Bonum Certa Men Certa

EPO and Microsoft Collude to Break the Law -- Part X: The Spectre of GDPR…

Previous parts:



GDPR and Microsoft
More about Microsoft's run-ins with European data protection authorities



Summary: António Campinos and his friends may have put the EPO in legal "hot water", having already outsourced EPO data to a serial GDPR violator with a notorious track record in other aspects, too

In April 2019 it was reported that "the Spectre of GDPR" continued to haunt the hallowed halls of Redmond, this time in the shape of an investigation ordered by the EU Data Protection Supervisor (EDPS) into Microsoft products used by EU institutions.



The move by the EDPS was prompted by the outcome of the Data Protection Impact Assessment which had been commissioned by the Dutch Ministry of Justice and Security in 2018.

"The move by the EDPS was prompted by the outcome of the Data Protection Impact Assessment which had been commissioned by the Dutch Ministry of Justice and Security in 2018."The EDPS noted that any EU institutions using the applications investigated by the Dutch authorities would face similar issues including "increased risks to the rights and freedoms of individuals".

The report of the EDPS on the "Outcome of own-initiative investigation into EU institutions’ use of Microsoft products and services" was published on 2 July 2020.

The EDPS identified a number of serious issues calling for further action, including the following:

● The licensing agreement between Microsoft and the EU institutions was formulated in loose manner that effectively permitted Microsoft to act as a data controller which the EDPS found inappropriate.

● The lack of control by EU institutions over which sub-processors Microsoft used and the lack of meaningful audit rights presented significant issues which needed to be addressed.

● EU institutions were unable to control the location of a large portion of the data processed by Microsoft. Nor did they properly control what was transferred out of the EU/EEA and how. There was also a lack of proper safeguards to protect data that left the EU/EEA.

● EU institutions had few guarantees at their disposal to defend their privileges and immunities and to ensure that Microsoft would only disclose personal data insofar as permitted by EU law.

According to the EDPS, the EU institutions lacked sufficient clarity as to the nature, scope and purposes of the data processing carried out by Microsoft and the risks to data subjects for the purpose of complying with their transparency obligations towards data subjects.

The EDPS recommended that all EU institutions perform tests using a revised and comprehensive approach in order to monitor and stem the flow of personal data generated by Microsoft products and services and sent to Microsoft.

"The EDPS recommended that all EU institutions perform tests using a revised and comprehensive approach in order to monitor and stem the flow of personal data generated by Microsoft products and services and sent to Microsoft."It remains to be seen whether or not the EDPS' beef with Microsoft will be resolved in an amicable manner or whether it will result in the imposition of GDPR fines which, in serious cases, can be as much as 4% of a company's worldwide annual revenue.

Microsoft has also had its fair share of grief with the data protection authorities in the EPO's main host country, Germany.

Back in July 2019 it was reported that the data protection authority in the state of Hesse had issued a ruling that Microsoft’s Office 365 could no longer be used by schools following the closure of a German data centre which had been used by Microsoft to provide cloud services.

This ruling came after several years of domestic debate about whether German schools and other state institutions should be using Microsoft software at all.

To allay German privacy concerns, Microsoft had invested millions in a German cloud service, and in 2017 Hesse authorities agreed that local schools could use Office 365 as long as German data remained in the country. But in August 2018 Microsoft decided to shut down the German service which meant that, once again, data from local Office 365 users would be transmitted across the Atlantic.

"...in August 2018 Microsoft decided to shut down the German service which meant that, once again, data from local Office 365 users would be transmitted across the Atlantic."In view of the changed circumstances, the data protection commissioner decided that there was now an unacceptable risk that users' data could be accessed by US authorities.

More recently, in October 2020, it was reported that at the Conference of German Federal and State Data Protection Supervisory Authorities, a majority of Germany's regional data protection commissioners supported a finding that Microsoft Office 365 did not comply with GDPR standards. They also made clear that changes were urgently needed to comply with the CJEU Schrems II judgment on cross-border data transfers.

Once again, it's too early to say whether this matter will be resolved in an amicable manner or whether it will result in the imposition of GDPR fines.

However, for some time now German lawyers have been warning their clients about the potential financial risks of using non-GDPR compliant software, including many widely used Microsoft products.

For example, one Hamburg-based law firm published the following advice in July 2020:

"...for some time now German lawyers have been warning their clients about the potential financial risks of using non-GDPR compliant software, including many widely used Microsoft products.""Using MS-Teams, Skype and other Office 365 services violates data protection law and may result in million Euro fines. That’s the conclusion of two papers recently issued by the Berlin Commissioner for Data Protection and Freedom of Information. There is urgent need for action in many companies now."

Time will tell whether or not such warnings are justified. However, based on past experience Microsoft is unlikely to be given an easy ride by the German and other European data protection authorities and this may well have some unpleasant fallout for commercial users of its services and products.

In the meantime German scepticism about Microsoft has surfaced in the European Parliament.

In February 2020, Klaus Buchner - a university professor, physicist, and MEP for the green-conservative Ecological Democratic Party - submitted the following question to the EU Commission:

Subject: Microsoft Windows 10 in European local authorities

IT is part of our critical infrastructure, and in European local authorities as well IT means Microsoft Windows and Microsoft Office. It is as if European drivers could only buy cars made by one US manufacturer. As a result, European local authorities and European industry are totally dependent on a foreign monopoly supplier and are required to kow-tow to a foreign legal system and comply with foreign court judgments, which apply to Microsoft in the EU as well. To make matters worse, Windows 10 systematically transmits personal data to Microsoft. Little is known about how that data is used. The upshot is that local authorities may find themselves facing legal action for breaches of the data protection rules and the German Industrial Constitution Law. Background: ‘[...] The Data Protection Officers of the Federal Government and the Länder see little scope for using Microsoft’s Windows 10 operating system in accordance with the law […]’

Instead, standard programmes could be developed at EU level and made available to local authorities free of charge. This standard software could also be hosted in regional data centres in the EU and interested local authorities could transfer their IT operations to those centres. Of course, each local authority would be required to tailor the standard programmes to local needs and operate them independently, either from their own data centres or in an EU cloud.

1. Are there alternatives to monopoly costs and data protection problems? 2. Does the Commission see any scope for offering greater support for the use of free openware such as Linux and OpenOffice / LibreOffice?


The answer which came back from EU Commissioner Thierry Breton was for the most part the usual hot air which didn't really address the elephant in the room.

"In the meantime German scepticism about Microsoft has surfaced in the European Parliament."However, Breton took advantage of the opportunity to plug the Commission's ongoing efforts to promote an "EU cloud initiative" which would "offer credible European alternatives to non-EU providers".

And with that, we conclude our potted history of Microsoft's long-running and continuing problems with European data protection authorities.

In the next part we will take a look at some "close encounters" between the software behemoth of Redmond and other regulatory authorities, in particular the trust-busters on both sides of the Atlantic.

Recent Techrights' Posts

Loss of Technical Merit(ocracy)
"buzzword diplomas"
World Wide Web: Only Criminals Would Want Real Security and Vouch for Themselves When They Use Encryption
In "modern" browsers, the podlock icon probably does not mean what users might think it means
[Meme] OSI Digging Its Very Own Grave (With Microsoft)
The very latest blog post from OSI is a hoot
Geminispace is More Trustworthy (and Private) Than the World Wide Web
Unlike the Web, Geminispace does not route the lion's share of traffic through a collective of spying companies
 
LinuxSecurity (Guardian Digital, Inc) Sloppy With Its 'Linux' Slop
This kind of stuff is killing the World Wide Web and ruins human knowledge
[Meme] Chin-dropping and Jaw-dropping (Considerable Drop in Patent Validity and Quality)
This drop is very much intentional
Gemini Links 10/10/2024: Untruth, SSH, Gopher, and More
Links for the day
Geminispace Beyond 4,100 Capsules
4,000 was less than 8 weeks ago
Links 10/10/2024: TikTok's Legal Problems, WeblogPoMo Challenges
Links for the day
[Meme] European Patent Convention and Vienna Convention Became Only Fictions (Laws and Constitutions Are Now Works of Fiction in Europe)
A political crisis and blunder
Almost a Thousand EPO Staff Protesting to EPO Member States That the Office Illegally Grants Software Patents and Other Invalid European Patents
"The outcome confirms that the concerns about the EPO’s ability to grant legally sound patents remain"
Junk Science
science is being compromised for business purposes
[Meme] Dismantling .io (Stick a Fork, the Hype is Done)
NVIDIA is an excellent new example of hype driving up fictional "value"
UNIX is 55 This Year, It is 6 Years Older Than Microsoft
It should be noted that the surviving co-creator of UNIX, Ken Thompson, 'moved' to GNU/Linux (Debian) in recent years
This Year, for the First Time Since August 2019 (Bill Gates MIT Scandal, Jeffrey Epstein Bribes), libreplanet-discuss Was Inactive an Entire Month
The MIT injustice remains and recent "libreplanet" events were held in a venue that's not MIT and far less prestigious than MIT (the "Wentworth" imitation)
[Meme] Different Ending for Jurassic Park
UNIX in old movies
Evolution of Hype
Passing fads and rebranding
Groklaw Will Hopefully Come Back
Sites should be able to run for decades with hardly any human role/interaction, but that's not where we are...
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, October 09, 2024
IRC logs for Wednesday, October 09, 2024
Gemini Links 09/10/2024: YouTube Woes, Post-Truth Slop
Links for the day
Nothing Will Be Secure and Robust to Failure Until Microsoft Windows is Eradicated and/or Disconnected From the Internet
Every system has limited capacity, Windows botnets push things to their limits
GNU/Linux Took Off at the BSDs' Expense (Amid Telecom Lawsuit) and the Rivalry Persists Because Microsoft is Negligible in the Server Space
UNIX or POSIX is the future
Links 09/10/2024: Samsung's Fall, Tensions Growing Near China
Links for the day
Gemini Links 09/10/2024: Retroware and gmlgcd 2.0
Links for the day
Links 09/10/2024: Microsoft's Surface Duo 2 Officially Dead, X/Twitter Shutdown in Brazil, and "OpenAI Is A Bad Business"
Links for the day
Technology: rights or responsibilities? - Part III
By Dr. Andy Farnell
[Meme] Bill Gates With a Side of "Linux"
Linux Foundation is trolling us with Bill Gates
Once Again Linux Foundation Makes It Clear It's Being 'Absorbed' by Bill Gates
Linux Foundation devotes about 2% of its budget to Linux
Links 08/10/2024: Australian Fines for Twitter (X), Fake Patent Courts Still Not Scuttled
Links for the day
World Wide Slop
If it quacks like a duck...
IBM is a Boys' Club
If IBM collapsed, the Red Hat engineers who work on GNU and Linux would simply work elsewhere (on the same projects)
The Miserable State of GAFAM
Looking for government handouts
Microsoft is Acting Like a Company That's Running Out of Money (But Still Pretends to be Wealthy in Order to Attract or Retain Shareholders)
Azure has had mass layoffs every year since 2020, yet Microsoft keeps telling shareholders that "clown computing" is growing
Dr. Andy Farnell's Article on Societal Disorganised Attachment and the Role of Social Control Media
The article is quite long and typos were still being fixed as recently as last night
Smear Alert: Linus Torvalds Asking for Better Commit Messages Makes Linus a (Grammar) Nazi
Maybe the "mainstream media" is looking for clickbait or maybe it's actively looking to make a scandal - a phony controversy with which to make the job of coordinating Linux unpleasant
Gemini Links 09/10/2024: Climate Doom and Clagrange
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, October 08, 2024
IRC logs for Tuesday, October 08, 2024
Dr. Andy Farnell's Article on Why Passwords Still Rock
"Seven for a secret never to be told"
[Meme] Driver Issues
Where do you want to drive today?
The Problem Isn't That New Cars Use Electricity But That They Use Too Many Bits of Electronics
"...and proprietary software wrapped in proprietary APIs and protocols all without a modicum of compartmentalisation," an associate adds
We're Turning 18 in 30 Days
30 days from now the site turns 18
GNOME Foundation Says It's Nearly Broke (Again), It's Getting Rid of More People (Only Women Get the Boot), and It Will Improve Communications and Transparency Even Though It Secretly Ousts People From the GNOME Foundation Board (for Secret Reasons)
It only talks about this months later (under strict gag orders, only public shaming of a person)
Gemini Links 08/10/2024: Guilt by Association, Workers vs Owners
Links for the day
Links 08/10/2024: War Updates, Samsung's Layoffs, and Gemini
Links for the day
Another Dose of Fake 'Articles' About Linux
Don't give visibility to the nonsense of Microsoft
Links 08/10/2024: Microsoft Deleting Office Documents Instead of Saving Them, "Threads Still Sucks"
Links for the day
gemini.techrights.org and techrights.org (Same Server, Not the Same Protocol)
We're reminding readers that everything in this site is fully accessible via gemini.techrights.org in Gemini Protocol
X Has Axed Itself. This is Great News and Further Affirmation of Everything We've Said About Social Control Media.
Don't waste any more time on social control media
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, October 07, 2024
IRC logs for Monday, October 07, 2024
Gemini Links 08/10/2024: Contingency Begets Complexity, Playing With Bezier Curves
Links for the day