Bonum Certa Men Certa

Breaking News: EDPS Admits That It is Powerless to Investigate Claims of GDPR Non-compliance at the EPO

Nothing says 'European data protection' like outsourcing communications to an American surveillance firm



Summary: Nobody is truly in charge at the EDPS (and in Europe at large); they say EPO is "company" and all one can do is kindly ask the EPO itself to obey the law and stop outsourcing European data to American military contractors

Back in March, Techrights started publishing its exposé about the EPO's sell-out of its digital sovereignty to Microsoft.



At around the same time this matter was brought to the attention of the European Data Protection Supervisor (EDPS).

"Its primary objective is to ensure that European institutions and bodies respect the right to privacy and data protection when they process personal data and develop new policies."The EDPS is an independent supervisory authority established by the European Union. Its primary objective is to ensure that European institutions and bodies respect the right to privacy and data protection when they process personal data and develop new policies.

You might have thought that the EDPS would be interested to learn about the alleged GDPR non-compliance at an intergovernmental institution which processes large amounts of personal data relating to EU citizens. You might even have expected them to carry out some kind of independent investigation like the Bavarian Data Protection Commissioner did back in 2015.

But sadly it turns out to be another case of "Not My Department".

"You might have thought that the EDPS would be interested to learn about the alleged GDPR non-compliance at an intergovernmental institution which processes large amounts of personal data relating to EU citizens."In its response to the complaint filed about the EPO, the EDPS has now stated that it is powerless to investigate claims of GDPR non-compliance at the second largest European intergovernmental institution.

Instead it suggests to the complainants that they "could contact EPO directly [...] by sending an email to DPO@epo.org".

The EDPS adds: "You can find this information in the company's Privacy Policy, available here: EPO - Data protection & privacy." (warning: epo.org link)

So as far as the EDPS is concerned, the EPO is a "company" rather than a public intergovernmental institution?

"So as far as the EDPS is concerned, the EPO is a "company" rather than a public intergovernmental institution?"Surely this is beyond a joke...

If EU citizens have a problem with the EPO's failure to comply with GDPR, the only available solution is to complain to the EPO?

And that is going to fix things?

Sounds like somebody in Brussels needs a reality check... URGENTLY!!!

Here's the text of the letter:

Our ref.: ⬆⬆⬆⬆⬆⬆⬆⬆⬆⬆⬆⬆⬆⬆



From: European Data Protection Supervisor

To: ⬆⬆⬆⬆⬆⬆⬆⬆⬆⬆⬆⬆⬆⬆⬆⬆⬆

Date: Friday, April 16, 2021

Dear ⬆⬆⬆⬆⬆⬆⬆⬆⬆⬆⬆⬆⬆⬆⬆

We are writing in response to your complaint submitted to the European Data Protection Supervisor (EDPS) on 11 March 2021.

We would like to point out that the EDPS is the independent authority of the European Union (EU) that deals with the supervision of the processing of personal data done by EU institutions and bodies[1]. In this sense, our tasks are similar to the tasks of national data protection authorities in the EU Member States, but apply only at the level of the European Union and its institutions[2].

We have analysed the matter raised in your message, and it appears that your request does not relate to the processing of personal data by EU institutions or bodies.

The EDPS has no supervisory competence over other international organisations. In consequence, we regret to inform you that your complaint, regardless its possible merits, falls outside the jurisdiction of the EDPS and we therefore do not have any authority to investigate it.

Please be informed that the seat agreements that the international organisations have with their host states usually grant them certain privileges and immunities. These often exclude the application of national law to the international organisation and therefore, the national data protection authority (DPA) of its host state may not be able to assist you either.

However, please be advised that you could contact EPO directly regarding your complaint by sending an email to DPO@epo.org. You can find this information in the company's Privacy Policy, available here: EPO - Data protection & privacy.

Yours sincerely,




EDPS Secretariat

| Tel. (+32) 228 31900 | Fax +32(0)22831950 | › Email edps@edps.europa.eu European Data Protection Supervisor Postal address: Rue Wiertz 60, B-1047 Brussels Office address: Rue Montoyer 30, B-1000 Brussels @EU_EDPS www.edps.europa.eu

This email (and any attachment) may contain information that is internal or confidential. Unauthorised access, use or other processing is not permitted. If you are not the intended recipient please inform the sender by reply and then delete all copies. Emails are not secure as they can be intercepted, amended, and infected with viruses. The EDPS therefore cannot guarantee the security of correspondence by email.

[1] According to Regulation (EU) 2018/1725 (see https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX:32018R1725 '... the European Data Protection Supervisor, shall monitor the application of the provisions of this Regulation to all processing operations carried out by a Union institution or body...' (see Article 1(3)). According to Article 3(10), the ‘Union institutions and bodies’ are the Union institutions, bodies, offices and agencies set up by, or on the basis of, the TEU, the TFEU or the Euratom Treaty (see http://europa.eu/about-eu/institutions-bodies/index_en.htm for a full list).

2 For example, like national data protection authorities we also provide advice to the legislator on new legislative proposals and on initiatives having an impact on data protection and privacy.




Data Protection Notice

According to Articles 15 and 16 of Regulation (EU) 2018/1725 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, please be informed that your personal data will be processed by the EDPS, where proportionate and necessary, for the purpose of investigating your complaint. The legal basis for this processing operation is Article 57(1)(e) of Regulation (EU) 2018/1725. The data processed will have been submitted by you, or from other sources during the inquiry of your complaint, and this may include sensitive data. Your data will only be transferred to other EU institutions and bodies or to third parties when it is necessary to ensure the appropriate investigation or follow up of your complaint. Your data will be stored by the EDPS in electronic and paper files for up to ten years (five years for prima facie inadmissible complaints) after the case closure, unless legal proceedings require us to keep them for a longer period. You have the right to access your personal data held by the EDPS and to obtain the rectification thereof, if necessary. Any such request should be addressed to the EDPS at edps@edps.europa.eu. Your data might be transferred to other EU institutions and bodies or to any third parties only where necessary to ensure the appropriate handling of your request. You may also contact the data protection officer of the EDPS (EDPS-DPO@edps.europa.eu), if you have any remarks or complaints regarding the way we process your personal data. You can find the full version of our data protection notice on complaint handling at: https://edps.europa.eu/data-protection/our-role-supervisor/complaints-handling-data-protection-notice_en.

___________________________ [1] According to Regulation (EU) 2018/1725 (see https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX:32018R1725 '... the European Data Protection Supervisor, shall monitor the application of the provisions of this Regulation to all processing operations carried out by a Community institution or body...' (see Article 1(2)). According to paragraph 1 of the same article, the ‘Community institutions or bodies’ are the institutions and bodies set up by, or on the basis of, the Treaties establishing the European Communities (see http://europa.eu/about- eu/institutions-bodies/index_en.htm for a full list). [2] For example, like national data protection authorities we also provide advice to the legislator on new legislative proposals and on initiatives having an impact on data protection and privacy.


Notice the mistakes with the footnotes, the repetition, the odd formatting etc. A rushed job? Did they properly investigate the complaint at all? Or did they look for excuses to dismiss it upfront? Did they use a template that refers to the subject as "company" or do they seriously think EPO is now a for-profit corporation? And if so, are corporations above the law and above the state? Here's the original [PDF] FWIW.

Recent Techrights' Posts

Secret Layoffs at Microsoft, Apparently More Sites Will Shut Down Entirely
vindicates us and serves to affirm what we've said for over a month
SLAPP Censorship - Part 156 Out of 200: Brett Wilson LLP Becoming Wilson FC
Now acting almost like one-person shop (lots of staff has fled this past year)
 
Northern Europe Leads the Pack in Abandoning Windows After Threats Made to Greenland (Says Clownflare Data)
Clownflare has a vast trove of data, so it cannot be easily dismissed as pure nonsense
Clownflare: In Past 12 Months Microsoft Windows Fell From ~80% to ~75% on Desktops/Laptops in Asia
Microsoft is deep in debt
The State of Slopfarms About "Linux" in August 2026
The Web needs serious cleanup, which curation can help deliver
IBM Offers Workers Some Money to Fire Themselves, It's Called "Next Step" and It's Allegedly 'Extended' (Not Enough Fools Have Fired Themselves)
Will IBM executives - including the CEO - ever be held accountable?
£5 Million Unsolicited/Undisclosed Bribes and What That Means to British Politics
It still remains unknown (disclosure denied) who helps fund the £1 million lawfare against us
[Satire] Pocock, Binface & nobodies vs Farage: defamation before UK High Court
Reprinted with permission from Daniel Pocock
The IBM Censorship Team, PIPs (Silent Layoffs) in IBM Europe
There seem to be many de facto layoffs going on at IBM right there
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, August 20, 2026
IRC logs for Thursday, August 20, 2026
Gemini Links 21/08/2026: "Ensmallening the BigWeb", "Rust Dependencies"
Links for the day
Links 20/08/2026: 'Linux' Foundation Promoting Slop Hype for Money (Hype as a Service), Malaysia’s Exports Jump 38% Year-on-Year
Links for the day
Gemini Links 20/08/2026: A "Break From Routine" and "Modem Was the Problem"
Links for the day
Clownflare Reckons GNU/Linux is on Almost 1 in 10 Laptops/Desktops in Western Europe
Western Europe and China are leaving more of GAFAM behind them
Looking Ahead at September
Rianne and I look forward to a productive September
Links 20/08/2026: Facebook "Ran Ads for an App That Promised to Nudify Female Politicians" and Facebook Faces "Social [Control] Media Addiction Trial"
Links for the day
Clownflare Sees GNU/Linux at 16% Market Share on Desktops/Laptops in Tajikistan
in Tajikistan it seems like adoption of GNU/Linux is exceptionally high, based on a very large data set associated with Web access
The Demise of Social Control Media Continues
Entering (anew) social control media in 2026 seems foolish
SLAPP Censorship - Part 155 Out of 200: Throwing Stones in Houses Made of Glass
character-assassination-as-a-service
Gemini Links 20/08/2026: Planners, Pantsing, Vinylyssee
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, August 19, 2026
IRC logs for Wednesday, August 19, 2026
Gemini Links 19/08/2026: "Big Boost in Autonomy" and "Answer of E-Mail"
Links for the day
Firefox in Trouble in the US, Down to Lowest Level in 20+ Years
more sites will stop or intentionally neglect Firefox support
Clownflare: More Than 1 in 5 Laptops or Desktops in El Salvador Run GNU/Linux or ChromeOS
Clownflare Radar reckons it's more like 20%+ now
SLAPP Censorship - Part 154 Out of 200: Computer-Generated Legal Filings From Men Who Are Salaried by Mass Plagiarism Companies in Another Continent (America)
This isn't the behaviour of a moral person but of some sort of "crypto bro" or "slop bro"
Fired by IBM for Medical Leave, Rampant Censorship of IBM Critics Explained
We've already caught and showed many cases where thelayoff.com deleted comments that were not even remotely racist
Links 19/08/2026: First Amendment Under Fire by White House of Cards, "Universities Were Forced to Pay Up" for Not Censoring
Links for the day
Gemini Links 19/08/2026: What Friendship Means, Sm0lNet/SmolNet, and New Feeds
Links for the day
Omarchy is Already Dying
Same as the life cycle of slopfarms
No, WSL (Windows With Fake 'Linux') Isn't Growing Faster Than Ubuntu, This Was Disinformation Spread by a Microsoft Propaganda Site, Then Spread by Slopfarms
Be sceptical; Microsoft is truly desperate for anti-Linux spin right now, seeing that Windows is in a freefall
Microsoft's Mass Layoffs Impact the Ability to Run Microsoft
Can Microsoft still run Microsoft?
Microsoft's Active Directory ("AD") and "Entra" Are National Security Threats
Even the US government concluded Microsoft could not be trusted for security; it issued a formal report about it in April 2024
Instant Impact: GNU/Linux Skyrockets to 10% in China Days After Policy Changes
Let's see what the 'aftermath' looks like by year's end
Links 19/08/2026: Timothy James King (AmigaDOS) Dies, GitHub Goes Offline, Finland Wants to Shun Social Control Media
Links for the day
Slop's Achilles Heel: It Increases the Workload, Not Just Costs
Set aside its inability to scale well
Improving techrights.org
Technical debt (like 17 years with WordPress) is something that's better to address early, not later
Mass Layoffs at Dropbox, Blame the Debt, Not Slop Hype
The debt of Dropbox Inc., which isn't an imaginary (estimated) thing, is over 4 billion dollars
Microsoft is 'Angel of Death' to Developers (Even Its Own), 'Voluntary' Layoffs Happening Again
From what we are hearing and reading, there are 'voluntary' layoffs again
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, August 18, 2026
IRC logs for Tuesday, August 18, 2026
Gemini Links 19/08/2026: Shirts, Handwriting, and Fights in Geminispace
Links for the day