• Latest
  • Trending
Office 365 in schools illegal under data protection law

Office 365 in schools illegal under data protection law

7. November 2022
ChatGPT and lawyers: recordings of the Weblaw launch event

Private AI use in the company

24. October 2025
Lego brick still protected as a design patent

App purchases, in-app purchases and sales tax

21. October 2025
dsgvo 1

What belongs in a DPA? Data processing agreement in accordance with Art. 28 GDPR

17. October 2025
Smart contracts in the insurance industry: contract design and regulatory compliance for InsurTech start-ups

Contract for work vs. service contract in software, AI and games projects

15. October 2025

Influencer contract: performance profile, rights/buyouts, labeling and AI content

13. October 2025
AI content for subscription platforms

AI content for subscription platforms

29. September 2025
E-sports finally charitable? What the government draft of the Tax Amendment Act 2025 really brings

E-sports finally charitable? What the government draft of the Tax Amendment Act 2025 really brings

23. September 2025
Clubs, photos and minors: managing consent properly

Clubs, photos and minors: managing consent properly

22. September 2025
AI faces, voice clones and deepfakes in advertising: rules of the game under the EU AI Act and German law

AI faces, voice clones and deepfakes in advertising: rules of the game under the EU AI Act and German law

17. September 2025
Modding in EULAs and contracts – what applies legally in Germany?

Modding in EULAs and contracts – what applies legally in Germany?

8. September 2025
Arbitration agreements in EULAs and developer contracts

Arbitration agreements in EULAs and developer contracts

7. September 2025
Chain of title in game development: building a clean chain of rights

Chain of title in game development: building a clean chain of rights

6. September 2025
Fail-fast clauses in media productions – what are they actually?

Fail-fast clauses in media productions – what are they actually?

5. September 2025
Founder’s agreement vs. shareholder agreement: setting the course for startups at an early stage

Founder’s agreement vs. shareholder agreement: setting the course for startups at an early stage

12. August 2025
Cheat software without code intervention: What the BGH really decided in the Sony ./. Datel case (I ZR 157/21)

Cheat software without code intervention: What the BGH really decided in the Sony ./. Datel case (I ZR 157/21)

11. August 2025
Digital integrity as a (new) fundamental right: status in Germany and the EU in 2025

Digital integrity as a (new) fundamental right: status in Germany and the EU in 2025

10. August 2025
European Economic Interest Grouping (EEIG)

EU Digital Decade 2030: Data law, Data Act & eIDAS 2 – what needs to be implemented in 2025

8. August 2025
Upload filters between copyright and personal rights

Upload filters between copyright and personal rights

7. August 2025
On-demand transmission right in the digital space: streaming, Section 19a UrhG and licensing

On-demand transmission right in the digital space: streaming, Section 19a UrhG and licensing

6. August 2025
Q&A: Legal issues for game developers

5-day guide: Founding a game development studio

5. August 2025
  • Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
Kurzberatung
Rechtsanwalt Marian Härtel - ITMediaLaw

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Rechtsanwalt Marian Härtel - ITMediaLaw

Office 365 in schools illegal under data protection law

7. November 2022
in Data protection Law
Reading Time: 3 mins read
0 0
A A
0
office 1356793 1280

1. preliminary remark

For years, there has been a debate in Germany about whether schools can use Microsoft’s Office 365 software in a privacy-compliant manner. In August 2017, the Hessian Commissioner for Data Protection and Freedom of Information (HBDI) issued a statement on Microsoft’s Deutschland-Cloud as the only German supervisory authority for data protection following an extensive review. In its statement at the time, the HBDI determined that Office 365 can be used by schools in the Germany Cloud in a data protection-compliant manner, provided that the tools provided by Microsoft (e.g., role and authorization concept, logging, etc.) are applied appropriately by the schools. In August 2018, Microsoft informed the public that contracts would no longer be offered for the Germany Cloud and that sales of this product would be discontinued. Since then, the HBDI has received inquiries from a large number of teachers and school administrators, as well as school boards, regarding the use of Office 365 in the European cloud. In addition, Office 365 has been massively promoted in the school landscape by individual school boards in recent months, irrespective of the unresolved data protection issues.

2. why the cloud application of Office 365 is currently illegal

The use of cloud applications by schools is generally not a problem under data protection law. Many schools in Hesse are already using cloud solutions. Whether it’s the learning platform or the electronic class register, for example, schools can use digital applications in a way that complies with data protection requirements, provided that the security of data processing and the participation of students are guaranteed. The legal situation is different for Office 365 as a cloud solution. For years, regulators have been in discussions with Microsoft. The crucial aspect here is whether the school, as a public institution, can store personal data (of children) in a (European) cloud that is exposed to possible access by US authorities, for example. Public institutions in Germany have a special responsibility with regard to the permissibility and traceability of the processing of personal data. The digital sovereignty of state data processing must also be guaranteed. In addition, there is another problem that was brought to the public’s attention by the Federal Office for Information Security in the fall of 2018. With the use of the Windows 10 operating system, a wealth of telemetry data is transmitted to Microsoft, the contents of which have not been conclusively clarified despite repeated requests to Microsoft. Such data is also transmitted when using Office 365.

3. can school use consent to solve the problem?

Up to now, schools have been dependent on the consent of the data subjects, insofar as digital, personal data processing takes place in or through schools. Whether the consent of the data subjects justifies digital, personal data processing in certain situations can be left open. In any case, in connection with the use of Office 365 in the cloud, consent does not offer a solution because the security and traceability of the data processing procedures are not guaranteed. Therefore, the data processing is inadmissible. Attempting to achieve a cure through a declaration of consent by the parents would also not sufficiently take into account the special protection rights of children, e.g. according to Art. 8 of the General Data Protection Regulation (GDPR). Thus, with the consent of the parents, the problem is not solved.

4. What are the prospects for using Office 365?

The HBDI is aware of the needs that vocational schools in particular have for the use of office packages. That is why there is also an interest in working with Microsoft to arrive at a solution that complies with data protection requirements. However, this is not due to the HBDI or the other federal regulatory authorities, but primarily to Microsoft itself. As soon as the possible access of third parties to the data in the cloud and the issue of telemetry data in particular have been resolved in a comprehensible and data protection-compliant manner, Office 365 can be used as a cloud solution by schools. Until that time, however, school can make use of other tools such as on-premises licenses on local systems.

5. other cloud solutions from e.g. Google and Apple

What is true for Microsoft is also true for Google’s and Apple’s cloud solutions. The cloud solutions of these providers have also not been presented transparently and comprehensibly to date. Therefore, it is also true here that data protection-compliant use is currently not feasible for schools.

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Tags: Data protection LawdigitalGeneral Data Protection RegulationGoogleInformationKILizenzPersonal dataPrivacyRegulationSicherheitSoftwareVerträge

Weitere spannende Blogposts

ECJ: Is YouTube a copyright provider?

YouTube: What to do about copyright extortion?
28. October 2019

On Friday, I said a few words about the new streaming platform Mixer from Microsoft(see this article). Actually, I wanted...

Read moreDetails

ECJ: How is “legitimate interest” to be interpreted in the GDPR?

privacy policy 3583612 1920
2. January 2023

The ECJ, on the basis of a reference for a preliminary ruling under Art. 98 para. 1 of the Rules...

Read moreDetails

USK and the guidelines on swastikas in games

5. August 2019

The discussion around the question of whether and under what conditions swastikas are allowed in computer games is in full...

Read moreDetails

Bavarian Administrative Court confirms decision on Facebook Custom Audiences

20. November 2018

Last month, the Bavarian State Office for Data Protection Supervision published a comprehensive checklist on how companies must handle Facebook's...

Read moreDetails

BGH on the OS-Link (EU Dispute Settlement Platform)

Attention: Vouchers to existing customers can be advertising!
19. September 2019

Now and then, as a lawyer, I suspect that colleagues and courts are too boring when they decide on legal...

Read moreDetails

Dealing with Fiverr, Upwork and other outsourcing platforms

Attention GoBD: Trap in the accounting of the self-employed
6. September 2019

I am always contacted by requests, such as how to deal with platforms such as Upwork, Fiverr, Freelancer.com, for example...

Read moreDetails

AI & Copyright: An Analysis

AI & Copyright: An Analysis
10. December 2022

AI & copyright is a new and important topic that worries many people. It is important to understand this issue...

Read moreDetails

Esport Teams & Streamer: What is part of a sponsorship agreement?

Terms and Conditions and Prohibited Clauses
10. December 2019

I regularly receive sponsorship agreements from clients with which companies or advertisers want to engage with esports teams or enter...

Read moreDetails

NFT and the copyright problem

“Invested” in tokens and nothing happened? Get money back?
30. January 2023

Already a few times I have subliminally pointed out in blog posts the problem of what NFT actually are and...

Read moreDetails
ChatGPT and lawyers: recordings of the Weblaw launch event
Law on the Internet

Private AI use in the company

24. October 2025

Private accounts on ChatGPT & Co. for corporate purposes are a gateway to data protection breaches, leaks of secrets and...

Read moreDetails
Lego brick still protected as a design patent

App purchases, in-app purchases and sales tax

21. October 2025
dsgvo 1

What belongs in a DPA? Data processing agreement in accordance with Art. 28 GDPR

17. October 2025
Smart contracts in the insurance industry: contract design and regulatory compliance for InsurTech start-ups

Contract for work vs. service contract in software, AI and games projects

15. October 2025

Influencer contract: performance profile, rights/buyouts, labeling and AI content

13. October 2025

Podcastfolge

Looking to the future: How technology is changing the law

Looking to the future: How technology is changing the law

18. February 2025

In the final episode of the first season of the ITmedialaw.com podcast, we take a look at the future of...

Read moreDetails
092def0649c76ad70f0883df970929cb

Influencers and gaming: legal challenges in the digital entertainment world

26. September 2024
AI in law: opportunities, risks and regulation – the IT Media Law Podcast Episode 3

AI in law: opportunities, risks and regulation – the IT Media Law Podcast Episode 3

24. September 2024
3c671c5134443338a4e0c30412ac3270

“Digital law decoded” with lawyer Marian Härtel

26. September 2024
c9c5d7fd380061a8018074c2ca5a81bf

Startups and innovation in Germany – challenges and opportunities

26. September 2024

Video

My transparent billing

My transparent billing

10. February 2025

In this video, I talk a bit about transparent billing and how I communicate what it costs to work with...

Read moreDetails
Fascination between law and technology

Fascination between law and technology

10. February 2025
My two biggest challenges are?

My two biggest challenges are?

10. February 2025
What really makes me happy

What really makes me happy

10. February 2025
What I love about my job!

What I love about my job!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung