Skip to content

Services, Wiki-Artikel und Blog-Beiträge durchsuchen

↑↓NavigierenEnterÖffnenESCSchließen
Microsoft products do not comply with German data protection laws!
Security Awareness

Microsoft products do not comply with German data protection laws!

Data protectionists have expressed new doubts about Microsoft products and data protection, but not all federal states agree.

Chris Wojzechowski Chris Wojzechowski Geschäftsführender Gesellschafter
Updated: October 2, 2024 3 min read read
IT-Grundschutz-Praktiker (TÜV) IT Risk Manager (DGI) § 8a BSIG Prüfverfahrenskompetenz Ausbilderprüfung (IHK)

TL;DR

A German data protection working group concluded that Microsoft 365 cannot be used in a GDPR-compliant way by public authorities, citing data transfers to third parties and opaque contracts. Roughly 96% of German federal agencies rely on Microsoft products. All German state data protection officers except Bavaria supported urgent action. The EU Data Protection Commissioner also launched initial investigations at the European level. The outcome of these proceedings remained open at the time of writing.

Table of Contents (2 sections)

Microsoft products have become an integral part of most companies and schools. Due to the Corona pandemic, Microsoft teams in particular gained users in addition to the usual products, such as Microsoft Word or Microsoft Power Point. At the data protection conference, data protection activists from Germany have now announced that Microsoft products do not comply with data protection laws in Germany.

Dependence on Microsoft products

A market analysis commissioned by the Federal Ministry states that approx. 96% of all German authorities use Microsoft products. This dependency could already have increased due to Corona, because many companies but also schools had to offer home office. With the product Microsoft-Teams Microsoft provides a product which contains many things which are needed for a successful home office. These include the ability to conduct video conferences, an integrated chat but also the possibility to share files quickly and easily with colleagues. If the dependence on this American company continues to grow, it will become more and more difficult to establish a solution that is compliant with data protection. This is because a group of data protection specialists from Germany have been sifting through and evaluating contracts and documents agreed between German authorities and Microsoft. The result of this investigation is that no data protection-compliant use of Microsoft 365 is possible. The fact that many authorities use Microsoft products without checking the requirements for data protection is particularly criticized. Microsoft products and data protection are a well-known topic, but the group is particularly critical of the passing on of data to third parties!

Microsoft products and the data protection problem: no unanimity

According to mirror information all state data protection officers agree that in this case, quick action must be taken before the dependency becomes too great. All but Bavaria agree with this opinion. The investigation of the data protection group is legally questionable. These doubts were communicated by the data protection authority of Bavaria in a circular mail and thus opposed the publication, but it should be mentioned that the headquarters of Microsoft Deutschland GmbH is located in Munich. Even the EU expresses legal doubts about Microsoft products and data protection. In a report by the European Data Protection Commissioner, initial investigations have already been conducted at EU level. It remains to be seen what the results and consequences will be of future investigations. But the issue between Microsoft products and data protection, both in Germany and in the EU, is far from over.

Next Step

Our certified security experts will advise you on the topics covered in this article — free and without obligation.

Free · 30 minutes · No obligation

Share this article

About the author

About the Author

Chris Wojzechowski
Chris Wojzechowski

Geschäftsführender Gesellschafter

E-Mail

Geschäftsführender Gesellschafter der AWARE7 GmbH mit langjähriger Expertise in Informationssicherheit, Penetrationstesting und IT-Risikomanagement. Absolvent des Masterstudiengangs Internet-Sicherheit an der Westfälischen Hochschule (if(is), Prof. Norbert Pohlmann). Bestseller-Autor im Wiley-VCH Verlag und Lehrbeauftragter der ASW-Akademie. Einschätzungen zu Cybersecurity und digitaler Souveränität erschienen u.a. in Welt am Sonntag, WDR, Deutschlandfunk und Handelsblatt.

10 Publikationen
  • Einsatz von elektronischer Verschlüsselung - Hemmnisse für die Wirtschaft (2018)
  • Kompass IT-Verschlüsselung - Orientierungshilfen für KMU (2018)
  • IT Security Day 2025 - Live Hacking: KI in der Cybersicherheit (2025)
  • Live Hacking - Credential Stuffing: Finanzrisiken jenseits Ransomware (2025)
  • Keynote: Live Hacking Show - Ein Blick in die Welt der Cyberkriminalität (2025)
  • Analyse von Angriffsflächen bei Shared-Hosting-Anbietern (2024)
  • Gänsehaut garantiert: Die schaurigsten Funde aus dem Leben eines Pentesters (2022)
  • IT Security Zertifizierungen - CISSP, T.I.S.P. & Co (Live-Webinar) (2023)
  • Sicherheitsforum Online-Banking - Live Hacking (2021)
  • Nipster im Netz und das Ende der Kreidezeit (2017)
IT-Grundschutz-Praktiker (TÜV) IT Risk Manager (DGI) § 8a BSIG Prüfverfahrenskompetenz Ausbilderprüfung (IHK)
Certified ISO 27001ISO 9001AZAV