Bonum Certa Men Certa

EPO and Microsoft Collude to Break the Law -- Part IX: Know Your Vendor…

Previous parts:



A big brother-like spy
The never-ending saga of Microsoft's run-ins with European data protection authorities



Summary: Microsoft is one of the world's worst offenders when it comes to privacy, but vendor assessment by the EPO conveniently overlooks the law

Even before GDPR came into effect in May 2018, data protection regulators in some European countries were starting to have their doubts about whether Microsoft's flagship product, its Windows operating system, was compliant with European data protection standards.



The first national authority to kick into action was the French National Data Protection Commission (CNIL).

Following an investigation which concluded in June 2016, CNIL issued Microsoft with a formal notice to comply with French data protection regulations. CNIL also ruled that the decision should be made public, given the scale of the violations in question.

"Following an investigation which concluded in June 2016, CNIL issued Microsoft with a formal notice to comply with French data protection regulations. CNIL also ruled that the decision should be made public, given the scale of the violations in question."No fewer than six violations of the French Data Protection Act were identified by CNIL, including continued transfer of data based on Safe Harbor principles despite the fact that the Safe Harbour Agreement had been invalidated by the CJEU in October 2015.

Microsoft was given three months – until 30 September 2016 – to end the identified violations of French Data Protection law or else face the prospect of a fine of up to €150,000.

In June 2017, it was reported that Microsoft had scaled back the volume of data it collected from Windows 10 PCs by "almost half". This led CNIL to announce that Windows 10 was no longer in breach of the country's data protection laws and that it had decided to close the case.

But that was only the first chapter in the never-ending saga of Microsoft's run-ins with European data protection authorities.

"Microsoft was given three months – until 30 September 2016 – to end the identified violations of French Data Protection law or else face the prospect of a fine of up to €150,000."A few months later in October 2017, it was reported that the Dutch data protection authority (Autoriteit Persoonsgegevens) had come to the conclusion that Microsoft was in breach of Dutch data protection law due to the way it processed the personal data of Windows 10 users.

According to the Dutch data watchdog, Microsoft made it impossible for users to give their valid consent to their personal data being processed due to the multiple ways in which that data might subsequently be used.

The Dutch regulator noted that Microsoft had promised to end its "violations", but warned that a failure to do so could lead it to impose a sanction.

After some back and forth with the regulator, Microsoft submitted a revised version of its software in April 2018. However, in the course of testing the revised version the Dutch agency found fresh grounds for concern, discovering what it called in a press release "new, potentially unlawful, instances of personal data processing".

"After some back and forth with the regulator, Microsoft submitted a revised version of its software in April 2018. However, in the course of testing the revised version the Dutch agency found fresh grounds for concern, discovering what it called in a press release "new, potentially unlawful, instances of personal data processing"."In the meantime GDPR had entered into force, and this led the Dutch data protection authority to refer its concerns to the competent lead EU privacy regulator under the new regulations. This was the national data protection authority where Microsoft's regional HQ for the EU is located, namely the Irish Data Protection Commission.

And so the seriously under-resourced Irish DPC added the Microsoft GDPR non-compliance case to an already long list of files concerning the cross-border data processing activities of multiple tech giants which had accumulated on its docket since the GDPR came into force in May 2018.

According to the most recently available reports from May 2020 the Microsoft case is still pending before the Irish Data Protection Commission.

The situation in the Netherlands became even hotter for Microsoft with the decision of the Dutch Ministry of Justice and Security in 2018 to commission a Data Protection Impact Assessment (DPIA) to be carried out on a range of Microsoft products, including Office 365.

"The situation in the Netherlands became even hotter for Microsoft with the decision of the Dutch Ministry of Justice and Security in 2018 to commission a Data Protection Impact Assessment (DPIA) to be carried out on a range of Microsoft products, including Office 365."The DPIA was commissioned because this was a clear-cut case of data processing on a large scale (by 300,000 government employees) which involved personal data, including data that could be potentially used to track the activities of employees.

The aim of the exercise was to assess the extent to which Microsoft's Office Online and the Mobile Office Apps could be deployed in a GDPR-compliant manner by Dutch government organisations.

The scope of the investigation included the five most commonly used Office 365 applications – Word, PowerPoint, Outlook, Excel and Microsoft Teams – in Office Online and the Mobile Office apps, in combination with the use of cloud storage services.

The final report [PDF], which was published in November 2018, identified a number of serious data protection risks, in particular the following:

● Loss of control over the use of personal data; ● Loss of confidentiality; ● Inability to exercise rights; ● Re-identification of pseudonymised data; ● Unlawful (further) processing.

It was noted that effective risk mitigation was outside of the users' control and could only be carried out by Microsoft.

"It was noted that effective risk mitigation was outside of the users' control and could only be carried out by Microsoft."The investigation found an unacceptable lack of control by users over the processing of personal data by Office 365 mobile applications. Because of this government organisations were advised to create policies for their employees stating that they were not to use mobile Office 365 applications.

As we shall see in the next part, the investigation by the Dutch authorities into the GDPR-compliance of Microsoft products prompted the European Data Protection Supervisor to announce its own investigation into Microsoft products used by EU institutions. ⬆

Recent Techrights' Posts

Brigading Against Women - Part XII - Toxic Masculinity, Hunting Women, Will Code for Sex
Who says things like these?
The Microsoft Lunduke Slop Problem
Microsoft Lunduke does not support Software Freedom; he serves to discredit many ideas championed by Free software or ideals articulated which are apolitical for the most part
CDMAG Covers Free Software, New Magazine From Decent People
If enough people accessed their site, they would not rely on social control media (third parties, censorship platforms)
Brigading Against Women - Part XI - An Abject Lack of Social Skills (and Not Knowing How to Handle Women)
GGG enjoy - if that's the right term - very bizarre or esoteric sex life
EPO Will Stop Working for 10 Days to Protest Against 'Cocaine King' and His Assault on Democracy, Lawfulness, Transfer of Power at EPO
Strikes, work stoppage, all rolled onto one
Techrights is International
There are many sites that focus on local communities or nations. We're not one of those sites.
 
Rust Causes Upgrade Issues in Ubuntu
They could just keep GNU coreutils in place (nothing was broken about it) and avoid Microsoft's back doors and TPMs
Losses From Slop Are "Investment", Hundreds of Billions in Debt Are "Growth Opportunity", Layoffs Are "Great to See", and Loss of Business Means "We Need a Slowdown" (for "Safety")
Microsoft is removing staff, as investment is apparently the act of shrtinking
Links 30/09/2026: "Understanding the LLM Bubble" and "Florida Senate Threatened Legal Action Against Newspapers"
Links for the day
It Looks Like Mass Layoffs at "Nordcloud, an IBM Company" Today (a Day Ahead of Red Hat)
Expect the same from Red Hat next
British Prime Minister Recognises Social Control Media as National Cohesion Problem
one has to wonder if addiction to social control media is not compatible with peace
The Future Isn't Social Control Media (Nothing Will be Left of It, Not Even Archives)
"Error code: 502 Bad Gateway"
GNU/Linux Usage in China is Increasing
China is leaving Microsoft and Windows behind
43 Years of GNU and GAFAM's (Especially Microsoft's) Attacks On It
GNU is very widely used (when people say "Linux commands" they typically mean "GNU programs"), hence it's being attacked a lot
Gemini Links 30/09/2026: Accelerationism, "The Billionaire is Wrong", Rant About LLM-generated Support E-mails
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, September 29, 2026
IRC logs for Tuesday, September 29, 2026
Black Brit on "Pictures Comparing Me to a Monkey" Because of Brett Wilson LLP Client
"Like Firm, Like Clients..."
President of the EPO Should be Kicked Out, Not Have His Term Terminated in 2028
The President is facing more scandals soon
David Gordon at The Register MS Keeps Feeding the Pyramid Scheme With Fake Articles That Say "AI" Dozens of Times
How can such a publisher still be taken seriously?
The Local Staff Committee The Hague (LSCTH) at the EPO Explains the Working Conditions and Crisis of Plunder (Less for Workers, a Lot More for Dictators Who Refuse to Leave Leadership Roles)
Next week will be epic
IBM Brings Avalanche to Red Hat October 1st 2026 (Thursday)
IBM is turning up the heat on staff
Links 29/09/2026: Mass Layoffs at Microsoft and Backlash Over Data Center Policy of Microsoft
Links for the day
5 Years Ago (September 29, 2021) Richard Stallman's Talk in Ukraine Noted
Let's hope the war will end soon
Links 29/09/2026: Acceleration, Morale, and ROOPHLOCH 2026
Links for the day
Links 29/09/2026: "Scam Altman Is Driving Drunk" and Anthropic Lies About Slop Usage
Links for the day
Brigading Against Women - Part X - When Actions of American Men Are Not Judged by Other American Men
"There is not the slightest suggestion that either Dr or Mrs Schestowitz did anything to invite or deserve it. They are both clearly and justifiably angered, dismayed, distressed and hurt by it."
European Patent Office (EPO) Series: A Source of Pride for Portugal?
In this part our focus returns to the main theme of this series, namely the current reappointment campaign of the EPO President, as we consider whether Campinos can still expect to enjoy the same level of support from the Portuguese political establishment as he did during the earlier stages of his career
Computers Freeze Because of UEFI Restricted Boot
damage is also done to computers running Windows
It is Very Expensive to Slow Down Techrights
Garrett's expensive hearing (costing the British taxpayers about 120,000 pounds; he doesn't live here and does not pay tax here) slowed us down for a few days, but we've picked up the pace since
Linux Has Conquered Mobile, But Desktops and Laptops Matter More
When people say the desktop "doesn't matter" they seem to be missing the point that workplaces use desktops (or laptops) and a lot of the work gets done not on skinnerboxes but "workstations" or terminals
Brigading Against Women - Part IX - "What Are You, a Racist?"
Because behind every strong man is a strong opinion?
Gemini Links 29/09/2026: "Digital Sabbath", Starting a GemCapsule, and Sterrenkijker 1.1.0
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, September 28, 2026
IRC logs for Monday, September 28, 2026
Brigading Against Women - Part VIII - Misogyny Embedded; Like Firm, Like Clients
It's about back doors
Chaos Imminent at Red Hat (This Week)
IBM is 'finishing the job' an ex-IBMer (Ron Hovsepian) did at Novell.
Microsoft Can PIP Workers (Silent Layoffs) Until Almost Nobody is Left
Microsoft is gradually vanishing
The Cyber Show Says Truth Always Requires a Fight, a Struggle
"Truth-tellers always face struggle and run risk"
Maladministration at the EPO as a Crisis for the EU and for Portugal's Image in Europe
Some time soon we'll publish a long article about what EPO leadership means to Portugal
3 Years of UK Hosting
We commend the webhost for standing firm in the face of misogyny
Tech Labeled "Smart" Does Not Make People Smart
People who insist on making everything digital are not advancing progress
Gemini Links 28/09/2026: Truncated Sleep, Plain Text, and Slop Problem Kept Out of Geminispace
Links for the day
Links 28/09/2026: "A Growing North Korea Problem" and Independent Journalism as a Lifeline
Links for the day
Links 28/09/2026: Microsoft Chatbot "Giving Extremely Specific Advice to a School Shooter on How to Maximize Casualties", ‘Suicidal Empathy’
Links for the day
Microsoft's Attacks on Courts in the Netherlands Result in GNU/Linux Growing to About 10% There
One core issue that justified this and led to this outcome is Microsoft's interference with the administration of justice
They Create the Conditions for People to Leave, This Way They Don't Call it "Layoffs"
We keep seeing many stories like these
Gemini Links 28/09/2026: Wildfire, DOS, and Backups
Links for the day
Brigading Against Women - Part VII - 'Trolling' Courts and Legal Systems in America and in the UK (Europe) Costs a Lot to Taxpayers
They only attend hearings after being arrested
European Patent Office (EPO) Series: The Portuguese Talent For Bureaucratic Empire Building
Portugal’s success in securing senior executive appointments at the EUIPO and the EPO is a notable example of how countries seek to strengthen their influence within European intergovernmental institutions
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, September 27, 2026
IRC logs for Sunday, September 27, 2026