Skip to content
Call, +49 511 47 55 58 10
lexICT GmbH, Home

System in use

Running Microsoft 365 in line with data protection law

Whether Microsoft 365 may be used has long been settled in most organisations. What decides lawfulness after that is the configuration, in particular how far logs can be analysed, how long content is retained, and who inside the organisation may access it.

Four years on the vendor’s defaults

The environment has been running for four years. Retention policies sit at the vendor’s defaults, the sign-in log reaches back months, and access to the reports lies with every administrator. There is a works agreement, dating from the year of the roll-out.

Lawfulness is decided by the configuration

Which settings decide on lawfulness is the question that follows the question of principle, and in practice it is rarely asked. The same environment can be set up so that it complies with the principles in Art. 5(1) GDPR and so that it does not.

Four settings the assessment starts from

Extent of logging

Which events are recorded and how long the record stays retrievable. Both are configurable, and both determine which analyses are possible at all.

Retention and deletion

Retention policies for mailboxes, file repositories and collaboration spaces. Without your own settings the vendor’s defaults apply, and they do not follow the periods in your own retention schedule.

Who inside the organisation may access

The separation of operation and analysis. Running a system requires no access to its contents, and who may initiate an analysis is a question of organisation and not of a role in the directory service.

Search across mailboxes and repositories

The functions for organisation-wide search and for preserving content for legal purposes. They are necessary for their purpose and at the same time the most powerful instrument of behavioural monitoring the environment offers.

Art. 25(2) GDPR requires data protection by default and names for that purpose the amount of data, the extent of processing, the period of storage and accessibility. Those are the same four settings.

Logs are employee data once they can be analysed

When logging turns into conduct and performance monitoring does not depend on intention. For section 87(1) no. 6 BetrVG the Federal Labour Court relies on objective suitability, and an environment recording sign-ins, access and activity per person is suitable.

Two purposes, the same data

Operations and securityMerkmalConduct and performance monitoring
From incident to personAn alert or a fault is the trigger, and the analysis follows it.Direction of analysisFrom person to findingA person is analysed without any trigger having occurred.
Section 26(1) BDSG or Art. 6(1)(f) GDPRNecessity for operations, documented balancing.Legal basisA narrow exceptionSection 26(1) sentence 2 BDSG requires documented factual indications for detecting criminal offences.
Measured by purposeFault analysis in days, security incidents longer.RetentionNo purpose of its ownKeeping data just in case justifies no period.
Co-determination anywayObjective suitability suffices, and intention is beside the point.InvolvementA framework is requiredWithout an agreement, both the exercise of co-determination and the rules for individual cases are missing.

The first row is the practical dividing line. An analysis that begins with an incident stays within operations. One that begins with a person is behavioural monitoring and needs a basis of its own.

The place of storage does not answer the transfer question

Where a third-country element remains despite storage in the Union is decided by Art. 44 GDPR. The provision covers every transfer, and access from a third country is a transfer even where no file is copied.

Four questions about operations, regardless of storage location

Liste zu erledigender Punkte

  • From which countries does support access the environment, and in which situations
  • Which sub-processors appear on the vendor’s list, and where are they established
  • Which fault and usage data leaves the environment for analysis by the vendor
  • For which of these transfers does an adequacy decision apply, and for which a safeguard under Art. 46 GDPR

Where a safeguard under Art. 46 GDPR is needed, the assessment under clause 14 of the standard contractual clauses applies on top. The list of sub-processors is the basis for it, not the seat of the contracting party.

How we support you in operating Microsoft 365

The work does not start with the contract but with a survey of the current state. Which logs run, how long they stay, who may analyse them and which retention policies are set. From that follows what is missing in the record of processing activities and which settings have to change.

The employment law side lies outside data protection law. Negotiating an agreement, proceedings before the conciliation board and the admissibility of analyses in dismissal proceedings run through the affiliated law firm.

Frequently asked questions

Is using Microsoft 365 lawful?

The question is too imprecise to answer. What is lawful or unlawful is a processing activity, and the same environment can be set up so that it complies with the principles in Art. 5 GDPR and so that it does not. The assessment therefore starts at the settings.

Is a works agreement needed?

Co-determination under section 87(1) no. 6 BetrVG applies, because the environment is objectively suitable for capturing conduct and performance. An agreement is the usual way of exercising it, and it can also serve as a legal basis where it meets the requirements of Art. 88(2) GDPR.

Does storage in the Union remove the third-country element?

Only for storage. Art. 44 GDPR covers every transfer, and access from a third country is a transfer even without a copy. What has to be examined is therefore support, remote maintenance, fault analysis and the list of sub-processors.

How long may logs be kept?

As long as necessary for the purpose specified, Art. 5(1)(e) GDPR. The purpose has to be settled first. A log for fault analysis needs days, one for investigating security incidents longer, and neither purpose justifies analysis by person.

Get in touch!

Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!

Contact us

Alternatively you can request a call back.