News: 1645614245

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Dutch govt issues data protection report card for Microsoft

(2022/02/23)


A [1]Data Protection Impact Assessment (DPIA) has been published by a Dutch ministry, noting that Microsoft still has work to do if the country's institutions are to use the company's products without all manner of mitigations.

The DPIA – issued by the Netherland's department of Justice and Security – focused on Teams, OneDrive, Sharepoint and Azure Active Directory and was conducted by SLM Rijk, the central negotiator for Microsoft, Google and AWS for Dutch government organisations, and by SURF, the central IT procurement organisation for Dutch universities.

The result? OK, but Microsoft must try harder.

[2]

The Dutch Ministry of Justice and Security has form when it comes to Microsoft. In 2019 it commissioned a report warning government institutions away from Microsoft Office Online and the company's mobile apps over worries regarding [3]data processing .

[4]

[5]

The [6]same outfit has produced this latest report and, although it noted that "Microsoft has implemented many legal, technical and organisational measures to mitigate the risks for data subjects when processing personal data" it warned there was still work to do around what the Windows giant is doing with data and called for a clear deadline on when End-to-End Encryption (E2EE) would be supported in group meetings and chat.

Mitigations suggested by the DPIA include enabling E2EE for Team 1-on-1 calls by default and not exchanging anything sensitive via the platform when E2EE isn't possible.

[7]

Other concerns centre around our old friend, telemetry collection. With Microsoft's [8]EU Data Boundary not due to be complete until the end of 2022 (meaning that some EU data might be transferred to the US) mitigations include simply accepting the risk until Microsoft is done and consider the use of pseudonyms where identities must remain confidential. Employee monitoring is also a worry, and the advice is to not enable Viva Insights and shut off functionality in Teams Analytics and reports.

The report said there was a "high risk related to unencrypted streaming and stored special categories of data," adding:

There is a high data protection risk related to the possible access by US law enforcement and secret services to very sensitive and special categories of personal data. This risk occurs even though the Teams, OneDrive and SharePoint Content Data are already exclusively processed and stored in the EU, because access to these data can be ordered through US legislation such as the US CLOUD Act.

[9]Dutch government: Did we say 10 'high data protection risks' in Google Workspace block adoption? Make that 8

[10]UK.gov admits it has not performed legally required data protection checks for COVID-19 tracing system

[11]Vodafone hounds Czech customers for bills after they were brute-forced with Voda-issued PINs

[12]Campaigners demand judicial review of NHS deal with Peter Thiel's AI firm Palantir

For Microsoft, as well as explaining how each of its service will work with the EU Data Boundary, the report requests measures such as a "functional Data Viewer Tool for OneDrive telemetry data on Windows and MacOS" and the disabling of Teams Analytics and reports by default.

The report concludes that if the mitigations are applied, then "there are no known high risks for the data processing." However, it did warn that should the European Data Protection Board (EDPB) assess the transfer risk posed by the use of the cloud giants as "much higher" even after the EU Data Boundary is complete, "organisations in the Netherlands would in fact no longer be able to use the services of US providers, and the consequences would be much greater than just the use of these Microsoft services." ®

Get our [13]Tech Resources



[1] https://www.rijksoverheid.nl/documenten/publicaties/2022/02/21/public-dpia-teams-onedrive-sharepoint-and-azure-ad

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YhZoPJtOGZ6zu8Id1TEPZAAAABA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2019/07/30/dutch_office_online_mobile/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YhZoPJtOGZ6zu8Id1TEPZAAAABA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YhZoPJtOGZ6zu8Id1TEPZAAAABA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.privacycompany.eu/blogpost-en/new-dpia-for-the-dutch-government-and-universities-on-microsoft-teams-onedrive-and-sharepoint-online

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YhZoPJtOGZ6zu8Id1TEPZAAAABA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://blogs.microsoft.com/eupolicy/2021/05/06/eu-data-boundary/

[9] https://www.theregister.com/2021/03/05/dutch_government_identifies_10_high/

[10] https://www.theregister.com/2020/07/20/uk_test_trace_data_protection/

[11] https://www.theregister.com/2018/09/07/vodafone_czech_republic_fraud/

[12] https://www.theregister.com/2021/02/24/nhs_palantir_judicial_review/

[13] https://whitepapers.theregister.com/



What about mandatory account for windows 11 ?

alain williams

This is a new slurp of personal data. Why is it necessary , how long is the data held, who is it shared with ?

GDPR files not issued

DevOpsTimothyC

Other concerns centre around our old friend, telemetry collection. With Microsoft's EU Data Boundary not due to be complete until the end of 2022 (meaning that some EU data might be transferred to the US) mitigations include simply accepting the risk until Microsoft is done and consider the use of pseudonyms where identities must remain confidential. Employee monitoring is also a worry, and the advice is to not enable Viva Insights and shut off functionality in Teams Analytics and reports.

So why aren't M$ being fined the GDPR 4% of turn over every day that this information is going to any of their US Datacentres.. It shouldn't be too hard for Microsoft to redirect that data to Azure in the EU, or have a GeoIP host so when anyone is in the EU then their data goes to EU DC's. I get the point of GeoIP's aren't perfect and when a European person goes outside of Europe their data would go elsewhere, but I'm trying to propose a realistic carrot and stick.

Granular access

b0llchit

The real question you should be asking is: why is there any direct or indirect connection to servers and organizations outside the EU?

We are talking about governmental and public institutions. Why can't we, with 400M+ people, create a system that is independent ? There should be no need for data-slurping third parties for the IT at user- and infrastructure-level. This should all be done within the boundaries of the EU.

Note, this is not about economic protectionism. It is purely a data-security issue. First rule of security: (s)he who needs no access shall not have direct or indirect access.

Re: Granular access

Pascal Monett

I think you're asking the wrong question. The actual question is : why use Microsoft products when you do not want any possibility of data exiting the EU ?

Borkzilla is a US company. It is understandable that its products are tied with its US servers.

If it is so important to keep data inside your own borders, use LibreOffice and make yourself a local cloud-based fileshare with encryption.

It's not as sexy, for sure, and you're probably going to need to replace Outlook with something else, but it responds to the demands.

Obviously, manglement is not going to have its pretty charts and PowerPoint presentations any more. Boo hoo.

Re: Granular access

b0llchit

Microsoft is not the only one here. We also have google, amazon, oracle and apple; just to name a few. Many "smaller" names have the same problem as the big names.

However, you are right, why are we using these products, when we know they are problematic. We can replace them if we put our EU mind to it. And that brings us back to the original question formulated differently: why are we giving (in-)direct access to those who should not have any access.

It sounds good, but in practice a joke

naive

They just write these things as a "get out of jail" card, nothing will be enforced.

In case a journalist asks for clarity, they are fed with censored documents and confronted with civil servant who are above the law, and can never be taken to task for dumping private data of citizens on random Azure servers all over the world.

Based on my current experiences at work, the theme is that nobody cares, because "everybody is migrating to Azure" right ?.

Hospitals, day care centers community administrations, they all run to hand the millions of tax payer money to MS.

Re: It sounds good, but in practice a joke

Doctor Syntax

Policy decisions are made by people who don't realise what alternatives exist nor the reasons for preferring them.

Doctor Syntax

When the EU Data Boundary is in place how will UK businesses be affected? The likes of Ress-Mogg & IDS seem intent on using the control we've taken back to make sure the answer is "very badly".

If you remove stricture from a large Perl program currently, you're just
installing delayed bugs, whereas with this feature, you're installing an
instant bug that's easily fixed. Whoopee.
-- Larry Wall in <199710050130.SAA04762@wall.org>