Bonum Certa Men Certa

EPO and Microsoft Collude to Break the Law -- The 'Smoking Gun': Hard Evidence That the EPO Has Been Lying About GDPR Compliance

What the EPO says:

EPO CA-20-19 page 49 of 88

Summary: The EPO's Annual Reports of the Board of Auditors help show that the cronies of Benoît Battistelli have been lying all along about GDPR compliance; António Campinos is, as expected, just another one of those Battistelli cronies, in effect passing EPO funds into a gambling black hole and overseas violators of everybody's privacy

We have managed to track down copies of the "audit reports" which allegedly confirm a close alignment between the EPO's data protection framework and the GDPR.



As far as we have been able to work out, the "audit reports" that the EPO refers to in its data protection "puff pieces" are the annual reports of the supposedly independent Board of Auditors (warning: epo.org link). One of these "independent" auditors is Battistelli's old crony from the INPI, Frederic Angermann.

" One of these "independent" auditors is Battistelli's old crony from the INPI, Frederic Angermann."Anyway, the annual audit report is usually issued as Administrative Council document no. 20 at the end of April or beginning of May each year.

So for 2020, the document is numbered CA/20/20 [PDF].

For 2019 it is CA/20/19 [PDF] and for 2018, the reference number is CA/20/18 [PDF].

"From this it can be seen that the the annual reports of the Board of Auditors just parrot the party line of EPO management..."We've made local copies as we want this to last and remain unchanged, just in case something mischievous was to happen at the EPO's end. As happened in the past...

The documents are publicly available via the official webpage of the Council (warning: epo.org link) and can be found using the search keyword "auditors".

The first mention of GDPR is in the 2018 audit report, CA/20/18, on page 6 of 81:

42) As of 25 May 2018, a new, uniform General Data Protection Regulation (GDPR) on data privacy will apply across the European Union (EU) to all organisations collecting and/or processing data from EU residents. 43) On July 2017, the President issued a task force with a mandate to assess the potential impact of this new EU GDPR on the EPO's current data protection guidelines. 44) It is noted that the EPO's current data protection guidelines are relatively closely in line with the new GDPR. However, an action plan is in place to address the potential impact of the GDPR on the EPO.


EPO CA-20-18 page 6 of 81

The 2019 audit report, CA/20/19, contains the following statement:
259) The new European General Data Protection Regulation (GDPR) has been in force since 25 May 2018. Even though the EU regulations do not directly apply to the EPO as an international organisation, basic principles have been implemented, as European citizens' data is processed at the EPO.


It then goes on to talk about a the implementation of a "data protection register to record all the processing operations carried out on personal data" which can be accessed by EPO employees on the EPO intranet. It is not accessible to external data subjects but external parties can make a data subject access request "thus ensuring the right to information". This is followed by a recommendation that data protection register needs to be updated and to be completed in order to ensure that all relevant information is available.

The report then states that the EPO's IT department, referred to as IM (= Information Management) is "only involved in the GDPR analysis on a high-level basis" and that IM does not prepare the necessary implementation, such as deletion concepts.

This section of the report concludes with a recommendation to include IM much more in the GDPR evaluation "to ensure that technical and organisational measures are addressed adequately. Additionally technical solutions need to be evaluated."

The 2020 audit report, CA/20/20, contains a section entitled "Analysis of implementation of GDPR requirements in the HR area" on page 7 of 89. According to this:

41. Since the Office, as an international organisation that does not fall under the EU regulations, is not subject to the General Data Privacy Regulation (hereinafter: "GDPR"), the internal "Guidelines for the protection of personal data" were developed and introduced by the Office with the latest revision in 2014. The abovementioned guidelines are very close to the requirements of the GDPR and Regulation (EU) 2018/1725 and as such are to be implemented and followed by the Office.


EPO CA-20-20 page 7 of 89

There are two short paragraphs explaining that "audit procedures were carried out in respect of the adherence of the Office to the requirements of the above-mentioned guidelines within the HR area" and that the audit "resulted in a number of recommendations", such as the need to update the Data Protection Registry and to define retention and deletion periods and actions for events such as retirement and leaving the Office.

"There hasn't actually been any independent audit of the EPO's data protection framework to determine the level of GDPR compliance."Additionally, it recommends that "the awareness of the responsibilities of controllers in terms of data protection topics should be raised, and regular training sessions should be held for the HR department, as well as for other departments working with the personal data, to inform them about critical areas in the data protection process."

From this it can be seen that the the annual reports of the Board of Auditors just parrot the party line of EPO management according to which "the EPO's current data protection guidelines are relatively closely in line with the new GDPR" (CA/20/18) and "the internal 'Guidelines for the protection of personal data' [which] were developed and introduced by the Office with the latest revision in 2014 ... are very close to the requirements of the GDPR and Regulation (EU) 2018/1725" (CA/20/20).

There hasn't actually been any independent audit of the EPO's data protection framework to determine the level of GDPR compliance.

All that we have are bald assertions of GDPR compliance by EPO management which have been rubber-stamped by the auditors without further ado.

"All that we have are bald assertions of GDPR compliance by EPO management which have been rubber-stamped by the auditors without further ado."Given that EPO management claimed at the time of adoption of the EPO's internal "Guidelines for the protection of personal data" in 2014 that they were closed aligned to the earlier EU Regulation (EC) 45/2001, it remains to be explained how these same Guidelines could now manage to be compliant with the GDPR which was not adopted by the EU until 2016 and entered into force in 2018.

Of course it's complete nonsense but as long as nobody actually goes to the trouble of carrying out an independent audit who's going to notice anything?

Recent Techrights' Posts

Society Will Only Improve Owing to People Who Push Boundaries
Push boundaries with ideas and facts, not with forbidden language
 
SLAPP Censorship - Part 111 Out of 200: Garrett and Graveley (the Latter Arrested for Strangling Women) Keep Ousting Their Collaboration in Litigation, Lawfare in a Foreign Continent
it's not law, it's just warfare disguised as "law"
European Patent Office (EPO) Series: Lobbying in Lisbon...
reappointment campaign lobbying has not been restricted to the "home front" in Portugal
Slop Making Its Way Into Terms Where It Does Not Belong
Hopefully by year's end Google News can successfully cull (and deprive of traffic) almost all slopfarms
Links 19/06/2026: Microsoft Patent Troll Intellectual Ventures in Europe, "World Cup of Internet Resilience"
Links for the day
Links 19/06/2026: Salesforce Data Thefts and GAFAM's Conspiracy Theories That Data Center Opposition is a Foreign Plot
Links for the day
Links 19/06/2026: The Retweeting Class and Data Centres as National Security Risk
Links for the day
Don't Attack the Wives (or Spouses) of Pundits/Activists/Journalists
We will be writing several series about this in the future
Internet Relay Chat (Shorthand IRC) is Still Growing
Contrariwise, social control media is waning
The Register MS Published a New Page With "AI" 21 Times in It. It Was Paid SPAM.
The former editor of the The Register MS admitted to me (directly) that he knew all this "AI" stuff was stupid hype
Murdoch's Wall Street Journal (WSJ) Associates Dependence on a Ponzi Scheme With "the Future"
Those ludicrous ads (disguised as rankings) from WSJ deserve scorn and ridicule
The XBox Story is Still Fast-Developing, the Layoffs Are Confirmed to be Happening Already (Mid-June), Just Not "Officially"
Workers have Microsoft have long braced for what is happening this summer and will accelerate further in two weeks' time
Fake News From Rupert Murdoch's WSJ Could Not Keep IBM From Sinking
"2026 Best Companies for the Future"?
To GNU, AV2 Adoption May be a Year If Not Years Away
The leap between versions means that there is fertile ground for incompatibilities
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, June 18, 2026
IRC logs for Thursday, June 18, 2026
Gemini Links 19/06/2026: "Born and Raised by the Internet", Fifteen Years in Gopher
Links for the day
Links 18/06/2026: Clown Computing Has Harmful Sound, Facebook "Must Face the Music (Infringement Litigation)"
Links for the day
Digital Sovereignty Discussed in the United Kingdom (UK)
Digital Sovereignty would be nice, but let's remember what contributes to it
IBM Adds Only More IBM Staff to the Fedora Council, They Like LLM Slop for Posting 'Articles'
It's like Canonical with Ubuntu, only worse
IBM Common Stock Down to About $250, It Was at $330 Just 17 Days Ago
Happy birthday IBM!
Microsoft's CEO Openly Admits XBox is Not Sustainable and Microsoft is Beginning to Admit Slop Isn't Working and Is Not Not Sustainable Either
Expect Microsoft cancellations next month (or later this month) to impact far more than XBox and some studios
EPO and Disabilities: Payments Allegedly Disabled
But people who do cocaine can claim paid "sick leave" (over 100,000 euros for no work at all) if the President sleeps with them
SLAPP Censorship - Part 110 Out of 200: Anti-SLAPP Reform Formally Advanced in the United Kingdom (UK) the Same Week the Serial Strangler From Microsoft (US) Does Forum-Shopping in the UK
The only language they understand is money. They don't understand privacy.
Links 18/06/2026: UK Social Media Ban for Minors, Finland Lifts a Nuclear Weapons Ban
Links for the day
'Article' With "AI" 27 Times in the Page, It's "Partner Content" (Paid Spam) as Usual at The Register MS
We deem this a timely reminder that a lot of the hype around slop is paid-for lies
Microsoft Layoffs Have Reportedly Already Started at ZeniMax
The overall scale is unknown
Cyber Show: "Our independence remains intact and we're set to continue relentlessly probing the world of digital technology with hard questions"
As one should
European Patent Office (EPO) Series: Leveraging the Lusitanian Connection
Mendonça no longer functions as an independent agent but rather as a fig-leaf for a mafia-like entity that prizes obedience over integrity and self-preservation over truth
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, June 17, 2026
IRC logs for Wednesday, June 17, 2026
The "Official" Numbers That Say "Microsoft Layoffs" Will be Misleading
The scale of the layoffs in gaming will be unprecedented
SLAPP Censorship - Part 109 Out of 200: When You Drag Family Members Into a Case Unrelated to Them Because Their Relative Published Something
This did not exactly surprise us given what we had already encountered
SUEPO Munich Informs/Contacts the German Government About the Situation at the European Patent Office (EPO)
Salary Erosion Procedure: Two letters to Germany
Gemini Links 17/06/2026: Feeling "Useful"; PISA Pen-and-Paper Cipher
Links for the day
Trajectory of O'Reilly: From Publisher of Books to Microsoft Advertiser
The state of the media is not good and when prolific book publishers start running ads as 'articles' or videos (never mind the disclosure) it is rather tasteless
Links 17/06/2026: Slop's “Crack Cocaine” Approach to Pricing, Microsoft's Rapid Shrinking of Gaming Business
Links for the day
Links 17/06/2026: "How Developers React to Slop-Scented Blog Posts", Police Caught Fabricating Evidence Using Slop
Links for the day
More Than 90% in European Patent Office (EPO) Ballot Vote for Continuation of Industrial Actions/Strikes, About Half Wish to Further Intensify These
Ballot results on intensification of actions
If Not Now, Then When?
If you are not part of the solution/s, then you're merely a vessel or passive participant
Microsoft Offers People 'Retirements' (Again) to Fake (Artificially Lower) Number of Layoffs, Those People Are Nowhere Near Retirement Age
Microsoft implicitly affirms huge cuts are coming
Gemini Links 17/06/2026: 10 Years in Canada, Wild Flower Explorations, and Microslop
Links for the day
European Patent Office (EPO) Series: The Portuguese Prodigy
In this part we will present some additional background information about Mendonça's activities before he joined the EPO
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, June 16, 2026
IRC logs for Tuesday, June 16, 2026