RT @[email protected]

~2 Jahre hat eine Arbeitsgruppe der Konferenz der unabhängigen Datenschutz-Aufsichtsbehörden von Bund und Ländern (DSK) versucht, Nachbesserungen bei Microsoft 365 zu erreichen.

👉 Zusammenfassung des Berichts der AG zu #MS365: https://datenschutzkonferenz-online.de/media/dskb/2022_24_11_festlegung_MS365_zusammenfassung.pdf

Festlegung der DSK: 👇

🐦🔗: https://twitter.com/alvar_f/status/1596179727311863809

After two years of negotiations with Microsoft, the joint committee of the German federal data protection authority and 17 state regulators (DSK) published a devastating statement that essentially says that organizations currently cannot use MS365 in a lawful way under the GDPR.

Key issues raised by the DSK working group include that Microsoft's data processing agreement does not make sufficiently clear how Microsoft uses personal data it allegedly processes on behalf of the client for its own business purposes.

This must be escalated to the EU level.

The document states that it's not clear how Microsoft uses personal data on its clients' users for its own 'business purposes' while Microsoft grants itself extensive rights to do so.

It also states that Microsoft generally processes telemetry data for its own purposes at scale.

Microsoft now markets itself as a trustworthy and responsible tech giant, but it's not.

While keeping a friendly face, it works hard to undermine regulation and normalize corporate data misuse, including at work, not to mention its surveillance marketing and defense businesses.

Well this blew up.

To be clear, the DSK's statement is an assessment, not an enforcement decision. But what's stopping German regulators from enforcement?

Problem is that MS365 is unavoidable in many areas. I think this requires a coordinated political effort at the EU level.

I wrote a bit about Microsoft, platform power and data in this thread from February:
https://twitter.com/WolfieChristl/status/1496083980252508163
Wolfie Christl on Twitter

“NL forced Microsoft to provide its software for govt and universities under data terms that prohibit MS from exploiting personal/behavioral data for its own purposes. ✅ It's possible ➡️ This is what everyone in the EU deserves, including Home/Pro users https://t.co/J2NVP2uNpN”

Twitter
Datenschutzkonferenz: Microsoft 365 ist und bleibt datenschutzwidrig

Einzelne Fortschritte Microsofts erkennen die Datenschützer Deutschlands an. Das reicht nicht.

heise online

Microsoft published another 7-page statement aggressively refuting the DSK report, German:
https://news.microsoft.com/wp-content/uploads/prod/sites/40/2022/11/2022.11_Stellungnahme-MS-zu-DSK_25NOV2022_FINAL.pdf

Btw. I wonder what exactly was the defined purpose and legal basis for MS to analyze "trillions of Microsoft 365 productivity signals" here?
https://twitter.com/WolfieChristl/status/1574488874201522178

Here's another 'study' that also claims to be based on "trillions of productivity signals in Microsoft 365" including Teams data, "collaboration activity across Microsoft 365 tools", "productivity patterns in Outlook", "anonymized Outlook calendar data":
https://www.microsoft.com/en-us/worklab/work-trend-index/great-expectations-making-hybrid-work-work
Great Expectations: Making Hybrid Work Work

The 2022 Work Trend Index Report reveals five urgent trends business leaders need to know about hybrid work.

Is this 'research'? Or marketing?

Which organizations and users contributed MS365 data to these 'studies'? Are they aware of it? Are they fine with Microsoft extracting knowledge from data on employees activity and internal processes?

How else does Microsoft exploit MS365 data?

The full 58-page DSK report assessing the MS365 data processing agreement is now available online:
https://twitter.com/alvar_f/status/1600526110357278724
Alvar C.H. Freude on Twitter

“#MS365-Bericht nun vollständig (außer Anlagen) online: https://t.co/spEOrA5yqZ – 58 Seiten Abschlussbericht der AG „Microsoft-Onlinedienste“ der Konferenz der unabhängigen #Datenschutz-Aufsichtsbehörden von Bund und Ländern. #DSGVO #Teamdatenschutz”

Twitter
@wchr there is no way to opt out.
@Bobo_PK I think this is what the dispute on the DPA (the contract that governs how Microsoft may use the data) between German regulators and Microsoft is about ;)
@wchr I had to evaluate teams in the former company. My result was that they stored our data in Amsterdam, so EU but because of the cloud act they will never be able to comply with GDPR.
@wchr I mean they even have monitoring solutions for employees in place that automatically detect whether you talk bad or want to leave your employer. They collect and snitch because their money givers are not the workers. #surveillanceCapitalism