Bonum Certa Men Certa

EPO and Microsoft Collude to Break the Law -- Part IX: Know Your Vendor…

Previous parts:



A big brother-like spy
The never-ending saga of Microsoft's run-ins with European data protection authorities



Summary: Microsoft is one of the world's worst offenders when it comes to privacy, but vendor assessment by the EPO conveniently overlooks the law

Even before GDPR came into effect in May 2018, data protection regulators in some European countries were starting to have their doubts about whether Microsoft's flagship product, its Windows operating system, was compliant with European data protection standards.



The first national authority to kick into action was the French National Data Protection Commission (CNIL).

Following an investigation which concluded in June 2016, CNIL issued Microsoft with a formal notice to comply with French data protection regulations. CNIL also ruled that the decision should be made public, given the scale of the violations in question.

"Following an investigation which concluded in June 2016, CNIL issued Microsoft with a formal notice to comply with French data protection regulations. CNIL also ruled that the decision should be made public, given the scale of the violations in question."No fewer than six violations of the French Data Protection Act were identified by CNIL, including continued transfer of data based on Safe Harbor principles despite the fact that the Safe Harbour Agreement had been invalidated by the CJEU in October 2015.

Microsoft was given three months – until 30 September 2016 – to end the identified violations of French Data Protection law or else face the prospect of a fine of up to €150,000.

In June 2017, it was reported that Microsoft had scaled back the volume of data it collected from Windows 10 PCs by "almost half". This led CNIL to announce that Windows 10 was no longer in breach of the country's data protection laws and that it had decided to close the case.

But that was only the first chapter in the never-ending saga of Microsoft's run-ins with European data protection authorities.

"Microsoft was given three months – until 30 September 2016 – to end the identified violations of French Data Protection law or else face the prospect of a fine of up to €150,000."A few months later in October 2017, it was reported that the Dutch data protection authority (Autoriteit Persoonsgegevens) had come to the conclusion that Microsoft was in breach of Dutch data protection law due to the way it processed the personal data of Windows 10 users.

According to the Dutch data watchdog, Microsoft made it impossible for users to give their valid consent to their personal data being processed due to the multiple ways in which that data might subsequently be used.

The Dutch regulator noted that Microsoft had promised to end its "violations", but warned that a failure to do so could lead it to impose a sanction.

After some back and forth with the regulator, Microsoft submitted a revised version of its software in April 2018. However, in the course of testing the revised version the Dutch agency found fresh grounds for concern, discovering what it called in a press release "new, potentially unlawful, instances of personal data processing".

"After some back and forth with the regulator, Microsoft submitted a revised version of its software in April 2018. However, in the course of testing the revised version the Dutch agency found fresh grounds for concern, discovering what it called in a press release "new, potentially unlawful, instances of personal data processing"."In the meantime GDPR had entered into force, and this led the Dutch data protection authority to refer its concerns to the competent lead EU privacy regulator under the new regulations. This was the national data protection authority where Microsoft's regional HQ for the EU is located, namely the Irish Data Protection Commission.

And so the seriously under-resourced Irish DPC added the Microsoft GDPR non-compliance case to an already long list of files concerning the cross-border data processing activities of multiple tech giants which had accumulated on its docket since the GDPR came into force in May 2018.

According to the most recently available reports from May 2020 the Microsoft case is still pending before the Irish Data Protection Commission.

The situation in the Netherlands became even hotter for Microsoft with the decision of the Dutch Ministry of Justice and Security in 2018 to commission a Data Protection Impact Assessment (DPIA) to be carried out on a range of Microsoft products, including Office 365.

"The situation in the Netherlands became even hotter for Microsoft with the decision of the Dutch Ministry of Justice and Security in 2018 to commission a Data Protection Impact Assessment (DPIA) to be carried out on a range of Microsoft products, including Office 365."The DPIA was commissioned because this was a clear-cut case of data processing on a large scale (by 300,000 government employees) which involved personal data, including data that could be potentially used to track the activities of employees.

The aim of the exercise was to assess the extent to which Microsoft's Office Online and the Mobile Office Apps could be deployed in a GDPR-compliant manner by Dutch government organisations.

The scope of the investigation included the five most commonly used Office 365 applications – Word, PowerPoint, Outlook, Excel and Microsoft Teams – in Office Online and the Mobile Office apps, in combination with the use of cloud storage services.

The final report [PDF], which was published in November 2018, identified a number of serious data protection risks, in particular the following:

● Loss of control over the use of personal data; ● Loss of confidentiality; ● Inability to exercise rights; ● Re-identification of pseudonymised data; ● Unlawful (further) processing.

It was noted that effective risk mitigation was outside of the users' control and could only be carried out by Microsoft.

"It was noted that effective risk mitigation was outside of the users' control and could only be carried out by Microsoft."The investigation found an unacceptable lack of control by users over the processing of personal data by Office 365 mobile applications. Because of this government organisations were advised to create policies for their employees stating that they were not to use mobile Office 365 applications.

As we shall see in the next part, the investigation by the Dutch authorities into the GDPR-compliance of Microsoft products prompted the European Data Protection Supervisor to announce its own investigation into Microsoft products used by EU institutions.

Recent Techrights' Posts

IBM: We Pay You to be Obedient or Deny You What You're Entitled to If You Don't Act Obediently
Good luck starting legal battles with a company that has almost as many lawyers (including aggressive patent lawyers) as it has geeks
Russian "Hybrid Attacks" Are Typically Microsoft TCO and/or Windows TCO (Total Cost of Ownership)
Information-related warfare relies a lot on computer systems
It Seems Like IBM is Firing 'Everybody' (Anywhere, Any Age, No Matter What Team)
Healthy companies would sack IBM's management (sacked by Board, bylaws etc.) but IBM is a sick company
Latest Stallman Talk (Event in Argentina) Published
Less than a day ago they released his talk
LLM Slop Becoming Rarer
Today we've found no LLM slop in our RSS feeds regarding "Linux"
 
Links 14/12/2025: Tensions in Asia, US Making Deals With Belarus
Links for the day
A Utopian and Very Dumb Vision of Technology, Based on Accounting Fraud
the "industry" has become insane and a lot of "the media" is going along with it
Links 14/12/2025: "The Slop of Things to Come", Goldman Sachs Nervous About Slop Bubble
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, December 13, 2025
IRC logs for Saturday, December 13, 2025
Google News is Google Noise
Google News is really hopeless, even on weekends
Links 13/12/2025: Jimmy Lai and Media Freedom on Trial, "OpenAI Researcher Quits, Saying Company Hiding the Truth"
Links for the day
Gemini Links 13/12/2025: Extensive Catchup With Gopherholes
Links for the day
Deliberate Lies or Glaring Distortions
Calling Torvalds anything "Soviet" or "Russian" would overlook the fact he comes from Finland and has Swedish roots
Canonical and Ubuntu: Working for Microsoft, Promoting Proprietary Surveillance (Dis)Services
Canonical started with a rich and overambitious Debian Developer. He wanted to become richer.
EPO People Power - Part XI - The Media in Europe is Ill and Complicit in Ills
We must all recognise that there's a problem here
Running With Technology
At least they always run Linux (all of them, since 2015)
Dealing With "Tech Cults"
If you think you identified a "Tech Cult", walk away
GAFAM is a Financial Problem and Sovereignty Risk, a Policy-Level (National Level) Boycott is Needed
Europe has plenty of skilled computer engineers
2026 Could Very Well be Last Year of XBox, Microsoft Dropped the Ball
It would be shocking is XBox can stage any kind of comeback
Links 13/12/2025: Social Control Media Bans and "Could Finland be Hiding a Blue Zone?"
Links for the day
Expecting Mass Layoffs, More Microsoft Workers Join Unions
they see tough times ahead
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, December 12, 2025
IRC logs for Friday, December 12, 2025
Links 12/12/2025: GAFAM Now Trying to Settle With Remaining News Sites It Plagiarised, "NATO's Rutte Says Alliance Is 'Russia's Next Target'"
Links for the day
Gemini Links 12/12/2025: Bad Joke, Western Union Blues, and More
Links for the day
Life Began at 40
This is what I wanted to do all along
To Linus Torvalds, the Microsoft Linux Foundation is Increasingly a Liability and Risk to the Brand
If Torvalds is no longer in control or "in charge", then somebody else is
EPO People Power - Part X - Together, We Can Fix the EPO
every call for action matters
IBM Layoffs in Europe as Well
IBM is a collapsing, dying old brand
EPO People Power - Part IX - Insiders Say the EPO's Chief Propagandist Effectively Ousted (on Fake 'Sick Leave') Because of Reporting by Techrights
So the EPO is in effect rewarding a cocaine addict
Litigation Transparency Until 2030 or 2031
The ultimate goal is to 1) improve the British legal system and 2) raise awareness of how this system works
Links 12/12/2025: Thunderbird Adds Proprietary Plug, "Catch-22 of Canadian Digital Sovereignty" Explained by Michael Geist (About GAFAM/US)
Links for the day
Developing Some New Software for the Sites
Sites that are static are in more control over their future and present direction
Julian Assange on Fake Activists in Silicon Valley
Julian Assange on Fake Activists in Silicon Valley
"In a modern economy it is impossible to seal oneself off from injustice."
― Julian Assange
EPO People Power - Part VIII - The Chipmunk on Cocaine, Now Deleting Videos
video has been removed
What If the Economy Isn't "Down" But Mostly Diverted? (While "AI" Fills a Gap for Capital That No Longer Exists in Tech)
"AI" is an "Arms Race", because they need to be bailed out by taxpayers' money
Techrights Site Search Was a Success After All
A few hiccups dealt with, ironed out
Valve's SteamOS, Microsoft Canonical's Ubuntu, and Other Platforms That Only Leverage Free Software (But Won't Protect It)
Ubuntu "took off" not because it was very good or very easy. Ubuntu "took off" because of ShipIt, i.e. because of a multi-millionaire subsidising its mass distribution (at a personal cost).
The Free Software Foundation (FSF) Paid Respect to Its Founder This Year, Now It Wants You to Join
We're glad to see the FSF paying respect to its founder in its Web site
2026 Guaranteed to Give Us Compromised Media Funded by "AI" Boosters to Promote "AI" and Sometimes be Composed by "AI" (Chatbots)
follow the money of the Ponzi scheme
Under IBM, Things Culminate at "AI-Equipped Customer Experience Transformation" at Red Hat
Whatever that even means
Andy Farnell and Helen Plews Now at the Wheel in Cybershow
Cybershow (Cyber|Show) has very good blog posts and episodes
Microsoft Trims More Jobs
The worst layoff year in 20 years, by the numbers
EPO People Power - Part VII - The Corporate Media and the Reference Sites (e.g. Wikipedia) Are Already Compromised and Complicit
Looking back at the whole thing, it's clear to me that Europe does not really have free press
EPO People Power - Part VI - Criticism Not Permitted, Media Subjected to Contempt by Cocaine Addicts Who Manage the Press for the EPO
Why won't any large publisher in Europe cover this? What does that say about the state of journalism in Europe?
"Smart" or "Intelligent" Agents and "Vibe Coding" Deletes Everything You Have
A high price to pay, no?
New Paper Shows That EPO "Growth" is Dictated From Above, Not Earned (More Monopolies Granted by Breaking Rules, Laws, Conventions)
"Targets for 2026 are currently being handed down to individuals."
EPO People Power - Part V - The European Media is Practically Dead When It Comes to Covering European Patent Office (EPO) Corruption
That sort of sums up where European media/press stands
Datacentre and Server Maintenance Next Week
The last time we rebooted into the latest stable kernel was 96 days ago
Afraid of Words, Not Afraid of Actions
Those corporations want us to bicker over words, not their actions
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, December 11, 2025
IRC logs for Thursday, December 11, 2025
IBM Workers Still Blast IBM Management for Firing Loads of Workers While Overpaying to Buy Useless Companies
IBM's CEO is killing the cow
LLM Slop About Linux Still Seems Scarce
LLMs aren't dead, but metrics published online say that their usage is fast declining
Links 12/12/2025: Oracle Shares Collapse After Slop Bubble Inflated (Circular Funding/Financing One's Own 'Clients'), "Trials by Jury" in UK Considered
Links for the day
Gemini Links 12/12/2025: 'Kinetic Energy' and Browsing Geminispace With a GUI, TUI, or CLI Client
Links for the day