European Data Protection Supervisor: EU Commission violated data rules
The European Union (EU) data protection authority has announced that the EU Commission violated the Union's privacy rules by using Microsoft 365 software.
12punto
The European Union (EU) data protection authority has reported that the EU Commission has violated the Union's privacy rules. The European Data Protection Supervisor, which aims to ensure that EU institutions comply with privacy and data protection rules when processing personal data and developing new policies, announced that its investigation into the EU Commission's use of Microsoft 365 software has been completed.
The statement declared, "The EU Commission's use of Microsoft 365 violates the data protection law for EU institutions and bodies."
APPROPRIATE MEASURES ARE NOT BEING TAKEN
The statement noted that the Commission failed to comply with rules regarding the transfer of personal data outside the EU when using the software in question, and that appropriate measures to ensure an equivalent level of protection for the transferred personal data were not taken.
The statement pointed out that the contract the Commission signed with Microsoft should have clearly specified what types of personal data are collected and for what purposes when using Microsoft 365.
Highlighting that the EU Commission must take measures to comply with privacy rules, the statement announced that the Commission has been instructed to suspend data transfers to companies and countries that do not have a privacy agreement with the EU and the European Economic Area by December 9.
Microsoft 365, which can be installed on computers, tablets, and phones, provides access to applications such as Word, Excel, PowerPoint, Outlook, and Teams.