The Austrian Data Protection Authority found Microsoft 365 Education used tracking cookies without consent and denied a data‑access request, violating GDPR. The DSB ordered Microsoft to delete the data, provide full access, and disclose its business‑purpose processing and any transfers to third parties.
Why it matters: The decision highlights Microsoft’s non‑compliance with GDPR in European schools and forces remedial actions.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.