GDPR check

Is Microsoft 365 GDPR compliant? What universities should check

Microsoft 365 is the backbone of mail, files and teaching at a large share of European universities, and it has been examined by more regulators and sector bodies than almost any other cloud suite. This page sets out what Microsoft documents for Microsoft 365 Education, what Dutch, German and EU authorities have said, and what a DPO should still settle locally.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

Microsoft 365 Education comes with a processor agreement (the Microsoft Products and Services DPA, May 2026 edition), an EU Data Boundary commitment for EU and EFTA tenants, published retention limits and broad ISO certification. It has also had an unusually long regulatory history: Dutch government DPIAs on diagnostic data since 2018, a critical German DSK finding in 2022, an EDPS decision against the European Commission in 2024 that was closed in 2025, and a Hessian report in 2025 concluding compliant use is possible. Whether a university can use it lawfully depends on its edition, tenant settings (diagnostic data, connected experiences, Copilot flex routing, third-party models) and its own DPIA.

What Microsoft documents publicly

Everything in this table comes from Microsoft's own documentation and was read on 7 October 2026. It covers Microsoft 365 used through an institutional (Microsoft Entra) tenant, not personal Microsoft accounts. Numbers in brackets refer to the sources at the end.

TopicWhat the vendor statesSource
Company and establishment Documented Microsoft Ireland Operations Limited, Leopardstown, Dublin, is named in the Microsoft Privacy Statement as controller for people in the EEA, UK and Switzerland where Microsoft acts as controller. For products an organisation provides, Microsoft says use is subject to the organisation's own policies. [6]
Editions Documented Microsoft lists Office 365 Education A1, A3 and A5 and Microsoft 365 Education A3 and A5, plus Student Use Benefits. Desktop apps are not in Office 365 A1. Customer Lockbox, Customer Key, Purview Audit (Premium) and eDiscovery (Premium) are listed only for A5. [8]
Where data is stored and processed With exceptions Customer data and pseudonymised personal data are stored and processed in the EU and EFTA for tenants with an EU or EFTA sign-up location; tenants with Multi-Geo Capabilities are out of scope. Microsoft documents continuing transfers for remote access, security operations, Entra directory data, some support data, network transit, Teams calling and federated chat, and preview services. [1], [2], [3]
Copilot flex routing Setting Flex routing lets Copilot inferencing run in the United States, Canada or Australia at peak demand. It is on by default for eligible tenants created after 25 March 2026; older tenants are told to check their setting. An AI Administrator can turn it off. [4], [3]
Data processing agreement Documented The Microsoft Products and Services Data Protection Addendum (English edition dated 22 May 2026) governs Microsoft 365, with Microsoft as processor for customer data. [5]
International transfers Documented The Privacy Statement says Microsoft Corporation complies with the EU-U.S. Data Privacy Framework and its UK and Swiss counterparts. The official DPF List search service returned errors on the check date, so we rely on Microsoft's own statement. [6]
Diagnostic data Configurable Microsoft 365 Apps send Required diagnostic data and, unless an admin changes the policy, Optional diagnostic data, which Microsoft says may also be used in aggregate to train machine learning features such as text predictions. Admins can choose Neither, but required service data and essential services data are still sent. Diagnostic data from Microsoft 365 Apps is included in the EU Data Boundary. [9], [2]
Connected experiences Configurable Admins have policy settings to choose whether to provide experiences that analyse content or download online content. Optional connected experiences, such as Bing-backed 3D Maps, fall under the Microsoft Services Agreement rather than the Product Terms. [9]
Retention and deletion Documented Customer content deleted by a user or admin is removed within at most 30 days. After a subscription ends, data is kept in a limited-function account for 90 days and all customer data is deleted no later than 180 days after expiry. [7]
Security certifications Documented Office 365 commercial services including Exchange Online, SharePoint Online, OneDrive for Business, Teams and Forms are listed in scope for ISO/IEC 27701, which builds on ISO/IEC 27001. [10]

Microsoft deserves credit for the level of detail here. Few vendors publish a service-by-service list of data that leaves their EU boundary, a retention table by data category, or a viewer that lets admins inspect diagnostic data.

What regulators and sector bodies have said

Microsoft 365 has a long public record. The summaries below are limited to official documents we read on the check date.

Netherlands, 2018 onwards. On 20 December 2018 the Dutch Minister of Justice and Security told parliament that a DPIA commissioned through SLM Microsoft Rijk had examined diagnostic data in Office, and that Microsoft had agreed to provide a setting to limit diagnostic data flows and full insight into the remaining flows [14]. The privacy controls Microsoft now documents for Microsoft 365 Apps, including the choice of Required, Optional or Neither, date from Version 1904 [9].

SURF DPIAs for higher education. SURF, with the Dutch Ministry of Justice and Security, published a DPIA on OneDrive, SharePoint and Teams on 23 February 2022 that found one high risk and six low risks. The high risk concerned the lack of end-to-end encryption for scheduled Teams meetings, and SURF advised Double Key Encryption or third-party encryption for special category data in OneDrive and SharePoint [12]. For Microsoft 365 Copilot, SURF advised institutions in December 2024 not to use it for the time being; its update of 27 May 2026 found no remaining high risks but kept two medium risks, on the opacity of the workplace harms filter and the up to 18-month retention of diagnostic data [11], [13]. Our Microsoft Copilot page covers that in more depth.

Germany. On 24 November 2022 the Datenschutzkonferenz (DSK) found that controllers could not demonstrate compliant use of Microsoft 365 on the basis of Microsoft's data protection addendum of 15 September 2022, mainly because of insufficient transparency about processing for Microsoft's own purposes [15]. On 15 November 2025 the Hessian commissioner (HBDI) published a report concluding that Microsoft 365 can be used in compliance in Hesse. The HBDI pointed to the EU Data Boundary and to changes since 2022, and said controllers must still carry out their own assessment and check their configuration [16].

EU institutions. The European Data Protection Supervisor found on 8 March 2024 that the European Commission's use of Microsoft 365 infringed Regulation (EU) 2018/1725 on purpose limitation, transfers and disclosures. On 11 July 2025 the EDPS concluded the infringements had been remedied after contractual and technical changes, and stressed that the closure covers only the provisions examined [17]. That case concerned an EU institution under a different regulation, but the issues it addressed are the same ones a university DPO will look at.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

What this means for a university

Validemic's analysis

The contract is mature; your configuration decides the rest. Article 28 GDPR requires a binding processor contract [19], and Microsoft's DPA, the EU Data Boundary and the published retention table answer most of the standard questions. The regulator history shows that the open points have shifted from the contract towards transparency about Microsoft's own processing and towards tenant settings. The HBDI's 2025 conclusion depends on the controller doing its own assessment [16].

Check your boundary status before relying on it. The EU Data Boundary applies only to EU or EFTA sign-up tenants without Multi-Geo [1]. Flex routing is on by default for eligible tenants created after 25 March 2026 [4], and federated Teams chats, PSTN calling, security operations and directory replication all involve documented transfers [2], [3]. Record these in your transfer impact assessment rather than treating the boundary as absolute.

Diagnostic data is a decision, not a default. Optional diagnostic data flows unless an admin changes the policy [9]. Many institutions set it to Required, and SURF's Copilot work shows that retention of diagnostic data remains a live issue [13]. The same applies to optional connected experiences, which move processing under consumer-style terms [9].

Your edition shapes your controls. Customer Lockbox, Customer Key and premium audit are listed only for A5 [8]. A university on A1 or A3 should check whether its DPIA assumes controls it has not licensed. Article 32 GDPR asks for security appropriate to the risk, and research data with special categories may need encryption that the institution controls [19], [12].

Copilot and agents arrive inside the suite. Copilot Chat and agent features reach users through the same tenant, so the Microsoft 365 DPIA and the AI decisions should be read together. See our pages on Microsoft Copilot and Microsoft Teams, and the forthcoming checks of OneDrive and Microsoft Forms.

Questions to ask before renewing or expanding Microsoft 365

  1. Is our tenant's sign-up location in the EU or EFTA, and have we ever bought or used Multi-Geo Capabilities?
  2. What is our current flex routing setting for Copilot, and who holds the AI Administrator role that can change it?
  3. Which diagnostic data level is enforced on managed and unmanaged devices, and are optional connected experiences disabled?
  4. Which of the documented EU Data Boundary transfers (federated chat, PSTN calling, support cases, security operations) apply to our usage, and are they in our transfer impact assessment?
  5. Does our edition include the controls our DPIA relies on, such as Customer Lockbox, Customer Key or premium audit?
  6. How are we notified of new subprocessors, and who in the institution reviews those notices?
  7. Have we reviewed the SURF DPIA findings and the HBDI's recommendations against our own settings?
  8. Which retention policies apply to mail, Teams chats and OneDrive for staff and students who leave?

The EU AI Act angle

Microsoft 365 itself is mostly not an AI system, but it now includes Copilot Chat and other AI features. Under Regulation (EU) 2024/1689 a university that enables them is a deployer [20]. Article 4 on AI literacy has applied since 2 February 2025, and the Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026, turned it into a duty to take measures to support staff AI literacy [21]. Using Microsoft 365 for drafting or summarising is not an Annex III high-risk use; using it to evaluate learning outcomes or decide admissions could be, and those Annex III rules apply from 2 December 2027 under the Omnibus [20], [21].

Sources

  1. Microsoft Learn, What is the EU Data Boundary? (text last updated 26 February 2025), retrieved 7 October 2026.
  2. Microsoft Learn, Continuing data transfers that apply to all EU Data Boundary Services, retrieved 7 October 2026.
  3. Microsoft Learn, Services that transfer a subset of data out of the EU Data Boundary on an ongoing basis (updated 1 October 2026), retrieved 7 October 2026.
  4. Microsoft Learn, Flex routing (EU and EFTA) (updated 29 September 2026), retrieved 7 October 2026.
  5. Microsoft Products and Services Data Protection Addendum (English, 22 May 2026), retrieved 7 October 2026.
  6. Microsoft Privacy Statement (last updated September 2026), retrieved 7 October 2026.
  7. Microsoft Learn, Data retention, deletion, and destruction in Microsoft 365, retrieved 7 October 2026.
  8. Microsoft Learn, Microsoft 365 Education service description, retrieved 7 October 2026.
  9. Microsoft Learn, Overview of privacy controls for Microsoft 365 Apps for enterprise, retrieved 7 October 2026.
  10. Microsoft Learn, ISO/IEC 27701 offering, retrieved 7 October 2026.
  11. SURF Vendor Compliance, Microsoft, retrieved 7 October 2026.
  12. SURF, DPIA on Microsoft OneDrive, SharePoint and Teams (23 February 2022), retrieved 7 October 2026.
  13. SURF, Privacy risks Microsoft 365 Copilot remain orange despite improvements (27 May 2026), retrieved 7 October 2026.
  14. Kamerstuk 26643 nr. 585, letter of the Minister of Justice and Security on data collection by Microsoft (20 December 2018), retrieved 7 October 2026.
  15. Datenschutzkonferenz, Festlegung zu Microsoft 365 (24 November 2022), retrieved 7 October 2026.
  16. HBDI, Microsoft 365 kann datenschutzkonform genutzt werden (press release of 14 November 2025 on the report of 15 November 2025), retrieved 7 October 2026.
  17. EDPS press release EDPS/2025/07, European Commission brings use of Microsoft 365 into compliance (28 July 2025), retrieved 7 October 2026.
  18. European Commission, Adequacy decisions, retrieved 7 October 2026.
  19. Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 28, 32 and 35, retrieved 7 October 2026.
  20. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Article 4 and Annex III, retrieved 7 October 2026.
  21. Regulation (EU) 2026/1744 (Digital Omnibus on AI), retrieved 7 October 2026.

About this page

We read Microsoft's Learn documentation, the Microsoft Privacy Statement, the DPA licensing page, SURF's vendor compliance publications, Dutch parliamentary papers, the DSK, HBDI and EDPS documents and the EU legal texts on 7 October 2026. The official Data Privacy Framework List could not be queried on that date. We did not test a tenant or review any customer-specific agreement, and some SURF pages were reachable only through SURF's vendor compliance site. "Not found" means we could not find information in public documentation; it does not mean it does not exist.

This page is not legal advice and is not a statement that Microsoft 365 is or is not GDPR compliant, which depends on your contract, configuration and use. If you work at Microsoft or spot an error, please contact us and we will correct it.

Frequently asked questions

Is Microsoft 365 Education covered by a data processing agreement?

Yes. Microsoft 365 is covered by the Microsoft Products and Services Data Protection Addendum (DPA), with Microsoft acting as processor for customer data. The current English edition is dated May 2026. Microsoft also describes some processing for its own legitimate business operations, which is one of the points German regulators criticised in 2022.

Does Microsoft 365 keep university data in the EU?

For tenants with a sign-up location in the EU or EFTA, Microsoft commits to store and process customer data and pseudonymised personal data inside the EU Data Boundary, with documented exceptions such as security operations, some support data, Entra directory replication, Teams calling features and Copilot flex routing. Tenants that bought Multi-Geo Capabilities are not in scope.

What did the German Datenschutzkonferenz say about Microsoft 365?

On 24 November 2022 the DSK found that controllers could not demonstrate compliant use of Microsoft 365 on the basis of Microsoft's data protection addendum of 15 September 2022. In November 2025 the Hessian commissioner (HBDI) published a report concluding that Microsoft 365 can be used in compliance in Hesse, provided controllers carry out their own assessment and configuration.

What diagnostic data does Microsoft 365 send to Microsoft?

Microsoft 365 Apps send required diagnostic data, and optional diagnostic data unless an admin changes the policy setting. Admins can choose Required, Optional or Neither, although required service data for connected experiences and essential services is still sent. Microsoft says diagnostic data excludes names, email addresses and file content.

Has SURF approved Microsoft 365 for Dutch universities?

SURF does not issue approvals. Its public DPIA on Teams, OneDrive and SharePoint (February 2022) found one high and six low risks, and its May 2026 update on Microsoft 365 Copilot found no high risks but two medium risks. Each institution still makes its own decision.