Privacy

Microsoft hit with EU privacy complaints over schools’ use of 365 Education suite

Comment

Image Credits: Bloomberg / Getty Images

Microsoft’s education-focused flavor of its cloud productivity suite, Microsoft 365 Education, is facing investigation in the European Union. Privacy rights nonprofit noyb has just lodged two complaints with Austria’s data protection authority.

The complaints examine the use of Microsoft’s cloud software by schools. The first one focuses on transparency and legal basis issues. noyb says it’s concerned minors’ data is being processed unlawfully — and its press release hits out at what it dubs “consistently vague” information provided by the tech giant about how children’s information is used.

The bloc’s General Data Protection Regulation (GDPR) sets out a high expectation of protection for children’s data. Transparency and accountability must be keystones whenever minors’ information is processed. A lawful basis is also required. Confirmed breaches of the regime can attract fines of up to 4% of global annual turnover, which could scale to billions of dollars in Microsoft’s case.

The privacy rights group’s complaint accuses Microsoft of trying to evade its legal responsibilities as a data controller of children’s information by using the contracts that schools have to sign to access its software to shift compliance onto them. noyb argues schools are not in a position to comply with the EU law’s transparency requirements or data access rights, as they cannot know what Microsoft is doing with kids’ data.

Microsoft 365 Education’s price point varies but the software package can be offered for free for schools that meet certain eligibility criteria.

“Microsoft provides such vague information that even a qualified lawyer can’t fully understand how the company processes personal data in Microsoft 365 Education. It is almost impossible for children or their parents to uncover the extent of Microsoft’s data collection,” said Maartje de Graaf, data protection lawyer at noyb, in a statement.

“This take-it-or-leave-it approach by software vendors such as Microsoft is shifting all GDPR responsibilities to schools. Microsoft holds all the key information about data processing in its software, but is pointing the finger at schools when it comes to exercising rights. Schools have no way of complying with the transparency and information obligations,” she added.

“Under the current system that Microsoft is imposing on schools, your school would have to audit Microsoft or give them instructions on how to process pupils’ data. Everyone knows that such contractual arrangements are out of touch with reality. This is nothing more but an attempt to shift the responsibility for children’s’ data as far away from Microsoft as possible.”

A second complaint filed by noyb Tuesday also accuses Microsoft of secretly tracking children. noyb says it found tracking cookies that were installed by Microsoft 365 Education despite the complainant not consenting to tracking. Per Microsoft’s documentation, these cookies analyze user behavior, collect browser data and are used for advertising, it added.

“Such tracking, which is commonly used for highly invasive profiling, is apparently carried out without the complainant’s school even knowing,” noyb wrote. “As Microsoft 365 Education is widely used, the company is likely to track all minors using their educational products. The company has no valid legal basis for this processing.”

Again, the GDPR sets a high bar for lawful use of children’s data for marketing purposes — requiring data controllers take special care to protect minors’ information and ensure any uses of minors’ information are fair, lawful and clearly conveyed.

noyb contends that Microsoft’s contracts, T&Cs and data flows do not live up to this bar.

“Our analysis of the data flows is very worrying,” said Felix Mikolasch, another data protection lawyer at noyb, in a statement. “Microsoft 365 Education appears to track users regardless of their age. This practice is likely to affect hundreds of thousands of pupils and students in the EU and EEA [European Economic Area]. Authorities should finally step up and effectively enforce the rights of minors.”

noyb is asking the Austrian DPA to investigate the complaints and determine what data is being processed by Microsoft 365 Education. It also urges the authority to impose a fine if it confirms the GDPR has been breached.

Microsoft was contacted for comment on noyb’s complaint. A company spokesperson emailed this statement: “M365 for Education complies with GDPR and other applicable privacy laws and we thoroughly protect the privacy of our young users. We are happy to answer any questions data protection agencies might have about today’s announcement.”

While the tech giant has a regional base in Ireland, which typically means cross-border GDPR complaints would end up being referred back to the Irish Data Protection Commission to look at, a spokesperson for noyb emphasized the “locally relevant” nature of the two Microsoft 365 Education complaints — saying they believe the Austrian DPA is competent to investigate.

“The complaints could actually stay in Austria,” the spokesperson told TechCrunch. “The case is very locally relevant because it concerns Austrian schools and Austrian pupils, so we hope the [Austrian DPA] will take matters into its own hands. Also, we have filed the complaints against Microsoft’s US entity instead of the EU branch.”

This is important as it could lead to swifter decision-making — and potential enforcement — on the complaints against Microsoft.

GDPR complaints focused on children’s data have led to some of the largest penalties to date, such as the €405 million fine Ireland imposed on Meta, back in the summer of 2022, for Instagram-related minor protection failures. Last year the video-sharing social network TikTok was also found in breach of legal requirements to keep kids’ data safe — receiving a €345 million fine.

Meanwhile, Microsoft’s cloud productivity suite remains under a broader legal cloud in the EU. Back in March the bloc’s own use of 365 was found in breach of the GDPR by the European Data Protection Supervisor — which imposed corrective measures, giving EU institutions until early December to fix the compliance issues identified.

A lengthy investigation of Microsoft 365 by German data protection authorities also identified a raft of problems back in the fall of 2022 — with the working group concluding at the time there was no way to use the software suite in a way that was compliant with the GDPR.

This report was updated with a comment from Microsoft

More TechCrunch

Simply submitting the request for a takedown doesn’t necessarily mean the content will be removed, however.

YouTube now lets you request removal of AI-generated content that simulates your face or voice

The news highlights that the fallout from the Evolve data breach on third-party companies — and their customers and users —  is still unclear.

Fintech company Wise says some customers affected by Evolve Bank data breach

The Supreme Court on Monday vacated two judicial decisions concerning Republican-backed laws from Florida and Texas aimed at limiting social media companies’ ability to moderate content on their platforms. The…

Supreme Court sends Texas and Florida social media regulation laws back to lower courts

Afloat, a gift delivery app that lets you shop from local stores and have gifts delivered to a loved one on the same day, is now available across the U.S. The…

Gifting on-demand startup Afloat goes nationwide

Exciting news for tech enthusiasts and innovators! TechCrunch Disrupt 2024 is just around the corner, and we have an incredible opportunity for you to elevate your brand’s visibility. How? By…

Drive brand impact with a Side Event at TechCrunch Disrupt

After Meta started tagging photos with a “Made with AI” label in May, photographers complained that the social networking company had been applying labels to real photos where they had…

Meta changes its label from ‘Made with AI’ to ‘AI info’ to indicate use of AI in photos

Investment app Robinhood is adding more AI features for investors with its acquisition of AI-powered research platform Pluto Capital, Inc. Announced on Monday, the company says that Pluto will allow…

Robinhood snaps up Pluto to add AI tools to its investing app

Vaire Computing, based in London and Seattle, is betting that chips that can do reversible computing are going to be the way forward for the world.

Vaire Computing raises $4.5M for ‘reversible computing’ moonshot which could drastically reduce energy needs

The EC has found that Meta’s “pay or consent” offer to Facebook and Instagram users in Europe does not comply with the bloc’s DMA.

Meta’s ‘pay or consent’ model fails EU competition rules, Commission finds

The round was led by KKR and Teachers’ Ventures Growth, an investment arm of Ontario Teachers’ Pension Plan.

Japan’s SmartHR raises $140M Series E as strong demand for HR tech boosts its ARR to $100M

RoboGrocery combines computer vision with a soft robotic gripper to bag a wide range of different items.

MIT’s soft robotic system is designed to pack groceries

This is by no means a complete list, just a few of the most obvious tricks that AI can supercharge.

AI-powered scams and what you can do about them

Identity.vc writes checks that range from €250,000 to €1.5 million into companies from the pre-seed to Series A stages.

Identity.vc is bringing capital and community to Europe’s LGBTQ+ venture ecosystem

Featured Article

Robot cats, dogs and birds are being deployed amid an ‘epidemic of loneliness’

In the early 1990s, a researcher at Japan’s National Institute of Advanced Industrial Science and Technology began work on what would become Paro. More than 30 years after its development, the doe-eyed seal pup remains the best-known example of a therapeutic robot for older adults. In 2011, the robot reached…

1 day ago
Robot cats, dogs and birds are being deployed amid an ‘epidemic of loneliness’

Apple’s AI plans go beyond the previously announced Apple Intelligence launches on the iPhone, iPad and Mac. According to Bloomberg’s Mark Gurman, the company is also working to bring these…

Apple reportedly working to bring AI to the Vision Pro

One of the earlier SaaS adherents to generative AI has been ServiceNow, which has been able to take advantage of the data in its own platform to help build more…

ServiceNow’s generative AI solutions are taking advantage of the data on its own platform

India’s top AI startups include those building LLMs and setting up the stage for AGI as well as bringing AI to cooking and serving farmers.

Here are India’s biggest AI startups based on how much money they’ve raised

We live in a very different world since the Russian invasion of Ukraine in 2022 and Hamas’s October 7 attack on Israel. With global military expenditure reaching $2.4 trillion last…

Defense tech and ‘resilience’ get global funding sources: Here are some top funders

Two separate studies investigated how well Google’s Gemini models and others make sense out of an enormous amount of data.

Gemini’s data-analyzing abilities aren’t as good as Google claims

Featured Article

The biggest data breaches in 2024: 1 billion stolen records and rising

Some of the largest, most damaging breaches of 2024 already account for over a billion stolen records.

2 days ago
The biggest data breaches in 2024: 1 billion stolen records and rising

Welcome back to TechCrunch’s Week in Review — TechCrunch’s newsletter recapping the week’s biggest news. Want it in your inbox every Saturday? Sign up here. This week, Apple finally added…

Apple finally supports RCS in iOS 18 update

Featured Article

SAP, and Oracle, and IBM, oh my! ‘Cloud and AI’ drive legacy software firms to record valuations

There’s something of a trend around legacy software firms and their soaring valuations: Companies founded in dinosaur times are on a tear, evidenced this week with SAP‘s shares topping $200 for the first time. Founded in 1972, SAP’s valuation currently sits at an all-time high of $234 billion. The Germany-based…

2 days ago
SAP, and Oracle, and IBM, oh my! ‘Cloud and AI’ drive legacy software firms to record valuations

Sarah Bitamazire is the chief policy officer at the boutique advisory firm Lumiera.

Women in AI: Sarah Bitamazire helps companies implement responsible AI

Crypto platforms will need to report transactions to the Internal Revenue Service, starting in 2026. However, decentralized platforms that don’t hold assets themselves will be exempt. Those are the main…

IRS finalizes new regulations for crypto tax reporting

As part of a legal settlement, the Detroit Police Department has agreed to new guardrails limiting how it can use facial recognition technology. These new policies prohibit the police from…

Detroit Police Department agrees to new rules around facial recognition tech

Plaid’s expansion into being a multi-product company has led to real traction beyond traditional fintech customers.

Plaid, once aimed at mostly fintechs, is growing its enterprise business and now has over 1,000 customers signed on

He says that the problem is that generative AI is not human or even human-like, and it’s flawed to try and assign human capabilities to it.

MIT robotics pioneer Rodney Brooks thinks people are vastly overestimating generative AI

Matrix is rebranding its India and China affiliates, becoming the latest venture firm to distance its international franchises. The U.S.-headquartered venture capital firm will retain its name, while Matrix Partners…

Matrix venture firm distances from India and China affiliates

Adept, a startup developing AI-powered “agents” to complete various software-based tasks, has agreed to license its tech to Amazon, and the startup’s co-founders and portions of its team have joined…

Amazon hires founders away from AI startup Adept

There are plenty of resources to learn English, but not so many for near-native speakers who still want to improve their fluency. That description applies to Stan Beliaev and Yurii…

YC alum Fluently’s AI-powered English coach attracts $2M seed round
  翻译: