Austria's data protection authority has determined that Microsoft violated the European Union's General Data Protection Regulation (GDPR) by unlawfully tracking students through its Microsoft 365 Education platform. The ruling followed a complaint filed by the privacy advocacy group noyb, which represented a parent who alleged that their child's data was processed without proper consent and that Microsoft failed to provide adequate information about how the data was used. The authority found that Microsoft used tracking cookies within the 365 Education suite, which is widely deployed in schools for cloud storage, communication, and productivity. The investigation revealed that Microsoft attempted to shift responsibility for GDPR compliance and access requests onto local schools and educational authorities, entities that had little to no control over the actual data processing. When the complainant sought access to the data being processed, Microsoft referred them to the local school, but the school could only provide minimal information, as it did not have access to the data held by Microsoft. This led to a situation where neither the school nor Microsoft provided the required transparency or access, violating Article 15 of the GDPR, which guarantees the right of access to personal data. The Austrian authority ordered Microsoft to provide complete information about the data it processes, including clear explanations of terms such as "internal reporting," "business modelling," and "improvement of core functionality." The ruling underscores the lack of transparency in Microsoft's data handling practices, making it difficult for schools to inform students and parents about how their data is managed. Microsoft has stated that it will review the ruling and maintains that its education products are designed to comply with GDPR standards. The decision could have significant implications for Microsoft's obligations to inform users across Europe about its data processing activities. Privacy advocates argue that the case highlights systemic issues in how large technology providers handle student data in educational settings. The complaint and subsequent ruling date back to the period of the COVID-19 pandemic, when many schools rapidly adopted online learning platforms like Microsoft 365 Education. The authority's findings may prompt further scrutiny of cloud-based educational tools and their compliance with European privacy laws. The case also demonstrates the challenges faced by individuals in exercising their data rights when responsibility is fragmented between technology providers and local institutions. The outcome may set a precedent for how similar cases are handled in other EU member states. Microsoft is now required to improve its transparency and provide users with clear, comprehensive information about the data it collects and processes through its education products.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
Austria's data protection authority determined that Microsoft illegally tracked students through Microsoft 365 Education and breached EU privacy law. The ruling centered on the handling of student data in the education-focused cloud service.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.