Microsoft 365 and the GDPR
Using Microsoft 365 offers companies many advantages. At the same time supervisory authorities frequently doubt that it is deployed in line with data protection law, and they do act against companies.
We support you in implementing the Microsoft 365 products in as privacy-friendly a way as possible, and so reduce your risk of becoming the target of supervisory measures.
Where we support you
- Data protection impact assessment for Microsoft 365
- Support with a privacy-friendly configuration
- Review and negotiation of the contractual basis
- Representation of your interests towards supervisory authorities
The points supervisory authorities start from
The objections of recent years concern the same places again and again. Knowing them allows you to align the configuration before an enquiry arrives.
- Telemetry and diagnostic data whose scope and purpose do not follow completely from the provider documentation
- Processing that Microsoft carries out for its own purposes and in which it therefore does not act as a processor
- Log and audit data for which retention and access often remain unregulated in house
- Default settings that transmit more than necessary unless adjusted
- Access from third countries in support cases and the question of which safeguards carry it
- A missing data protection impact assessment, or one that has not been kept up to date
What employee data adds
As soon as evaluations about individual employees become possible, co-determination joins data protection law. Section 87(1) no. 6 of the German Works Constitution Act already applies where a system is capable of monitoring conduct or performance, and an intention to monitor is not required. For Microsoft 365 this concerns activity and collaboration analytics in particular, as well as the audit logs. A works agreement can carry both at once, the involvement of the works council and the basis under data protection law. More on this under co-determination.
Microsoft 365 in use or planned?
We review configuration and documentation before the authority asks.
Request an assessmentFrequently asked questions
Is using Microsoft 365 prohibited?
No. There is no blanket prohibition. The German data protection authorities did assess the deployment in the configuration examined at the time as not compliant, and supervisory authorities pick the point up. What matters is therefore the specific configuration and its documentation, not the product as such.
Do we need a data protection impact assessment?
In many constellations yes. Deploying a cloud platform with extensive telemetry and employee data suggests a high risk. Even where you reach a different conclusion in the end, the assessment has to be carried out and documented.
The supervisory authority is asking about our deployment. What now?
Do not answer off the cuff. What you write binds you in the further proceedings. We first review what is actually configured and documented and draft the response on that basis.
Does the EU Data Boundary settle the third-country question?
It eases it but does not settle it. Customer data, log data and support data of European customers are stored and processed within the EU. Access from third countries remains possible in individual support cases, and the group remains subject to US law. What still has to be examined is the certification status under the EU-U.S. Data Privacy Framework, the safeguards agreed and which data arise in the first place.
Does the same apply to Copilot as to Microsoft 365?
The basic questions remain and further ones are added. Copilot draws on the existing data in the tenant and thereby makes visible where access rights are drawn too widely. On top of that come the transparency duties under Art. 50 of the AI Act, co-determination under section 87(1) no. 6 of the German Works Constitution Act, and the question of how long inputs and outputs are retained. Cleaning up permissions therefore belongs before the rollout.