News: 1595273821

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft accused of sharing data of Office 365 business subscribers with Facebook and its app devs

(2020/07/20)


Updated Microsoft is being sued for allegedly sharing its Office 365 customers' business data with Facebook app developers, partners, and subcontractors in violation of its data privacy promises.

The lawsuit was filed in US District Court in San Francisco, on behalf of plaintiffs Frank Russo, Koonan Litigation Consulting, and Sumner Davenport & Associates, all Office 365 customers.

The [1]complaint [PDF] says that – while Microsoft has repeatedly promised its business customers that it would only use their data to provide purchased services, that it would share their data with subcontractors only on a need-to-know basis, and that it will never share their data with third-parties – those claims are false.

Privacy Shield binned after EU court rules transatlantic data protection arrangements 'inadequate' [2]READ MORE

"In fact, contrary to its representations, Microsoft has regularly shared – and continues to share – its business customers' data with Facebook and other third parties," the complaint says. "The data is shared even when neither the customers nor their contacts are Facebook users."

The complaint contends Microsoft has shared data with hundreds of subcontractors when not necessary for purchased services, and that some of these downstream firms have suffered data breaches. It also claims Microsoft routinely uses business customers' emails, documents, calendars, location data, and media files to develop new products, to gather business intelligence, and otherwise derive commercial benefit.

The trio says that this means Microsoft has violated the US Wiretap Act, the US Stored Communications Act, and consumer protection laws in the State of Washington.

Still, as long as the devs were trustworthy...

In particular, the plaintiffs claim that Microsoft automatically shares customers' business contacts with Facebook, without consent, whether or not the customers or their contacts are Facebook users.

"Even if a customer discovers and disables this Facebook-sharing 'feature' after activating Office 365 or Exchange Online services, the damage has already been done," the complaint says, pointing to the [3]Cambridge Analytica scandal as an example of the potential harm.

"At that point, the business customer’s contacts have been shared with Facebook. As Microsoft explains in an obscure technical instruction, '[o]nce contacts are transferred to Facebook, they cannot be deleted from Facebook's systems except by Facebook.'"

As a result, business customers' data can be accessed not just by Facebook, "but also by whomever Facebook shares the data with, and whomever those entities decide to share the data with, ad infinitum ."

Chain of data command

Then there's the issue of third-party developers. The complaint says that "even if a business customer did not download a third-party application (and thus did not consent to sharing its data with the third-party), Microsoft nonetheless transmits the non-consenting business customer’s data to third-party developers if another Office 365 user consented to the application."

The lawsuit insists Microsoft's claims that it abides by System and Organization Controls (SOC 1 and SOC 2) standards are false, pointing to the company's own documentation stating that Microsoft Graph does not comply with SOC 1 or SOC 2.

"Because Microsoft’s Graph automatically gathers all business customers’ Office 365 and Exchange Online data, and Graph does not comply with SOC standards, Microsoft’s handling and use of business customers’ Office 365 and Exchange Online data also does not comply with SOC standards," the complaint says.

The lawsuit is seeking class certification on behalf of Microsoft's non-governmental business customers and damages to be determined.

Microsoft did not immediately respond to a request for comment at time of publication. ®

Updated to add

“We’re aware of the suit and will review it carefully,” a Microsoft spokesperson told The Register after this story was filed.

“However, while the allegations themselves are not very specific, as we understand them we don’t believe they have merit. We have an established history of both robust privacy protections and transparency, and we’re confident that our use of customer data is consistent with the instructions of our customers and our contractual commitments.”

Get our [4]Tech Resources



[1] https://www.courtlistener.com/recap/gov.uscourts.cand.362635/gov.uscourts.cand.362635.1.0.pdf

[2] https://www.theregister.com/2020/07/16/privacy_shield_struck_down/

[3] https://www.theregister.com/2018/03/22/ico_cambridge_analytica_raid_delayed/

[4] https://whitepapers.theregister.com/

Anyone surprised?

oiseau

... means Microsoft has violated the US Wiretap Act, the US Stored Communications Act, and consumer protection laws in the State of Washington.

Whaaat?

Nooooo ...

Impossible.

Really now ...

Is anyone at all surprised?

I mean, if you're using Office 365 or Exchange Online, it's expected to happen, with or without your consent. ie: basic common sense should have told you that it would.

O.

Please keep this story updated and on the front page, if accurate.

elDog

This is huge. Not unexpected from the corporate world run amok.

ratfox

Wait. The claim is that by default , unless you turn off an option somewhere in some disused-leopard-lavatory settings screen, Microsoft sends the email address of its paying customers to Facebook? If it's true, wow. Just wow.

Just waiting for the email from corp IT...

Anonymous Coward

We've got the one saying uninstall Zoom from laptops and work phones, we've got the one saying uninstall TikTok from work phones and your own phones if you BYOD, but I ain't holding my breath for the one about not using Office 365 since they've gone all-in and drunk the MS kool aid.

Still, at least working at a place which has locked themselves into Office 365 means I can have some downtime every couple of weeks.

Check the small print

Anonymous Coward

Microsoft is not sharing your data, it's the internet that's sharing your data...

For example, you can state that you are not sharing your customers data with anyone, but you sell access to the data logs to anyone. You're not "sharing" the data, they are reading your logs and paying you for it. Legally you can document this on page 94 of the user privacy agreement that everyone clicks the box "yes I read the document" to use the app.

LibreOffice

beep54

Yet another perfectly satisfied customer.

Cloud based idiocy

Anonymous Coward

It's like telling a secret. As soon as you put your valuable data in the cloud, on somebody else's servers, you have lost control of that data forever. It's not your data any more. You have no way of knowing, let alone controlling who has access to it or what they do with it. You can't take it back, you can't delete it. You can't even access it yourself unless you keep up the payments.

If your data is supposed to be confidential, then keep it confidential. Do not put it in the cloud. Keep it on your own servers. Employ competent and trustworthy people to manage it. It baffles me how many people don't understand this.

I would like to electrocute everyone who uses the word 'fair' in connection
with income tax policies.
-- William F. Buckley