{"id":24228,"date":"2022-04-26T00:01:00","date_gmt":"2022-04-25T22:01:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=24228"},"modified":"2022-04-25T18:35:30","modified_gmt":"2022-04-25T16:35:30","slug":"datenschutz-microsoft-365-muss-ab-sommer-2022-in-baden-wrttembergs-schulen-ersetzt-worden-sein","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2022\/04\/26\/datenschutz-microsoft-365-muss-ab-sommer-2022-in-baden-wrttembergs-schulen-ersetzt-worden-sein\/","title":{"rendered":"Data protection: Microsoft 365 banned in Germany's Baden-W&uuml;rttemberg's schools by summer 2022"},"content":{"rendered":"<p><img decoding=\"async\" title=\"Stop - Pixabay\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" alt=\"Stop - Pixabay\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/06\/Stop01.jpg\" align=\"left\">[<a href=\"https:\/\/www.borncity.com\/blog\/2022\/04\/25\/datenschutz-microsoft-365-muss-ab-sommer-2022-in-baden-wrttembergs-schulen-ersetzt-worden-sein\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]The use of Microsoft 365 at schools in German state of Baden-W\u00fcrttemberg has been banned after the summer 2022. Schools must offer suitable alternatives for students and teachers. This is pointed out by the State Commissioner for Data Protection and Freedom of Information of Baden-W\u00fcrttemberg, Dr. Stefan Brink, in a recent press release. This is a failure with an announcement, because the data protection officer had already noted in 2021 that he had serious concerns about the GDPR conform use of Microsoft 365 (including Office 365) in Baden-W\u00fcrttemberg's schools after an audit lasting several months.<\/p>\n<p><!--more--><\/p>\n<h2>Ban after the end of this school year <\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/vg02.met.vgwort.de\/na\/efbe76cecb2b43e293cd1227a42562a6\" width=\"1\" height=\"1\">In a <a href=\"https:\/\/www.baden-wuerttemberg.datenschutz.de\/nutzung-von-ms-365-an-schulen\/\" target=\"_blank\" rel=\"noopener\">statement<\/a> dated April 25, 2022, the State Commissioner for Data Protection and Freedom of Information of Baden-W\u00fcrttemberg, Dr. Stefan Brink, comments on the use of Microsoft 365 (MS 365) in schools in this state. I became aware of the issue via the following tweet.<\/p>\n<p><a href=\"https:\/\/twitter.com\/golem\/status\/1518520550997565440\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" title=\"Microsoft 365 (MS 365) an Schulen in Baden-W&uuml;rttember\" alt=\"Microsoft 365 (MS 365) an Schulen in Baden-W&uuml;rttember\" src=\"https:\/\/i.imgur.com\/h3ckUpP.png\"><\/a><\/p>\n<p>The message from the State Commissioner for Data Protection and Freedom of Information (LfDI) Baden-W\u00fcrttemberg is crystal clear:<\/p>\n<blockquote>\n<p>As of the coming school year (2nd half of 2022), the use of MS 365 at schools must be terminated or its data protection-compliant operation must be clearly demonstrated by the responsible schools<\/p>\n<\/blockquote>\n<p>After the summer vacations in 2022, schools must, according to the LfDI, offer alternatives to the MS 365 cloud service for school operations. Dr. Stefan Brink will soon approach schools known to him that use the cloud service Microsoft 365 (MS 365) or MS Teams from Microsoft. The LfDI will inform the schools of its legal assessment on the use of this online service and ask for a binding timetable for switching to alternatives. To bridge the gap until the summer vacations in 2022, the state commissioner expects that teachers and students will be offered alternatives.<\/p>\n<h2>Microsoft 365 not compliant with GDPR<\/h2>\n<p>The State Commissioner for Data Protection and Freedom of Information (LfDI) in Baden-W\u00fcrttemberg monitored the use of MS 365 over a long period of time in an intensive and extensive process. Fueatures of MS 365 that were particularly questionable from a general data protection perspective (GDPR) had already been switched off or deactivated as far as possible. This included, for example, the collection of telemetry and diagnostic data. Furthermore, additional security functions were implemented and accounts were only assigned to teachers, but not to students.<\/p>\n<p>In April 2021, the LfDI informed the Ministry of Education about the data protection assessment of this pilot project and recommended against using the tested version of MS 365 in schools due to high data protection risks and to promote alternative solutions. Despite intensive testing and cooperation with the parties involved, the pilot project did not succeed in finding a solution that complied with data protection law. <\/p>\n<p>In a nutshell: Microsoft 365 cannot be used in schools in a privacy-compliant manner (GDPR compiant). The statement of the LfDI and the results of the audit have been publicly available for some time (e.g. via Documents <a href=\"https:\/\/www.baden-wuerttemberg.datenschutz.de\/empfehlung-lfdi-online\/\" target=\"_blank\" rel=\"noopener\">Dokumente Online: Empfehlung zum Pilotprojekt zur Nutzung MS 365 an Schulen<\/a>, Nov. 2021, and summary under<a href=\"https:\/\/www.baden-wuerttemberg.datenschutz.de\/ms-365-schulen-hinweise-weiteres-vorgehen\" target=\"_blank\" rel=\"noopener\">Hinweise des LfDI zur Nutzung von Microsoft 365 durch Schulen<\/a>). The Ministry of Education and Cultural Affairs subsequently announced that it would rely on a data protection-compliant digital education platform in the future.&nbsp; <\/p>\n<h2>Alternative solutions<\/h2>\n<p>In his statement, the State Commissioner points out that alternative digital tools are now also available. These have already been used many times over a longer period of time and can still be used successfully.  <\/p>\n<ul>\n<li>For example, Moodle or itslearning, which are offered to schools by the Ministry at no additional cost, can be used as learning management systems.\n<li>The integration of the web conferencing system BigBlueButton is integrated in each case, so that video conferencing can also be carried out.  <\/li>\n<\/ul>\n<p>Schools that believe that their use and configuration of MS 365 meets the legal requirements and that wish to continue using the cloud service must now justify to the data protection officer how they intend to ensure data protection-compliant operation and clearly demonstrate this in accordance with their accountability obligations under Article 5(2) of the General Data Protection Regulation.  <\/p>\n<p>The entire process naturally throws a spotlight on Microsoft and its Office365 as well as Microsoft 365 solution. The company has had time and opportunity since 2020 to make the whole thing watertight in terms of data protection in accordance with the GDPR, but has probably not done so. Politicians and Microsoft acted according to the principle of \"hope, we'll get through\". At this point I won't address other questions like: Public money = Public code (which isn't useable for license feeds) or vendor lockin with Microsoft 365. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]The use of Microsoft 365 at schools in German state of Baden-W\u00fcrttemberg has been banned after the summer 2022. Schools must offer suitable alternatives for students and teachers. This is pointed out by the State Commissioner for Data Protection and &hellip; <a href=\"https:\/\/borncity.com\/win\/2022\/04\/26\/datenschutz-microsoft-365-muss-ab-sommer-2022-in-baden-wrttembergs-schulen-ersetzt-worden-sein\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,580,2],"tags":[2523,1805,261],"class_list":["post-24228","post","type-post","status-publish","format-standard","hentry","category-office","category-security","category-windows","tag-data-protection","tag-microsoft-365","tag-privacy"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/24228","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=24228"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/24228\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=24228"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=24228"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=24228"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}