Microsoft is once again in the crosshairs of European (EU) authorities , following two complaints by the Austrian advocacy group Noyb accusing the company of monitoring and collecting children's data through its 365 Education software in schools.

In the past, the Noyb group has filed other similar complaints against OpenAI, Meta, Spotify, and other tech giants.
Noyb claims that Microsoft 365 Education “installed cookies that, according to Microsoft’s own documentation, behavior user data browser,” without the school being aware. The defense team also claims that Microsoft is not clear about what it does with student data and could potentially be secretly tracking children.
See also: EU: Research in Meta on negative effects of Instagram, Facebook on children
“Our analysis of the data flows is very worrying. Microsoft 365 Education appears to be tracking users regardless of their age,” said Felix Mikolasch, a data protection lawyer at Noyb. “This practice is likely to affect hundreds of thousands of pupils and students in the EU and EEA. Authorities should finally strengthen and effectively enforce the rights of minors.”
Another charge has to do with violating the General Data Protection Regulation (GDPR), since, as the complaint says, Microsoft does not provide access or information to schools regarding its privacy and data collection policies for children.
“Microsoft keeps all the basic information about data processing in its software, but puts the responsibility on schools to exercise rights,” said Maartje de Graaf, another lawyer at Noyb. “Schools have no way to comply with the transparency and information obligations.”
See also: United Kingdom: Smartphone ban for children under 16?

The European Union's legislation on the protection of children's data is strict and specific, aiming to protect the personal data of minors. The General Data Protection Regulation (GDPR) includes specific provisions for the protection of children's data, recognizing that children need particular protection, as they may be less aware of the risks and consequences of the processing of their data.
The GDPR requires data controllers to provide information in a way that is understandable to children. This information must be clear and simple so that children can understand what kind of data is being collected and for what purpose. This includes explaining their rights in relation to their data, such as the right to access, rectify and delete their data.
See also: United Kingdom: Social media companies must strengthen child safety
EU law also requires companies to take appropriate technical and organizational measures to protect children's data from unauthorized access, loss or destruction.
Violating the GDPR could result in a fine of €20 million or 4% of a company's annual global turnover (whichever is the greater).
Source: www.engadget.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
