An investigation by the European Union’s Data Protection Supervisor (EDPS) is analyzing Microsoft contracts with EU organizations following a discovery by the Dutch government that found Microsoft software violated the General Data Protection Regulation (GDPR).
The EDPS is an authority charged with monitoring EU institutions’ compliance with data protection rules. In December, new outsourcing guidelines gave contractors direct responsibility for ensuring compliance. If an organization uses a third party to provide services, it’s liable for data processing done on its behalf and must ensure its contracts abide by the new rules.
Microsoft products are under EDPS investigation following a Dutch government report that expressed concern about data collection in Microsoft Office ProPlus, which contains popular software like Word and Outlook. It claims to have found eight GDPR violations in Office ProPlus and Office 365. EDPS plans to look into which Microsoft tools and services are in use among EU institutions and whether their Microsoft contracts comply with the newest GDPR changes.
“Any EU institutions using the Microsoft applications investigated in this report are likely to face similar issues to those encountered by national public authorities, including increased risks to the rights and freedoms of individuals,” the EDPS explained in a press release on the news.
It’s worth noting that Microsoft responded to the Dutch government’s concerns earlier this year, when it announced plans to introduce changes to ProPlus by the end of April 2019.
Read more details here.
Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry’s most knowledgeable IT security experts. Check out the Interop agenda here.
Dark Reading’s Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio