In a rather ironic moment, the European Commission, well known for their massive fines to tech companies for breaching data protection law, have been found to breach EU privacy rules by their very own watchdog.
The European Data Protection Supervisor (EDPS) has found that the EU Commission failed to issue appropriate safeguards for personal data shared with non-EU countries.
Specifically, the EDPS has found that the EU Commission’s use of Microsoft 365 was in breach of several key data protection rules.
For this contract, the EDPS found that EU Commission did not sufficiently specify what types of personal data are to be collected and for which explicit and specified purposes when using Microsoft 365.
“It is the responsibility of the EU institutions, bodies, offices and agencies (EUIs) to ensure that any processing of personal data outside and inside the EU/EEA, including in the context of cloud-based services, is accompanied by robust data protection safeguards and measures,” Wojciech Wiewiórowski, EDPS, said.
“This is imperative to ensure that individuals’ information is protected, as required by Regulation (EU) 2018/1725, whenever their data is processed by, or on behalf of, an EUI.”
Recommended reading
- Meta’s Pay-or-Consent Model Under GDPR Fire
- Italian DPA Says OpenAI in Breach of GDPR
- Data Privacy Day: Where are We and How Did We Get Here?
Therefore, the EDPS has ordered the EU Commission to suspend all data flows resulting from the use of Microsoft 365 to Microsoft and to its affiliates located in countries outside the EU and the European Economic Area, as well as bring its processing operations into compliance with EU regulations.
While the EU Commission has yet to respond with a comment on the ruling, a Microsoft spokesperson said: “Concerns raised by the European Data Protection Supervisor relate largely to stricter transparency requirements under the EUDPR, a law that applies only to the European Union institutions.”





