Skip to main content

The Ísland.is App

Data Protection Authority Frontpage
Data Protection Authority Frontpage

Data Protection Authority

European Commission brings use of Microsoft 365 into compliance with data protection rules for EU institutions and bodies

30th July 2025

Following enforcement proceedings by the European Data Protection Supervisor (EDPS), the European Commission has demonstrated compliance with Regulation (EU) 2018/1725 in relation to its use of Microsoft 365 as examined by the EDPS.

This follows the EDPS’ Decision of 8 March 2024, which identified a number of infringements and imposed corrective measures on the Commission.

The key improvements and compliance measures applied by the Commission include:

  • Purpose Limitation: The Commission has explicitly specified the types of personal data processed and the purposes of processing in its use of Microsoft 365.

  • Transfers to Third Countries: The Commission has also determined the specific recipients and purposes for which personal data in its use of Microsoft 365 is allowed to be transferred, and ensured compliance with Article 47 of Regulation (EU) 2018/1725. This is complemented by technical and organisational measures implemented by the Commission and Microsoft, thereby reducing the possibility for transfers to third countries not covered by an adequacy decision to occur.

  • Disclosures and Notifications: Additional contractual provisions ensure that only EU or Member State law may require that Microsoft or its sub-processors omit notification to the Commission of disclosure requests for personal data in the Commission’s use of Microsoft 365 processed within the EEA, or that they disclose such data.

Further information is to be found in the EDPS’s press release.

Data Protection Authority

Contact us

postur@personuvernd.is

Telephone: (+354) 510 9600

Opening hours

Weekdays from 10 am to 12 pm and 1 pm to 3 pm

Telephone consultation on Thursdays from 9 am to 12 pm

Address

Laugavegur 166, 4th floor

105 Reykjavík, Ísland

Identification number: 560800-2820