Bonum Certa Men Certa

EPO and Microsoft Collude to Break the Law -- Summing Up: EPO Administrative Council Still Asleep at the Wheel

Previous parts:



EPO's council heads



Summary: AC chair Josef Kratochvíl (CZ) and deputy chair Borghildur Erlingsdóttir (IS) seem to be unperturbed by the sell-out of the EPO's "digital sovereignty" taking place on their watch

For quite some time now it has been an open secret that the data protection framework at the EPO is not fit for purpose.



Back in the spring of 2014 the Bavarian Data Protection Commissioner, Dr Thomas Petri, carried out his own independent investigation into the matter following a complaint and he came to the conclusion that "nobody was really in charge".

Together with his colleague the Federal German Data Protection Commissioner, Andrea Vosshoff, Dr Petri raised serious concerns about the state of data protection at the EPO. However, their urgent pleas for reform fell on deaf ears.

"So it's difficult to see how such a manifestly deficient framework which hadn't changed in the meantime could be considered meet the even more stringent standards imposed by GDPR in 2018."When the EU GDPR came into effect in May 2018, Battistelli attempted to pull the wool over the eyes of the EPO's stakeholders and the general public by issuing a self-serving communiqué (warning: epo.org link) proclaiming the EPO's commitment to "ensuring the highest level of data protection" and announcing that "a recent audit report has confirmed a close alignment with the GDPR legal framework".

The only problem here is that Dr Petri, a serious and well-regarded independent expert on data protection law found that the EPO's data protection framework failed to measure up to pre-GDPR standards in 2014.

So it's difficult to see how such a manifestly deficient framework which hadn't changed in the meantime could be considered meet the even more stringent standards imposed by GDPR in 2018.

As a matter of fact, a report commissioned by the EPO staff union SUEPO from external legal experts in 2016 came to the conclusion that the EPO's data protection framework was not compliant with EU data protection standards and was in urgent need of a radical overhaul.

It's worth citing a few passages from that report for the record:

The European Union does, quite rightly, take data protection seriously. Yet the framework at the EPO gives rise to significant cause for concern, which has also been expressed by the national data protection authorities of the main host state – the Federal Republic of Germany.

The Guidelines for the Protection of Personal Data in the European Patent Office (‘EPO DataProtection Guidelines’ or ‘EPO DPG’), which were unilaterally adopted by the President and which entered into force on 1st April 2014. The current EPO DPG appear to fail to meet the standards of both EU data protection law and the national data protection laws of the Contracting States, in particular, the host countries of the EPO. As such, they do not provide a satisfactory framework for safeguarding the data protection rights of data subjects within the Office.

A key component of the EU data protection framework and which is reflected in the national data protection laws of all EU member states is the existence of an independent oversight body; yet this is conspicuously absent at the EPO. Indeed, the deficiencies in the existing system of data protection established by the EPO's Data Protection Guidelines have come to the attention of the national data protection authorities in the host state of the EPO's headquarters (Germany) and have even been the subject of a discussion in the Legal Affairs Committee of the German Federal Parliament (Bundestag).


In the meantime, very little has changed at the EPO apart from the arrival of a new Data Protection Officer via "the talent pipeline from the EUIPO in Alicante” in April 2020 as previously reported by Techrights.

"Unfortunately for all concerned, the Administrative Council appears to have completely abdicated its responsibilities in this regard."When all is said and done, the task of ensuring that the EPO's data protection framework is fit for purpose is a matter of fundamental legal and political significance which lies within the responsibility of the governing body of the organisation, namely the Administrative Council.

This is not something which can be simply delegated to the EPO management to deal with on its own initiative.

Unfortunately for all concerned, the Administrative Council appears to have completely abdicated its responsibilities in this regard.

The Council gives the distinct impression that it is "asleep at the wheel" as the senior management of the EPO proceeds to sell out the organisation's "digital sovereignty" to a US multinational corporation behind its back.

EPO cruise
Once again, the EPO's Administrative Council seems to be asleep at the wheel



Of course the Council has only got itself to blame for the precarious and potentially disastrous situation which has now developed.

After all they were the ones who permitted their sense of judgement to be corrupted by the former Council Chairman Battistelli and agreed to follow his proposal to disband the independent Audit Committee in 2011.

With the benefit of hindsight it is now apparent that, by acting as an accessory to Battistelli's Machiavellian intrigues and acquiescing in the disbandment of the Audit Committee, the Council followed a misguided course of action which has had far-reaching and detrimental effects on the integrity of EPO governance.

It comes as no real surprise to see that - having deprived itself of any genuinely independent source of advice by means of an ignominious act of self-mutilation at the urging of Battistelli - the Council is now unable to react in an robust manner to defend the EPO's "digital sovereignty" and to ensure that the organisation's data protection framework is fit for purpose and truly GDPR-compliant.

These are matters of fundamental importance and legitimate concern not only to EPO staff but also to all other stakeholders, including the general public.

Unfortunately the current Council under the stewardship of its chair, Josef Kratochvíl (Czech Republic), and deputy chair, Borghildur Erlingsdóttir (Iceland), does not appear to appreciate the seriousness of the issues and stake and seems unlikely to take appropriate remedial action unless and until something dramatic happens to jolt it out of its complacent slumber.

Recent Techrights' Posts

Rust is Starting to Seem More Like Microsoft-hosted "Digital Maoism", Not a Legitimate Effort to Improve Security
Maybe this is very innocent, but they seem to have taken a solid, stable program from a high-profile Frenchman and looked for ways to marry it with GitHub, i.e. Microsoft/NSA
 
Links 08/05/2025: Mass Layoffs at Google Again, India/Pakistan Tensions Continue to Grow, New Pope (US) Selected
Links for the day
"Victory Day" - Part I: That is the Day Microsofters Who Assault Women Pay for Their Actions in Foreign Land (Using "Guns for Hire" Who Attack Their Own Country for American Dollars)
Adding a friend from Microsoft to the docket didn't help
Gemini Links 08/05/2025: Practical Gemini Use Case, Shutdown of the Blanket Fort Webring
Links for the day
Links 08/05/2025: "Slop Presidency", US Government Defunds Public Broadcasting
Links for the day
Lasse Fister, Organiser of Libre Graphics Meeting, Points Out the Code of Conduct is Likely Violated by the Same People Who Promote Codes of Conduct (and Then Bully Him Into Cancelling a Keynote)
I am starting to see Lasse Fister as another victim
LLM Slop Attacks Not Only Sites of Free Software Projects But Also Bug Reporting Systems (Time-wasting, in Effect "DDoS")
Microsoft, the leading purveyor and promoter of slop, is a cancer
The Richard Stallman (RMS) "European Tour" Carries on In Spite of the Nuremberg Incident
Some people spoke about how they saw yesterday's talk
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, May 07, 2025
IRC logs for Wednesday, May 07, 2025
The CoC Means the Founder of GNU/Linux Cannot Talk and a 72-Year-Old Man With Cancer is Somehow a "Safety" Risk?
Those who don't like RMS are not forced to attend his talks
Gemini Links 07/05/2025: A Shopping Spree and Digital Gardening
Links for the day
Links 07/05/2025: Pegasus Guilty and a Path Towards EU Without Russian Energy
Links for the day
People Used to Talk
If pets can live a measurably happy life without gadgets and "apps", why can't humans?
Outsourcing GNU/Linux to Microsoft GitHub Promoted by Microsoft LLM Slop and Army Officers
Something doesn't seem right
Weaponisation of For-Profit Dockets - Part III: No More Media Lawsuits From Brett Wilson LLP This Year, One Can Only Guess Why
People leak a lot of material to Techrights because they know, based on the track record, that the sources will be protected and whatever gets published will stay online, in full, no matter how stubborn an effort (even lawsuits and blackmail) will be sent its way
Gemini Links 07/05/2025: Adopting GrapheneOS, Further Enshittification of Flickr
Links for the day
Links 07/05/2025: CISA Gutted, Debt-Saddled (Likely Insolvent) 'Open' 'AI' (Proprietary Slop) Faking Its Financial State Again
Links for the day
Finland, Lithuania, and Latvia Fortify Their Digital Border With GNU/Linux
This month's data from statCounter is particularly interesting near the Baltic Sea
The European Patent Office (EPO) Has a Very Profound Corruption Issue, Far More Urgent an Issue Than Pronouns
a rather long document
Richard Stallman Gives Public Talk at Technical University of Liberec, Czech Republic
"For programs that you could run, and for network services that could do your own computing, under what circumstances is it reasonable to trust them?"
Today We Turn 18.5
The eighteenth "and a half" anniversary
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, May 06, 2025
IRC logs for Tuesday, May 06, 2025
Microsoft Finally Admits That XBox is ****
In this case, "enshittification" is an understatement
Another Wave of Microsoft Layoffs Comes Shortly. Microsoft Propaganda Sites and Slopforms Powered by Microsoft LLMs Already Spew Out Face-Saving Nonsense.
Based on last month's leak, some very extensive layoffs are now imminent [...] Perhaps we can expect a lot of noise, some of it spewed out by bots, to distract from or belittle the impending mass layoffs
Ubuntu Becomes Microsoft GitHub, Based on Decision Made by British Army Officer
You're hopeless, Canonical
Slopwatch: Microsoft Slop, Anti-Linux Slop, and IBM Marketing Itself as a Slop Company
Microsoft-controlled LLM spewing out garbage about "Linux"
Links 06/05/2025: Microsoft's Assassination of Skype After Years of Failure, Slop Hallucinations Are Getting Worse
Links for the day
Links 06/05/2025: Changing Places and StarGrid for PalmOS
Links for the day
Windows and Microsoft Causing Serious Data Breaches, Media Rushes to Blame That on "Linux" Somehow
While selling us some rusty old propaganda about how moving to Microsoft GitHub (Rust) will improve security
Making Site Archives More Easily Accessible (Approaching 50,000 Blog Posts)
Efforts to censor us have always backfired badly
Weaponisation of For-Profit Dockets - Part II: Hiding Behind Lawyers and Barristers Who Lack Standards so as to Engage in Classic Corporate Extortion
They're trying to scare people and they misuse their licence to operate
Links 06/05/2025: LLMs/Chatbots Attract More Scrutiny (Getting Worse Over Time), PwC Has Many Layoffs
Links for the day
Thanks for listening. How can this Morse feed be further improved?
Right now any and all feedback on the audio would be helpful
statCounter: Bing's Market Share Lower Right Now Than It Was When LLM Hype Began (With "Bing Chat")
If anybody gains at Google's expense in search, it is BRICS' alternatives such as Yandex
Gemini Links 06/05/2025: Failure and Proxmox Cluster
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, May 05, 2025
IRC logs for Monday, May 05, 2025