EU raises "serious concerns" over Microsoft's role as data processor
EPDS tells EU organisations that outsourcing any data processing means they’re still responsible


The European Data Protection Supervisor has expressed "serious concerns" that Microsoft may have violated data protection laws through product and service agreements with EU institutions, preliminary results of an investigation have revealed.
The early results follow an initial probe by the Dutch data regulator into the data collection practices of Windows Pro and Windows 10 Home, based on their testing of changes to Microsoft's data collection policies.
After finding issues with Microsoft's data practices in 2018, the Minister of Justice and Security warned users to ditch OneDrive and Office 365 in the interim before demanding changes from the software giant.
Further checks in August of the changes Microsoft had since implemented showed that despite "concrete improvements", the company was still remotely collecting some forms of data from its users. This, according to investigators, constituted a potential violation of the General Data Protection Regulation (GDPR).
The EDPS, an independent organisation that manages the application of GDPR across the continent, has subsequently weighed in with the results of its own probe into contracts Microsoft has agreed with EU institutions.
The EDPS also organised an EU software and cloud suppliers customer council in the Hague on 29 August, which led to the creation of the Hague Forum.
This collective aims to discuss how to take back control over IT services offered by big tech companies, while establishing how institutions can establish standard contractual terms instead of accepting vendor-led user agreements.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"We expect that the creation of The Hague Forum and the results of our investigation will help improve the data protection compliance of all EU institutions," said assistant EDPS Wojciech Wiewirowski.
"The agreement reached between the Dutch Ministry of Justice and Security and Microsoft on appropriate contractual and technical safeguards and measures to mitigate risks to individuals is a positive step forward.
"Through The Hague Forum and by reinforcing regulatory cooperation, we aim to ensure that these safeguards and measures apply to all consumers and public authorities living and operating in the EEA."
The EDPS also warned that outsourcing the processing of personal data still means organisations are accountable for the activities conducted on their behalf.

Keumars Afifi-Sabet is a writer and editor that specialises in public sector, cyber security, and cloud computing. He first joined ITPro as a staff writer in April 2018 and eventually became its Features Editor. Although a regular contributor to other tech sites in the past, these days you will find Keumars on LiveScience, where he runs its Technology section.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard Published
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd Published
-
Tech leaders worry AI innovation is outpacing governance
News Business execs have warned the current rate of AI innovation is outpacing governance practices.
By Emma Woollacott Published
-
Top data security trends
Whitepaper Must-have tools for your data security toolkit
By ITPro Published
-
SEC data breach rules branded “worryingly vague” by industry body
News The new rules announced last week leave many questions unanswered, according to security industry experts
By Ross Kelly Published
-
The gratitude gap
Whitepaper 2023 State of Recognition
By ITPro Published
-
Meta sues ‘data scraping for hire’ service that collected info on 600k users
News Meta says tackling data scraping will require a “collective effort” from platforms and policymakers
By Ross Kelly Published
-
Building a data governance strategy in 2023
In-depth Data governance will continue to expand as attitudes change and businesses look to optimise the value of their data
By Keri Allan Published
-
FCC plans strict overhaul of 15-year-old US data breach regulations
News Telcos could no longer be able to use negligence as a defence for data breaches as the FCC also seeks to hasten public notification of breaches
By Rory Bathgate Published
-
UK follows EU in securing data deal with South Korea
News The deal will foster cross-border collaboration between businesses by reducing administrative and financial frictions
By Zach Marzouk Published