GDPR in practice
Is Microsoft 365 GDPR-compliant?
5 min readby Norbert Demps
The question usually arrives when it is already urgent: a tender wants a statement, a client asks, a supervisory authority has been in touch. The honest answer is less comfortable than a yes or a no, but it is workable.
Briefly: Microsoft 365 can be operated in a compliant way, but "compliant" is not a property of the product. It is the outcome of an overall assessment of your processing — and in that assessment there is one gap no contract closes.
Why there is no simple yes
The GDPR does not certify products. The controller is whoever decides purposes and means — that is you, not Microsoft. Microsoft is a processor. A vendor can give you tools that make compliance possible; it cannot declare compliance on your behalf.
This is not a technicality. It moves the question from "is this product acceptable?" to "can I describe what happens to the data, and does that description hold up?".
What regulators actually objected to
Two findings matter in practice, and both are routinely quoted in abbreviated form.
The Datenschutzkonferenz, the body of German supervisory authorities, concluded by majority in 2022 that Microsoft's data protection addendum at the time did not allow a demonstrably compliant deployment. The criticisms included processing for Microsoft's own purposes and insufficient transparency about which telemetry and diagnostic data flow for which purpose. Microsoft has improved the terms since; the discussion is not closed and the contractual position keeps moving.
The European Data Protection Supervisor found in 2024 that the European Commission had breached data protection rules in its own use of Microsoft 365 — among other things because it had not sufficiently specified what personal data are collected for which purposes. The striking part is not the reprimand but its addressee: if an organisation with that much negotiating power and those resources cannot produce the specification, the task is not smaller for a mid-sized company.
What does not follow: that Microsoft 365 is prohibited. What does follow: the burden of demonstrating compliance sits with you, and it is not trivial.
The gap no contract closes
Even with a clean processing agreement, current standard contractual clauses and documented technical measures, one point remains.
Microsoft is a US company. The CLOUD Act obliges US providers to produce data in their possession, custody or control — regardless of where that data is stored. The EU Data Boundary keeps your data inside the EU. It does not change which legal system the company holding it answers to.
The core of it is simple: a processing agreement governs behaviour. It does not govern capability. As long as the provider holds readable data, the provider can be compelled to produce it, whatever it has promised you contractually. Since Schrems II this is precisely the point at which a transfer impact assessment has to become defensible — with supplementary measures, not with supplementary assurances.
The EU-US Data Privacy Framework adequacy decision of July 2023 restored a legal basis for transfers to certified US organisations. It does not repeal the CLOUD Act and is itself under legal challenge. Anyone making a decision that runs for years should budget for that basis moving again.
What you can do without changing systems
Four things, in order of effort:
1. Document properly. Records of processing activities, a current processing agreement, standard contractual clauses, and a transfer impact assessment that names the CLOUD Act explicitly rather than working around it. This is legwork, and it is the foundation for everything else.
2. Constrain telemetry and diagnostic data. A noticeable share of the regulatory criticism was not about your content but about the data the software generates while running. Whatever can be switched off or reduced to the necessary minimum should be — and the decision belongs in the file.
3. Enable the EU Data Boundary, but classify it correctly. It settles the residency question. It does not settle the jurisdiction question. Claiming both in the same document is the kind of thing an audit notices.
4. Encrypt before the data leaves the building. This is the only measure on the list that changes the technical facts rather than the description of them. An encryption gateway sits between your people and the cloud: documents, mail and individual fields are encrypted before they reach Microsoft, and the keys stay with you. What arrives is ciphertext. It cannot be read, indexed, analysed, or produced in response to an order.
Nothing changes for your people: search, sorting and the familiar interface keep working, because the gateway decrypts on the way back for those you have authorised.
What this means for an audit
The difference between the first three points and the fourth is the difference between a better description and a smaller risk.
With points 1 to 3 you are saying: we have regulated everything that can reasonably be regulated, and we trust the provider to keep to it. With point 4 you are saying: the provider cannot read our content at all. The second sentence is considerably harder to attack in an audit, because it does not depend on behaviour.
That does not settle every question. Metadata — who, when, with whom — still accrues at the provider, and encryption has to be operated and recoverable. But the part of the assessment that is hardest to argue away has been answered.
The answer in one paragraph
Microsoft 365 is neither inherently GDPR-compliant nor inherently unlawful. The deployment becomes compliant through what you document, configure and secure technically. The one gap that documentation and configuration leave open — that a US provider holds readable data and can be compelled to hand it over — is closed only by encryption with keys that stay with you.
This article is a practitioner's assessment, not legal advice. For a binding evaluation of your own case, talk to your data protection officer.
What a gateway would look like on your tenant is described on the cloud encryption page. If you would rather discuss the case: we will also tell you when it is not worth it.