DPC (Ireland) - Microsoft Operations Ireland Limited

From GDPRhub
Revision as of 03:02, 19 December 2023 by Gauravpathak (talk | contribs) (Created page with "{{DPAdecisionBOX |Jurisdiction=Ireland |DPA-BG-Color=background-color:#013d35; |DPAlogo=LogoIE.png |DPA_Abbrevation=DPC |DPA_With_Country=DPC (Ireland) |Case_Number_Name=Microsoft Operations Ireland Limited |ECLI= |Original_Source_Name_1=DPC |Original_Source_Link_1=https://www.dataprotection.ie/sites/default/files/uploads/2023-12/13.12.2023%2520Microsoft%2520Ireland%2520Operations%2520Limited%2520Decision.pdf |Original_Source_Language_1=English |Original_Source_Langua...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
DPC - Microsoft Operations Ireland Limited
LogoIE.png
Authority: DPC (Ireland)
Jurisdiction: Ireland
Relevant Law: Article 12(4) GDPR
Article 17 GDPR
Article 58(2)(b) GDPR
Type: Complaint
Outcome: Upheld
Started: 28.07.2021
Decided: 15.11.2023
Published:
Fine: n/a
Parties: Microsoft Operations Ireland Limited
National Case Number/Name: Microsoft Operations Ireland Limited
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): English
Original Source: DPC (in EN)
Initial Contributor: Gauravpathak

The Irish DPC reprimanded Microsoft Operations Ireland Limited for failing to inform the data subject about the availability of a judicial remedy and for not erasing personal data upon request, thereby violating Article 12(4) and Article 17 GDPR.

English Summary

Facts

A data subject submitted a complaint to Bavarian DPA stating they submitted an erasure request to Microsoft to erase certain content from its search engine, which was from the data subject's website. However, Microsoft refused to do so by claiming public interest.

Subsequently, the data subject wrote to Microsoft seeking the deletion of all their personal data from Microsoft websites. Thereafter, Microsoft replied to the data subject that it would remove two URLs but not the others due to public interest.

Again, the data subject contacted Microsoft to erase their personal data, and this time, Microsoft shared the instructions to close a Microsoft account.

Meanwhile, the complaint was transferred to DPC as it was the Lead Supervisory Authority.

Through a series of communications with Microsoft, the DPC could get the data subject's personal data deleted. However, the data subject rejected the option of closing their complaint as Microsoft took a lot of time deleting their personal data, and the data subject feared its possible disclosure to third parties.

Accordingly, the DPC continued with its investigation and framed the following issue-

"Whether Microsoft's handling of the Complainant's erasure requests was compliant with Articles 12 and 17 of the GDPR"?

Holding

The DPC held that based on the documentation on record, it is clear that Microsoft did tell the data subject that they had the option of approaching a supervisory authority when Microsoft denied their erasure request. However, Microsoft did not inform the data subject about its right to a judicial remedy at any stage of its communications with Microsoft, thereby violating Article 12 GDPR.

In addition, Microsoft also admitted that it should have accepted certain URLs for delisting in the first instance but failed to do so. Microsoft's action on those complaints started only later; hence, the same was not without undue delay, as required under Article 17 GDPR.

Based on the above, the DPC reprimanded Microsoft under Article 58(2) GDPR and directed it to revise its internal policies and procedures to prevent future violations.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the English original. Please refer to the English original for more details.