MS365 Data

3.1. Identification data

3.2. Content data

3.3.1. Diagnostic data

3.3.2.“Service-generated” (raw) audit data (SGD)

3.3.3. Aggregated “service-generated” data.

3.3.4. “Connected experiences service data

3.4. Special category (sensitive) data

“Double-key encryption” (DKE)

EU-based (Ireland) Cedefop tenant

EU-based (Ireland) Cedefop tenant

Cedefop is controller

  1. Technical assistance, support and troubleshooting, including Security incident management 
    
  1. Backups
    

Cedefop is controller

Cedefop is controller

approval of Cedefop “Customer lockbox"

approval of Cedefop “Customer lockbox"

Required

Optional

Essential services

disabled (configuration set to value “Neither”)

disabled (configuration set to value “Neither”)

Pseudonymised

EU-based (Ireland) Cedefop tenant

Microsoft US retrieves, pseudonymises and aggregates

Standalone Online services

Cloud-connected experiences

Processor Connected Experiences

Controller Connected Experiences (optional)

Disabled

disabled

EU-based (Ireland) Cedefop tenant

Transferred to Microsoft USA but expected to change by end of 2022, as can be seen in the public announcement on the ‘EU Data Boundary for the Microsoft Cloud’

Transferred to Microsoft USA but expected to change by end of 2022, as can be seen in the public announcement on the ‘EU Data Boundary for the Microsoft Cloud’

Transferred to Microsoft USA but expected to change by end of 2022, as can be seen in the public announcement on the ‘EU Data Boundary for the Microsoft Cloud’

Transferred to Microsoft USA but expected to change by end of 2022, as can be seen in the public announcement on the ‘EU Data Boundary for the Microsoft Cloud’

Supplementary measures

ILA, uses Standard Contractual Clauses 2010/87/EU (Controller to Processor) . Data exporter for the transfers which take place under the ILA is the processor (Microsoft Ireland Operations Ltd.) and the data importer the sub-processor (Microsoft Corp.). Onward transfers from Microsoft Corp. to sub- processors use adequacy decisions or other agreements #. DIGIT and Microsoft are amending the ILA to reflect the introduction of the new SCCs

DPA allows MS Ireland to process for some authorised purposes

Additional technical measures: Strong encryption in transit and at rest. Communications between Microsoft’s servers take place over TLS (Transport Layer Security) or IPSec worldwide

Microsoft is not under any specific legal obligation to decrypt any information prior to its disclosure to the US authorities.

the transfer of the personal data concerned to the United States is effectively subject to appropriate safeguards

Public announcement on the ‘EU Data Boundary for the Microsoft Cloud’

The processing data for Microsoft’s business operations 1, 2, 3, 5 and 6, Microsoft de-identifies the data (generally by relying on aggregated statistical data based on data containing pseudonymous identifiers)

Cedefop limits to the minimum possible the “Identification data” attributes saved on Microsoft Azure (cloud) Active directory

DPA allows MS Ireland to process for some authorised purposes

Simple encryption for SNC data