3 ms·
Microsoft is in a difficult position here. Just taking the GDPR, they are presumably the data controller and they are passing on potentially personally identifi
by janosd 4y ago
Microsoft is in a difficult position here. Just taking the GDPR, they are presumably the data controller and they are passing on potentially personally identifiable information to OSM without a data processing agreement. They are vulnerable to a right to be forgotten request, which they can then not fulfill. Given Bing's global reach, I'm sure this is not the only issue. I'd be really careful trying to attribute this issue to malice on Microsoft's part.
- Misdicorl 4y agoNot really. Microsoft has inserted their own identity system into an OSM application they built. There's no problem if there's a login modal to use your OSM identity to make edits. They can even have a "let Microsoft manage my OSM account" checkbox with the relevant legalese if they want that to be slick.
- janosdebugs 4y agoBut there's the problem: if you don't have an OSM account, the user needs to go sign up for one. If Microsoft creates the account for them, that's not just legalese, they might still be seen as the data controller. Or, at least it may be problematic enough to give the in-house lawyers a headache.
- Misdicorl 4y agoBut that's not a problem at all! That's exactly the desired/required operation. OSM wants a very clear demarcation: this may be a Microsoft application, but you are an OSM community member (if you want to contribute). That's perfectly encapsulated by a signup/login barrier. Any slick-ness on top of that fundamental requirement is sugar
- maxerickson 4y agoIt'd be better not to build the weird limited account on top of OSM and not capture the edits. It's not a difficult position at all.