Austria’s Data Protection Authority rules that Microsoft 365 Education cookies tracked students without consent.

In a significant decision that is sure to resonate across Europe and beyond, Austria’s Data Protection Authority (DSB) has ruled that Microsoft 365 Education cookies unlawfully tracked students without valid consent, thus exposing EU GDPR compliance issues in school technology deployments.

EU privacy advocacy group, None of Your Business (NOYB), had filed a formal complaint against Microsoft in 2024, arguing that the education platform installed tracking cookies on students’ devices without their knowledge or consent.

The DSB found that the cookies were capable of collecting information on user behaviour, browser data, analytics and advertising – all activities that contravene the EU GDPR for handling the personal data of young people at school.

Four weeks to comply

The ruling has declared a four-week window for Microsoft to remove the tracking cookies. The DSB pointed out that the cookies are not essential for the education platform to work and therefore there is no legal reason for them to be deployed. In fact, neither the Austrian Ministry of Education nor the school at the centre of the original complaint knew that Microsoft 365 Education installed tracking cookies, indicating a lack of transparency on the issue.

Shifting the blame

During the investigation, Microsoft attempted to shift the blame onto its subsidiary in Ireland, which it says is responsible for its rollouts in European schools. However, the Austrian regulator rejected this, stating that it was clear that decisions about Microsoft’s product design are made in the USA.

As schools increasingly rely on cloud-based tools from large US-based software companies for learning and collaboration, this decision could open the door for similar cases from across the EU.

Read more details from TelecomLead

And more here from NOYB

Author