Bonum Certa Men Certa

EPO and Microsoft Collude to Break the Law -- Part IX: Know Your Vendor…

Previous parts:



A big brother-like spy
The never-ending saga of Microsoft's run-ins with European data protection authorities



Summary: Microsoft is one of the world's worst offenders when it comes to privacy, but vendor assessment by the EPO conveniently overlooks the law

Even before GDPR came into effect in May 2018, data protection regulators in some European countries were starting to have their doubts about whether Microsoft's flagship product, its Windows operating system, was compliant with European data protection standards.



The first national authority to kick into action was the French National Data Protection Commission (CNIL).

Following an investigation which concluded in June 2016, CNIL issued Microsoft with a formal notice to comply with French data protection regulations. CNIL also ruled that the decision should be made public, given the scale of the violations in question.

"Following an investigation which concluded in June 2016, CNIL issued Microsoft with a formal notice to comply with French data protection regulations. CNIL also ruled that the decision should be made public, given the scale of the violations in question."No fewer than six violations of the French Data Protection Act were identified by CNIL, including continued transfer of data based on Safe Harbor principles despite the fact that the Safe Harbour Agreement had been invalidated by the CJEU in October 2015.

Microsoft was given three months – until 30 September 2016 – to end the identified violations of French Data Protection law or else face the prospect of a fine of up to €150,000.

In June 2017, it was reported that Microsoft had scaled back the volume of data it collected from Windows 10 PCs by "almost half". This led CNIL to announce that Windows 10 was no longer in breach of the country's data protection laws and that it had decided to close the case.

But that was only the first chapter in the never-ending saga of Microsoft's run-ins with European data protection authorities.

"Microsoft was given three months – until 30 September 2016 – to end the identified violations of French Data Protection law or else face the prospect of a fine of up to €150,000."A few months later in October 2017, it was reported that the Dutch data protection authority (Autoriteit Persoonsgegevens) had come to the conclusion that Microsoft was in breach of Dutch data protection law due to the way it processed the personal data of Windows 10 users.

According to the Dutch data watchdog, Microsoft made it impossible for users to give their valid consent to their personal data being processed due to the multiple ways in which that data might subsequently be used.

The Dutch regulator noted that Microsoft had promised to end its "violations", but warned that a failure to do so could lead it to impose a sanction.

After some back and forth with the regulator, Microsoft submitted a revised version of its software in April 2018. However, in the course of testing the revised version the Dutch agency found fresh grounds for concern, discovering what it called in a press release "new, potentially unlawful, instances of personal data processing".

"After some back and forth with the regulator, Microsoft submitted a revised version of its software in April 2018. However, in the course of testing the revised version the Dutch agency found fresh grounds for concern, discovering what it called in a press release "new, potentially unlawful, instances of personal data processing"."In the meantime GDPR had entered into force, and this led the Dutch data protection authority to refer its concerns to the competent lead EU privacy regulator under the new regulations. This was the national data protection authority where Microsoft's regional HQ for the EU is located, namely the Irish Data Protection Commission.

And so the seriously under-resourced Irish DPC added the Microsoft GDPR non-compliance case to an already long list of files concerning the cross-border data processing activities of multiple tech giants which had accumulated on its docket since the GDPR came into force in May 2018.

According to the most recently available reports from May 2020 the Microsoft case is still pending before the Irish Data Protection Commission.

The situation in the Netherlands became even hotter for Microsoft with the decision of the Dutch Ministry of Justice and Security in 2018 to commission a Data Protection Impact Assessment (DPIA) to be carried out on a range of Microsoft products, including Office 365.

"The situation in the Netherlands became even hotter for Microsoft with the decision of the Dutch Ministry of Justice and Security in 2018 to commission a Data Protection Impact Assessment (DPIA) to be carried out on a range of Microsoft products, including Office 365."The DPIA was commissioned because this was a clear-cut case of data processing on a large scale (by 300,000 government employees) which involved personal data, including data that could be potentially used to track the activities of employees.

The aim of the exercise was to assess the extent to which Microsoft's Office Online and the Mobile Office Apps could be deployed in a GDPR-compliant manner by Dutch government organisations.

The scope of the investigation included the five most commonly used Office 365 applications – Word, PowerPoint, Outlook, Excel and Microsoft Teams – in Office Online and the Mobile Office apps, in combination with the use of cloud storage services.

The final report [PDF], which was published in November 2018, identified a number of serious data protection risks, in particular the following:

● Loss of control over the use of personal data; ● Loss of confidentiality; ● Inability to exercise rights; ● Re-identification of pseudonymised data; ● Unlawful (further) processing.

It was noted that effective risk mitigation was outside of the users' control and could only be carried out by Microsoft.

"It was noted that effective risk mitigation was outside of the users' control and could only be carried out by Microsoft."The investigation found an unacceptable lack of control by users over the processing of personal data by Office 365 mobile applications. Because of this government organisations were advised to create policies for their employees stating that they were not to use mobile Office 365 applications.

As we shall see in the next part, the investigation by the Dutch authorities into the GDPR-compliance of Microsoft products prompted the European Data Protection Supervisor to announce its own investigation into Microsoft products used by EU institutions.

Recent Techrights' Posts

Let Them Eat 'Apps'
Go Appless
Linux Runs Almost Everything, But They Almost Never Tell You This (No Marketing Budget)
Only about 1% (or at most 2%) of the Linux Foundation's budget goes towards Linux; a lot is routed towards Bill Gates and Microsoft promotion
Free Software Community Folks Are Closer Together Than the Cliques and Opportunists Rallying Around "Open Source" (Openwashing, Marketing, Conniving)
Generally speaking, freedom-loving geeks learn to reject morbid elements and trolls, who end up expelled
Growing Poverty Rates in the United States of America (or Elsewhere) Beneficial to GNU/Linux Adoption
Toxic politics around the world, including the US, may mean weaker economies
European Patent Office (EPO) Illegally Turning to Slop Behind Closed Doors, Staff Objects to This Hidden Catastrophe
Who stands to gain from all this and at whose expense?
After US Government Funding Cuts the Centralisation of the Web (Especially Certificate Authority Let's Encrypt) is at Risk
They try to pull the plug on open protocols with decent encryption available (unless it is outsourced to third parties)
When Microsoft Folks Who Literally Strangle Women Try to Strangle Microsoft Critics
Speaking to Court staff yesterday, they too are shocked about those SLAPPs
Martinique: Windows Down to All-Time Low
we cannot expect Windows to ever recover
 
Links 25/03/2025: Clownflare’s Slop and Bounties on Fake Patents
Links for the day
Links 25/03/2025: Terrace Workbench and Spellcheck in LibreOffice on FreeBSD
Links for the day
The Open Source Initiative (OSI) Might Get 'Forked' Soon
Someone who read our series has already taken a leading role
IBM Layoffs in the United Kingdom (UK) in 2025
Should Free software people trust such a secretive company?
Roku Will 'Lead' Attempts to Abolish the Illegal and Unconstitutional Unified Patent Court (UPC), Which Represents EPO Corruption and Lobbyism Spreading Upwards Inside the EU
When bribery buys policies and courts, even illegal policies and courts
Gemini Links 25/03/2025: Relaxation, Literary "Movements", and Gemini Mentions
Links for the day
Links 25/03/2025: Putin Sends Children to Battle, 23andMe Drowns as People's Highly Personal DNA Data Floats
Links for the day
Anticipated in 2018: Lilie James & Location tracking, Googlists complained
Reprinted with permission from Daniel Pocock
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, March 24, 2025
IRC logs for Monday, March 24, 2025
IBM (and Red Hat) on a Fast Train to Nowhere
What is the future of Fedora when IBM keeps removing its leadership?
Press Reports Say Almost 10,000 Western IBMers Laid Off
We've been trying to verify/corroborate this somehow
Gemini Links 24/03/2025: "Live Off the Land" and Life Without YouTube
Links for the day
Planet Ubuntu (or Ubuntu Planet) is LLM Slop
Reading chatbots' output is bad use of time
Days Ago yewtu.be Found a Workaround That Made Invidious Work Again. Then Google Broke All the Instances (Again).
"Youtube changed something again, so if a video does not play, it's because of that."
The European Patent Office (EPO) is Slowly Killing Its Own Staff; All It Cares About Is Money
The Office hasn't been run by a scientist for about 18 years already
Links 24/03/2025: US Detaining Innocent People, F-35 Contracts Suspended Due to Hostilities
Links for the day
Cellphones (Mobile Phones) in Classrooms
A recent study confirmed that people's intelligence has dropped in recent years/decades
Is the FSF Being 'Trolled' by Microsofters Pushing C# (Microsoft)?
Who stands to benefit from training people to use and spread Microsoft?
Matthew J. Garrett is "Former Microsoft Researcher", According to Microsoft's Serial Strangler
Their argument is something along the lines of, "what Roy published damaged my career prospects, so I want Roy to pay me...
Links 24/03/2025: Political Catchup and Environmental Concerns
Links for the day
Windows Has Now Fallen to Rather Ridiculous 3% "Market Share" in Iraq (Windows Was Measured at 100% Back in 2010)
Iraq is not a place where Windows can make a comeback
Gemini Links 24/03/2025: Working With Music and Unconscious Influence
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, March 23, 2025
IRC logs for Sunday, March 23, 2025
Critics of IBM's Strategy Aren't Racists, But...
the situation is saddening as it serves to obscure the severity of the problem
Mauritania: Windows Falls to All-Time Low of 6% (It Used to be Over 99%)
Windows is 0% in mobile
New USPTO Memo Makes Fighting Patent Trolls Even Harder
The U.S. Patent and Trademark Office (USPTO) just made a move that will protect bad patents at the expense of everyone else
Outline of Open Source Initiative Coverage to Come (Now That Consensus is Changing)
Policing Wikipedia and attacking critics is not a sustainable strategy
An "EU OS" Would Need European Components
There are many European (or Europe-led) distros of GNU/Linux. EU OS developers ought to look at those.
Gemini Links 23/03/2025: "Connor of the Cats" and CSS Naked Day
Links for the day
Links 22/03/2025: Science and Antoine Beaupré on "Losing the War for the Free Internet"
Links for the day
We Probably Served Close to 100 Million Gemini Requests
Many of these requests probably came from bots, but it's hard to distinguish (to block them) ... This coming summer Gemini Protocol will turn 6
Just Because Microsoft Resents Techrights Doesn't Mean SLAPPs Will Silence Techrights
To confront lies the best solution is to speak truth
Windows at New Low Levels in Madagascar (Population About 33 Million)
Madagascar does not need Microsoft
Slop Images Are Bad Optics, Including for Perl.org
Slop devalues one's genuine work
What Happened to the Open Source Initiative (OSI) Elections: Proprietary Software Companies in Control, the Scandals Cannot be Hidden Anymore
We'll talk about it later this month and next month
Slopwatch: Fake News About Security Using LLMs That Make Fake 'Articles' About "Linux" (With Slop for Images)
This cannot end well
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, March 22, 2025
IRC logs for Saturday, March 22, 2025