Bonum Certa Men Certa

EPO Breaking the Law With Microsoft and Promoting Fake 'Encryption' That Violates Confidentiality on Many Levels

Video download link



Summary: An explanation of how truly ridiculous the EPO has become, handing over to Microsoft (and to the US government) just about all of the EPO's communications in direct violation of the law, as well, so the only question now is, will the law actually be enforced soon? Contact your local MP/MEP and report this to him/her.

THE EPO is breaking the law. The António Campinos regime is just as bad as Benoît Battistelli's, even when it comes to privacy and pressuring judges to allow unlawful patents, such as software patents.



Steve Rowan - Vice President DG1 - Patent Granting ProcessIn parts of the series prior to this one, including Part II, we explained what the EPO had done and why it's illegal. I recorded a video (the one above) prior to the publication of Part II.

It's a long video, we could add a lot of links to it (I thought of many that would be relevant while recording it, but failed to take notes throughout), though the ones that seem of most relevance are Microsoft and the NSA relations, the latest Exchange fiasco (as recently as hours ago they still try to distract from it), how end-to-end encryption (e2ee) really works and some background about Stephen Rowan. The full text of the communication is reproduced below:

04.02.2021

Home > Organisation > DG 1 > The Vice-President > Announcements > 2021

Outlook Migration to the Cloud



Data encryption requirements for sending highly confidential data via Outlook

As announced in previous intranet items published in May and December 2020, our Outlook mailboxes are being transferred to the cloud. The transfer will take place in phases and cover only emails since 1 January 2021. As regards the patent grant process, only the following documents are classed as "EPO strictly confidential" and must not be sent by email without encryption: (i) application documents of unpublished applications (EP, PCT, national) (ii) search reports, search opinions, communications and decisions relating to unpublished applications (iii) search statements resulting in the disclosure of unpublished application documents (Guidelines B-III, 2.4; B-IV, 2.4) (iv) documents excluded from file inspection (documents which are marked as non-public in DI+, such as dissenting opinions, medical certificates, PACE requests, etc.) Guidance for the storage of strictly confidential information in the cloud The storage of strictly confidential documents in the cloud should be avoided, and data should not be copied unnecessarily from the EPO's specialised document management systems such as DI+. In practice, this means that, instead of e.g. copying data into an email, you should send a link to the document in the document management system (see also "How to send an email with document links or zipped attachment via Outlook"). Where sharing of strictly confidential data is necessary, the data must be encrypted before storing it in the cloud or sending a link to it via email. It is strongly recommended that you do not send the data directly in an email but instead encrypt the document, store it in the cloud, e.g. on SharePoint or OneDrive, and then send the recipients a link to the encrypted document by email. The password then needs to be shared via a separate channel, e.g. in a Teams chat, via Skype or on the telephone. Sending encrypted attachments is strongly discouraged, as they might not pass spam filters: using encrypted attachments is a very common way to infect user computers, so our email gateways do not allow encrypted attachments to be sent from or to our Outlook cloud instance. The easiest and safest way of encrypting a document is to use the built-in capabilities of the Office programs. Simply protect the document with a password, which also will encrypt the document with a strong encryption algorithm. Obviously, this password should be safe. As a rule of thumb, it should be about as complex as our login passwords, but of course not identical to a password already used. Chat is a good way to send the password, as a long random password can be easily copied and pasted from the chat into the password prompt in the Office program. Examples of how to apply encryption in popular Office programs are in the document annexed here.

Reasons and background

The level of security provided by Microsoft's cloud services is very high and will even mean an improvement in information security for our email system. In the cloud, our mailboxes will be protected by the most sophisticated systems. Email in Microsoft's datacentres is stored with a high standard of encryption, both in transit and at rest. With the help of contract terms, a data protection agreement and technical implementation, the EPO has ensured the best possible protection for the data stored using Microsoft's cloud services. Microsoft guarantees that the data itself is stored on EU servers within the jurisdiction of the European data protection rules (GDPR). Under the US Foreign Intelligence and Surveillance Act (FISA) and the US Clarifying Lawful Overseas Use of Data Act (CLOUD Act), Microsoft is obliged to grant security and intelligence agencies access to data stored in its cloud, even when stored on EU servers. However, the protection level offered by Microsoft is still sufficiently high for DG 1 processes in place for confidential data exchange not to need encryption. By contrast, to comply with the highest standards, which of course include the requirements imposed under the GDPR, encryption is needed for strictly confidential data. The guidance on the use of cloud tools therefore states that it is only strictly confidential data that must not be stored in plain form in the cloud, whereas merely confidential information can be stored there without limitations. The EPO defines "strictly confidential" in its "policy for information classification" (document attached) as: EPO strictly confidential: Information unauthorised disclosure of which could compromise or cause severe damage to the EPO or could cause damage to an identifiable individual or his or her reputation. Access control cannot be delegated by the information owner, and is restricted to registered named persons only. See here for more information. The vast majority of DG 1 documents do not fall into this category, and this is true for typical performance related data too, since even poor performance must be regarded as "normal" working behaviour and cannot be considered to actually cause damage to an individual. For strictly confidential data, additional access control measures, such as registering people with access, are already implemented where required.

04.02.21 | Author: Steve Rowan - Vice President DG1 - Patent Granting Process


In Part III, which we will publish tomorrow, lots more will be shown.

Recent Techrights' Posts

In Techrights, Gemini and HTTP/HTML Are Very Different
Those were never equivalents or mirrors, those are two things that are inherently different and are maintained by different teams
"The War on Children" Explained by The Cyber Show
Consumer protection and the war on children
 
Hate Consumes the Haters
If you hate someone (or something) and you're willing to do anything for "hate rituals", then at the end the emotion will outweigh reason and it'll backfire, surely
GNU/Linux Rises Some More Internationally, statCounter Now Estimates Its Usage on Desktops/Laptops at 7.7%
significant growth for GNU/Linux in Japan, China, Thailand, Vietnam, Indonesia and Cambodia
IBMers on PIPs and the Age (or Cost) Factor
People in their 50s seem to be targeted as they are considered "expensive"
Sad State of Troll-Feeding British Media (Establishment Channels Promoting Total Idiots)
Breeding ignorance means people will assume they have a choice between two pieces of trash: "Nige" or a literal trash can
Links 27/07/2026: Sleepless Japan PM Takaichi Becomes Unpopular and Data Centre Magnate Confiscate Land Without Consent
Links for the day
A Few Hours Ago The Register MS Published an 'Article' With "AI" 32 Times in It, Including First Word in Headline and Summary. It Was Paid SPAM "Sponsored by Hammerspace".
The lost media is engaging in self-harm
Microsoft is Down
This relates in a timely fashion to what we published yesterday
Gemini Links 27/07/2026: Gemified Internet RFCs, “Junk DNA” Is Commented-Out Code, and More
Links for the day
The Techrights Gemini Capsule Was Never a Mirror
Techrights has long taken accessibility quite seriously
Americans Are Not Our Masters
If you are subjected to online abuse, don't give up
Daniel Pocock Campaigns Around "Safety of Children Online" and "Cybersecurity"
There seems to be a growing 'coalition' in the UK based around important issues which impact the entire planet
XBox the Console is Practically Finished (Unofficially), Even the Streaming ("Live") or DRM Service is Dead
XBox has never been closer to profitability
Many CEOs Are Just Glorified Scammers With Suits and Ties
Economies cannot function when few people abuse them for self-enrichment
After statCounter Figures Out Many "Unknowns" Were in Fact GNU/Linux the "Market Share" Estimate in China More Than Doubles
Japan is the same for similar reasons
peppe8o - a Site About Raspberry Pi, Arduino and Electronics - Has Turned Into a Slopfarm
We won't be linking to it anymore
Feeding 'the Children'
Maybe some time soon we'll do a fund-raiser to help feed the birds
Japan: GNU/Linux Crosses the 5% Threshold, Two Years Ago It Was Only 1%
Now it's at over 5%
We Need More Transparency
Our heads of state are very much aware of and concerned about SLAPPs and censorship
EPO Cocainegate and Current EPO/EU Series to Carry on for Months to Come
Another week has begun
When IBM "Managers Have to Mark 15% of Their Teams as Low Performers" a PIP Means Likely Layoffs (Disguised as a Performance Issue)
"IBM is a Law firm with an I/T department."
Links 27/07/2026: Chatbots Lead to Suicides, Social Control Media Intentionally Designed for Addiction
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, July 26, 2026
IRC logs for Sunday, July 26, 2026
Daniel Pocock in Mainstream Media Again
AFR wrote an article today. It is about Pocock and another contender.
Millions of Daily Requests
4.5+ million requests in 4 days
In statCounter, a Lot of "Unknown" Turns Out to be GNU/Linux
GNU/Linux has more than doubled
3,500 Active Gemini Capsules Soon
How much longer before 3,500+ active? A month?
Gemini Links 26/07/2026: European Eclipse, Writing About Writing, and Comments on Formatting Gopher Posts
Links for the day
Stigma of Being Laid Off by Microsoft
One might call this the "curse" of having worked for Microsoft
Silent Layoffs (PIPs) Have Allegedly Accelerated Since IBM's Stock Cratered
"IBM is Managing Decline, Not Building Growth"
Non-Techs Using Slop Run Fedora and It's Turning Out to be a Total Disaster
RIP, Fedora?
Gemini Links 26/07/2026: Beach Day, CAs, and Plaintext
Links for the day
Sweden Needs GNU/Linux and Free Software, Not GAFAM
home of IKEA and ABBA
Being Pro-Slop is Death Knell to One's Credibility
It's not hard to see Ubuntu users resisting and antagonising this
Maintenance Today
Preparing for more mass-publication activities
Links 26/07/2026: "Zelenskyy Says Russia Wants To Bring North Korean Troops Into Ukraine", Muslim Van Ramming Attack on Berlin Pride
Links for the day
Centrica fraud exposed: worse than Palestine Action 'terrorists' with cardboard placards
Reprinted with permission from Daniel Pocock
Links 26/07/2026: "Nate Silver Discovers the Educated Poor" and "India’s “Cockroach” Protest Movement Faces State Repression"
Links for the day
The Slop Bubble is Killing the Planet, Not Just the Economy
The chatbot/LLM speculation bubble not only causes a health crisis, a mental health epidemic, and climate change; it's also crashing the economy on several levels
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, July 25, 2026
IRC logs for Saturday, July 25, 2026
IBM Hammers a CoI Into a CoCed Fedora, RIP Fedora?
Also in the "Fedora is dead" dept. today
Gemini Links 25/07/2026: Zoo, MUD, Literature, EMF Camp, and e-ID
Links for the day
European Patent Office (EPO) Series: The Solution of No Choice: A Shortlist of One
deployment of the "shortlist of one" by Campinos
Wife of Dan Williams Has Explained Mental Factors Leading to His Death
"We need to be open and honest about mental health," his wife pleads
Several New Series Coming Soon
we'll publish 8 series in tandem, in parallel
Insolvency as the New Norm in the United States' Economy
this is vastly worse than then 2008 subprime mortgage crisis
IBM's CEO Might 'Retire' or 'Step Down' by Christmas
PIP the CEO
Misleading Articles About YouTube and Google Financial Performance
The future of Google is self-serving monopolisation and destruction of the Web
Microsoft Cannot Survive the Fall of Windows
It has amassed way too much debt
Links 25/07/2026: Hong Kong Squashing Criticism/Dissent, Mirror Caught Breaking Into Voicemail
Links for the day
PIPs Are Shrinking IBM and "IBM is Managing Decline, Not Building Growth"
IBM is going down the drain
IBM is Killing the Fedora Community, Replacing It With LLM Slop From IBM Staff
Krishna buys companies only to gut them. They've all learned this from experience.
Give Me Your "Dumbest" (Devices)
Why can't people accept that a "modern "smart" "phone" isn't necessary to check the time (overkill) and playing social control media "on the go" is far from necessary?
Earlier This Year Dan Williams Prepared for Scenario Where Linus Torvalds Dies
He had only just started a job at NVIDIA
Links 25/07/2026: Data Breaches Abundant and Attribution Imperiled in the Age of Slop Hype
Links for the day
Gemini Links 25/07/2026: Poetry and Plaintext Pages
Links for the day
What is Doctor of Philosophy (Ph.D.)
In many cases, the acronym became a misnomer
IBM PIPs Continue Until Morale Improves, Silent or Quiet Firings at IBM Explained
IBM is a dying company
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, July 24, 2026
IRC logs for Friday, July 24, 2026