Bonum Certa Men Certa

EPO and Microsoft Collude to Break the Law -- Part IX: Know Your Vendor…

Previous parts:



A big brother-like spy
The never-ending saga of Microsoft's run-ins with European data protection authorities



Summary: Microsoft is one of the world's worst offenders when it comes to privacy, but vendor assessment by the EPO conveniently overlooks the law

Even before GDPR came into effect in May 2018, data protection regulators in some European countries were starting to have their doubts about whether Microsoft's flagship product, its Windows operating system, was compliant with European data protection standards.



The first national authority to kick into action was the French National Data Protection Commission (CNIL).

Following an investigation which concluded in June 2016, CNIL issued Microsoft with a formal notice to comply with French data protection regulations. CNIL also ruled that the decision should be made public, given the scale of the violations in question.

"Following an investigation which concluded in June 2016, CNIL issued Microsoft with a formal notice to comply with French data protection regulations. CNIL also ruled that the decision should be made public, given the scale of the violations in question."No fewer than six violations of the French Data Protection Act were identified by CNIL, including continued transfer of data based on Safe Harbor principles despite the fact that the Safe Harbour Agreement had been invalidated by the CJEU in October 2015.

Microsoft was given three months – until 30 September 2016 – to end the identified violations of French Data Protection law or else face the prospect of a fine of up to €150,000.

In June 2017, it was reported that Microsoft had scaled back the volume of data it collected from Windows 10 PCs by "almost half". This led CNIL to announce that Windows 10 was no longer in breach of the country's data protection laws and that it had decided to close the case.

But that was only the first chapter in the never-ending saga of Microsoft's run-ins with European data protection authorities.

"Microsoft was given three months – until 30 September 2016 – to end the identified violations of French Data Protection law or else face the prospect of a fine of up to €150,000."A few months later in October 2017, it was reported that the Dutch data protection authority (Autoriteit Persoonsgegevens) had come to the conclusion that Microsoft was in breach of Dutch data protection law due to the way it processed the personal data of Windows 10 users.

According to the Dutch data watchdog, Microsoft made it impossible for users to give their valid consent to their personal data being processed due to the multiple ways in which that data might subsequently be used.

The Dutch regulator noted that Microsoft had promised to end its "violations", but warned that a failure to do so could lead it to impose a sanction.

After some back and forth with the regulator, Microsoft submitted a revised version of its software in April 2018. However, in the course of testing the revised version the Dutch agency found fresh grounds for concern, discovering what it called in a press release "new, potentially unlawful, instances of personal data processing".

"After some back and forth with the regulator, Microsoft submitted a revised version of its software in April 2018. However, in the course of testing the revised version the Dutch agency found fresh grounds for concern, discovering what it called in a press release "new, potentially unlawful, instances of personal data processing"."In the meantime GDPR had entered into force, and this led the Dutch data protection authority to refer its concerns to the competent lead EU privacy regulator under the new regulations. This was the national data protection authority where Microsoft's regional HQ for the EU is located, namely the Irish Data Protection Commission.

And so the seriously under-resourced Irish DPC added the Microsoft GDPR non-compliance case to an already long list of files concerning the cross-border data processing activities of multiple tech giants which had accumulated on its docket since the GDPR came into force in May 2018.

According to the most recently available reports from May 2020 the Microsoft case is still pending before the Irish Data Protection Commission.

The situation in the Netherlands became even hotter for Microsoft with the decision of the Dutch Ministry of Justice and Security in 2018 to commission a Data Protection Impact Assessment (DPIA) to be carried out on a range of Microsoft products, including Office 365.

"The situation in the Netherlands became even hotter for Microsoft with the decision of the Dutch Ministry of Justice and Security in 2018 to commission a Data Protection Impact Assessment (DPIA) to be carried out on a range of Microsoft products, including Office 365."The DPIA was commissioned because this was a clear-cut case of data processing on a large scale (by 300,000 government employees) which involved personal data, including data that could be potentially used to track the activities of employees.

The aim of the exercise was to assess the extent to which Microsoft's Office Online and the Mobile Office Apps could be deployed in a GDPR-compliant manner by Dutch government organisations.

The scope of the investigation included the five most commonly used Office 365 applications – Word, PowerPoint, Outlook, Excel and Microsoft Teams – in Office Online and the Mobile Office apps, in combination with the use of cloud storage services.

The final report [PDF], which was published in November 2018, identified a number of serious data protection risks, in particular the following:

● Loss of control over the use of personal data; ● Loss of confidentiality; ● Inability to exercise rights; ● Re-identification of pseudonymised data; ● Unlawful (further) processing.

It was noted that effective risk mitigation was outside of the users' control and could only be carried out by Microsoft.

"It was noted that effective risk mitigation was outside of the users' control and could only be carried out by Microsoft."The investigation found an unacceptable lack of control by users over the processing of personal data by Office 365 mobile applications. Because of this government organisations were advised to create policies for their employees stating that they were not to use mobile Office 365 applications.

As we shall see in the next part, the investigation by the Dutch authorities into the GDPR-compliance of Microsoft products prompted the European Data Protection Supervisor to announce its own investigation into Microsoft products used by EU institutions.

Recent Techrights' Posts

Linus Torvalds Blasts Software Freedom Conservancy (SFC) for Attempting to 'Protect' Linux
Like it 'protects' women
New Record for GNU/Linux in Australia (at Microsoft's Expense)
Windows is at an all-time low, GNU/Linux... all-time high
Fighting Over Whose Pockets Are Deeper (or Who Borrows More Money)
When processes favour those who are more wealthy (or more willing to go into infinite debt or steal money of other people) those processes match the attributes of lawfare rather than law
Starting a Book With a Flawed Premise or Weak Hypothesis
To me, Schneier is a sort of "RMS of sec"
Microsoft's Mass Layoffs (30,000+ in 2025) Not About "AI", Just Business Failure
"AI" is replacing... the old excuses for mass layoffs
EPO People Power - Part XVI - Berenguer Does Not Speak German, So What Did He Tell German Police That Busted Him?
based in Germany and does not speak the language
Challenges for EPO Insiders to Try to Tackle in 2026
Nothing will get solved as long as the circus that runs this show tries to keep the circus going
 
Once Again, GAFAM Deletes All Your Data, Only Corrects This After Millions of People Lead an Uproar Online ("Richard Stallman Warned Us About This")
No lessons learned, eh?
You Know Your Critics Are Jealous and Have Inferiority Complex When...
One day we'll write about all this in great depth
"But Corruption is Everywhere"
"We'll always have Polio..."
Days Without Slop About "Linux"
It's time to move on
Links 27/12/2025: Canada Post Strike Called Off, Debate About Europeans "Working Over Christmas"
Links for the day
Gemini Links 27/12/2025: Household Appliances and Flight Fright
Links for the day
Links 27/12/2025: US Cracking Down on Whistleblowers, Expanding Bombardment Campaigns Worldwide
Links for the day
Resuming EPO Coverage Today, Can António Campinos 'Survive' Cocainegate?
We said we'd continue in the weekend
Links 27/12/2025: More Attacks on Media (Meduza Co-founder Sentenced to Prison in Absentia), "What Owning Music Means To Me"
Links for the day
Gemini Links 27/12/2025: geminiprotocol.net Downtime and Capsular Gemlog Manager
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, December 26, 2025
IRC logs for Friday, December 26, 2025
Tossing Embarrassing News Under the Christmastime Bus
This isn't just some coincidence; those are conscious choices
Victim-Blaming in Debian
Verhelst previously did blame-shifting when Debian suicide clusters happened
IBM Cuts in Japan, Red Hat is Attached to a Sinking Ship
IBM, which controls Red Hat, is a rapidly shrinking company
Manchester United Dumped Microsoft Because Qualcomm Sort of Did
The Windows PCs were an utter failure
Free Software Foundation (FSF) Supported by Unconventional Digital Bartering Communities
But no strings attached
Geminispace: 5,000 Capsules in 2026
There are 4.8k now
Gemini Links 26/12/2025: Careful What You Eat and "My Secret Santa"
Links for the day
The Indigenous Community Versus Corporate AstroTurt and 'Cancel Culture'
Good people will recognise exactly what's happening here and respond to it tactfully
Richard Stallman: Epstein is a Serial Rapist. Bill Epsteingate: Epstein is a Friend.
Supporting the FSF (or Richard Stallman) is supporting those who asserted Epstein had serially raped women
The Paradox of GAFAM: Saying You Protect Women, Appointing Abusers of Women to Run the Company
older articles
Censored by FreeBSD Core Team Secretary, Reinstated After Talking About it in Public
FreeBSD misfiring a CoC?
Links 26/12/2025: Chatbot Toys Terrorising Children, US Undeclared "War on Terror" Unilaterally Extends to Nigeria During Holidays
Links for the day
Links 26/12/2025: French Postal Services Under Russian Attack, U.S. Cheetos Accuse People Who Obstruct Information Warfare by Russia of "Censorship"
Links for the day
Debian's Daniel Kahn Gillmor is Wrong, Signal is No "Gold Standard" (It's Also Promoted by Proponents of Back Doors)
I'm not too sure why Debian or the ACLU would wish to associate with this
Next Year Will be the Year of Quantum, Just Like 2020, 2015, 2010, 2005 and So On
"Quantum" is the future
The Silent Power of Coercion Over Speech
The important thing is optics
Kazakhstan Doesn't Need GAFAM Datacentres (Spy Hubs)
Suffice to say, as far as we can gather nothing came out from the empty (false) promises of GAFAM's "data centers in Kazakhstan"
So Simple That You Can Touch and Feel It
In light of recent experiences
Christmas Music Project: Back to When Music Was Music
now Canonical (or Ubuntu) says we should make available tens of gigabytes of disk space
Internet Relay Chat (IRC) Under Attack by Cross-Network Spam Floods
So far we've been spared (our network has not been targeted at all) [...] Let's hope the spam won't discourage the hundreds of thousands of people worldwide who still use IRC
An "AI-Infused" Windows
Microsoft Windows isn't becoming a worthless pile of garbage by accident
Microsoft Laid Off Over 30,000 People This Year, Coders Are "Too Expensive"
Go get some popcorn. Microsoft "slopware" is about to get real!
Critics Have Long Said Microsoft Produces "Slopware", Microsoft Wants to Prove Them Right
Slop instead of code is a step in the right direction?
The Top 8 Innovations of IBM in 2025
What innovations will come out from IBM in 2026?
And as the Year Turns...
The significance of new years isn't based on geology or astronomy or anything like that
Appliances Versus Computers
Replacing a computer inside an object of some kind or inside an appliance (which nowadays includes "modern" cars) isn't simple and isn't cheap
A Dark Side of Europe
They try hard to silence people who speak about these issues
Why People Love Techrights (and Also Loved "Boycott Novell")
I will continue to publish for many decades to come
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, December 25, 2025
IRC logs for Thursday, December 25, 2025
Browsing Techrights With a GUI and 10 Megabytes of RAM Per Tab
Some people say it's not possible in 2025, maybe in part because they depend on very bloated software
A Tribute to Richard Stallman
It's about knowledge and sharing
Links 26/12/2025: Impermanence, Salt and Thermometer, Freetube
Links for the day
Gemini Links 25/12/2025: Hibernation and TV Detox
Links for the day
Canonical is Making the Cost of PCs Very High, Due to Unnecessary Ubuntu Bloat
They say the reason for the price surge is LLM hype/frenzy
Canonical's Ubuntu is Bloatware
How did Ubuntu get so fat?
The EPO is a Very Vicious Organisation You Neither Wish to Join Nor Stay in for "Too Long"
Consider what the EPO thinks of its own workers, the staff that actually does real work
2026 Will Hopefully Turn Out to be Slopless
we seem to be starting the post-Christmas period on the right footing
Links 25/12/2025: Mail Carriers in "a Murky Future", Dihydroxyacetone Man’s "Chip Embargo Against China Backfiring Spectacularly"
Links for the day
The Register MS: All I Want For Xmas is Microsoft
they actually put effort into it
How to Win Nobel Prize for Peace
Do you get to Heaven (or peace platitudes) by sleeping with 72 virgins?
The Right to Repair (Especially When Products Are So Poorly Made)
Many electrical appliances fail often/quick and are nearly impossible to repair
Links 25/12/2025: Ample Cover-up Found in Jeffrey Epstein Files; ChatGPT Causes Psychosis, Not a Good Use Case
Links for the day
Giving Money to Free Software
In life, people must make sacrifices to do what's right and just
The Register MS: Don't Use Linux
That really says a lot about The Register MS
EPO People Power - Part XV - EPO Cocainegate to Resume This Weekend
The next installment (number 16) will probably come out this weekend
Microsoft: XBox is Going "Online", "Cloud"...
XBox as a console is pretty much dead
The Year of the Bubble
We hope that in 2026 the marketing liars will find some new buzzwords to latch onto and quit calling everything "AI"
Mozilla Firefox is a GAFAM Browser With Slop, Move to a Free Software Web Browser
on mobile the options would be more limited
libera.chat Was Under Attack Last Night
Several months from now libera.chat turns 5
Free Software Foundation (FSF) Raises Over $300,000 Before Christmas
the FSF made it past $300,000
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, December 24, 2025
IRC logs for Wednesday, December 24, 2025