The European Data Protection Authority (EDPS) has concluded that the European Commission’s use of Microsoft 365 violated several key provisions of the Union’s regulation dealing with the processing of personal data by its institutions. These include, among other things, provisions on the transfer of personal information to unsafe third countries and the specification of categories of personal information and the purpose of processing in the processing agreement. The provisions are similar to the provisions of the European Personal Protection Regulation and the Icelandic Personal Protection Act.
The EDPS has proposed to the Commission to stop all information flows resulting from its use of Microsoft 365 to Microsoft, its business partners and sub-processors, located outside the European Economic Area and for which an equivalence decision has not been taken, from 9 December 2024. The EDPS has also proposed to the Commission to bring processing operations in connection with the use of Microsoft 365 in other respects in accordance with the regulation in question.
The EDPS press release can be read here.