login
login
Image header Agence Europe
Europe Daily Bulletin No. 13368
Contents Publication in full By article 14 / 36
SECTORAL POLICIES / Digital

European Commission breached data protection rules in its contract with Microsoft, says EDPS

The European Data Protection Supervisor (EDPS) found, on Friday 8 March, in the conclusions of an investigation conducted since May 2021, that the European Commission had breached a number of data protection rules in its contract with Microsoft.

Specifically, the EDPS considers that the contract between the Commission and Microsoft 365 is not sufficiently precise as to the type of personal data collected and the purposes for which it is collected. The European supervisor is therefore asking the Commission to put its house in order before 9 December 2024, failing which data flows with Microsoft will have to be suspended.

It is the responsibility of the EU institutions, bodies, offices and agencies to ensure that any processing of personal data outside and inside the EU/EEA, including in the context of cloud-based services, is accompanied by robust data protection safeguards and measures”, explained the European Data Protection Supervisor, Wojciech Wiewiórowski.

For its part, one of the Commission’s spokespersons said that the results of the investigation would have to be “analysed” before any “conclusions could be drawn”. “The Commission has received the decision of the European Data Protection Supervisor regarding their investigation into the Commission’s use of Microsoft 365. The Commission will now need to analyse this decision (...) and is confident that it applies with the data protection rules”, the spokesperson added. (Original version in French by Thomas Mangin)

Contents

SOCIAL AFFAIRS - EMPLOYMENT
ECONOMY - FINANCE - BUSINESS
INSTITUTIONAL
SECTORAL POLICIES
EXTERNAL ACTION
SECURITY - DEFENCE
FUNDAMENTAL RIGHTS - SOCIETAL ISSUES
COUNCIL OF EUROPE
NEWS BRIEFS