Privacy

Microsoft hit with EU privacy complaints over schools’ use of 365 Education suite

Comment

Image Credits: Bloomberg / Getty Images

Microsoft’s education-focused flavor of its cloud productivity suite, Microsoft 365 Education, is facing investigation in the European Union. Privacy rights nonprofit noyb has just lodged two complaints with Austria’s data protection authority.

The complaints examine the use of Microsoft’s cloud software by schools. The first one focuses on transparency and legal basis issues. noyb says it’s concerned minors’ data is being processed unlawfully — and its press release hits out at what it dubs “consistently vague” information provided by the tech giant about how children’s information is used.

The bloc’s General Data Protection Regulation (GDPR) sets out a high expectation of protection for children’s data. Transparency and accountability must be keystones whenever minors’ information is processed. A lawful basis is also required. Confirmed breaches of the regime can attract fines of up to 4% of global annual turnover, which could scale to billions of dollars in Microsoft’s case.

The privacy rights group’s complaint accuses Microsoft of trying to evade its legal responsibilities as a data controller of children’s information by using the contracts that schools have to sign to access its software to shift compliance onto them. noyb argues schools are not in a position to comply with the EU law’s transparency requirements or data access rights, as they cannot know what Microsoft is doing with kids’ data.

Microsoft 365 Education’s price point varies but the software package can be offered for free for schools that meet certain eligibility criteria.

“Microsoft provides such vague information that even a qualified lawyer can’t fully understand how the company processes personal data in Microsoft 365 Education. It is almost impossible for children or their parents to uncover the extent of Microsoft’s data collection,” said Maartje de Graaf, data protection lawyer at noyb, in a statement.

“This take-it-or-leave-it approach by software vendors such as Microsoft is shifting all GDPR responsibilities to schools. Microsoft holds all the key information about data processing in its software, but is pointing the finger at schools when it comes to exercising rights. Schools have no way of complying with the transparency and information obligations,” she added.

“Under the current system that Microsoft is imposing on schools, your school would have to audit Microsoft or give them instructions on how to process pupils’ data. Everyone knows that such contractual arrangements are out of touch with reality. This is nothing more but an attempt to shift the responsibility for children’s’ data as far away from Microsoft as possible.”

A second complaint filed by noyb Tuesday also accuses Microsoft of secretly tracking children. noyb says it found tracking cookies that were installed by Microsoft 365 Education despite the complainant not consenting to tracking. Per Microsoft’s documentation, these cookies analyze user behavior, collect browser data and are used for advertising, it added.

“Such tracking, which is commonly used for highly invasive profiling, is apparently carried out without the complainant’s school even knowing,” noyb wrote. “As Microsoft 365 Education is widely used, the company is likely to track all minors using their educational products. The company has no valid legal basis for this processing.”

Again, the GDPR sets a high bar for lawful use of children’s data for marketing purposes — requiring data controllers take special care to protect minors’ information and ensure any uses of minors’ information are fair, lawful and clearly conveyed.

noyb contends that Microsoft’s contracts, T&Cs and data flows do not live up to this bar.

“Our analysis of the data flows is very worrying,” said Felix Mikolasch, another data protection lawyer at noyb, in a statement. “Microsoft 365 Education appears to track users regardless of their age. This practice is likely to affect hundreds of thousands of pupils and students in the EU and EEA [European Economic Area]. Authorities should finally step up and effectively enforce the rights of minors.”

noyb is asking the Austrian DPA to investigate the complaints and determine what data is being processed by Microsoft 365 Education. It also urges the authority to impose a fine if it confirms the GDPR has been breached.

Microsoft was contacted for comment on noyb’s complaint. A company spokesperson emailed this statement: “M365 for Education complies with GDPR and other applicable privacy laws and we thoroughly protect the privacy of our young users. We are happy to answer any questions data protection agencies might have about today’s announcement.”

While the tech giant has a regional base in Ireland, which typically means cross-border GDPR complaints would end up being referred back to the Irish Data Protection Commission to look at, a spokesperson for noyb emphasized the “locally relevant” nature of the two Microsoft 365 Education complaints — saying they believe the Austrian DPA is competent to investigate.

“The complaints could actually stay in Austria,” the spokesperson told TechCrunch. “The case is very locally relevant because it concerns Austrian schools and Austrian pupils, so we hope the [Austrian DPA] will take matters into its own hands. Also, we have filed the complaints against Microsoft’s US entity instead of the EU branch.”

This is important as it could lead to swifter decision-making — and potential enforcement — on the complaints against Microsoft.

GDPR complaints focused on children’s data have led to some of the largest penalties to date, such as the €405 million fine Ireland imposed on Meta, back in the summer of 2022, for Instagram-related minor protection failures. Last year the video-sharing social network TikTok was also found in breach of legal requirements to keep kids’ data safe — receiving a €345 million fine.

Meanwhile, Microsoft’s cloud productivity suite remains under a broader legal cloud in the EU. Back in March the bloc’s own use of 365 was found in breach of the GDPR by the European Data Protection Supervisor — which imposed corrective measures, giving EU institutions until early December to fix the compliance issues identified.

A lengthy investigation of Microsoft 365 by German data protection authorities also identified a raft of problems back in the fall of 2022 — with the working group concluding at the time there was no way to use the software suite in a way that was compliant with the GDPR.

This report was updated with a comment from Microsoft

More TechCrunch

Huffington Post founder Arianna Huffington and OpenAI CEO Sam Altman are throwing their weight behind a new venture, Thrive AI Health, that aims to build AI-powered assistant tech to promote…

OpenAI Startup Fund backs AI healthcare venture with Arianna Huffington

The essential labor of data work, like moderation and annotation, is systematically hidden from those who benefit from the fruits of that labor. A new project puts the lived experiences…

Data workers detail exploitation by tech industry in DAIR report

Hello and welcome back to TechCrunch Space. I hope everyone had a great Independence Day. On to the news!

TechCrunch Space: SpaceX’s big plans for Starship in Florida

Featured Article

Valuations of startups have quietly rebounded to all-time highs. Some investors say the slump is over. 

Generative AI businesses aside, the last couple of years have been relatively difficult for venture-backed companies. Very few startups were able to raise funding at prices that exceeded their previous valuations.   Now, approximately two years after the venture slump began in early 2022, some investors, like IVP general partner Tom…

7 hours ago
Valuations of startups have quietly rebounded to all-time highs. Some investors say the slump is over. 

VPN makers report having received a notification from Apple that their apps have been removed from the App Store in Russia.

Apple removes VPN apps at request of Russian authorities, say app makers

Europe’s next-generation launch vehicle, the Ariane 6, is poised to lift off for the first time tomorrow, as the continent looks to build out sovereign access to space and ensure…

Ariane 6 is the future of European heavy-lift launch — for better or worse

Over the past few days, Ghost says it has achieved two major milestones in its move to become a federated service.

Substack rival Ghost federates its first newsletter

The Samsung event will feature updates to the Galaxy Z Fold, Galaxy Z Flip, as well as more details on the Galaxy Ring and Galaxy AI.

Samsung Unpacked 2024: What we expect and how to watch Wednesday’s hardware event

Amazon has released an all-new version of its Echo Spot ahead of Prime Day, the company announced on Monday. The 2024 version of the Alexa-enabled smart alarm clock costs $79.99,…

Amazon revives its Echo Spot with an upgraded look and improved audio

One of the vendors to benefit from the database boom is Tembo, a startup creating a platform that lets developers deploy different flavors of Postgres.

Tembo capitalizes on the database boom and lands new cash to expand

TechCrunch Disrupt 2024 is set to welcome an impressive lineup of judges for the Startup Battlefield 200 competition, presented this year by Google Cloud. These judges will decide which company…

Mayfield’s Navin Chaddha is coming to TechCrunch Disrupt 2024

Numerous concerns are weighing on the minds of many, whether it’s current global conflicts, climate change or the precarious state of the economy, it is no surprise that the world…

Art therapy app Scribble Journey lets you express emotions through doodles

Pestle addresses the common problem of finding recipes on the web.

Pestle’s app can now save recipes from Reels using on-device AI

These efforts have come as Lucid is looking to start building its Gravity SUV by the end of this year.

Lucid Motors sets new record for EV deliveries as it seeks ‘escape velocity’

Berlin-based food delivery giant Delivery Hero has warned investors it may “ultimately” face an antitrust fine of up to €400 million. The development, reported earlier by Reuters, follows unannounced raids…

Delivery Hero warns it could face €400M antitrust fine

Featured Article

Investors chase wealth tech startups in India as affluent class grows

The high-net-worth and ultra-high-net-worth segments are booming in India, prompting some wealth management firms to aggressively expand their relationship manager networks to capture this market.

1 day ago
Investors chase wealth tech startups in India as affluent class grows

Featured Article

Seed VCs are turning to new ‘pro rata’ funds that help them compete with the big firms

Three companies with new funds deploy capital to support seed and Series A VCs looking to exercise their pro rata rights.

1 day ago
Seed VCs are turning to new ‘pro rata’ funds that help them compete with the big firms

Here are the latest companies venturing into the gaming scene and details about each offering, including pricing, examples of titles and supported devices. 

YouTube and LinkedIn have games now, and here’s how you can play them

Featured Article

CIOs’ concerns over generative AI echo those of the early days of cloud computing

CIOs trying to govern generative AI have the same concerns they had about cloud computing 15 years ago, but they’ve learned some things along the way.

1 day ago
CIOs’ concerns over generative AI echo those of the early days of cloud computing

It sounds like the latest dispute between Apple and Fortnite-maker Epic Games isn’t over. Epic has been fighting Apple for years over the company’s revenue-sharing requirements in the App Store.…

Epic Games CEO promises to ‘fight’ Apple over ‘absurd’ changes

As deep-pocketed companies like Amazon, Google and Walmart invest in and experiment with drone delivery, a phenomenon reflective of this modern era has emerged. Drones, carrying snacks and other sundries,…

What happens if you shoot down a delivery drone?

A police officer pulled over a self-driving Waymo vehicle in Phoenix after it ran a red light and pulled into a lane of oncoming traffic, according to dispatch records. The…

Waymo robotaxi pulled over by Phoenix police after driving into the wrong lane

Welcome back to TechCrunch’s Week in Review — TechCrunch’s newsletter recapping the week’s biggest news. Want it in your inbox every Saturday? Sign up here. This week, Figma CEO Dylan…

Figma pauses its new AI feature after Apple controversy

We’ve created this guide to help parents navigate the controls offered by popular social media companies.

How to set up parental controls on Facebook, Snapchat, TikTok and more popular sites

Featured Article

You could learn a lot from a CIO with a $17B IT budget

Lori Beer’s work is a case study for every CIO out there, most of whom will never come close to JP Morgan Chase’s scale, but who can still learn from how it goes about its business.

2 days ago
You could learn a lot from a CIO with a $17B IT budget

For the first time, Chinese government workers will be able to purchase Tesla’s Model Y for official use. Specifically, officials in eastern China’s Jiangsu province included the Model Y in…

Tesla makes it onto Chinese government purchase list

Generative AI models don’t process text the same way humans do. Understanding their “token”-based internal environments may help explain some of their strange behaviors — and stubborn limitations. Most models,…

Tokens are a big reason today’s generative AI falls short

After multiple rejections, Apple has approved Fortnite maker Epic Games’ third-party app marketplace for launch in the EU. As now permitted by the EU’s Digital Markets Act (DMA), Epic announced…

Apple approves Epic Games’ marketplace app after initial rejections

There’s no need to worry that your secret ChatGPT conversations were obtained in a recently reported breach of OpenAI’s systems. The hack itself, while troubling, appears to have been superficial…

OpenAI breach is a reminder that AI companies are treasure troves for hackers

Welcome to Startups Weekly — TechCrunch’s weekly recap of everything you can’t miss from the world of startups. Sign up here to get it in your inbox every Friday. Most…

Space for newcomers, biotech going mainstream, and more