European Commission's use of Microsoft 365 infringes data protection law for EU
edps.europa.eu
edps.europa.eu
They feel confident because they believe the words of providers or what is said in contract or "paper" agreements that the US will not spy on them when it is possible. Despite all previous examples of shamelessly doing what they wanted. Like when there was undercover operations to retrieve the fingerprints of political leaders.
And who's going to provide the politicians a better way of doing it? Not only does IT lead by example in blind trust of the cloud, but they only sell their services that way also.
In fact, we have a precedent in France regarding Microsoft crawling itself in inside our military:
https://www.april.org/en/french-ministry-defence-and-microso...
> Like buying warfare boats that are working thanks to servers in foreign countries?
I assumed it's that bad already.
> In fact, we have a precedent in France regarding Microsoft crawling itself in inside our military:
Are you going to get rid of Intel as well as Microsoft?
This is where smaller and more specialized providers can gain ground, and in some areas has done so. When the large providers focus on price and ignoring the law, smaller providers can compete with a better (but more expensive) product.
The biggest hurdle for a positive change is that in many situations, IT companies that ignore the law can often gain more by paying fines and splitting the cost among multiple won contracts, than smaller companies that follow the law. There is a similar problem in procurement where a large company can have a strategy to agree to anything in order to win all contracts, then relying on their lawyers to limit the fallout when they eventually fail to deliver. Systematic abusing the legal system should simply lead to increased fines.
"Free and open" is not a silver bullet. Neither is Microsoft, but Microsoft has been providing government services for decades, and they know the ins and outs, the requirements, the policies, the access levels and a billion other details. None of that exists in "free and open". I wouldn't be surprised if just resolving the complex web of Active Directories in a small government department will make anyone mad.
> You will get locked in to the one/two vendors that can make those free and open document formats and protocols work
You don't seem to understand what the phrase "locked-in" means. A document format that is open and documented is not lock-in at all. It's the opposite - it enables people to create competing and integrated solutions without licensing proprietary software. Better yet, it incentives companies like Microsoft and Google to support something other than their own document format if they want to be competitive. An effective democracy cannot have a government that only supports customers of a product.
"Locked-in" are the poor saps that license Microsoft software to control their battleships, their SAM sites, their CIWS and their TACANs. Nobody is ever going to disrupt their dominance even if Active Directory is the worst option available on the market. The lack of meaningful competition and standardization literally costs lives in some industries. It's why every modernized military is backed by a government that strictly drafts and defines it's demands for competing contractors.
An open document format in the context of a government is only as good as the integrations made with these formats.
What you seem to not understand is why the "poor saps" are locked into Google, Oracle etc. Because OSS is incapable of understanding that a format or a protocol on their own are worth nothing
"The EDPS has therefore decided to order the Commission, effective on 9 December 2024, to suspend all data flows resulting from its use of Microsoft 365 to Microsoft and to its affiliates and sub-processors located in countries outside the EU/EEA not covered by an adequacy decision."
Does it mean suspend flows to Microsoft anywhere and to its affilietes and sub-processors outside EEA?
Or does it mean suspend flows to (Microsoft and to its affilietes and sub-processors) which are located outside EEA?
In other words can data still flow to Microsoft within EEA?
> The EDPS has also decided to order the Commission to bring the processing operations resulting from its use of Microsoft 365 into compliance with Regulation (EU) 2018/1725.
Which, to me, reads like they can keep using Microsoft 365, they just need to work with Microsoft to bring it in compliance.
So my guess is your second interpretation.
That is the reason for the drama over the last years concerning Privacy Shield etc.
The background being that there's little competition for the M365 ecosystem in general, least of all in the EU. EU has homegrown "bits and pieces" that could, maybe, somehow, go head to head with the equivalent bits from M365. But as soon as you need more of them you hit the integration and synergies wall and the advantages of M365 get compounded.
We're not talking about high volumes of traffic, this is mostly internal tools for few hundreds/thousands people, of those few dozens at best concurrently connected?
With all due respect those are few servers worth of hardware plus redundancy, plus all the security you want.
Imho the real devil is the reliance on the suite itself, which is hard to replace, especially when you get mail/calendar/sharepoint/office/etc all bundled in one.
The question isn't about "concurrent users". The question is about processes, documents, revisions, access levels, interdepartmental access, policies, and a billion other details.
That would not be allowed if it stayed in the EU, and there is literally no technical reason why it has to be sent to the US ever.
Ursula von der Leyen wants to be relected, but people in the EU are not asked about this. If find this highly suspicious.
I also for example find the UKs habit suspicious, where the change of a prime minister does not lead to a general election. The UK probably has the largest number of unelected prime ministers of any western country. And it's not voted for like the US president (Electoral College aside). After being voted into the parliament with a majority, an UK party could elect any prime minister they want.
I've recently talked to someone from Switzerland about all of this, where much more is voted on by the general public, and how this changes peoples mind, about how they feel responsible for politics. People don't see a dividing line between politics and themselves. Wish more countries would be like Switzerland.
The current German gov't silently issued a statement in December 2023 of IT license cost on federal level for the upcoming years which essentially was 6 billion EUR to Microsoft and Oracle.
1. They throw valuable tax-payer money at companies who do tax evasion.
2. They simply ignore the _fact_ that we've been spied on by our allies.
3. They became over-dependent on US tech which trickled down into all fine-granular processes of private and public institutions.
4. They make it additionally hard for local companies to compete with their regulation frenzies.
Don't know what to say anymore but mocking them and mention what might happen if Trump gets re-elected and discovers this dependency. If US is playing hardball, Germany will be back in stone age.
...
I mean they might have different ToS/Privacy Terms, but I it would still be high risk due to MS track record of "accidentally" undoing or ignoring various "I don't want to be tracked" choices.
Like tbh. from a privacy POV MS has become a joke, I mean how hard do you have to mess up that google is preferable bay a not so small margin.
Is it too much to hope for a Blender-like foundation to run an open source project that is actually competitive?
Alternatives did exist, who remembers Lotus Notes, Word Perfect, Open Office, Apple Pages, ..., but to use them today would be akin to deploying a new fangled AI web app as a Flash application.
You can get a 365 licence (Teams, OneDrive/Sharepoint, Powerpoint, Excel, Word, Outlook & hosted exchange) for $12.50/month.
It's only really Google that's competing at this price point (Broadly both their 'standard' packages are approx. the same price).
Plus I've not come across a product that's better than being Excel than Excel is (and your analyst and finance teams will hate you if you take Excel away!).
But IMO the real moat in M365 is that it also bundles Microsoft Entra ID (formerly AAD) licenses and it's strongly integrated to it + SharePoint.
This way you can have "basic IT stuff" you expect in a company like company users, groups, shared folders, file permissions, etc...
Then MS is violating GDPR and must come into compliance, less it risks turning into a cashcow for the EU and get fined billions of dollars day after day.
This isn't GDPR specifically, this is something like "GPDR for EU institutions", so stricter.
It would be similar to a federal law in the US that dictate that no information stored in the tax office, police databases or social security administration may be shared or stored outside the US. US citizens may expect that when dealing with the US government, information stored about them stays inside the US.
In the context of internal security and national sovereignty, it make sense to have dedicated regulation. It similar to how lawyers/doctors has more strict regulation regarding personal information that other professions.
As with all laws in Europe, GDPR has a chief purpose to be abused by the rulers and used against the public and the public interest. That's a long standing tradition in Europe, and I feel that it's only people here that don't "get it" and actually believe the propaganda. You don't believe Apple propaganda, Monsanto propaganda, or Republican propaganda. So why swallow EU propaganda?
So who is 'they' and what were the documents? I'm American so I'm not deeply familiar with this area.
In the US you don't have this kind of financing I believe, because your political parties pay for themselves by endless fundraising from their voters.
Because the argument (as you describe it) doesn't make any sense, so I would expect they already have another nonsensical interpretation of some other law at hand from before GDPR applied.
Not in the field anymore, but I wouldn't be surprised if somebody took the data protection authority to court over this in the near future.
I don't find it very surprising that they could and did use the GDPR "loophole" to close the public sector from public insight. Before GDPR there were very clear laws of transparency making sure that they could not deny giving out public documents. And if they did, they'd be taken to court and always loose. They would still try denying some public documents and threatening court would work against that.
With a data protection authority on their side, they finally got the law on their side, using tactics such as saying that there is a risk that these documents end up on an American server. While at the same time using Microsoft services and American servers themselves. Which is the subject of the OP article.
Appointing a crooked head of a data protection authority or any authority is easy and it is legal. Circumventing laws is not that easy. But it is easier when you have more laws that are more open for interpretation.
The right thing to do would have been to make transparency laws more powerful than GDPR laws, because it was obvious that they would be abused. Now the EU has GDPR laws enforced on a union-wide basis, but not wholesome transparency laws enforced on a union-wide basis.
I really can see no legitimate reason for stalling on giving that detail.
Because I vote for my EU representatives. Sure one doesn't have to "believe" everything, but not believing _anyone_ is also a dangerous slippery ride down the conspiracy lane.
Ideally there are are legal avenues for redress in your situation. If there are not, that is more likely to be the problem than a conspiracy of propaganda.
Change the word "propaganda" to "marketing", if it is offensive to you.
As with all gross generalizations and simplifications this is false. As in: the issue is more complex that you make it out to be
You are free to believe what you want but it is getting old to say that people who do not agree with you are falling for some ruse. Maybe they know something you don't?
But you know what? Note taken and thanks.