On-Prem

Public Sector

European Commission broke its own data privacy law with Microsoft 365 use

Euro folk have until December to put house in order


The European Commission has been reprimanded for infringing its own data protection regulations when using Microsoft 365.

The rebuke came from the European Data Protection Supervisor (EDPS) and is the culmination of an investigation that kicked off in May 2021, following the Schrems II judgement.

According to the EDPS, the EC infringed several data protection regulations, including rules around transferring personal data outside the EU / European Economic Area (EEA.)

According to the organization, "In particular, the Commission has failed to provide appropriate safeguards to ensure that personal data transferred outside the EU/EEA are afforded an essentially equivalent level of protection as guaranteed in the EU/EEA.

"Furthermore, in its contract with Microsoft, the Commission did not sufficiently specify what types of personal data are to be collected and for which explicit and specified purposes when using Microsoft 365."

While the concerns are more about EU institutions and transparency, they should also serve as notice to any company doing business in the EU / EEA to take a very close look at how it has configured Microsoft 365 regarding the EU Data Protection Regulations.

Wojciech Wiewiórowski, the European Data Protection Supervisor, said: "It is the responsibility of the EU institutions, bodies, offices and agencies (EUIs) to ensure that any processing of personal data outside and inside the EU/EEA, including in the context of cloud-based services, is accompanied by robust data protection safeguards and measures.

"This is imperative to ensure that individuals' information is protected."

The EC has been ordered to suspend all data flows through the use of Microsoft 365 to Microsoft and any of its tentacles that might reside outside the EU / EEA and not covered by an adequacy decision. The EC must also make its processing operations with Microsoft 365 compliant, and has a deadline of December 9, 2024, to demonstrate compliance.

The latter order gives an insight into the seriousness of the infringements. Corrective actions in order to ensure compliance include a transfer-mapping exercise to identify what personal data is transferred to which recipients in which third countries and to ensure the types of personal data are sufficiently determined in relation to the purposes for which they are processed.

According to the EDPS' findings: "Many of the infringements found concern all processing operations carried out by the Commission, or on its behalf, when using Microsoft 365, and impact a large number of individuals."

The problem appears to be more on the doorstep of the EC and how it is using Microsoft 365 rather than the Windows behemoth itself.

A spokesperson for Microsoft said: "Our customers in Europe can continue to use Microsoft 365 in full compliance with the GDPR and can count on our continued support and guidance.

"Concerns raised by the European Data Protection Supervisor relate largely to stricter transparency requirements under the EUDPR, a law that applies only to the European Union institutions. We will review the EDPS' decision and work with the European Commission to address the remaining concerns." ®

Send us news
29 Comments

The unlicensed OneDrive free ride ends this month

Kind old Microsoft is worried about security and compliance ... nothing to do with a free storage loophole

Brit government contractor CloudKubed enters administration

Home Office, Department for Work and Pensions supplier in hands of FRP Advisory

Azure, Microsoft 365 MFA outage locks out users across regions

It's fixed, mostly, after Europeans had a manic Monday

Database tables of student, teacher info stolen from PowerSchool in cyberattack

Class act: Cloud biz only serves 60M-plus folks globally, no biggie

Apple's interoperability efforts aren't meeting spirit or letter of EU law, advocacy groups argue

Free Software Foundation Europe and others urge European Commission to double down on DMA

Copilot invades Microsoft 365 Personal and Family for an extra three bucks a month

Many users less than impressed by unexpected arrival of AI assistant in Word

Microsoft tests 45% M365 price hikes in Asia-Pacific to see how much you enjoy AI

Won’t say if other nations will be hit, but will ‘listen, learn, and improve’ as buyers react – so far with anger

EU demands a peek under the hood of X's recommendation algorithms

Commission insists the timing has nothing to do with Musk meddling in German politics ahead of election

One third of adults can't delete device data

Easier to let those old phones gather dust in a drawer, survey finds

Fining Big Tech isn't working. Make them give away illegally trained LLMs as public domain

It's all made from our data, anyway, so it should be ours to use as we want

Microsoft investigating 365 Office activation gremlin

Says it's not sure what the issue is but points at admins tweaking licensing options

Apple and Meta trade barbs over interoperability requests

Both are only thinking about the best interests of users, of course