Skip to content
Call, 0511 – 47 55 58 11

Microsoft 365 and the GDPR

Using Microsoft 365 offers companies many advantages. At the same time supervisory authorities frequently doubt that it is deployed in line with data protection law, and they do act against companies.

We support you in implementing the Microsoft 365 products in as privacy-friendly a way as possible, and so reduce your risk of becoming the target of supervisory measures.

Where we support you

The points supervisory authorities start from

The objections of recent years concern the same places again and again. Knowing them allows you to align the configuration before an enquiry arrives.

What employee data adds

As soon as evaluations about individual employees become possible, co-determination joins data protection law. Section 87(1) no. 6 of the German Works Constitution Act already applies where a system is capable of monitoring conduct or performance, and an intention to monitor is not required. For Microsoft 365 this concerns activity and collaboration analytics in particular, as well as the audit logs. A works agreement can carry both at once, the involvement of the works council and the basis under data protection law. More on this under co-determination.

Microsoft 365 in use or planned?

We review configuration and documentation before the authority asks.

Request an assessment

Frequently asked questions

Is using Microsoft 365 prohibited?

No. There is no blanket prohibition. The German data protection authorities did assess the deployment in the configuration examined at the time as not compliant, and supervisory authorities pick the point up. What matters is therefore the specific configuration and its documentation, not the product as such.

Do we need a data protection impact assessment?

In many constellations yes. Deploying a cloud platform with extensive telemetry and employee data suggests a high risk. Even where you reach a different conclusion in the end, the assessment has to be carried out and documented.

The supervisory authority is asking about our deployment. What now?

Do not answer off the cuff. What you write binds you in the further proceedings. We first review what is actually configured and documented and draft the response on that basis.

Does the EU Data Boundary settle the third-country question?

It eases it but does not settle it. Customer data, log data and support data of European customers are stored and processed within the EU. Access from third countries remains possible in individual support cases, and the group remains subject to US law. What still has to be examined is the certification status under the EU-U.S. Data Privacy Framework, the safeguards agreed and which data arise in the first place.

Does the same apply to Copilot as to Microsoft 365?

The basic questions remain and further ones are added. Copilot draws on the existing data in the tenant and thereby makes visible where access rights are drawn too widely. On top of that come the transparency duties under Art. 50 of the AI Act, co-determination under section 87(1) no. 6 of the German Works Constitution Act, and the question of how long inputs and outputs are retained. Cleaning up permissions therefore belongs before the rollout.

Related