Microsoft promises to challenge all government requests for customer data
Stance taken following EU advice to firms on complying with a ruling invalidating the EU-US data transfer mechanism


Microsoft has vowed to challenge all requests that any government or security agency makes to access its customers’ data, and will even compensate firms where it’s forced to legally grant access.
Cross-border transfers have come under litigation and regulatory action in recent months, especially after a European court invalidated the key EU-US data transfer mechanism under the terms of GDPR. July’s ruling meant the long-established Privacy Shield was deemed unsuitable for protecting EU residents’ data from extensive US surveillance mechanisms, with concerns US authorities can extract customer data as and when desired, without adequate safeguards and protections.
In light of recommendations issued by the European Data Protection Board (EDPB) on how companies can comply with the ruling, Microsoft has now committed to challenging every request for data.
The firm will challenge every government request for public sector or enterprise customer data, from any government, where there’s a lawful basis for doing so. Where customer data is handed to authorities in violation of GDPR, Microsoft will provide financial compensation to affected customers, it has said. These are commitments that Microsoft claims go beyond the recommendations of the EDPB.
“With today’s announcement, we are moving to be the first company to respond to the EDPB’s guidance with new commitments that demonstrate the strength of our conviction to defend our customers’ data,” said Microsoft’s corporate vice president for global privacy and regulatory affairs and chief privacy officer, Julie Brill.
“Microsoft has already demonstrated that we provide strong protections for our customers’ data, we are transparent about our practices and we defend our customers’ data. We believe the new steps we’re announcing today go beyond the law and the EDPB draft recommendations, and we hope these additional steps will give our customers added confidence about their data.”
The company’s position on this matter is a statement of support for the EU’s position - and represents another example of Microsoft increasingly aligning itself with its desires on tech policy.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
For example, towards the end of last year, Microsoft committed to implementing ‘strong encryption’ in its products as opposed to ‘end-to-end encryption’, which public authorities around the world, including Interpol, have railed against.
The EU has, incidentally, earlier this month edged closer to a full ban on end-to-end encryption in platforms such as WhatsApp and Signal, according to a leaked document.

Keumars Afifi-Sabet is a writer and editor that specialises in public sector, cyber security, and cloud computing. He first joined ITPro as a staff writer in April 2018 and eventually became its Features Editor. Although a regular contributor to other tech sites in the past, these days you will find Keumars on LiveScience, where he runs its Technology section.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
EU and US reach agreement on Privacy Shield replacement
News Privacy campaigner Max Schrems suggests the deal amounts to a "patchwork approach" that will ultimately fail
By Bobby Hellard Published
-
Zoom is no longer compatible with GDPR, Hamburg data watchdog claims
News Regulator claims city officials are using a "legally highly problematic system"
By Bobby Hellard Published
-
European court invalidates primary EU-US data transfer mechanism
News Privacy Shield ruled to be incompatible with GDPR in landmark case
By Dale Walker Published
-
What is EU-US Privacy Shield?
In-depth A look at the now invalidated framework US companies relied on to transfer data to and from the European Union
By Dale Walker Last updated
-
EU seeks Privacy Shield changes in its first annual review
News Proposals include tougher rules around non-compliance and greater cooperation between US and EU authorities
By Dale Walker Published
-
Safe Harbour replaced with EU-US Privacy Shield
News The new agreement may take effect from July if both parties agree on its directions
By Clare Hopping Published
-
European data protection supervisor says Privacy Shield not robust enough
News Giovanni Buttarelli said the European Commission needs to develop a longer-term solution for sharing data across continents
By Joe Curtis Published
-
Has the US forced Reddit to secretly hand over user data?
News Disappearance of "warrant canary" seen as tacit admission of government data request
By Joe Curtis Published