System in use
Running Microsoft 365 in line with data protection law
Whether Microsoft 365 may be used has long been settled in most organisations. What decides lawfulness after that is the configuration, in particular how far logs can be analysed, how long content is retained, and who inside the organisation may access it.
Four years on the vendor’s defaults
The environment has been running for four years. Retention policies sit at the vendor’s defaults, the sign-in log reaches back months, and access to the reports lies with every administrator. There is a works agreement, dating from the year of the roll-out.
Lawfulness is decided by the configuration
Which settings decide on lawfulness is the question that follows the question of principle, and in practice it is rarely asked. The same environment can be set up so that it complies with the principles in Art. 5(1) GDPR and so that it does not.
Four settings the assessment starts from
Extent of logging
Which events are recorded and how long the record stays retrievable. Both are configurable, and both determine which analyses are possible at all.
Retention and deletion
Retention policies for mailboxes, file repositories and collaboration spaces. Without your own settings the vendor’s defaults apply, and they do not follow the periods in your own retention schedule.
Who inside the organisation may access
The separation of operation and analysis. Running a system requires no access to its contents, and who may initiate an analysis is a question of organisation and not of a role in the directory service.
Search across mailboxes and repositories
The functions for organisation-wide search and for preserving content for legal purposes. They are necessary for their purpose and at the same time the most powerful instrument of behavioural monitoring the environment offers.
Art. 25(2) GDPR requires data protection by default and names for that purpose the amount of data, the extent of processing, the period of storage and accessibility. Those are the same four settings.
Logs are employee data once they can be analysed
When logging turns into conduct and performance monitoring does not depend on intention. For section 87(1) no. 6 BetrVG the Federal Labour Court relies on objective suitability, and an environment recording sign-ins, access and activity per person is suitable.
Two purposes, the same data
| Operations and security | Merkmal | Conduct and performance monitoring |
|---|---|---|
| From incident to personAn alert or a fault is the trigger, and the analysis follows it. | Direction of analysis | From person to findingA person is analysed without any trigger having occurred. |
| Section 26(1) BDSG or Art. 6(1)(f) GDPRNecessity for operations, documented balancing. | Legal basis | A narrow exceptionSection 26(1) sentence 2 BDSG requires documented factual indications for detecting criminal offences. |
| Measured by purposeFault analysis in days, security incidents longer. | Retention | No purpose of its ownKeeping data just in case justifies no period. |
| Co-determination anywayObjective suitability suffices, and intention is beside the point. | Involvement | A framework is requiredWithout an agreement, both the exercise of co-determination and the rules for individual cases are missing. |
The first row is the practical dividing line. An analysis that begins with an incident stays within operations. One that begins with a person is behavioural monitoring and needs a basis of its own.
The place of storage does not answer the transfer question
Where a third-country element remains despite storage in the Union is decided by Art. 44 GDPR. The provision covers every transfer, and access from a third country is a transfer even where no file is copied.
Four questions about operations, regardless of storage location
Liste zu erledigender Punkte
- From which countries does support access the environment, and in which situations
- Which sub-processors appear on the vendor’s list, and where are they established
- Which fault and usage data leaves the environment for analysis by the vendor
- For which of these transfers does an adequacy decision apply, and for which a safeguard under Art. 46 GDPR
Where a safeguard under Art. 46 GDPR is needed, the assessment under clause 14 of the standard contractual clauses applies on top. The list of sub-processors is the basis for it, not the seat of the contracting party.
How we support you in operating Microsoft 365
The work does not start with the contract but with a survey of the current state. Which logs run, how long they stay, who may analyse them and which retention policies are set. From that follows what is missing in the record of processing activities and which settings have to change.
The employment law side lies outside data protection law. Negotiating an agreement, proceedings before the conciliation board and the admissibility of analyses in dismissal proceedings run through the affiliated law firm.
Frequently asked questions
Is using Microsoft 365 lawful?
The question is too imprecise to answer. What is lawful or unlawful is a processing activity, and the same environment can be set up so that it complies with the principles in Art. 5 GDPR and so that it does not. The assessment therefore starts at the settings.
Is a works agreement needed?
Co-determination under section 87(1) no. 6 BetrVG applies, because the environment is objectively suitable for capturing conduct and performance. An agreement is the usual way of exercising it, and it can also serve as a legal basis where it meets the requirements of Art. 88(2) GDPR.
Does storage in the Union remove the third-country element?
Only for storage. Art. 44 GDPR covers every transfer, and access from a third country is a transfer even without a copy. What has to be examined is therefore support, remote maintenance, fault analysis and the list of sub-processors.
How long may logs be kept?
As long as necessary for the purpose specified, Art. 5(1)(e) GDPR. The purpose has to be settled first. A log for fault analysis needs days, one for investigating security incidents longer, and neither purpose justifies analysis by person.
More questions from this area
HR management systems
In data protection terms an HR management system is only as good as its access model.
Video surveillance
The yardstick for private video surveillance is Art. 6(1)(f) GDPR and not section 4 BDSG.
Cookies and tracking
Sec. 25(1) TDDDG covers access to terminal equipment and applies regardless of whether personal data arise in the course of it.
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.