Bonum Certa Men Certa

EPO and Microsoft Collude to Break the Law -- Part X: The Spectre of GDPR…

Previous parts:



GDPR and Microsoft
More about Microsoft's run-ins with European data protection authorities



Summary: António Campinos and his friends may have put the EPO in legal "hot water", having already outsourced EPO data to a serial GDPR violator with a notorious track record in other aspects, too

In April 2019 it was reported that "the Spectre of GDPR" continued to haunt the hallowed halls of Redmond, this time in the shape of an investigation ordered by the EU Data Protection Supervisor (EDPS) into Microsoft products used by EU institutions.



The move by the EDPS was prompted by the outcome of the Data Protection Impact Assessment which had been commissioned by the Dutch Ministry of Justice and Security in 2018.

"The move by the EDPS was prompted by the outcome of the Data Protection Impact Assessment which had been commissioned by the Dutch Ministry of Justice and Security in 2018."The EDPS noted that any EU institutions using the applications investigated by the Dutch authorities would face similar issues including "increased risks to the rights and freedoms of individuals".

The report of the EDPS on the "Outcome of own-initiative investigation into EU institutions’ use of Microsoft products and services" was published on 2 July 2020.

The EDPS identified a number of serious issues calling for further action, including the following:

● The licensing agreement between Microsoft and the EU institutions was formulated in loose manner that effectively permitted Microsoft to act as a data controller which the EDPS found inappropriate.

● The lack of control by EU institutions over which sub-processors Microsoft used and the lack of meaningful audit rights presented significant issues which needed to be addressed.

● EU institutions were unable to control the location of a large portion of the data processed by Microsoft. Nor did they properly control what was transferred out of the EU/EEA and how. There was also a lack of proper safeguards to protect data that left the EU/EEA.

● EU institutions had few guarantees at their disposal to defend their privileges and immunities and to ensure that Microsoft would only disclose personal data insofar as permitted by EU law.

According to the EDPS, the EU institutions lacked sufficient clarity as to the nature, scope and purposes of the data processing carried out by Microsoft and the risks to data subjects for the purpose of complying with their transparency obligations towards data subjects.

The EDPS recommended that all EU institutions perform tests using a revised and comprehensive approach in order to monitor and stem the flow of personal data generated by Microsoft products and services and sent to Microsoft.

"The EDPS recommended that all EU institutions perform tests using a revised and comprehensive approach in order to monitor and stem the flow of personal data generated by Microsoft products and services and sent to Microsoft."It remains to be seen whether or not the EDPS' beef with Microsoft will be resolved in an amicable manner or whether it will result in the imposition of GDPR fines which, in serious cases, can be as much as 4% of a company's worldwide annual revenue.

Microsoft has also had its fair share of grief with the data protection authorities in the EPO's main host country, Germany.

Back in July 2019 it was reported that the data protection authority in the state of Hesse had issued a ruling that Microsoft’s Office 365 could no longer be used by schools following the closure of a German data centre which had been used by Microsoft to provide cloud services.

This ruling came after several years of domestic debate about whether German schools and other state institutions should be using Microsoft software at all.

To allay German privacy concerns, Microsoft had invested millions in a German cloud service, and in 2017 Hesse authorities agreed that local schools could use Office 365 as long as German data remained in the country. But in August 2018 Microsoft decided to shut down the German service which meant that, once again, data from local Office 365 users would be transmitted across the Atlantic.

"...in August 2018 Microsoft decided to shut down the German service which meant that, once again, data from local Office 365 users would be transmitted across the Atlantic."In view of the changed circumstances, the data protection commissioner decided that there was now an unacceptable risk that users' data could be accessed by US authorities.

More recently, in October 2020, it was reported that at the Conference of German Federal and State Data Protection Supervisory Authorities, a majority of Germany's regional data protection commissioners supported a finding that Microsoft Office 365 did not comply with GDPR standards. They also made clear that changes were urgently needed to comply with the CJEU Schrems II judgment on cross-border data transfers.

Once again, it's too early to say whether this matter will be resolved in an amicable manner or whether it will result in the imposition of GDPR fines.

However, for some time now German lawyers have been warning their clients about the potential financial risks of using non-GDPR compliant software, including many widely used Microsoft products.

For example, one Hamburg-based law firm published the following advice in July 2020:

"...for some time now German lawyers have been warning their clients about the potential financial risks of using non-GDPR compliant software, including many widely used Microsoft products.""Using MS-Teams, Skype and other Office 365 services violates data protection law and may result in million Euro fines. That’s the conclusion of two papers recently issued by the Berlin Commissioner for Data Protection and Freedom of Information. There is urgent need for action in many companies now."

Time will tell whether or not such warnings are justified. However, based on past experience Microsoft is unlikely to be given an easy ride by the German and other European data protection authorities and this may well have some unpleasant fallout for commercial users of its services and products.

In the meantime German scepticism about Microsoft has surfaced in the European Parliament.

In February 2020, Klaus Buchner - a university professor, physicist, and MEP for the green-conservative Ecological Democratic Party - submitted the following question to the EU Commission:

Subject: Microsoft Windows 10 in European local authorities

IT is part of our critical infrastructure, and in European local authorities as well IT means Microsoft Windows and Microsoft Office. It is as if European drivers could only buy cars made by one US manufacturer. As a result, European local authorities and European industry are totally dependent on a foreign monopoly supplier and are required to kow-tow to a foreign legal system and comply with foreign court judgments, which apply to Microsoft in the EU as well. To make matters worse, Windows 10 systematically transmits personal data to Microsoft. Little is known about how that data is used. The upshot is that local authorities may find themselves facing legal action for breaches of the data protection rules and the German Industrial Constitution Law. Background: ‘[...] The Data Protection Officers of the Federal Government and the Länder see little scope for using Microsoft’s Windows 10 operating system in accordance with the law […]’

Instead, standard programmes could be developed at EU level and made available to local authorities free of charge. This standard software could also be hosted in regional data centres in the EU and interested local authorities could transfer their IT operations to those centres. Of course, each local authority would be required to tailor the standard programmes to local needs and operate them independently, either from their own data centres or in an EU cloud.

1. Are there alternatives to monopoly costs and data protection problems? 2. Does the Commission see any scope for offering greater support for the use of free openware such as Linux and OpenOffice / LibreOffice?


The answer which came back from EU Commissioner Thierry Breton was for the most part the usual hot air which didn't really address the elephant in the room.

"In the meantime German scepticism about Microsoft has surfaced in the European Parliament."However, Breton took advantage of the opportunity to plug the Commission's ongoing efforts to promote an "EU cloud initiative" which would "offer credible European alternatives to non-EU providers".

And with that, we conclude our potted history of Microsoft's long-running and continuing problems with European data protection authorities.

In the next part we will take a look at some "close encounters" between the software behemoth of Redmond and other regulatory authorities, in particular the trust-busters on both sides of the Atlantic.

Recent Techrights' Posts

EPO Staff Can Go Listen to Richard Stallman Next Week in Munich (Technical University of Munich, Rudolf-Diesel Hörsaal (MW2001) on Campus Garching at 18:00)
"The talk is open to the public and attendance is free. Registration is not required."
At IBM, Relocation Means Layoffs (Downsizing)
Silent or 'invisible' layoffs?
Dystopian Trends in Technology Make Richard Stallman More Relevant Than Ever
It's good to see him attracting vast audiences
Richard Stallman (RMS) Announced His Talk Less Than 24 Hours Before It Took Place and Still Filled Up the Auditorium at Sapienza Università di Roma
Photos from yesterday evening [...] It looks like it was a very successful event
 
Attacks on Techrights Are Only Making Techrights Bigger and Even More Popular
A week ago they offered to settle with us
Epic Metaphor for End of IBM: "The IBM Demolition is Down to the Last Shards!"
Nothing lasts forever
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, October 14, 2025
IRC logs for Tuesday, October 14, 2025
Proprietary and DRM Prisons Spiralling Down the Sinkhole? Not Just Yet.
Let's hope that more people will flee to GNU/Linux
The European Patent Office (EPO), the Second-Largest Institution in Europe, is Cracking Down on Recreational Activities
Without AMICALE activities, and as staff already says it's pressured to work more for less, how can the EPO recruit bright people?
Transparency: FSFE financial reports exclude speaker fees and expenses
Reprinted with permission from Daniel Pocock
Many Developers Have Many Political Views, They'll Never Agree on Everything
It's an effort to divide and destroy, not build
Gemini Links 14/10/2025: An Opportunity to Consider GNU/Linux and Another Simple IRC Client
Links for the day
Slopwatch: UbuntuPIT, LinuxSecurity, Google News, and the Serial Slopper Brian Fagioli
Nothing of merit here, just more slop
Links 14/10/2025: Lack of Trust in Slop and "Retirement Challenges"
Links for the day
Rhonda D'Vine, Gerfried Fuchs, Pronouns & Debian pregnancy cluster
Reprinted with permission from Daniel Pocock
Central Staff Committee of the European Patent Office (EPO) Warns That EPO Management is Robbing or Manipulating Pension Funds Again
Faking "growth" is just about as bad as forgery
Probably a Lot Worse Than LLM Slop: GNOME Tying Itself to Divisive Politics, Even Where It's Clearly Not Relevant
Something has gone terribly wrong in GNOME
Links 14/10/2025: Microsoft OneDrive Scanning Faces in Photos (Without Asking First), "OpenAI Says It Will Move to Allow Smut"
Links for the day
They Generally Don't Like Scholars, as They're Less Compelled or Pressured to Repeat What Corporations and Oligarchs Say
People who loathe scholars have an agenda in mind that, unlike that of reasonable people, revolves around controlling people
Belated New Article About Last Thursday's Lecture by Richard Stallman in Helsinki, Finland
there are good reasons to pay with cash, not limited to privacy
Attacking Richard Stallman Has Become 'Career Suicide'
If you're going to viciously attack somebody, make sure your arguments are rock-solid
Microsoft's Failing XBox Business Has Turned Games Into Funerals
How does it feel to depend on Microsoft?
Yesterday's "Distinguished Lecture" by Richard Stallman Possibly Attended by Close to 1,000 People
The capacity of the place is about 900
Slop Poisons Everything
Imagine wanting to find what Torvalds has just said or what has just been released
Taking Software Freedom 'Mainstream'
interest in Software Freedom must have grown
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, October 13, 2025
IRC logs for Monday, October 13, 2025
Gemini Links 14/10/2025: Ada Lovelace Day, Sony CLIE PEG-TG50 Review, Why to Avoid Network Solutions
Links for the day
The EPO's War on Techrights Was a Massive Mistake
The EPO started the SLAPPs after we had published a few hundreds of articles; we've since then published close to 6,000 because the attacks on us emboldened insiders to help us
General-Purpose Computers to Become Growing Area of Coverage
Without them, we have little left for controlling our lives
"They missed a great opportunity to shut up." -Jacques Chirac
Brett Wilson LLP has been trying to cheat the legal system many times
Harassment evidence: Switzerland, overcrowded fitness and yoga centers, incompetence and racism in accident response
Reprinted with permission from Daniel Pocock
Vincent Danjean & Debian NXIVM collateral, blackmail risks
Reprinted with permission from Daniel Pocock
In Sweden This Past Friday Richard Stallman Explained Why Copyleft is Important
And he didn't have to 'bash' BSDs, either
IBM Layoffs Due to a Lack of Money and Company Debt Rising by Almost 10 Billion Dollars in 6 Months
IBM didn't buy Red Hat for any ideological reasons; it was a fast "cash grab" for revenue
Forbes Already Stopped Being a News Sites. Now It's a Spam and Propaganda Platform for "Paying Partners" (Companies).
news from Forbes became very scarce
Is the Second-Largest Institution in Europe (EPO) Gradually Becoming More Like a Sweatshop?
Underpaid, unqualified, inexperienced and incompatible people are already recruited to replace veteran examiners
The Register MS Has No FOSS Coverage Anymore
The Editor in Chief is like a Microsoft plant
Links 13/10/2025: "Toasty Subwoofer" and WiFi Speakers "Are About To Go Dumb"
Links for the day
Gemini Links 13/10/2025: iNaturalist and Tove Jansson’s Moominpappa at Sea
Links for the day
Microsoft Does Not Deny That Large Retailers Like Walmart, Costco and Target Are Giving Up on XBox (and Not Stocking It)
No doubt XBox is in trouble and rumours suggest that more mass layoffs are imminent
We'll Encourage Richard Stallman to Talk About Software Patents at the EPO Next Week When He Visits Munich (EPO Headquarters)
Go listen to Richard Stahlmann
Investigative Journalism Protects Society From Corruption, Crimes Against Women, Assaults on Civil Society
"what is the point of men doing military practice to defend a system that is so rotten?"
Swiss pimp usurping reputation of legendary Tissot boss Francois Thiébaud from France (BaselWorld, SWATCH Group SA)
Reprinted with permission from Daniel Pocock
Paris 'Love Nest' & Debian Outreachy: from Lycée Lakanal to ENS Cachan, Cr@ns, nepotism
Reprinted with permission from Daniel Pocock
Richard Stallman to Give Public Talk in 3 Hours, Then in the Technical University of Munich (Germany) Next Week
Richard Stallman at TUM on 21.10.2025 18:00, MW2001
Arnaud Parreaux lost case defending rogue employer
Reprinted with permission from Daniel Pocock
Mathieu Elias Parreaux declared bankrupt in Switzerland
Reprinted with permission from Daniel Pocock
Breakdown of the Rule of Law and Patent Law in the European Union (EU)
The EPO cannot recruit suitably qualified patent examiners this way, let alone retain them
Gemini Links 13/10/2025: Good Films, Wizard of Earthsea, Upgrading the Steam Controller's Stick
Links for the day
Leaks and Whistleblowers: Our Plan for Today
Society simply cannot advance when too many people self-censor
It's Not Justice When One Side Denies the Other Side the Ability to Even Speak
At this stage, Brett Wilson LLP is in my humble opinion acting in contempt of the Court
Links 13/10/2025: Australian Catholic University Uses Slop to Libel Students, Canada Threatens to Kill Beluga Whales
Links for the day
How Not to Silence Tux Machines (It'll Only Backfire, Badly)
defending Microsoft while attacking this site
Slopwatch: UbuntuPIT and Google News
It seems abundantly clear that Google News and Google in general participates in the slop epidemic
Vincent Danjean (not INTERPOL), Claire Bardel & Debian pregnancy cluster
Reprinted with permission from Daniel Pocock
Christmas lynchings: Martin Krafft (madduck), Penny Leach (mjollnir) & Debian pregnancy cluster
Reprinted with permission from Daniel Pocock
Gemini Links 13/10/2025: Birthdays and "Committee Unable to Contact Nobel Prize Winner"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, October 12, 2025
IRC logs for Sunday, October 12, 2025