I don't think the EU politicians/regulators are bad at what they're trying to do. It's simply that what they're trying to do is to look tough on privacy while actually not pissing off the deep-pocketed megacorps and the politicians they can/do fund on either side of the Atlantic. Which is different than what I'd like them to do, of course.
Privacy Shield was canned years ago but your company is most likely moving data to an American "Anti-Virus" provider under this framework.
It might imply that o365 sevices in the EU/EEC will increase in price - but I'm quite certain the data privacy will be better.
Remember that this has implications for all businesses that deliver on government contracts in the EU - they would all have to move away, for example not hosting email with o365 because government won't communicate details involving GDPR protected data over untrusted services (even with encryption enabled).
However, due to enforcement being absent or taking ages, there are too few legal decisions and big expensive enforcement actions that one can point to. Currently everything is really still fear, uncertainty and doubt, the hammer hasn't come down yet. I'm not sure if it ever will, at least not before EU institutions or other member states such as France force Germany to stop dragging its feet.
On the other hand it made us research and use European alternatives such as Hetzner (they have a cloud too, although with less SaaS offerings), OVH or Scaleway.