Microsoft Tracking Order Shakes EU Data Rules
Based on research by NOYB
Microsoft has been ordered to stop tracking school children via cookies in its Education suite, a ruling that sends a clear warning to every Swedish CTO and CISO relying on US-based cloud giants. The Austrian Data Protection Authority found that Microsoft illegally installed tracking cookies on minors’ devices without consent, analyzing behavior and collecting browser data for advertising purposes. This is not just an educational sector issue; it highlights a systemic compliance gap in how major tech providers handle user data across the EU.
The regulator rejected Microsoft’s attempt to shift responsibility to its Irish subsidiary, confirming that Microsoft US makes the relevant decisions. This means the company is directly subject to EU data protection laws, not shielded by a jurisdictional loophole. The core violation is the lack of valid consent for processing sensitive behavioral data. For organizations using Microsoft 365, this confirms that default tracking mechanisms are unlawful under current EU privacy standards. The authority gave Microsoft four weeks to cease this tracking, setting a precedent that affects all users of the platform, including enterprises and public sector bodies.
For Swedish companies, the risk is immediate and concrete. If your organization uses Microsoft 365, you may be processing personal data in violation of GDPR due to the provider’s non-compliant tracking practices. This creates a direct liability for your company as the data controller. You must audit your current data processing agreements and verify that no unlawful tracking occurs. Ignoring this could lead to significant fines and reputational damage, especially if sensitive employee or customer data is involved. The German data protection authorities have already signaled similar concerns, indicating a broader enforcement trend against non-compliant US tech services.
This case reinforces the urgent need to process data locally within the EU or Sweden. Relying on US providers with a history of ignoring EU privacy norms exposes your organization to unpredictable regulatory risks and potential data breaches. By choosing infrastructure that respects local jurisdiction and data sovereignty, you eliminate the risk of being caught in cross-border legal disputes. Secure your data by keeping it within a compliant, local ecosystem where you retain full control and accountability.