All articles
21. 11. 2018
2 min read

Microsoft faces fines for violating GDPR

We’ve pointed out before that even the greats face similar problems when it comes to GDPR. This time, Microsoft got the Black Peter for flaws in its Office suite.

As part of complying with GDPR regulations, fcompanies must ensure that users are made abundantly clear about what data is being stored about them, as well as having the ability to turn that storage off. It’s imperative that all sensitive data is kept under control, but that can also become a double-edged sword. In fact, Microsoft is likely to pay a hefty price for this collection of information.

Dutch data protection authorities have targeted Microsoft and its office suite Microsoft Office ProPlus (Office 2016 and Office 365). So where is the problem? Imagine a situation where a user repeatedly presses the “backspace” key to delete an entire word. In this case, Microsoft sends the entire sentence for analysis to improve the repair help system. Dozens of engineers then work on such analysis. None of this would presumably be such a problem, except that Microsoft does not adequately inform users that there is statistical data being sent, what exactly is being analyzed, and for what purpose. It also lacks the ability to turn off this sending.

Another problematic point is that this data was stored on servers in the US. However, Microsoft has tried to rectify this transgression and some of the data is already being processed within the European Union.

Since Microsoft is working with the Dutch authorities to remedy this, it is possible that the overall impact of the problem can be mitigated. An assessment of compliance with the corrective measures is expected to take place in spring 2019, which will also determine whether a fine will be imposed and the amount of any fine.

If you don’t want to end up like this giant, get expert advice. You’ll save yourself a lot of paperwork and explaining and the money you won’t have to pay in fines can be invested in your business.

Have a project?

Get in touch and we'll discuss how we can help.
Contact us

More articles

1 Aug 2026

Cyber Resilience Act: New Rules for Secure Software and Digital Products

The European Union is introducing another important regulation in the field of cybersecurity. It is called the Cyber Resilience Act, or CRA for short, and applies to all products with a digital component. This means not only smart devices, but also software, applications, and systems that connect to a network or communicate with another service…
Read the article
15 Jul 2026

Withdrawal button – Wontilles responds in advance to new legislative requirements

The legislative environment in the field of e-commerce is undergoing constant changes, which place high demands on online shop operators.
Read the article
1 Jun 2026

Railsformers at the Faculty of Arts at the OU: Ruby on Rails in practice and now also in IT business

At the Faculty of Science of the University of Ostrava, we have long been giving students practical experience with Ruby on Rails development and showing them what it looks like to work on real web applications. From the original pilot course, we have developed a stable course Ruby on Rails I and II, which we…
Read the article