Bonum Certa Men Certa

EPO and Microsoft Collude to Break the Law -- Part IX: Know Your Vendor…

Previous parts:



A big brother-like spy
The never-ending saga of Microsoft's run-ins with European data protection authorities



Summary: Microsoft is one of the world's worst offenders when it comes to privacy, but vendor assessment by the EPO conveniently overlooks the law

Even before GDPR came into effect in May 2018, data protection regulators in some European countries were starting to have their doubts about whether Microsoft's flagship product, its Windows operating system, was compliant with European data protection standards.



The first national authority to kick into action was the French National Data Protection Commission (CNIL).

Following an investigation which concluded in June 2016, CNIL issued Microsoft with a formal notice to comply with French data protection regulations. CNIL also ruled that the decision should be made public, given the scale of the violations in question.

"Following an investigation which concluded in June 2016, CNIL issued Microsoft with a formal notice to comply with French data protection regulations. CNIL also ruled that the decision should be made public, given the scale of the violations in question."No fewer than six violations of the French Data Protection Act were identified by CNIL, including continued transfer of data based on Safe Harbor principles despite the fact that the Safe Harbour Agreement had been invalidated by the CJEU in October 2015.

Microsoft was given three months – until 30 September 2016 – to end the identified violations of French Data Protection law or else face the prospect of a fine of up to €150,000.

In June 2017, it was reported that Microsoft had scaled back the volume of data it collected from Windows 10 PCs by "almost half". This led CNIL to announce that Windows 10 was no longer in breach of the country's data protection laws and that it had decided to close the case.

But that was only the first chapter in the never-ending saga of Microsoft's run-ins with European data protection authorities.

"Microsoft was given three months – until 30 September 2016 – to end the identified violations of French Data Protection law or else face the prospect of a fine of up to €150,000."A few months later in October 2017, it was reported that the Dutch data protection authority (Autoriteit Persoonsgegevens) had come to the conclusion that Microsoft was in breach of Dutch data protection law due to the way it processed the personal data of Windows 10 users.

According to the Dutch data watchdog, Microsoft made it impossible for users to give their valid consent to their personal data being processed due to the multiple ways in which that data might subsequently be used.

The Dutch regulator noted that Microsoft had promised to end its "violations", but warned that a failure to do so could lead it to impose a sanction.

After some back and forth with the regulator, Microsoft submitted a revised version of its software in April 2018. However, in the course of testing the revised version the Dutch agency found fresh grounds for concern, discovering what it called in a press release "new, potentially unlawful, instances of personal data processing".

"After some back and forth with the regulator, Microsoft submitted a revised version of its software in April 2018. However, in the course of testing the revised version the Dutch agency found fresh grounds for concern, discovering what it called in a press release "new, potentially unlawful, instances of personal data processing"."In the meantime GDPR had entered into force, and this led the Dutch data protection authority to refer its concerns to the competent lead EU privacy regulator under the new regulations. This was the national data protection authority where Microsoft's regional HQ for the EU is located, namely the Irish Data Protection Commission.

And so the seriously under-resourced Irish DPC added the Microsoft GDPR non-compliance case to an already long list of files concerning the cross-border data processing activities of multiple tech giants which had accumulated on its docket since the GDPR came into force in May 2018.

According to the most recently available reports from May 2020 the Microsoft case is still pending before the Irish Data Protection Commission.

The situation in the Netherlands became even hotter for Microsoft with the decision of the Dutch Ministry of Justice and Security in 2018 to commission a Data Protection Impact Assessment (DPIA) to be carried out on a range of Microsoft products, including Office 365.

"The situation in the Netherlands became even hotter for Microsoft with the decision of the Dutch Ministry of Justice and Security in 2018 to commission a Data Protection Impact Assessment (DPIA) to be carried out on a range of Microsoft products, including Office 365."The DPIA was commissioned because this was a clear-cut case of data processing on a large scale (by 300,000 government employees) which involved personal data, including data that could be potentially used to track the activities of employees.

The aim of the exercise was to assess the extent to which Microsoft's Office Online and the Mobile Office Apps could be deployed in a GDPR-compliant manner by Dutch government organisations.

The scope of the investigation included the five most commonly used Office 365 applications – Word, PowerPoint, Outlook, Excel and Microsoft Teams – in Office Online and the Mobile Office apps, in combination with the use of cloud storage services.

The final report [PDF], which was published in November 2018, identified a number of serious data protection risks, in particular the following:

● Loss of control over the use of personal data; ● Loss of confidentiality; ● Inability to exercise rights; ● Re-identification of pseudonymised data; ● Unlawful (further) processing.

It was noted that effective risk mitigation was outside of the users' control and could only be carried out by Microsoft.

"It was noted that effective risk mitigation was outside of the users' control and could only be carried out by Microsoft."The investigation found an unacceptable lack of control by users over the processing of personal data by Office 365 mobile applications. Because of this government organisations were advised to create policies for their employees stating that they were not to use mobile Office 365 applications.

As we shall see in the next part, the investigation by the Dutch authorities into the GDPR-compliance of Microsoft products prompted the European Data Protection Supervisor to announce its own investigation into Microsoft products used by EU institutions. ⬆

Recent Techrights' Posts

libera.chat is an Agenda-Peddling Platform Run by Agenda-Peddling Individuals
The volunteers of libera.chat ("staff") aren't working for free, they work towards an agenda
Secret Microsoft Layoffs and Maybe Another "Voluntary Exit Program at Microsoft in October"
there's a morale crisis at Microsoft
Many Topics to Cover
Drops in a big ocean
Gemini Links 04/10/2026: Peace in Outage, Pen Pals, and deGoogling
Links for the day
 
Links 05/10/2026: "Congress Must Investigate War Profiteers Once Again" and Update on Thomson Reuters v. Ross Intelligence
Links for the day
Nobel Season is Plutocracy Week
Later this week the billionaires will give a fake "Nobel" (in "Economics") to someone who parrots their preferred narrative and those same billionaires will use "Nobel" to bless the promoter of their latest pyramid scheme/buzzword
GNU/Linux Market Share in North America 13% This Past Weekend
It is perhaps not shocking that adoption of GNU/Linux is very high there
When Did Europe Begin to Side With White-Collar Criminals (or Participate in Suppressing People Who Oppose Them)?
How much corruption can we tolerate before the European Union becomes another Russian Federation?
Libera Chat's "Level of Control Might Make Sense for a Corporate Platform"
IRC is not centralised
Brigading Against Women - Part XVIII - Turning Censorship Attempts (Articles About Matthew Garrett) Into Mild Redactions
What Lozza did two years ago
Greenland Needs Digital Sovereignty
the large icy island isn't moving to GNU/Linux as quickly as the rest of Europe
Tracker of Internet Relay Chat Networks Out of Service (But Not Down) Since Thursday
We should note that the number of unique networks they track has grown since we last checked
Gemini Links 05/10/2026: NixOS, Guix, Codeberg Banning Slop, and "Gopher Apps on Android"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, October 04, 2026
IRC logs for Sunday, October 04, 2026
MIT Technology Review (MTR) Reinforces MIT's Role in Promoting Slop (Pyramid Scheme) in Exchange for Money
MIT is a poster boy (or child) of institutional corruption, perverts, and corporate takeover
Proving Wrong Those Slop Maximalists and Boosters, GAFAM Says Slop is a Nuisance and Bans/Hides the Slop Submissions
People who say slop in projects is inevitable or even desirable are usually cheaters with self-guilt
Links 04/10/2026: “AI Torture Chamber” and "Aggressive Push to Integrate Hey Hi (AI) Slop Into Schools Is Turning Into a Disaster"
Links for the day
How Microsoft Hides Massive Layoffs From the Media (as Explained by Microsofters)
"rewards" are not exactly rewarding
Brigading Against Women - Part XVII - The Appeal
more to be known towards the end of the year
Links 04/10/2026: Fires Rage in Borneo and Mass Layoffs at Disney
Links for the day
Garrett's Litigation Partner is Unemployed Again
losing one's job
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, October 03, 2026
IRC logs for Saturday, October 03, 2026
Teaser/Taster
Tomorrow morning we'll have an important story regarding "GGG"
Gemini Links 03/10/2026: Book Swaps and Book Crossing, Hidden Figures (2016), Apps and Tools for Research and Writing
Links for the day
Michael Catanzaro Seems to be Missing the Point
Calling people you disagree with "Ostriches" is lazy name-calling
Free Software Foundation (FSF) Turns 41
People who want humans and communities to maintain their software chains (and by extension their digital life) will back GNU
Links 03/10/2026: "Banned Books Week 2026" and "American Journalist Imprisoned as a Spy in Russia"
Links for the day
In Case Anybody Still Believes Microsoft Lunduke Cares About GNU/Linux...
GNU/Linux users aren't bots
Gemini Links 03/10/2026: Speculative Realism, Paper2SlopBot, Joplin, and Offline Experiment
Links for the day
Union Syndicale Fédérale (USF) Tries to Compel the European Patent Office (EPO) to Actually Function Properly
We'll be covering the EPO a lot more soon
Brigading Against Women - Part XVI - When Your Own Colleagues Complain About You Maybe the Problem is You
"if 2 people tell you that you're drunk, you go to sleep"
Links 03/10/2026: Slop-Generated War Songs and "Privatisation Has Failed"
Links for the day
Proprietary Software Giant Microsoft is Quietly Laying Off Lots of Employees, Insider Explains How It's Done
about Microsoft exits
United States: More Than One in Ten Using GNU/Linux on Laptop/Desktop
Clownflare Radar seems to show a similar trend
Brigading Against Women - Part XV - Trying to Put Women in Prisons
We'll soon get to the 'meat' or the 'beef', showing how "Gas The Jews" Lozza helped Garrett a few days after we had sued him in September 2024
A Leap in GNU/Linux Usage, Japan's Share in Particular
One thing that merits attention right now is Japan. It looks like it's adopting GNU/Linux instead of GAFAM.
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, October 02, 2026
IRC logs for Friday, October 02, 2026