Austrian Regulator Rules Microsoft Violated GDPR with 365 Education Data Practices
The Austrian Data Protection Authority has ruled that Microsoft violated GDPR by illegally tracking students using its 365 Education platform, according to a complaint filed by the privacy group noyb. The decision highlights Microsoft’s failure to provide complete information about data processing when responding to access requests, instead shifting responsibility to schools and local education authorities, which lacked control over the data. The ruling, stemming from a complaint filed during the rapid shift to online learning in the COVID-19 pandemic, mandates that Microsoft clarify how it uses student data, including terms like ‘internal reporting’ and ‘business modelling,’ and disclose any third-party data transfers. The authority rejected Microsoft’s claim that its Ireland subsidiary was responsible, affirming that decisions were made by Microsoft US. This decision could have significant implications for Microsoft’s transparency obligations across Europe. The school and federal education authorities were also found non-compliant for failing to provide adequate data processing information, though the provincial authority was cleared. Microsoft maintains that its 365 Education platform complies with GDPR and is reviewing the ruling. Privacy advocate Max Schrems criticized Microsoft for shifting responsibilities to European customers, urging a fundamental change in its product setup to ensure GDPR compliance.
