Auditors, lawyers, tax consultants and management consultants: Four perspectives. One solution. Worldwide. Find out …
Our clients entrust us with their most important legal matters. Learn more about our legal services!
Tax laws are complex and dynamic. We face the challenge of tax law together with you - find out more.
Baker Tilly advises CFL on container vessel acquisition
US tariffs: Short term optimization – medium-term preparation
Germany’s Coalition Agreement and Tax Law – A Document to Fiscal Pragmatism
BAG overturns forfeiture clause for share options after termination
Art. 273a ZPO: More protection for trade secrets in civil proceedings
Social insurance obligation for freelance teachers only from 2027
Industry-specific knowledge is essential in order to create the best conditions for customised solutions. Find out …
Baker Tilly advises biotech startup Real Collagen GmbH investment by US investor
Energy study: Uncertainty slows down investments by industry and utilities in Germany
After ECJ ruling: Financial investors still have no direct access to medical care centers
Benefit from bundled interdisciplinary competencies, expert teams and individual solutions. Learn more!
Baker Tilly offers a wide range of individual and innovative consulting services. Find out more!
In order to ensure that you can use the American cloud service provider Microsoft 365 securely and in compliance with data protection regulations, there are a few things to bear in mind. Work with our experts to create the best possible basis for your company or authority.
Microsoft 365 (formerly Office 365) is one of the most frequently used software solutions for German companies and numerous public authorities. The service offers your company or authority a variety of applications or apps that can help you to make communication and work in your teams, divisions or departments easier, faster and more convenient. However, using the service can be associated with various challenges, as the German data protection supervisory authorities have expressed criticism regarding its data protection-compliant use. This is due, among other things, to the fact that Microsoft is an American company and the national laws in the USA do not currently provide personal data protection comparable to that of EU law. We can advise you in connection with data protection for Microsoft 365 and help you with data protection-compliant integration in your company or authority.
Data protection problem? Contact us for further information
From a data protection perspective, the use of Microsoft 365 entails certain risks for companies and authorities, which is why the use of the software has already been increasingly criticized. For example, an assessment report (from 11/2022) by the independent German data protection supervisory authorities of the federal and state governments (DSK) expresses concerns about the application’s data protection compliance. In view of the ongoing criticism from the data protection supervisory authorities, Microsoft has repeatedly made changes to its contracts and the design of its services, but these have not yet softened the authorities' concerns. The main data protection risk to which your company or authority may be exposed is a GDPR breach. Such a breach can result in the risk of warnings and fines.
Learn more about the EU standard data protection clause for the international transfer of data and about legal protection in the event of surveillance mechanisms by US security authorities (only available in German).
As a company or public authority in Germany, it is therefore not easy for you to use Microsoft 365 in compliance with data protection regulations and to provide your employees with the market-leading applications or apps.
Microsoft 365 offers your company or public authority a wide range of applications or apps that can help you to make communication and work in your teams, divisions or departments easier, faster and more convenient. However, in order to come closer to the German requirements regarding the handling of personal data, the American company has to repeatedly make changes to its own data protection regulations. Here, Microsoft provides a statement on what personal data is collected by Microsoft devices, software and services and how and for what purpose the company stores it. It has not yet been legally clarified whether these measures can eliminate the uncertainties in connection with data transfers between Europe and the USA.
Microsoft 365 is a fixed standard for office activities in Germany, but is not easily GDPR-compliant in terms of data protection law. There are no sufficient recommendations from the supervisory authorities on how Microsoft 365 can be used in compliance with data protection law, as GDPR-compliant use always depends on the individual case. A GDPR-compliant implementation of the application can be highly complex, depending on the company.
Leave this task to us. We help you to use Microsoft 365 services for your business as securely and in compliance with data protection regulations as possible so that you can classify unnecessary risks and reduce them through technical and organizational measures.
Our experienced lawyers will show you quick and uncomplicated ways to use Microsoft 365 in compliance with data protection regulations:
Your benefits:
Dr. Christian Engelhardt, LL.M.
Partner
Attorney-at-Law (Rechtsanwalt)
Get in contact with us
Contact now
Companies with 20 or more employees are required to appoint a data protection officer. As an external data protection officer, we support you with our expertise in all data protection issues.
The appointment of an external data protection officer has various advantages for companies:
As data protection officers, we support you in setting up and implementing a GDPR-compliant data protection organization in your company. All of our consultants are licensed attorneys who additionally practice in labor law or IT law, two areas of law with the greatest points of contact with data protection law.
Since the introduction of the GDPR in May 2018, controllers have been subject to a large number of documentation and verification obligations. As external data protection officers, we support you in creating and updating the documents relevant to you:
We offer training for employees and managers that is tailored specifically to your company and your needs. Training courses can be held annually or on an as-needed basis. We will be happy to coordinate the specific content of the training with you. Possible topics include:
Sarah BuschSenior Manager Attorney-at-Law (Rechtsanwältin)
Dr. Christian Engelhardt, LL.M.Partner Attorney-at-Law (Rechtsanwalt)
PD Dr. Jens Thomas FüllerSenior Manager Attorney-at-Law
Philip KochManager Attorney-at-Law (Rechtsanwalt)
Maximilian PörtnerSenior Manager Attorney-at-Law (Rechtsanwalt)