4 ms·
I would love to know more about how this discussion is in Denmark. Also how the Danish public sector is talking about GDPR/Cloud Act in relation to O365 and sim
by pkz 7y ago
I would love to know more about how this discussion is in Denmark. Also how the Danish public sector is talking about GDPR/Cloud Act in relation to O365 and similar services.
- msla 7y ago> Also how the Danish public sector is talking about GDPR/Cloud Act in relation to O365 and similar services. "Microsoft says it. We believe it. That settles it." Really, there's no other option: Even if they magically got the ability to audit source code, the whole point of a cloud service is that the code can be changed at any point. Even if you extract a promise from Microsoft that the code won't be changed... well, see Figure 1. You're operating on trust that Microsoft will abide the agreement, and trust that you'll be able to magically tell if they don't.
- moksly 7y agoI’m not personally aware of any facial recognition projects for attendance. Never seen it debated either. We have thousands of schools though, so who knows. As far as the GDPR goes it actually didn’t have a huge technical impact on the public sector. We’ve had stricter local laws for decades, and have build our systems accordingly. We also don’t track you for advertising. So for us the GDPR has mostly been a bureaucratic change, and you’ll notice that’s also the majority of violations. It’s not that data aren’t protected, it’s that no one knows where the contract is, or that we haven’t documented elaborate procedures for whatever. 95% of the GDPR impact on the public sector had been law and legalisation. So the GDPR actually doesn’t impact O365 94 public cloud at all as long as you go to iso27000 certified vendors who provide privacy shield or whatever it’s called these days. That’s not to say that we aren’t debating public cloud. Because we are. This has more to do with national laws though, we have war-time contingency plans from the cold-war era. Like I said, we had much stricter policies before the GDPR was even a thing. The issue is that it makes public cloud illegal, but we can’t operate the most digitalised public sector in the world without public cloud. So far everyone is moving to AWS and Azure, pretending the flawed bureaucracy will eventually go away, but our politicians and national digitalisation agency has been refusing to give any meaningful heading, so who knows? At some point though, someone is going to ask if the privacy bureaucracy is really worth the money it’s costing. At our place you could hire 10 extra teachers a year, just to cover the bureaucratic processes that don’t actually increase security, because a contract or a nice incident plan isn’t actually going to stop anyone from hacking you.