CTPDA (Spain) - RPS-2025/082

From GDPRhub
CTPDA - RPS-2025/082
Authority: CTPDA (Andalusia)
Jurisdiction: Spain
Relevant Law: Article 5(1)(b) GDPR
Article 5(1)(a) GDPR
Article 6 GDPR
Article 13 GDPR
Article 25 GDPR
Article 30 GDPR
Article 32 GDPR
Article 35 GDPR
Type: Complaint
Outcome: Upheld
Started: 01.03.2023
Decided: 02.12.2025
Published:
Fine: n/a
Parties: Dirección General de Innovación y Formación del Profesorado
National Case Number/Name: RPS-2025/082
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Spanish
Original Source: CTPDA (in ES)
Initial Contributor: bms

The DPA held that the Ministry of Education and Sports of Andalusia’s provision of cloud-based educational services to public schools violated GDPR provisions relating to transparency, privacy by design, international data transfers and DPIA duties. The Ministry used Microsoft as a processor for this activity.

English Summary

Facts

In November 2020, the Regional Ministry of Education and Sports of Andalusia, acting as controller, entered into a collaboration agreement with Microsoft Ireland Operations Limited, acting as processor, for the provision of cloud-based educational services to public schools wishing to use them.

The services covered by the agreement included Microsoft Office Online applications, such as Outlook, Word, Excel, PowerPoint and OneNote, as well as Exchange, Forms, OneDrive, SharePoint, Teams and Sway. These services provided communication, collaboration, productivity and cloud storage functionalities for the education sector.

Under the agreement, Microsoft Ireland Operations Limited had access to personal data under the responsibility of the controller in order to provide the relevant cloud-based educational services.

In March 2023, the DPA received a complaint alleging several infringements of the GDPR and the Spanish data protection framework. The complaint concerned, in particular:

- Article 25 GDPR, on data protection by design and by default, due to the alleged failure to adopt appropriate technical and organisational measures to reduce the risk that users would upload special categories of personal data, inappropriate images or audiovisual material to the system.

- Article 13 GDPR, concerning the information to be provided to data subjects when their personal data is collected.

- Articles 44–49 GDPR, concerning international transfers of personal data to third countries or international organisations without the required safeguards, conditions or derogations.

- Article 30 GDPR, due to the alleged lack of adequate information in the controller’s record of processing activities regarding international data transfers.

- Article 35 GDPR, concerning the alleged absence of a data protection impact assessment in relation to the use of the cloud-based educational services.

Holding

The DPA upheld the complaint and found that the controller infringed the GDPR because it had not implemented appropriate data protection by design and by default measures to mitigate the risk that users could upload special categories of personal data, images or audiovisual material to the cloud services. It also failed to provide adequate Article 13 GDPR information to pupils, families and teachers about the processing, carried out international data transfers without demonstrating that the safeguards, conditions or derogations under Articles 4449 GDPR were met, failed to record those transfers properly in its Article 30 GDPR record of processing activities, and had not carried out a DPIA before starting the processing, despite the risks involved.

The DPA ordered the controller to adopt corrective measures, including the following:

- Submit an action plan identifying the measures to be implemented to remedy the non-compliance, together with an implementation timeline and justification for that timeline.

- Provide evidence that appropriate technical and organisational measures had been adopted to mitigate the high risk that users may enter special categories of personal data into the cloud-based educational services.

- Provide documentation demonstrating the means or measures used to inform data subjects about the processing of their personal data, in compliance with Articles 13 and 14 GDPR.

- Suspend data flows to the processors and sub-processors’ facilities located in third countries that are not subject to an adequacy decision, except where the relevant safeguards, conditions or derogations under Articles 44–49 GDPR are met.

- Submit copies of the instructions and protocols provided to members of the educational community regarding which photographs and audiovisual content may appropriately be uploaded to the cloud-based educational services, and which content should not be included.

- Indicate the control and monitoring mechanisms implemented in relation to the uploading of photographs and audiovisual content.

- Provide documentary evidence that the record of processing activities had been amended to include appropriate information on international data transfers, in accordance with Article 30 GDPR.

- Provide documentary evidence of a data protection impact assessment carried out in accordance with Article 35 GDPR.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.

Document suitable for publication on the Council Portal
RESOLUTION OF SANCTIONING PROCEEDINGS FOR INFRINGEMENT OF PERSONAL DATA PROTECTION REGULATIONS
Resolution RPS-2025/082
Sanctioning Procedure PS-2024/088
File RCO-2023/037
Entity initiated: Directorate General for Innovation and Teacher Training (Ministry of Educational Development and Vocational Training)
Reason for the complaint: Non-compliance with personal data protection regulations in the agreement signed between Microsoft Ireland Operations Limited and the Ministry of Education and Sport (current Ministry of Educational Development and Vocational Training)
Articles affected: 5.1.a), 5.1.b), 6, 13, 25, 30, 32, 35 and 44 to 49 GDPR
33 LOPDGDD
Abbreviations:
GDPR. REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
LOPDGDD. Organic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights.
LOPDP. Organic Law 7/2021, of 26 May, on the protection of personal data processed for the purposes of prevention, detection, investigation and prosecution of criminal offenses and execution of criminal penalties.
LTPA. Law 1/2014, of June 24, on Public Transparency in Andalusia
CTPDA STATUTES. Statutes of the Council for Transparency and Data Protection of Andalusia, approved by
Decree 434/2015, of September 29.
LPAC. Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations
LRJSP. Law 40/2015, of October 1, on the Legal Regime of the Public Sector.
ENS. Royal Decree 311/2022, of May 3, regulating the National Security Framework.
BACKGROUND
First. Filing of the complaint.

1. On March 1, 2023, the complaint filed by the complainant, alleging a violation of personal data protection regulations, was received by the Andalusian Council for Transparency and Data Protection (hereinafter, the Council).

2. The claimant states the following grounds for the claim:
“Through this document, I bring to your attention six irregularities and infractions that I have observed in the agreement established between Microsoft and the Ministry of Education and Sport (now the Ministry of Educational Development and Vocational Training) for the provision of educational services in the cloud in public schools under the ownership of the Ministry (the agreement can be accessed at this address: https://www.juntadeandalucia.es/sites/default/files/2021-01/Convenio_31.pdf) and which violate Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights, which is abbreviated as follows:
Page 1 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
I will comply with the Spanish Data Protection Act (LOPD) and the General Data Protection Regulation 2016/679, abbreviated as the GDPR.

1. Infringements considered very serious under Article 72.1, b) and d) of the LOPD.

When the service is activated, the enrollment of students and teachers on the platform is done automatically, based on the IdEA users hosted in the Séneca Information System.

Prior to this process, the interested parties (teachers, administrative and service staff, and students or their guardians in the case of minors under 14 years of age) were not asked for prior consent. Therefore, the following personal data are collected: user identifier of the Séneca Information System (IdEa identifier), name and surname, role (Teacher/student)
and school code are provided to Microsoft without the prior consent of the data subjects.

In the case of students, the opening of the account cannot be justified without their consent or that of their guardians (for those under 14 years of age) based on the provisions of the Organic Law of Education, specifically its twenty-third provision, since Microsoft is not an educational institution. Under the agreement signed between the Regional Ministry of Education and Microsoft, this company becomes the data controller and, as such, can only process the data as established by law (for teaching and guidance purposes). If it processes the data for other purposes, it must request consent; and this is the case here, since clause 3.4 of the agreement establishes the possibility of experimentally testing and verifying the use and capabilities of different advanced technologies of Educational Services in the Cloud applied to the digital transformation of the education sector, such as big data and other related technologies. with the interests of this company, which have nothing to do with the teaching and guidance function established by the LOE (Organic Law of Education).

Clause 7.6 of the agreement states that “The personal data whose processing is entrusted to the Collaborating Company may affect the following categories of interested parties: end users (students, teachers, parents or legal guardians), including the workers and contractors of the educational centers; and anyone else who
transmits data through the Educational Cloud Services, including people who
collaborate and communicate with end users...”. This occurs when students
use the platform from home, or when teachers or students generate documents
on the platform, or upload documents to Drive containing families' personal data.
And in these cases, parents or legal guardians are not asked for consent at any time.
2. Security risk when using IdEa credentials.
In the case of teachers, in addition to their first and last name, information is being provided about their teaching work, their workplace, and the IdEa identifier used to access the Teacher Portal and SENECA, where there is a large amount of information about their work history, salary data, training data, procedures they have carried out
with the administration, information about their health, and also data about the students they teach. class, which includes data of the special category. For this reason,
I believe that handing over these credentials to a company like Microsoft is inappropriate
and carries a very high risk, considering the technological capabilities of this
company and its thirst for data.

This same risk to the security of personal data from handing over IdEa credentials occurs with students, since these credentials grant access to PA-SEN, a platform where personal data such as grades, attendance records, absence justifications, communications with teachers, etc., are stored. This risk is aggravated by the fact that some of this data is of the special category and pertains to minors.

Page 2 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Portal of Advice
3. Infringement considered very serious under the LOPD, art. 72.1, e)
At no time is consent obtained from students or their families
for the processing of data concerning health, religion, ideology, beliefs, sexual life, or racial origin.

During the use of Microsoft 365 platform applications, teachers or students themselves may upload documents to Drive, or send them via the platform's email, or create spreadsheets or text documents with information that reveals special category data about students. For example: an essay for the History subject in which opinions on political ideologies are requested, or the very common shared document to provide information to tutors before the evaluation, or when creating a shared folder with a student's psycho-pedagogical reports in Drive; special category data is provided unknowingly and without the consent from the students and their families. In fact, these are procedures that are already carried out routinely.
Clause 7.4 of the agreement states the following: “Under no circumstances will the Regional Ministry of Education and Sport provide the Collaborating Company with data of special categories as defined in Article 9 of the GDPR.” However, this data is being provided.

4. Infringement considered very serious under the Spanish Data Protection Act (LOPD), art. 72.1, h)
At no time before or after the creation of the accounts do the educational centers fulfill the duty to inform established in Article 13 of Regulation (EU) 2016/679.
They do not provide the data subjects with the basic information established in Article 11 of the LOPD, nor do they provide them with an email address or other means that allows easy and immediate access to the remaining information.

5. Infringement considered very serious under the LOPD, art. 72.1, l)
In Annex I of the agreement, “Terms of Online Services,” in the section “Data Protection and Security,” states that:

“The terms of the DPA (Data Protection Addendum) apply to the Online Services. For the Main Online Services, the location of inactive Customer Data can be found in Annex 1.”

In Annex 1: Notifications, the section “Location of Inactive Customer Data for Core Online Services” states:

“Office 365 Services. If the Customer provisions its tenant in Australia, Canada, the European Union, France, Germany, India, Japan, South Africa, South Korea, Switzerland, the United Kingdom, the United Arab Emirates, or the United States, Microsoft will store the following Customer Data at rest only within that geo-area: (1) Exchange Online mailbox content (email body, calendar entries, and email attachment content), (2) SharePoint Online site content and files stored on that site, and (3) files uploaded to OneDrive for Business.”

The European Commission does not consider many of these countries to have an adequate level of data protection.And in the Data Protection Addendum (https://aka.ms/DPA), under the section “Data Transfer and Location - Data Transfers,” it states:

“The Customer designates Microsoft to transfer Customer Data and Personal Data to the United States or any other country in which Microsoft or its Sub-chargers operate.”

Page 3 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's website
I recall that the Court of Justice of the European Union (CJEU) invalidated Commission Decision (EU) 2016/1250 of July 12, 2016, known as the Privacy Shield, for data transfers to the United States.

6. Processing of Photographs and Audiovisual Content
Clause 7.8 of the agreement between Microsoft and the Regional Ministry of Education states:
“The data controller must also assess, in relation to the processing of photographs and audiovisual content, whether these correspond to the purpose of the processing, being adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed, taking into consideration the principle of data minimization set out in Article 5.1 c) of the GDPR.”
At no point has the Regional Ministry of Education established any mechanisms for assessing this content. This is also a significant irregularity.

Given that we are dealing with five infringements considered very serious under the Spanish Data Protection Act (LOPD), affecting more than 900,000 minors, their families, teachers, and administrative and support staff; that there are only a few months left until the end of the school year,
that during these few months two assessments take place in which a
high volume of data related to academic performance, discipline and
others related to health, religion, ideology…., that is, special category data, which
will very likely be exported to countries without the same level of protection, and because
data of minors
of special category data has also very likely already been exported, I request this Council to urgently apply Article 69 of the LOPD:
“In cases where the Spanish Data Protection Agency considers that the continuation
of the processing of personal data, its communication or international transfer would entail a serious impairment of the right to the protection of personal data,
it may order the controllers or processors to block the data
and cease its processing and, in the event of non-compliance with said mandates, proceed to immobilize it.”
Second. Prior referral to the Data Protection Officer (DPO). Articles 37.1 and 65.4 of the Spanish Organic Law on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).

On May 23, 2023, the complaint was referred to the DPO of the Regional Ministry of Educational Development and Vocational Training so that, within a maximum period of one month, they could provide information regarding the circumstances described in the complaint, the measures in place at the time the events occurred, as well as any measures that could have been adopted both in relation to what was stated in the complaint and, where applicable, to prevent similar situations from occurring in the future, and any other information and documentation. However, this Council did not receive a response in this regard.

Third. Admission of the complaint and initiation of Preliminary Investigation Proceedings (Articles 65.5 and 67.1 LOPDGDD; Article 55.2 LPAC).

On December 20, 2023, the Director of the Council agreed to accept the complaint and initiate preliminary investigative proceedings to better determine the relevant facts and circumstances that would justify initiating a possible sanctioning procedure for a data protection violation.

Fourth. Regarding the Preliminary Investigative Proceedings
1. In order to complete the information related to the reported events, on December 21, 2023, the Data Protection Officer (DPO) was requested to submit information and documentation on the causes of the incident and the actions taken in relation to the complaint.

Page 4 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
The content of the aforementioned requirement was as follows:
- Specific determination of the processing activity related to the complaint and identification of the data controller.
- Copy of the record of processing activities relating to the aforementioned activity, with the data required by Article 30 GDPR and its legal basis.
- Data relating to the implementation and use of the Cloud-Based Educational Services, indicating the number of centers, teachers, and students involved in their use.

- Copy of the report, if any, from the Data Protection Officer on the draft of the
“Collaboration Agreement between the Regional Ministry of Education and Sport of the Andalusian Government and Microsoft for the provision of Educational Services in the Cloud in public schools owned by the Regional Ministry of Education and Sport of the Andalusian Government” (hereinafter, the Agreement) prior to its signing.

- Copy of the Data Protection Impact Assessment (hereinafter, DPIA) prior to the signing of the Agreement or, if none exists, the (mandatory) risk analysis of the processing (or processing activities) involved.

The Agreement's term of validity is two years, having been signed in 2020.
A copy of any document that has updated, renewed, or modified the Agreement in any of its terms, or extended its validity, is required, including the terms and conditions or data processing annex for Microsoft as the data processor currently applicable to the Agreement.

Regarding clauses 3.4 and 3.5 of the Agreement:

Confirmation of whether the processing described in clauses 3.4 and 3.5 is being carried out.

Confirmation of whether the processing described in clauses 3.4 and 3.5 would include data from students and/or their legal representatives. Confirmation as to whether consent is being requested or is planned to be requested in the event of carrying out the processing described in clauses 3.4 and 3.5, or what the legal basis for such processing would be.

If it is considered that the legal basis for the processing described in clauses 3.4 and 3.5 derives from Additional Provision 23 of Organic Law 2/2006, of May 3, and therefore does not require consent, justification of said legal basis must be provided, taking into account its expressly experimental nature.

Confirmation as to whether the “personalization of content” mentioned in said clauses requires or implies profiling of data subjects and whether it could involve automated individual decision-making. - Regarding clauses 3.5 and 4.2.3 of the Agreement, further information is requested on access to the referenced Early Adoption Programs, specifically, what the programs consist of, what technology supports them, their purpose, and their use. Please indicate whether the fact that these programs are considered "beta functionalities" has been taken into account.

Page 5 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal

Page 5 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal - Copy of the clause(s) under which interested parties are informed of the creation of accounts and the use of the Educational Cloud Services (students, parents/guardians for children under 14, teachers, and administrative staff) regarding the processing of their personal data pursuant to Article 13 of the GDPR.

- Confirmation of whether Microsoft is provided with the IdEA credentials (username and/or password) of teachers and students.

- Copy of the instructions and protocols addressed to users who are members of the educational community regarding the photographs and audiovisual content that are appropriate to include in the Educational Cloud Services and those that should not be included, based on this assessment.

- Whether special categories of personal data are processed in the Cloud-Based Educational Services and, if not, instructions or protocols addressed to members of the educational community who use the system to prevent their inclusion.

- List of countries and companies receiving international data transfers.

- Indication of whether the content of Annex II and Annex 2 “Standard Contractual Clauses (Data Processor)” has been adapted to the new standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council. If applicable, a copy thereof.

On page 24, paragraph three of the Agreement states the following: “Products that are not from Microsoft. Microsoft may make Products that are not from Microsoft available to the Customer through the Customer’s use of the Online Services (for example, through a store or gallery, or as search results) or through a Microsoft online store (such as Microsoft Store for Business or Microsoft Store for Education).[…]”. Information is requested on whether these third-party services are currently being used by the Ministry, whether they are made available to teachers and/or students, and, if so, whether authorizations are being managed in any way, whether measures are being taken to ensure that the legal guardians of children under 14 years of age grant or withhold consent for their use and are informed thereof. If the use of these services requires payment, information on whether it is possible to register bank cards or other forms of payment through the platform and, if so, the measures adopted for their proper use, taking into account that a large proportion of users are minors.
- Any other information or documentation you consider relevant.

2. In response to the aforementioned request, on January 30, 2024, a report was received from the Data Protection Officer (DPO), to which was attached a report from the Director General of Advanced Technologies and Educational Transformation, with the following content:
“3. Legal Basis
Page 6 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
[…]
Point 1.1: “Infringements considered very serious in Article 72.1, b) and d) of the LOPD. Upon activation of the service, the enrollment of students and teachers on the platform is done automatically, starting from the IdEA users hosted in the Seneca Information System. Prior to this process, the interested parties (teaching staff, administrative and service staff, and students or their guardians in the case of minors under 14 years of age) were not asked for their prior consent [...]” In the Agreement with Microsoft, Page 8, point 7.7: “The data controller will require the express consent of the interested parties or their representatives for the processing of data not included among those that educational centers may collect from students in accordance with Additional Provision 23 of Organic Law 2/2006, of May 3, on Education.”
Additional Provision 23 of Organic Law 2/2006, of May 3, amended by Organic Law 3/2020, of December 29, states:
[…] In the enrollment process, detailed information is provided on data protection in accordance with the General Data Protection Regulation (GDPR). It is clearly specified that the student's personal data will be incorporated for the management of admission and enrollment, with the specific purpose of processing the corresponding applications.

Furthermore, information is provided on how to exercise the rights of access, rectification, and others with respect to their data. Therefore, a clear and transparent understanding is established with the students regarding how and why their data will be retained and processed in the Ministry's computer system.

In accordance with the agreement signed between the Ministry of Educational Development and Vocational Training and Microsoft, and in accordance with the current legal framework, the processing of student data is limited exclusively to the educational sphere. This understanding aligns with the legal provisions governing the use of personal data for educational purposes, thus ensuring the legal compliance of the aforementioned agreement, and therefore not requiring authorization from the students.

Point 1.2: “[…] in clause 3.4 of the agreement The possibility of experimentally testing and verifying the use and possibilities of different advanced technologies of Cloud-Based Educational Services applied to the digital transformation of the education sector is established, including big data and others related to the interests of this company, which have nothing to do with the teaching and guidance function established by the LOE (Organic Law of Education) […]”
The exact text of point 3.4 of the agreement reads:
3.4. Possibility of experimentally testing and verifying the use and possibilities of different advanced technologies of Cloud-Based Educational Services applied to the digital transformation of the education sector, such as: big data, analysis of learning indicators, collaborative work, content personalization, cloud-based work, virtual reality, and augmented reality.
The statement that it makes of “and others related to the interests of this company, which have nothing to do with the teaching and guidance function” is a mere assumption without any basis.

Point 1.3: “[…] And this occurs when the students uses the platform from home, or
when teachers or students generate documents on the platform, or upload documents to Drive with personal data of families. And in these cases, parents or legal guardians are not asked for consent at any time.”

This point 1.3 links directly to the answer given in point 1.1.
Page 7 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council Portal
Point 2: “Security risk when using IdEA credentials. In the case of teachers,
in addition to their first and last name, information is being provided about their teaching work, their workplace, and the IdEa identifier used to access the Teacher Portal

and SENECA, where there is a wealth of information about their work history, remuneration data, training data, procedures they have carried out with the administration, information about their health, and also data about the students they teach, including data from the special category. For this reason, I believe that providing
those credentials to a company like Microsoft is inappropriate and carries a very
high risk […]” The agreement details the data shared with Microsoft:
• User ID in the Séneca Information System.
• Users' first and last names.
• Role (teacher/student).
• School Code.
Both systems operate independently, and under no circumstances does Microsoft
have the ability to access Séneca's computer systems (PASEN), which
are properly protected under rigorous security measures.
Point 3: “Infringement considered very serious under the LOPD, art. 72.1, e) At no time is consent obtained from students or their families for the processing of data concerning health, religion, ideology, beliefs, sexual life, or racial origin. […] Clause 7.4 of the agreement states the following: “Under no circumstances will the Regional Ministry of Education and Sport provide the Collaborating Company with special categories of data as defined in Article 9 of the GDPR.” However, such data is being provided.


[…] It is important to note that uploading information (such as the example provided in the complaint) to the Microsoft cloud is not done as a data transfer to the company, but rather as part of providing a cloud storage service. Microsoft, as the provider of this service, undertakes to:
1. Use and process the uploaded data exclusively to provide educational cloud services, following the client's instructions and within the framework of legitimate business operations related to those services.

2. Not acquire any rights to the data uploaded by users, beyond what is strictly necessary to provide the aforementioned services.

3. Implement appropriate security measures for data protection, including encryption and key management.

4. Not disclose or provide access to the data to third parties without the client's express authorization or unless required by law.

5. Comply with current personal data protection regulations, assuming the role of data processor.

6. Delete or return Data uploaded to the cloud will be deleted upon completion of services or at the client's request, unless a legal obligation prevents it.

It should be noted that Microsoft, in its role as a cloud service provider, will not process data hosted on its platform to obtain detailed information on specific users. The company's commitment is strictly limited to the provision of educational cloud services and legitimate commercial operations related to those services, refraining from any analysis of data that involves the identification or extraction of individual personal information, in accordance with applicable privacy and personal data protection regulations.

Page 8 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal

Point 4: “Very serious infringement under the Spanish Data Protection Act (LOPD), art. 72.1, h) At no time before or after the creation of the accounts do the educational institutions fulfill the duty to provide information established in Article 13 of Regulation (EU) 2016/679. They do not provide the data subjects with the basic information established in art. 11 of the LOPD, nor do they provide them with an email address or other means that allows them to easily and immediately access the remaining information.”
• This point is addressed in Section 1.1.

[...]
Section 5: “Very serious infringement under the Spanish Data Protection Act (LOPD), art. 72.1, I) […] The European Commission does not consider many of these countries to have an adequate level of data protection.” […] I recall that the Court of Justice of the European Union (CJEU) invalidated Commission Decision (EU) 2016/1250 of 12 July 2016, known as the Privacy Shield, for data transfers to the United States.

[…] As reflected in the agreement, and to be concise regarding the location of data storage:
• Personal data processed under this agreement will be stored on the servers of the Regional Government of Andalusia, as well as on the servers of Microsoft Ireland Operations Limited, a collaborating company that provides Educational Cloud Services, headquartered in Dublin, Ireland, and on other servers located in third countries or international organizations, provided they comply with European Union data protection regulations. (Clause 6.2)
• If the processor must transfer personal data to a third country or an international organization, pursuant to Union law or the law of the Member State to which it is subject, it shall inform the controller of such lawful transfer, specifying the country of destination and the appropriate safeguards. (Clause 7.11.d)
• All transfers of personal data outside the European Union, the European Economic Area, The United Kingdom and Switzerland for providing Educational Cloud Services
will be governed by the Standard Contractual Clauses found in Annex 2 (Clause 7.12)
• Microsoft is certified under the Privacy Shield Framework and the commitments it entails, although Microsoft does not rely on the EU-U.S. Privacy Shield Framework as the legal basis for transfers of personal data in light of the judgment of the Court of Justice of the EU in case C-311/18. (Annex 1)
That is, the agreement stipulates that Microsoft is authorized to store and process personal data at any location where Microsoft or its subcontractors have facilities, provided they adhere to the stipulations concerning data transfers outlined in the Data Processing Addendum. This addendum, which forms part of Annex 2 of the agreement, standardizes the conditions under which may involve the transfer of personal data outside the European Economic Area (EEA) or Switzerland. Pursuant to this addendum, Microsoft undertakes to comply with the GDPR and ensure an appropriate level of protection for personal data.
Point 6: “Processing of photographs and audiovisual content. Clause 7.8 of the agreement
between Microsoft and the Ministry of Education states: “the data controller must also assess, in relation to the processing of photographs and audiovisual content, whether
these correspond to the purpose of the processing, being adequate, relevant and limited
to what is necessary in relation to the purposes for which they are processed, in consideration of the principle of data minimization set out in Article 5.1 c) of the GDPR.” At no time has the
Regional Ministry of Education established mechanisms for evaluating this content.[…]”
Page 9 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
In each educational center, the Organizational and Operational Regulations (ROF), integrated
within the Center Plan, stipulate the relevant provisions regarding the use of photographic and audiovisual material.
4. Further Information
In response to the request for further information, the following should be noted:
[…]
Point 3. Data relating to the implementation and use of Educational Services in the Cloud, indicating the number of centers, teachers, and students involved in their use.

As of January 19, 2024, we have over 1,000 centers participating in this agreement. This represents approximately 74,000 teachers/employees (including administrative staff), around 525,000 students, and the use of approximately 28.6 TB of storage. A table with more detailed data is shown below:
[…]
Point 5. […] There is no record of a data protection impact assessment prior to the signing of the agreement.

[…]
Point 7. Regarding clauses 3.4 and 3.5 of the Agreement:
[…] Early Adoption Programs (EAPs) are described in clauses 3.4 and 3.5 of the agreement.

There are two types of EAPs:
• Invitation-only programs (not public).

• Public beta programs with voluntary enrollment.

[…] Before clients can participate in a PAT, they must complete a test request and acknowledge that they are using a preliminary version of the relevant feature or functionality.

As described in clauses 3.5 and 4.2.3 of the agreement, the purpose and use of Early Adoption Programs is to test and verify beta functionalities.

The purpose of early access programs is to give clients the opportunity to use/test functionality as we develop it and provide feedback; this may include beta functionality, among other things.

To date, the Department of Educational Development and Vocational Training has not participated in any Early Adoption program.

[…]
Item 9. Copy of the clause(s) under which interested parties are informed of the creation of accounts and the use of the Educational Cloud Services (students, parents/legal guardians for children under 14, teachers, and administrative staff) regarding the processing of their personal data pursuant to Article 13 of the GDPR.

Page 10 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
During the enrollment process, detailed information is provided on data protection in accordance with the General Data Protection Regulation. It is clearly specified that
the student's personal data will be incorporated for the management of admissions and enrollment,
with the specific purpose of processing the corresponding applications. Furthermore, information is provided
on how to exercise the rights of access, rectification, and others, with respect to
their data. Therefore, a clear and transparent understanding is established with the students
regarding how and why their data will be retained and processed in the department's computer system.

[…] The services provided by Microsoft are designed to be used by educational institutions, which, in the exercise of their public functions, may process personal data
necessary for education without requiring explicit consent, as stipulated
by regulations such as the LOPD and the GDPR. The creation of accounts is justified within the applicable regulations, as can be verified in the document provided by the Spanish Data Protection Agency at the following link: https://www.aepd.es/documento/criterios-tratamiento-datos-personales-centros-educativos.pdf
Furthermore, it is worth noting that school administrations remain open and willing to answer any questions or requests for information from families, demonstrating a commitment to transparency and the active participation of parents/guardians in the educational process. Tutors, in their role as direct liaisons with families, play a crucial role in addressing and resolving any concerns or questions related to the platform and its privacy and security practices.
The content of the agreement is publicly available and accessible to anyone through this link: https://juntadeandalucia.es/sites/default/files/2021-01/Convenio_31.pdf
Point 10. Confirmation of whether Microsoft is provided with the IdEA credentials (username and/or password) of teachers and students.
Microsoft receives the IdEA code, as well as the first and last names of both teachers and students, excluding passwords. Access to Microsoft services is through the Junta de Andalucía's CAS (Centralized Authentication Service) identification system, providing an additional layer of security.

Item 11. Copy of the instructions and protocols for users within the educational community regarding the photographs and audiovisual content that are appropriate to include in the Educational Cloud Services and those that should not be included, based on this assessment.

Regarding this matter, the following actions have been taken:
a) Publication of the Agreement and its Addendum.
b) In accordance with the Andalusian Plan for Ongoing Teacher Training, the Teacher Resource Centers (CEPs) have provided various training activities related to the use of the Microsoft platform. Similarly, guidance has been extended to those centers that have selected the Working Group or In-School Training modalities, linked to their Training Plan, concerning this platform.

c) Furthermore, a web space has been enabled within the page

https://eaprendizaje.ced.juntaandalucia.es/microsoft365/
It has not been deemed necessary to issue additional specific instructions on privacy and
data protection policy, given that the agreement is protected under the existing legal framework in educational legislation.

[…] Page 11 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council Portal
Item 12. Whether special categories of personal data are processed in the Educational Services in the Cloud and, if not, instructions or protocols addressed to members of the educational community who use the system to prevent their inclusion.

[…] The agreement specifically mentions that the Ministry of Education and Sport (currently the Ministry of Educational Development and Vocational Training), as the data controller, will not provide Microsoft, in its role as data processor, with special categories of personal data as defined in Article 9 of the GDPR. This is clearly established in clause seven of the agreement (pages 6 and 7 of the agreement document). Therefore, the processing of special categories of personal data is not contemplated within the framework of this agreement.

Regarding “[…] instructions or protocols directed to members of the educational community who use the system to prevent their inclusion,” please refer to the response to Point 11.
Point 13. List of countries and companies receiving international data transfers.

Annex 1 of the agreement states that Microsoft will store data at rest only within the geo-area where the client has provisioned the service; not in others. In this case, since the client (the Regional Ministry of Educational Development and Vocational Training in this instance) has provisioned its tenant in the European Union, the applicable geo-area, where Microsoft stores data at rest, is precisely the European Union.

Additionally, Microsoft has introduced the EU Data Boundary, an initiative that ensures data retention within the European Union, not only for data at rest but also during processing. This measure aims to minimize data transfers outside the European Union, offering greater data privacy protection. More details about this initiative are available at the following link: https://learn.microsoft.com/es-es/privacy/eudb/eu-data-boundary-learn
Item 14. Indicate whether the content of Annex II and Annex 2 "Standard Contractual Clauses (Data Processor)" has been adapted to the new standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council. If applicable, a copy thereof.

Microsoft has updated the Standard Contractual Clauses in accordance with European Commission Decision 2021/914/EC. Specifically, it is the ‘Personnel-to-Person’ module, which can be downloaded from the following link: http://aka.ms/MS-SCC and is also attached as a PDF document (Microsoft General - Standard Contractual Clauses (Microsoft P2P) (9.15.2021).pdf).
The agreement includes detailed information on updates to the Standard Contractual Clauses, as well as the conditions associated with them. This information can be found in the section entitled “DPA Terms: Validity and Updates,” specifically under the subheading “Limits on Updates.”
Item 15. On page 24, third paragraph of the Agreement, the following is mentioned: "Products
that are not Microsoft products. Microsoft may make Products that are not Microsoft products available to the Customer through the Customer's use of the Online Services (for example, through a store or gallery, or as search results) or through a Microsoft online store (such as Microsoft Store for Business or Microsoft Store for Education).[...]". Information is required on whether these third-party services are currently being used by the Department, whether they are made available to teachers and/or students and, if so, whether authorizations are being managed in any way, whether measures are being taken to ensure that the legal guardians of children under 14 years of age grant or withhold consent for their use and are informed thereof. If the use of these services requires payment, information on whether it is possible to register bank cards or other payment methods.
Page 12 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
payment through the platform and, if so, the measures adopted for its appropriate use, taking into account that a large proportion of users are minors.

Currently, from the main Microsoft account management console, which affects all other accounts, the "Access to Office Store" option is not selected, therefore, it is not possible to access the Microsoft Store. [...]”
The following documentation was also attached:
− Copy of the “Report AJ-CED 2020/472 Collaboration Agreement to be signed between the Ministry of Education and Sport of the Regional Government of Andalusia and Microsoft for the provision of educational services in the cloud in public schools under the jurisdiction of the Ministry of Education and Sport of the Regional Government of Andalusia,” dated September 30, 2020.
− Copy of the “Validation Report from the General Technical Secretariat on the draft Collaboration Agreement to be signed between the Ministry of Education and Sport of the Regional Government of Andalusia and Microsoft for the provision of educational services in the cloud in public schools under the jurisdiction of the Ministry of Education and Sport of the Regional Government of Andalusia.” of the Regional Ministry of Education and Sport of the Andalusian Regional Government,” dated July 29, 2020.
− Copy of the “Addendum extending the Collaboration Agreement between the Regional Ministry of Education and Sport of the Andalusian Regional Government and Microsoft for the provision of cloud-based educational services in public schools owned by the Regional Ministry of Education and Sport of the Andalusian Regional Government,” dated November 25, 2022.
− Copy of the “Data Transfer Agreement” signed between Microsoft Ireland Operations Limited and Microsoft Corporation, dated September 13, 2021.
3. On October 30, 2024, as an extension of the request made by this Council on December 21, 2023, the Data Protection Officer was requested to submit the following information/documentation:
− Clause One of the Agreement relating to the The "Purpose of the Agreement" section states:
"The activities that the parties develop and, where applicable, agree upon, in accordance with clauses three and four, within the monitoring committee established in clause nine, shall also form part of the purpose of this agreement, provided that this does not entail the adoption of commitments other than those contemplated in clause four, in which case, it would have to be agreed upon through the appropriate addendum to this agreement."

" In this regard, clause 3.4 of the Agreement, which states “3.4. Possibility of testing and experimentally verifying the use and possibilities of different advanced technologies of Cloud-Based Educational Services applied to the digital transformation of the education sector, such as: big data, analysis of learning indicators, collaborative work, content personalization, cloud-based work, virtual reality, and augmented reality”:
a) Confirmation of whether the processing described in the aforementioned clause 3.4 is being carried out.

b) Confirmation of whether the processing described in clause 3.4 would include the data of students and/or their legal representatives.

Page 13 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
c) Confirmation of whether consent is being requested or is planned to be requested in the event that the treatments described in clause 3.4 are carried out, or what the legal basis for such treatments would be.

d) If it is considered that the legal basis for the treatments described in clause 3.4 derives from Additional Provision 23 of Organic Law 2/2006, of May 3, and therefore does not require consent, justification of said legal basis, taking into account the expressly experimental nature of the treatments.

e) Confirmation of whether the “personalization of content” mentioned in said clause requires or implies profiling of data subjects and whether it could involve automated individual decision-making.

− Copy of the clause(s) under which data subjects are informed of the processing of their personal data pursuant to Article 13 GDPR.

− Copy of the instructions or protocols addressed to users who are members of the educational community regarding the photographs and audiovisual content that are appropriate to include in the Educational Cloud Services and those that should not be included, based on said assessment.

− - Regarding international data transfers:
Clause 7.11.e) of the Agreement establishes, with respect to “Subcontracting,” that: “The
processor undertakes not to subcontract any of the services that form part of the subject matter of this agreement that involve the processing of personal data, except for
limited or auxiliary services related to the provision of Educational Cloud Services.
By formalizing this agreement, the controller authorizes the subcontracting provided for in Annex II of this agreement, in accordance with the current list of sub-processors provided by the processor.”

And in the aforementioned Annex II, it is stipulated with respect to “Data Transfers” that:
“Customer Data and Personal Data that Microsoft processes on behalf of the Customer
may not be transferred to, or stored and processed in, a geographic location except in accordance with the DPA Terms and the safeguards provided below in this
section. Subject to these safeguards, the Customer authorizes Microsoft to
transfer Customer Data and Personal Data to the United States or any
other country in which Microsoft or its Subprocessors operate and to store and
process Customer Data and Personal Data for the purpose of providing the Online Services, without prejudice to the other provisions of the DPA Terms.
All transfers of Customer Data and Personal Data outside the European Union, the European Economic Area, the United Kingdom, and Switzerland to provide the Online Services will be governed by the Standard Contractual Clauses found in Annex 2.
[…]”.
Furthermore, according to Annex 1 of the Agreement, section “Core Online Services”:
“Location of Inactive Customer Data for Core Online Services
For Core Online Services, Microsoft will store Customer Data in storage within certain significant geographic areas (each, a Geo-area)
Page 14 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council Portal
as indicated below unless otherwise specified in the specific terms of the Online Service:
◦ Office 365 Services. If the Customer provisions its tenant in Australia, Canada,
the European Union, France, Germany, India, Japan, South Africa, South Korea, Switzerland, the
United Kingdom, the United Arab Emirates, or the United States, Microsoft will store The following Customer Data at rest only within that Geoarea: (1) Exchange Online mailbox content (email body, calendar entries, and email attachment content), (2) SharePoint Online site content and files stored on that site, and (3) files uploaded to OneDrive for Business.

◦ Microsoft Intune Online Services. When the Customer provisions a Microsoft Intune tenant account for deployment in an available Geoarea, then, for that service, Microsoft will store Customer Data at rest within that specific Geoarea, except as specified in the Microsoft Intune Trust Center.

◦ Microsoft Power Platform Core Services. If the Customer provisions its tenant in Australia, Canada, Asia Pacific, France (excluding Microsoft Power Virtual Agents), India, Japan, the European Union, the United Kingdom, or the United States, Microsoft will store Customer Data at Rest will only be stored within that Geoarea, except as specified in the “Data Location” section of the Microsoft Power Platform Trust Center.

◦ Microsoft Azure Core Services. If the Customer configures a specific service for deployment within a Geoarea, then for that service, Microsoft will store Customer Data at Rest within the specified Geoarea. Certain services may prevent the Customer from configuring the deployment in a specific data center Geoarea and may store backups in other locations. See the Microsoft Trust Center (which Microsoft may update from time to time, but to which Microsoft will not add exceptions regarding existing services in the general release) for more details.
• Microsoft Cloud App Security. If the Customer provisions its tenant in the European Union or the United States, Microsoft will store inactive Customer Data only within that Geo-area, except as described in the Microsoft Cloud App Security Trust Center.

• Microsoft Dynamics 365 Core Services. When the Customer provides a Dynamics 365 Core Service for deployment in an available Geo-area, then, for that service, Microsoft will store Customer Data at rest within that specific Geo-area, except as described in the Microsoft Dynamics 365 Trust Center.

• Microsoft Defender Advanced Threat Protection Services.

When the Customer provisions a Microsoft Defender Advanced Threat Protection tenant for deployment in an available Geo-area, then, for that service, Microsoft will store Customer Data at rest within that specific Geo-area, except as specified in the Microsoft Defender Advanced Threat Protection Trust Center.

Page 15 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council Portal
◦ Microsoft Threat Protection. When the Customer provisions a Microsoft Threat Protection tenant for deployment in an available geo-area, then, for that service, Microsoft will store Customer Data at rest within that specific geo-area, except as specified in the Microsoft Threat Protection Trust Center.
The report from the Director General of Advanced Technologies and Educational Transformation, dated January 22, 2024, states that: “Annex 1 of the agreement indicates that Microsoft will store data at rest only within the geo-area where the customer has provisioned the service; not in others.” In this case, given that the client (the Regional Ministry of Educational Development and Vocational Training in this instance) has its tenant provisioned in the European Union, the applicable geo-area, where Microsoft stores the data at rest, is precisely the European Union.
a) Therefore, confirmation as to whether or not the personal data for which the Regional Ministry of Educational Development and Vocational Training is responsible, under the Agreement signed with Microsoft, is transferred to third countries outside the European Economic Area.
b) If applicable, a list of the countries and companies receiving the international data transfers.
c) Indication as to whether the content of Annex II and Annex 2, “Standard Contractual Clauses (Data Processor),” of the agreement signed between the Regional Ministry of Education and Sport and Microsoft Ireland Operations Limited has been adapted to the new standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914 of
4 June 2021 regarding standard contractual clauses for the transfer of
personal data to third countries in accordance with Regulation (EU) 2016/679
of the European Parliament and of the Council. If applicable, a copy thereof.

d) If applicable, what safeguards and/or measures are currently in place to ensure the legal validity of transfers to third countries?

4. In response to the above request, on 11 November 2024, the Council received a report from the Data Protection Officer (DPO) to which was attached a report from the Director General of Innovation and Teacher Training, which, among other things, stated:
“[…] Point 1. Clause 1 of the Agreement relating to the “Purpose of the Agreement”
stipulates:
[…]
a) The processing described in clause 3.4 of the agreement is not being carried out nor is it planned.
b) As the processing that is the subject of this request for information is not taking place, and is not
c) Since the processing activities covered by this information request have not occurred and are not covered by the agreement, their scope has not been determined.

d) Since the processing activities covered by this information request have not occurred and are not covered by the agreement, this does not apply.

Page 16 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
e) Since the processing activities covered by this information request have not occurred and are not covered by the agreement, this does not apply.

To date, the Ministry of Educational Development and Vocational Training has not participated in any Early Adoption program and does not intend to do so.

Point 2: Copy of the clause(s) under which interested parties are informed of the processing
During the enrollment process, detailed information is provided on data protection in accordance with the General Data Protection Regulation (GDPR). It is clearly specified that the student's personal data will be incorporated for the management of admission and enrollment, with the specific purpose of processing the corresponding applications. Furthermore, information is provided on how to exercise the rights of access, rectification, and others with respect to their data. Therefore, a clear and transparent understanding is established with students regarding how and why their data will be retained and processed in the Ministry's computer system.

[…] The Ministry of Educational Development and Vocational Training is currently working to include the necessary information on the processing of personal data, pursuant to Article 13 of the GDPR, in the student enrollment envelope. This action will be available
during the enrollment process for the 2025/2026 academic year.

Point 3: Copy of the instructions or protocols addressed to users who are members
of the educational community regarding the photographs and audiovisual content that are appropriate to include in the Educational Cloud Services and those that should not be included,
as a result of said assessment.

As previously communicated to the CTPDA:
Regarding this matter, the following actions have been taken:

a) Publication of the Agreement document and Addendum to it https://juntadeandalucia.es/sites/default/files/2021-01/Convenio_31.pdf

b) In accordance with the Andalusian Plan for Ongoing Teacher Training, the Teacher Training Centers (CEPs) have provided various training activities related to the use of the Microsoft platform. Similarly, guidance has been extended to those centers that have selected the Working Group or In-Center Training modalities, linked to their Training Plan, regarding this platform.

c) Furthermore, a web space has been enabled within the page https://www.juntadeandalucia.es/educacion/eaprendizaje/microsoft365/

d) All Andalusian educational centers are developing their Digital Action Plan, a strategic document that details, in the different lines of action, the coverage of digital educational services in the cloud. (has established mechanisms for evaluating this content)
Page 17 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
It has not been deemed necessary to issue additional specific instructions on privacy and data protection policy, given that the agreement is protected under the existing legal framework in educational legislation.

In each educational center, the Organization and Operation Regulations (ROF), integrated within the Center Plan, establish mechanisms for evaluating this content through the provisions relevant to the use of photographic and audiovisual material. The same applies to the Digital Action Plans of the educational centers.

Furthermore, during October 2024, the document “Guide on the Protection of Personal Data for Educational Centers in Andalusia” (https://www.ctpdandalucia.es/sites/default/files/inline-files/guiaproteccion-datos-centros-educativos-andalucia.pdf) was distributed to all Andalusian teachers via the Séneca messaging system.

In addition to the above, the Regional Ministry of Educational Development and Vocational Training is working to publish instructions for all Andalusian teachers regarding the handling of photographs and audiovisual content in Educational Cloud Services. This will be available in the second term of the 2024/2025 academic year.

4. Regarding international data transfers
a) Therefore, confirmation as to whether or not the personal data under the responsibility of the Regional Ministry of Educational Development and Vocational Training, pursuant to the Agreement signed with Microsoft, are transferred to third countries outside the European Economic Area.

Generally, personal data is stored and processed exclusively within the EU/EFTA territory. This commitment is called the “EU Data Boundary” and constitutes an additional protection that Microsoft has been gradually deploying in the service since 2023. The only exceptions to the EU Data Boundary are documented in the product terms (final sections of this webpage).

EU Data Boundary
Location of Customer Data for EU Data Boundary Services
For EU Data Boundary Services, Microsoft will store and process Customer Data and Personal Data within the EU Data Boundary as detailed below. Customer must configure EU Data Boundary Services as follows:
For Azure, Customer must deploy the service into an Azure region located within the
EU Data Boundary. See Data Residency in Azure (https://azure.microsoft.com/explore/
global-infrastructure/data-residency) for more information. For services that do not
enable deployment into a specified Azure region, Customer must follow the instructions
tions at Configuring Azure non-regional services for the EU Data Boundary (https://
learn.microsoft.com/privacy/eudb/eu-data-boundary-configure-azure-nonregional-ser-
vices).
For Dynamics 365 and Power Platform, if Customer provisions a tenant with a bi-
lling address in the EU or EFTA, that tenant will be in-scope for the EU Data Boundary if
Customer also creates all of its environments within a Geo inside the EU Data Bounda-
ry.
Página 18 de 73. Resolución RPS-2025/082, de 02 de diciembre - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Documento apto para ser publicado en el Portal del Consejo
For Microsoft 365, if Customer provisions a tenant in the EU or EFTA, that tenant will
be in-scope for the EU Data Boundary, except for those tenants where Customer has
also purchased the Microsoft 365 MultiGeo Capabilities add-on that enables customers
to expand Microsoft 365 tenant presence to multiple geographic regions or countries
(https://learn.microsoft.com/microsoft-365/enterprise/microsoft-365- multi-geo?
view=o365-worldwide).
Use of EU Data Boundary Services may result in limited transfers of Customer Data or Per-
sonal Data outside the EU Data Boundary, as set forth below and further detailed in trans-
parency documentation for the EU Data Boundary located at https://learn.microsoft.com/
en-us/privacy/eudb/eu-data-boundary-learn or successor location. Any such transfers will
be conducted in accordance with the Data Protection Addendum and the Product Terms.
• Remote Access. Microsoft personnel located outside the EU Data Boundary may remote-
ly access data processing systems in the EU Data Boundary as necessary to operate,
troubleshoot, and secure the EU Data Boundary Services.
• Customer-Initiated Transfers. Customers may initiate transfers outside the EU Data
Boundary, such as by accessing EU Data Boundary Services from locations outside the
EU Data Boundary, sending an email to a recipient located outside the EU Data Bounda-
ry, or use of EU Data Boundary Services in combination with other services not in the EU
Data Boundary.
• Protecting Customers. Microsoft transfers limited data outside of the EU Data Boundary
as necessary to detect and protect Customers against security threats.
• Directory Data. Microsoft may replicate limited Microsoft Entra directory data from
Microsoft Entra ID (including username and email address) outside the EU Data Bounda-
ry to provide the service.
• Network Transit. To reduce routing latency and to maintain routing resiliency, Microsoft
uses variable network paths that may occasionally result in transit of data outside the
EU Data Boundary.
• Service and Platform Quality and Management. When required to monitor and maintain
service quality or to ensure accuracy of statistical measures of service use or performan-
ce, pseudonymized Personal Data may be transferred outside of the EU Data Boundary.
• Service-Specific Transfers. See transparency documentation referenced above for infor-
mation about transfers applicable to specific EU Data Boundary Services.
b) En su caso, relación de países y compañías destinatarias de las transferencias
internacionales de datos.
La relación completa se recoge en el documento publicado en esta página: Service Trust
Portal
c) Indicación si se ha adaptado el contenido del Anexo II y del Anexo 2 “Cláusulas
Contractuales Tipo (encargado del tratamiento)” del convenio suscrito entre la
Consejería de Educación y Deporte y Microsoft Ireland Operations Limited a las
nuevas cláusulas contractuales tipo aprobadas por la Decisión de Ejecución (UE)
2021/914 de la Comisión de 4 de junio de 2021 relativa a las cláusulas contrac-
tuales tipo para la transferencia de datos personales a terceros países de confor-
midad con el Reglamento (UE) 2016/679 del Parlamento Europeo y del Consejo.
En su caso, copia del mismo.
Sí, como se indica en el DPA, las exportaciones de datos personales se realizan de confor -
midad con las cláusulas contractuales tipo aprobadas por la Comisión European en la Deci-
sión 2021/914 de 4 de junio de 2021. En concreto, se trata de las cláusulas según el módu-
lo ‘transferencia de encargado a encargado’, formalizadas entre Microsoft Ireland Opera-
Página 19 de 73. Resolución RPS-2025/082, de 02 de diciembre - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Documento apto para ser publicado en el Portal del Consejo
tions Limited (Irlanda) y Microsoft Corporation (Estados Unidos). Una copia de las mismas
está disponible en este enlace: http://aka.ms/ms-scc
d) En su caso, ¿Qué garantías y/o medidas se adoptan actualmente para asegurar
la validez legal de las transferencias a terceros países?
Microsoft ha adoptado salvaguardas adicionales, tal y como se estipula en el Apéndice C
“Addendum de Garantías Adicionales”, con esta finalidad”.
5. Como ampliación a la respuesta recibida, el 11 de noviembre de 2024, dado que los links facili-
tados no se podían abrir, este Consejo, el 20 de noviembre de 2024, solicitó al DPD la siguiente
documentación:
 Copia del listado completo de países y compañías destinatarias de las transferencias
de datos a terceros países.
 Copia de las nuevas cláusulas contractuales tipo aprobadas por la Decisión de Ejecu-
ción (UE) 2021/914 de la Comisión de 4 de junio de 2021 relativa a las cláusulas con-
tractuales tipo para la transferencia de datos personales a terceros países de confor-
midad con el Reglamento (UE) 2016/679 del Parlamento Europeo y del Consejo.
 Copia del Apéndice C “Addendum de Garantías Adicionales”.
6. En respuesta al citado requerimiento, el 26 de noviembre de 2024, se recibió informe del DPD
adjuntando informe del Director General de Innovación y Formación del Profesorado donde, en-
tre otras cuestiones, informaba:
“Punto 1 a): En relación a la solicitud de remisión del documento “Relación de países y
compañías destinatarias de las transferencias internacionales de datos.”, se adjunta docu-
mento solicitado con nombre “Microsoft General - Online Services Subprocessors List
(07.2.2024).pdf” , descargado desde el enlace https://servicetrust.microsoft.com/Documen-
tPage/403b812e-3291-4398-ba73-101e8036ef3b
Punto 1 b): En relación a la solicitud de remisión del documento “Cláusulas Contractuales
Tipo”, se adjunta documento solicitado con nombre “Microsoft General - Standard Contrac-
tual Clauses (Microsoft P2P) (9.15.2021).pdf” descargado desde el enlace http://aka.ms/ms-
scc
Punto 1 c): En relación a la solicitud de remisión del documento “Addendum de Garantías
Adicionales”, se adjunta documento solicitado con nombre “MicrosoftProductandServices-
DPA(WW)(Spanish)(Jan022024) (CR).pdf”
Asimismo, se adjuntaba:
- Copia del “Data Transfer Agreement (P2P) betwen Microsoft Ireland Operations Limited and
Microsoft Corporation”, de fecha 13 de septiembre de 2021.
- Copia de la “Addendum de Protección de Datos de los Productos y Servicios de Microsoft” ac-
tualizada el 2 de enero de 2024.
Página 20 de 73. Resolución RPS-2025/082, de 02 de diciembre - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Documento apto para ser publicado en el Portal del Consejo
Quinto. Acuerdo de inicio de procedimiento sancionador. (arts. 68 LOPDGDD; Art. 64
LPAC).
1. El 2 de diciembre de 2024 el director del Consejo dictó Acuerdo de Inicio de procedimiento sancio-
nador contra la Dirección General de Innovación y Formación del Profesorado (Consejería de De-
sarrollo Educativo y Formación Profesional), con CIF NNNNN, por las presuntas infracciones:
− Infracción tipificada en el artículo 83.4.a) RGPD y calificada a efectos de prescripción como
grave en el artículo 73.d) LOPDGDD por vulneración del artículo 25 RGPD referido a la pro-
tección de datos desde el diseño y por defecto en relación con la falta de adopción de medi-
das organizativas que resulten apropiadas para aplicar de forma efectiva los principios de
protección de datos desde el diseño y por defecto, en los términos exigidos por el artículo
25 RGPD en referencia a la falta de medidas para minimizar el riesgo de que los usuarios in-
cluyan categorías especiales de datos en el sistema.
− Infracción tipificada en el artículo 83.4.a) RGPD y calificada a efectos de prescripción como
grave en el artículo 73.d) LOPDGDD por vulneración del artículo 25 RGPD referido a la pro-
tección de datos desde el diseño y por defecto en relación con la falta de adopción de medi-
das organizativas que resulten apropiadas para aplicar de forma efectiva los principios de
protección de datos desde el diseño y por defecto, en los términos exigidos por el artículo
25 RGPD en referencia a la falta de medidas para minimizar el riesgo de que los usuarios in-
cluyan imágenes y material audiovisual inapropiado en el sistema.
− Infracción tipificada en el art. 83.5.b) RGPD y calificada a efectos de prescripción como muy
grave, en el artículo 72.1.h LOPDGDD por vulneración del articulo 13 RGPD referido a la in -
formación que deberá facilitarse cuando los datos personales se obtengan del interesado en
relación con la omisión del deber de informar a los interesados acerca del tratamiento de
sus datos personales conforme a lo dispuesto en el artículo 13 RGPD.
− Infracción tipificada en el art. 83.5.c) RGPD y calificada a efectos de prescripción como muy
grave en el artículo 72.l) LOPDGDD por vulneración de los artículos 44 a 49 RGPD referidos a
las transferencias de datos personales a terceros países u organizaciones internacionales en
relación con la transferencia internacional de datos personales a un destinatario que se en-
cuentre en un tercer país o a una organización internacional, cuando no concurran las ga-
rantías, requisitos o excepciones establecidos en los artículos 44 a 49 del RGPD.
− Infracción tipificada en el art. 83.4.a) RGPD y calificada a efectos de prescripción como leve
en el artículo 74.l) LOPDGDD por vulneración formal del artículo 30 RGPD referido a la falta
de información en el registro de actividades de tratamiento de la relativa a las transferen-
cias internacionales de datos.
− Infracción tipificada en el art. 83.4.a) RGPD y calificada a efectos de prescripción como gra-
ve en el artículo 73.t) LOPDGDD por vulneración del artículo 35 RGPD referido a la evalua-
ción de impacto relativa a la protección de datos en relación con el uso el uso de los Servi-
cios Educativos en la Nube sin haber llevado a cabo la evaluación de impacto exigida en el
artículo 35 RGPD.Conversely, the initial agreement did not find any violations regarding some of the reported facts, as explained in the legal grounds of this resolution for a better understanding of the claim as a whole.


2. The initiation agreement was notified to the entity on December 2, 2024, and the entity submitted
allegations which, in summary, stated the following:
Page 21 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
“[…] 4. Allegations
Firstly, it should be noted that in response to the various requests for information and subsequent
requests for further information submitted by this Council, the Ministry of Educational Development and Vocational Training has provided answers through its Data Protection Officer, supplying the requested data at all times and acting
diligently.
Secondly, since the signing of the Agreement in 2020, the degree of implementation and use of
the Microsoft platform Teams has experienced exponential growth, allowing its adoption in more than 1,000 schools throughout Andalusia, with over 82,000 teacher accounts and nearly 561,000 student accounts, thanks to its ease of use and satisfactory user experience, as reflected in the following table:
[…]
Considering this context of use, and always prioritizing the security and data protection of Andalusian students, the immediate suspension of the service to meet the Council's requirements would seriously harm the students' educational process. Certain organizational aspects of the school environment, which must be established in a planned manner and in accordance with the school year, would be considered serious infractions.

It should be noted that since 2020, schools have been developing and implementing new teaching and pedagogical methodologies around these digital tools and resources, which implies to directly impact and modify the teaching and learning processes, as well as student assessment procedures. This new methodological paradigm, if altered immediately, could produce serious distortions and harm to the education of minors and, therefore, have as a direct consequence an unfavorable and adverse effect on their academic and personal development, with very negative consequences for their school progress.

Furthermore, the lack of its own high-quality and technologically powerful resources on the part of the Administration, such as those provided by Microsoft, makes it necessary to continue with the services guaranteed through the aforementioned agreement. Currently, there is no alternative from this Administration that guarantees, under equal conditions, the educational service provided to 561,000 students, 82,000 teachers, and 1,000 educational centers through the signed collaboration agreement, the corporate tools being clearly insufficient compared to the potential that Microsoft has been successfully providing.

Therefore, ceasing to provide these services immediately would have a completely negative impact on the education of Andalusian students, and at the same time, very detrimental effects from the point of view of teaching, learning, and assessment processes, which could undermine the right to an education with full guarantees of quality and equity, as basic principles of the education system.

Notwithstanding the above, we must highlight that in the addendum signed on November 26, in section IV of the preamble, both parties commit to: “…/… continue with the technical work initiated since July 2024 for the implementation of a new agreement that contributes to updating and improving the terms and clauses of the current one…” Both parties are firmly committed to signing a new agreement in July 2025 that provides a satisfactory response and solves the problems.
Page 22 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
More and deficiencies detected by the Transparency and Data Protection Council of Andalusia.

In relation to the proven facts referred to by the Council, the following allegations are made by the Ministry
competent in matters of education:
FIRST.- [In relation to the alleged commission of infringements 2.a, 2.b and 2.c]
Regarding data protection from the design of the actions and in relation to the
adoption of organizational measures that are appropriate to effectively apply
the principles of data protection from said design and by default, in the terms required
by Article 25 GDPR from the General Directorate competent in matters of Innovation, since the course In 2024-2025, appropriate technical and organizational measures are being developed to limit the high risk of system users introducing special categories of data into the Microsoft Teams platform.

In this regard, during the 2022-2023 and 2023-2024 academic years, the Regional Ministry responsible for education specified the measures for developing the digital competence of schools, teachers, and students through the Resolution of September 20, 2022, issued by the then Directorate General for Advanced Technologies and Educational Transformation, regarding measures to promote digital competence in publicly funded schools within the framework of the #CompDigEdu Territorial Cooperation Program. These measures include:

• Ensuring that all schools have a Digital Plan integrated into their Educational Project that structures the organizational and academic strategies undertaken collectively to transform the school into a digitally competent educational organization.”
As a complement to the measure described above, the Regional Ministry with jurisdiction over education issued Resolutions of February 24, 2022, August 2, 2022, and October 10, 2024, from the Directorate General for Teaching Staff and Human Resources Management, which launched a public call for applications for the temporary assignment of tenured teaching staff in Andalusia for the development of the #CompDigEdu territorial cooperation program, within the framework of component 19, 'National Digital Skills Plan,' of the Recovery and Resilience Facility.
The purpose of these actions was the selection and appointment of Technical Teaching Advisors (hereinafter TTAs), distributed among the Teacher Resource Centers and the Central Services of the Regional Ministry to support the design and implementation of the Digital Action Plan. the publicly funded schools in our community. In the current
school year, and with the aim of continuing to promote the transformation of schools into digitally
competent educational organizations, the Technical Teaching Advisory Offices support schools in the design and development of a personalized Digital Action Plan tailored to their school community, advising and providing guidance in accordance with the Organic Law on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD) and the provisions of the General Data Protection Regulation (GDPR),

with special attention to Article 25 and Article 13, providing guidelines to minimize the
risk of users including special categories of data, as well as the use of inappropriate images and audiovisual material, while also providing them with information on the
processing of personal data.

Page 23 of 73. Resolution RPS-2025/082, of December 2nd - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
Among the functions of the Digital Action Teams (ATDs) are the following:
• To support educational centers as mentors in the design, implementation, and evaluation of the Digital Action Plan.

• To promote training activities in accordance with the guidelines established in the Digital Action Plan that allow for the improvement of teachers' digital competence.

• To participate in the organization of training activities on educational digital competence.

• To encourage the positive use of Information and Communication Technologies and promote tools that optimize digital security with the aim of identifying and preventing potential risks and threats.

As support resources, the ATD network has created guides for the development of the Digital Action Plan (accessible from the following link). URL:

https://www.juntadeandalucia.es/educacion/portals/web/transformacion-digital-educativa/
contents/-/contents/detailed_guides_for_the_development_of_the_pad) proposing different
Lines of Action and tasks for their achievement based on the different descriptors
that make up the DigCompOrg framework, thus contributing to establishing standards and
instructions for the responsible use of educational platforms used in teaching, guaranteeing the privacy of personal data and the non-disclosure of data
of a special nature. Furthermore, in the communications and training sessions that the ATD
maintains with schools, the Council's "Guide on the protection of personal data
for educational centers in Andalusia" is presented (accessible from the following URL: guia-
proteccion-datos-centros-educativos-andalucia.pdf).
These recommendations can be consulted in the Digital Plans of Schools Each of the Andalusian educational centers (accessible from the following URL: https://seneca.juntadeandalucia.es/seneca/descargas/codigo_centro/pad, for example https://seneca.juntadeandalucia.es/seneca/descargas/21000759/pad), and the Educational Inspectorate will be responsible for supervising these plans for their certification. In each educational center, the Organizational and Operational Regulations (ROF), integrated within the Center Plan, will reflect the provisions relevant to the use of photographic and audiovisual material established in the Center's Digital Action Plan.Furthermore, and linked to the training related to the development of the Digital School Plan, Andalusian teachers have access to online training activities to enhance their skills in aspects related to the Digital Teaching Competence Framework, and specifically in aspects related to the effective application of data protection principles.

In this regard, as of the date of this document, the number of Andalusian teachers with some level of accreditation of digital teaching competence according to the #DigCompEdu Reference Framework is over 80,000, thus guaranteeing the formal acquisition of knowledge on these aspects.

[…] In relation to this matter, the following additional actions have been taken:
a) Publication of the Agreement document and its Addenda
Page 24 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
b) The Teacher Resource Centers (CEPs) have provided various training activities related to the use of the Teams platform. Similarly, support has been extended to those centers that have selected the training modalities of Working Group or In-School Training, regarding this platform.

c) Furthermore, a web space has been enabled within the page

https://www.juntadeandalucia.es/educacion/eaprendizaje/gsuite
Considering the actions taken, it has not been deemed necessary to issue
specific additional instructions on privacy and data protection policy, given that the
agreement is protected under the existing legal framework in educational legislation.

In relation to this matter, it is worth recalling what was indicated in previous reports submitted to
this Council:
“[…] Furthermore, in the legal sphere, it should be noted that the processing of data is
covered by the following legitimate grounds, and therefore does not require the consent of
the data subjects or their legal representatives:
Additional Provision 23 of Organic Law 2/2006, of May 3, according to which: “Educational centers may collect the personal data of their students that are necessary
for the exercise of their educational function. This data may refer to the origin and family and social environment, personal characteristics or conditions, the development and results of their schooling, as well as any other circumstances whose knowledge is necessary for the education and guidance of the students.”
Finally, it should be noted that in addition to the corrective actions being developed in the areas of information and communication on the one hand, and in the ongoing professional development of teachers in the area of digital teaching competence on the other, a specific information document is being prepared to inform interested parties about the processing of their personal data in accordance with the provisions of Article 13 GDPR, and which will be included in the enrollment envelope for the 2025/2026 academic year.
SECOND.- [Regarding the alleged commission of infringement 2.d]
Through a report dated November 12, 2024, the General Directorate responsible for innovation informed the Council, and in relation to the alleged infringement referenced above, of the Next:

“Generally, personal data is stored and processed exclusively within the EU/EFTA territory. This commitment is called the “EU Data Boundary” and constitutes additional protection that Microsoft has gradually deployed in the service since 2023. The only, limited exceptions to the EU Data Boundary are documented in the product terms (last points on this webpage).”
Later, in the analysis carried out by that Council, they indicate the following: “However, this point has not been documented.” It should be noted that, through the third extension of information requested by that Council, the Regional Ministry has provided the following supporting documentation:
Page 25 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
• Regarding the request for submission of the document “List of countries and companies receiving international data transfers,” the requested document is attached, named “Microsoft General - Online Services Subprocessors List (07.2.2024).pdf,” downloaded from the link https://servicetrust.microsoft.com/DocumentPage/403b812e-3291-4398-ba73-101e8036ef3b
• Regarding the request for submission Regarding the document “Standard Contractual Clauses”, the requested document, titled “Microsoft General - Standard Contractual Clauses (Microsoft P2P) (9.15.2021).pdf”, downloaded from http://aka.ms/ms-scc, is attached.

Regarding the request for the document “Addendum of Additional Guarantees”, the requested document, titled “MicrosoftProductandServicesDPA(WW) (Spanish) (Jan022024)(CR).pdf”, is attached.

• Furthermore, as indicated in the DPA, exports of personal data are carried out in accordance with the standard contractual clauses approved by the European Commission in Decision 2021/914 of 4 June 2021. Specifically, these are the clauses under the "processor-to-processor transfer" module, formalized between Microsoft Ireland Operations Limited (Ireland) and Microsoft Corporation (United States).

A copy of these clauses is available at this link: http://aka.ms/ms-scc
Finally, for the provision of the service, Microsoft has adopted additional safeguards, as stipulated in Appendix C, "Addendum of Additional Guarantees," for this purpose.

In summary, the various information requests from the Council have been answered by providing supporting documentation that substantiates the arguments presented, scrupulously complying with the provisions of the GDPR and, more specifically, Articles 44 to 49.
THIRD.-[Regarding the alleged commission of infringement 2.e]
Pursuant to Article 30 of the GDPR and considering the Council's opinion on the lack of information in the register of processing activities concerning international data transfers, the Directorate General responsible for innovation will register a new specific data processing activity in the Register of Processing Activities of the Regional Ministry, related to the execution of the COLLABORATION AGREEMENT BETWEEN THE REGIONAL MINISTRY OF EDUCATION AND SPORT OF THE REGIONAL GOVERNMENT OF ANDALUSIA AND MICROSOFT IRELAND OPERATIONS LIMITED FOR THE IMPLEMENTATION PROVISION OF CLOUD SERVICES FOR EDUCATIONAL CENTERS IN PUBLIC SCHOOLS OWNED BY THE MINISTRY OF EDUCATION AND SPORT OF THE REGIONAL GOVERNMENT OF ANDALUSIA
FOURTH.- [Regarding the alleged commission of infringement 2.f]
Pursuant to Article 35 GDPR concerning the data protection impact assessment related to the use of the Microsoft Teams platform, the competent Ministry for education reiterates to the Council the information provided in the various reports submitted in response to the different requests for information or clarification, in which it is indicated that no data protection impact assessment was carried out prior to the signing of the Agreement. Currently, the Regional Ministry of Educational Development and Vocational Training is already conducting the impact assessment study related to the
Page 26 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
data protection in order to establish a new collaboration agreement with the cloud-based educational services provider Microsoft, which includes a model of the controller-processor clause provided for in Executive Decision 2021/914 of the
European Commission on standard contractual clauses for the transfer of personal data to third countries pursuant to EU Regulation 2016/679.

(This document is suitable for publication on the Council's Portal.) We conclude by highlighting the following key points:
FIRST.- The Regional Ministry of Educational Development and Vocational Training is aware
of the need to adapt the current agreement to the guidelines issued by the Andalusian Council for Transparency and Data Protection, demonstrating this commitment in the
commitments made in the extension addendum signed on November 26, 2024. Both parties have committed to signing a new agreement for this purpose. The commitment to sign this agreement is July 2025, after the end of the school year,
in order to avoid interference with the teaching and learning processes of the students and with the organization and operation of the schools. A new agreement will be implemented in September of the 2025/2026 academic year, addressing the requirements issued.

SECOND.- The lack of its own resources of such high quality and technological power on the part of the Administration, compared to those provided by Microsoft, makes it necessary to continue with the services guaranteed through the aforementioned agreement. Currently, there is no alternative on the part of this Administration that would enable, under equal conditions, the educational service provided to 561,000 students, 82,000 teachers, and 1,000 educational centers thanks to the signed collaboration agreement, with the corporate tools being clearly insufficient compared to the potential that Microsoft has been successfully providing from a pedagogical point of view. This new
methodological paradigm of Information and Communication Technologies, if it were
eliminated immediately, could produce serious distortions and harm in the education
of minors and, therefore, have as a direct consequence an unfavorable
and adverse effect on their academic and personal development with very negative consequences
for their school progress.Therefore, if these services were to cease immediately, it would cause a completely negative and difficult-to-compensate impact on the education of Andalusian students, and at the same time, serious and highly detrimental effects from the point of view of the planning of teaching, learning, and assessment processes, which could undermine the right to an education with full guarantees of quality and equity, as basic principles of the education system, in order to avoid a digital divide that would undoubtedly hinder equal opportunities to achieve full personal development and equal rights that help overcome any discrimination and universal access to education, as a compensatory element.

The magnitude of this challenge requires that the necessary changes be addressed with a margin of progression and planning to avoid causing further harm to the students.”
Sixth. Proposed resolution. (Art. 89 LPAC).
1. Once the procedural investigation was completed, the corresponding proposed resolution was drawn up, establishing a ten-day period for submitting allegations, in accordance with Article 89.2 LPACAP and in relation to Article 73.1 of the same law.
2. The proposed resolution was notified to the body involved on November 12, 2025, which submitted allegations which, in summary, stated the following:
Page 27 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication in the Council Portal
“[…] In view of the above, the following allegations are made:
FIRST.- ON THE ALLEGED INFRINGEMENTS OF ART. 25 GDPR (Special Categories and Images).
The Proposal alleges infringements due to the lack of minimization measures (Art. 25).
This Department reiterates that, as stated in the previous statement of allegations, relevant organizational measures have been implemented to mitigate these risks. These measures are not generic, but rather constitute this Administration's specific mechanism for permeating the data protection culture in an environment with thousands of self-employed users:
1. The deployment of Digital Action Plans (DAPs) in the centers, which require the centers to analyze their use of the tools.

2. The work of the network of Technical Teaching Advisory Offices (ATD), which act as supervisory and control delegates, advising schools on the responsible use of the platforms, including the privacy implications.

3. The accreditation of more than 80,000 teachers in digital competence, which includes specific training in the secure handling of information.

4. The existence of the resources and information portal https://www.juntadeandalucia.es/educacion/eaprendizaje/microsoft365/.

We understand that the Proposal considers these measures insufficient a priori. However, they are the main and most effective organizational means for applying Article 25 "by default" in a decentralized educational environment. This Department is aware that the implementation of additional technical measures and specific minimization protocols (which the Instruction notes are lacking) is a direct result of the Data Protection Impact Assessment (DPIA) that has already been planned (as detailed in Allegation Five). Therefore, the complete correction of this infringement is intrinsically linked to the timeline for carrying out said DPIA, for which the Proposal itself grants us a deadline.

SECOND.- ON THE ALLEGED INFRINGEMENT OF ARTICLE 13 GDPR (Duty to Inform).

We reiterate what has already been stated: this Department has planned the correction of this formal omission. The specific information document is being prepared to inform interested parties in accordance with Article 13 GDPR, with the commitment to include it in the registration envelope. This planning demonstrates the commitment to correct the infringement in the most effective and universal manner possible, ensuring that all new and existing interested parties are duly informed at the time of re-enrollment.

THIRD.- REGARDING THE ALLEGED INFRINGEMENT OF ARTICLE 30 GDPR (Record of Processing Activities).
This Ministry reiterates what was stated in its statement of objections of December 18, 2024: the formal omission in the existing Record of Processing Activities is acknowledged, and immediate rectification will be carried out. This rectification will be implemented through the creation of a new processing activity specific to the Agreement, which will include all the sections required by Article 30, including, in detail, those relating to international transfers, destination countries, and the safeguards applied.

FOURTH.- REGARDING THE ALLEGED INFRINGEMENT OF ARTICLES 44-49 GDPR (International Transfers).

The Proposed Resolution bases the infringement and the suspension of data flows on an alleged lack of adequate safeguards, considering the Standard Contractual Clauses (SCC) provided insufficient and characterizing the information as "contradictory".

Page 28 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
This Department must oppose this legal conclusion, since the architecture of international data transfers by the data processor (Microsoft) strictly complies with Chapter V of the GDPR through a cascading system of safeguards that covers all possible scenarios, as detailed below:
1. Transfers to the USA: Coverage by Adequacy Decision (Art. 45 GDPR). It is a well-known and legally binding fact that the European Commission adopted Implementing Decision (EU) 2023/1795 of 10 July 2023, concerning the adequacy of the level of protection of personal data under the EU-US Data Privacy Framework. Microsoft Corporation is certified on the official list of said Framework.

Consequently, any data transfer to the parent company in the United States (the primary destination of the alleged support or infrastructure transfers) is lawful under Article 45 of the GDPR, without the need for specific authorization or additional supplementary measures, as it is considered to offer a level of protection comparable to that of the European Union. The Draft Resolution fails to assess this fundamental fact that governs the main data flow.

2. Transfers to third countries without adequate safeguards: Adequate Safeguards (Art. 46 GDPR).

For any residual transfers that may occur to other countries without an adequacy decision (e.g., global technical support operations), the implementation of a triple "security belt" that satisfies the requirements of Article 46 of the GDPR and the Schrems II ruling has been documented:

• Legal Level: Subscription to the updated Standard Contractual Clauses (SCCs) in accordance with Commission Implementing Decision (EU) 2021/914 (Processor-Processor Module), in force between Microsoft Ireland Operations Ltd. and its sub-processors.

• Supplementary Contractual Level: Adherence to the "Addendum of Additional Guarantees" (DPA - Appendix C), submitted to the administrative file. This binding instrument obliges the provider to legally challenge any data access request from third-country governments that does not comply with international standards, guaranteeing the effective protection of data subjects' rights.

• Technical and Security Level: Transfers are not carried out "in a vacuum," but are protected by technical measures certified under international standards ISO/IEC 27001 (Information Security), ISO/IEC 27017 (Cloud Security), and SOC 2 and SOC 3 audits.

These certifications serve as expert evidence that data access is logically and physically restricted, encrypted in transit and at rest, neutralizing the risk of unauthorized access in the destination country.

3. Minimization by design: "EU Data Boundary". Finally, it is reiterated that the deployment model is based on the EU Data Frontier, ensuring that the main storage and processing of student and faculty data takes place within the European Union, reducing international transfers to what is strictly necessary for the technical operation of the service.

FIFTH.- ON THE ALLEGED INFRINGEMENT OF ARTICLE 35 GDPR (Data Protection Impact Assessment).

This Ministry reiterates what has already been stated: a Data Protection Impact Assessment (DPIA) was not carried out prior to the signing of the Agreement in 2020. However, it is noted that this situation is already being rectified, and the performance of said DPIA has been planned as a prior and essential step for drafting the new Agreement. The complexity of an analysis of this magnitude, which must cover the processing of data from hundreds of thousands of minors, justifies the need for a reasonable implementation period, such as the one granted by the Proposal itself.

Page 29 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
SIXTH.- ON GOOD FAITH AND THE COMMITMENT TO RECTIFY.

As a qualified mitigating factor (Art. 76.2.b LOPDGDD), the diligence of this Ministry must be taken into account, as it has not only actively collaborated but has also proceeded to regularize the contractual relationship.

Although the signing of the new Agreement has not yet materialized due to the extreme technical and legal complexity involved in the EIPD/TIA required for a service of this magnitude, the irrefutable proof of our commitment is the Extension Addendum signed on November 26, 2024. In its FOURTH Recital, both parties formally commit to "...continue with the technical work initiated since July 2024 for the implementation of a new agreement that contributes to updating and improving all the terms and clauses of the current one."This demonstrates that the rectification is not a promise, but rather the legal act that formally initiates the regularization process, a process which, as indicated in the Introduction, has already materialized with the commencement of the Action Plan.

SEVENTH.- ON THE DISPROPORTIONALITY OF THE SUSPENSION OF DATA FLOWS (Proposal, Second.d).

Without prejudice to the defense presented in Allegation Four, we consider that the measure of "ordering [...] the suspension of data flows" is particularly burdensome and disproportionate to the public interest.

This Department, as demonstrated, provides services to more than 561,000 students and 82,000 teachers through this platform. The suspension of the service, even if deferred, would cause serious harm to the essential public service of education (Article 27 of the Spanish Constitution), affecting the principle of the best interests of the child and the principle of continuity of public services. A halt to the pedagogical and communication tools on which the methodology of thousands of schools is based would imply a massive and unjustified disruption.

We understand that the Instruction itself has considered this harm by setting such a broad deadline (July 31, 2026). Therefore, we believe that the coercive measure of Article 58.2.j) (suspension) is not the most appropriate, and that the measure of Article 58.2.d) (ordering that operations be brought into compliance with the regulations) is more proportionate, as it calls for regularization within a set timeframe, an objective that this Ministry shares and for which it is already working diligently.
Based on the foregoing allegations, this Directorate General requests the following:
1) That this document be accepted as submitted and that the ALLEGATIONS to the Proposed Resolution dated November 12, 2025, be considered as such.
2) That, based on these allegations, the Proposed Resolution be amended, and consequently:
1. That the corrective measure contained in section 2.d) of the Proposed Resolution, relating to the suspension of international data flows, be reconsidered.

2. That the replacement of said suspension measure (Art. 58.2.j GDPR) with an order to comply with the regulations (Art. 58.2.d GDPR) be considered, subject to compliance with the provisions of the aforementioned articles. 44-49 to the delivery and validation of the Data Protection Impact Assessment (DPIA) and the associated Transfer Impact Analysis (TIA), within the already established deadline of July 31, 2026.
3. That the following be taken into consideration as mitigating circumstances: good faith, lack of intent, active collaboration, and the adoption of corrective measures (planned and under development) by this Ministry, for the purpose of determining the final Resolution issued, in accordance with Articles 76 and 77 of the LOPDGDD.”
Page 30 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
PROVEN FACTS
From the documents contained in the file and From the actions carried out, the following can be considered as proven facts:
First. That on November 27, 2020, the Ministry of Education and Sport (currently the Ministry of Educational Development and Vocational Training) signed with Microsoft Ireland Operations Limited the “Collaboration Agreement between the Ministry of Education and Sport of the Regional Government of Andalusia and Microsoft for the provision of educational services in the cloud in public educational centers owned by the Ministry of Education and Sport of the Regional Government of Andalusia” (hereinafter, the Agreement), the purpose of which is to establish the conditions of collaboration between the parties for the provision and use of Educational Services in the Cloud (hereinafter, “Educational Services in the Cloud” or “the Services”) in public educational centers owned by the Ministry of Education and Sport of the Regional Government of Andalusia that wish to use said services. The Services being Educational Cloud Services, a product encompassing a range of cloud-based communication, collaboration, and storage services offered for the educational sector,
which can be used with various hardware and software configurations.

The Educational Cloud Services included within the scope of this Agreement are listed below:
• Microsoft Office online applications:
- Outlook: email client
- Word: word processor
- Excel: spreadsheet program
- PowerPoint: presentation editor
- OneNote: collaborative digital notebook and multimedia tool
• Exchange: email exchange service
• Forms: questionnaires/forms
• OneDrive: cloud storage
• SharePoint: content management system
• Teams: collaboration, communication, and productivity tool
• Sway: digital storytelling tool
Second. That by virtue of the aforementioned Agreement, Microsoft Ireland Operations Limited, as the data processor, has access to the personal data under the responsibility of the Regional Ministry in order to provide the Educational Cloud Services included within the scope of this Agreement.

The processing of personal data carried out by Microsoft Ireland Operations Limited is regulated
by Clause Seven of the Agreement “Data Protection”, as well as by Annex II thereof “Microsoft Online Services Data Protection Addendum, dated July 21, 2020”.

Page 31 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council Portal
Third. It has been established that the entity under investigation has not adopted adequate technical or organizational measures to limit the high risk of system users entering special categories of data into the
Cloud Educational Services.

Fourth. It has been established that the entity under investigation has not adequately informed students, their family members, and faculty members about the processing of their personal data. in accordance with Article 13 GDPR.

Fifth. It has been established that international data transfers to third countries are carried out, but it has not been established that the guarantees, requirements, or exceptions established in Articles 44 to 49 GDPR are met.

Sixth. It has been established that the entity under investigation does not have adequate measures in place, such as instructions and protocols for users who are members of the educational community, regarding the photographs and audiovisual content that are appropriate to include in the Educational Cloud Services and those that should not be included, as well as an indication of the control and monitoring mechanisms in this regard.

Seventh. It has been established that the entity under investigation's record of processing activities does not include data transfers to third countries or international organizations, nor does it identify said third countries or international organizations in the corresponding section for the processing activities "Training Support Platforms" and "Digital Ecosystem." Educational Authority of Andalusia” nor in any other, in accordance with Article 30 GDPR.
Eighth. It has been established that the entity involved did not carry out a Data Protection Impact Assessment, as required by Article 35 GDPR, prior to the commencement of the processing.
LEGAL BASIS
First. On jurisdiction.
1. In accordance with the provisions of Articles 57.1 and 64.2 LOPDGDD and Article 43.1 LTPA in relation to Article 3.1 LTPA, this Council, as the regional authority for the protection of personal data and within its scope of competence, is responsible for exercising the sanctioning power and the powers provided for in Article 58 GDPR.
2. The authority to adopt this resolution lies with the Director, pursuant to Article 48.1.i) LTPA and Article 3.1 LTPA. 10.3.i) Statutes.

3. It should also be noted that, pursuant to Article 16.5 of Decree 434/2015, of September 29, which approves the Statutes of the Transparency and Data Protection Council of Andalusia, “[t]he Council's civil servants, when carrying out investigative functions in matters within the Council's competence, shall have the status of agents of the authority,” with the resulting consequences for the obligated parties regarding the provision of information requested of them in the course of such investigative functions.

4. This procedure is initiated as a result of an alleged breach of data protection regulations by an entity under the Council's control with respect to compliance with said regulations. Therefore, in this case, only those issues raised by the complainant in relation to the matter of protection-
Page 32 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
of personal data, which fall within the sphere of responsibility of the aforementioned entity.

Second. On the processing of personal data.

1. Article 2.1 of the GDPR states: “[t]his Regulation applies to the processing, whether wholly or partly by automation, of personal data, as well as to the non-automated processing of personal data contained in or intended to be included in a filing system.”

2. Article 4.1 of the GDPR defines “personal data” as “[a]ny information relating to an identified or identifiable natural person (“data subject”); An identifiable natural person is any person whose identity can be determined, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.The personal data referred to in the complaint includes data relating to the user identifier in the Séneca Information System, the user's name and surname, role (teacher or student), the code of the educational center to which the user is assigned, email address, and personal data included in documents, presentations, spreadsheets, images, or audiovisual content.

3. In accordance with Article 4.2 of the GDPR, the processing of personal data is “any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.”

In this case, the processing activity related to the complaint consists of providing the Regional Ministry with services related to the availability and use of Educational Cloud Services in the Regional Ministry's public schools.

Specifically, the processing operations to be carried out will be the collection, recording, structuring, modification, storage, extraction, consultation, transmission, dissemination, interconnection, comparison, limitation, deletion, destruction, retention, and communication.

Regarding the aforementioned processing operations, the entity involved has a Record of Processing Activities, having reported that these operations fall under the processing activities “Training Support Platforms”1 and “Andalusian Digital Educational Ecosystem”2. The stated purposes of these processing activities, as declared in the Record of Processing Activities, are, respectively, “Management of training activities and educational resources offered through telematics networks by the Regional Ministry responsible for education” and “Offering the educational community a virtual learning environment.”

Finally, Article 4.7 of the GDPR considers the data controller to be “…a public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing…” This identification of the data controller should be understood as being supplemented by the specification of the third party in Article 4.7. 4.10 GDPR, and therefore include
1 https://juntadeandalucia.es/protecciondedatos/detalle/166533.html
2 https://juntadeandalucia.es/protecciondedatos/detalle/180649.html
Page 33 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
"persons authorized to process personal data under the direct authority of the controller...".

The data controller is the Directorate General for Innovation and Teacher Training of the Ministry of Educational Development and Vocational Training (Art. 4.7 GDPR).

5. Article 4.8 of the GDPR defines a data processor as “…the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller…” This identification of the data processor must be understood as supplemented by the definition of a third party in Article 4.10 of the GDPR, and therefore includes “persons authorized to process personal data under the direct authority of the controller or the processor.”

The data processor for these processing activities is Microsoft Ireland Operations Limited (Article 4.8 GDPR).
Third. On the legal classification of the facts.

As previously stated, on November 27, 2020, the Regional Ministry of Education and Sport (currently the Regional Ministry of Educational Development and Vocational Training) signed an agreement with Microsoft Ireland Operations Limited. The purpose of this agreement is to establish the terms of collaboration between the parties for the provision and use of Educational Cloud Services in public schools under the jurisdiction of the Regional Ministry of Education and Sport of the Andalusian Regional Government that wish to use these services. Under this agreement, Microsoft Ireland Operations Limited, as the data processor, has access to the personal data under the responsibility of the Regional Ministry in order to provide the services included within the scope of the agreement.

This Council highly values the fact that the Regional Ministry decided to adopt a legally binding act to regulate, in accordance with Article 28 of the GDPR, the relationship between the controller and the processor in the use of Cloud-Based Educational Services, instead of leaving each educational institution to regulate this matter on its own, with the risks of inconsistencies in the exercise of the right to data protection that this entailed.

As indicated in the Background section, the complainant filed a complaint with this Council regarding the possible breaches detailed below of the personal data protection regulations arising from the Agreement for the provision of Cloud-Based Educational Services in the public educational institutions of the Regional Government of Andalusia.

1. Considerations regarding the lawfulness of the processing and whether consent is required for it.

1.1. Alleged facts that prompted the processing of the complaint.

The complainant alleges that upon activation of the service, the enrollment of students and faculty on the platform is done automatically, using IdEA users hosted in the Séneca Information System, without requesting prior consent from the interested parties (faculty, administrative and service staff, and students or their guardians in the case of minors under 14 years of age).

1.2. Legal considerations regarding the possible existence of an infringement.

In order to determine the liability of the entity involved, it will be necessary to ascertain whether the opening of the Microsoft accounts for students and faculty was carried out in accordance with any of the conditions of lawfulness contemplated in the aforementioned Article 6 of the GDPR, for which it will be necessary to analyze the applicable regulations.

Page 34 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
Article 1 of Organic Law 2/2006, of May 3, on Education (hereinafter, LOE) establishes in its section n) as a principle that should inspire the Spanish education system “The promotion and encouragement of research, experimentation and educational innovation” and as an aim of said education system “The training to guarantee the full integration of students into the digital society and the learning of a safe use of digital media that is respectful of human dignity, constitutional values, fundamental rights and, particularly, respect for and guarantee of individual and collective privacy” (Art. 2.1.l). Likewise, Article 111 bis, concerning “Information and Communication Technologies,” stipulates:
“[…] 2. Virtual learning environments used in publicly funded educational institutions shall facilitate the implementation of specific educational plans designed by teachers to achieve concrete curriculum objectives, and shall contribute to extending the concept of the classroom in time and space. Therefore, respecting interoperability standards, they shall allow students access, from any location and at any time, to the learning environments available in the educational institutions where they study, with full respect for the applicable regulations on intellectual property, privacy, and personal data protection. They shall also promote the principles of universal accessibility and design for all, both in formats and content, as well as in tools and virtual environments.” Learning.

[...]
5. Educational authorities and school management teams will promote the use of information and communication technologies (ICT) in the classroom as an appropriate and valuable teaching and learning tool. Educational authorities must establish the conditions that make it possible to eliminate risk situations in schools arising from the inappropriate use of ICT, with special attention to online violence. Confidence and security in the use of technologies will be fostered, paying special attention to eliminating gender stereotypes that hinder the acquisition of digital skills under equal conditions.

6. The Ministry of Education and Vocational Training will develop and review, after consulting with the Autonomous Communities, the frameworks for digital competence that guide initial and ongoing teacher training and facilitate the development of a digital culture in schools and classrooms.

7. The Administrations Public institutions will ensure that all students have access to the necessary digital resources to guarantee the right to education for all children on equal terms.

In any case, the information and communication technologies (ICTs) and teaching resources used will comply with the regulations governing information services and the information society, as well as intellectual property rights, raising awareness of the importance of respecting the rights of others.

In the specific context of the Autonomous Community of Andalusia, Article 4.1 of Law 17/2007,
of December 10, on Education in Andalusia (hereinafter, LEA), in its section c), establishes as a principle of the Andalusian education system the “Permanent improvement of the education system, promoting its innovation and modernization and the evaluation of all the elements that comprise it,” and in its Article 5, as an objective of the aforementioned Law, “g) Incorporate the new skills and knowledge necessary to function in society, with special attention to linguistic communication and the use of information and communication technologies.”
Page 35 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council PortalLikewise, the LEA recognizes as a right of students “Access to information and communication technologies in educational practice and the safe use of the Internet in educational centers” (article 7.1.e).

For its part, the LOPDGDD itself, in Article 83, regulates the “Right to Digital Education” and establishes that:
“1. The education system shall guarantee the full integration of students into the digital society and the learning of a safe and respectful use of digital media, respecting human dignity, constitutional values, fundamental rights, and, in particular, respect for and guarantee of personal and family privacy and the protection of personal data. Actions taken in this area shall be inclusive, particularly with regard to students with special educational needs.
Educational authorities shall include in the design of the elective subjects the digital competence referred to in the previous section, as well as elements related to risk situations arising from the inappropriate use of ICT, with special attention to situations of online violence.

2. Teachers shall receive the digital skills and training necessary for teaching and transmitting this knowledge.” of the values and rights referred to in the previous section. […]”.

Finally, the Twenty-Third Additional Provision of the LOE regulates the processing of “Students’ Personal Data” by stating:
“1. Educational institutions may collect the personal data of their students that are necessary for the exercise of their educational function. This data may refer to their family and social origin and environment, personal characteristics or conditions, the development and results of their schooling, as well as any other circumstances whose knowledge is necessary for the education and guidance of the students.
2. Parents or guardians and the students themselves must collaborate in obtaining the information referred to in this article. The enrollment of a student in an educational institution will entail the processing of their data and, where applicable, the transfer of data from the institution where they were previously enrolled, under the terms established in data protection legislation. In any case, the information referred to in this section will be strictly necessary for the teaching function.” and
guidance counselor, and may not be used for purposes other than educational purposes without express consent.

3. In the processing of student data, technical and organizational standards will be applied to guarantee its security and confidentiality. Teachers and other staff who, in the course of their duties, access personal and family data or data that affects the honor and privacy of minors or their families will be bound by the duty of confidentiality.

4. The transfer of data, including confidential data, necessary for the educational system, will preferably be carried out electronically and will be subject to legislation on the protection of personal data. In the case of data transfers between Autonomous Communities or between them and the State, the minimum conditions will be...
Page 36 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
agreed upon by the Government with the Autonomous Communities, within the framework of the Sectoral Conference on Education.
To this we must add that, in accordance with the provisions of recital 43 of the GDPR,
when the controller is a public authority, the legal basis for processing should not, as a general rule, be the data subject's consent insofar as
there is a clear imbalance of power between the data subject and the controller
and, consequently, the consent may not be considered freely given.

Therefore, taking into account the legal framework for education, this Council understands that the opening of student and teacher accounts with Microsoft Ireland Operations Limited and the processing of their personal data for the primary educational and guidance purpose, in those schools that have included the use of Cloud-based Educational Services in their school plan, would find its legitimizing basis in Article 6.1.e) of the GDPR: “processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller”; without the need to obtain the consent of the data subjects themselves. Therefore, no infringement is found to have been committed by the entity in question.

Notwithstanding the foregoing, this Council has analyzed the document relating to “Office 365” that is available on the Ministry's website and has verified that in the question:
“Is any type of authorization necessary to request accounts for students? The creation of accounts for students under 14 years of age must have the authorization of their parents or legal guardians. This authorization will be managed by the educational centers through the Séneca Information System. For students over 14 years of age, authorization from parents or legal guardians will not be necessary.”

Accordingly, it is not clear to educational centers that the processing is not based on consent and that such consent may have been requested by some centers from legal guardians at some point in the process. Therefore, it would be advisable
to issue clear instructions to the management and educational centers of the Regional Ministry
to refrain from carrying out actions that could lead to confusion, such as requiring
consent from the parents of children under 14 years of age or informing them that such consent is necessary.

However, as already stated, the information provided in this section regarding the legitimacy of the processing refers only to the processing necessary for the provision of educational and guidance services in centers where the use of Microsoft Services has been included.

Section 7.7 of the Agreement stipulates that “7.7. The data controller will require the express consent of the data subjects or their representatives for the processing of data not included among those that educational centers may collect from students in accordance with Additional Provision 23 of Organic Law 2/2006, of May 3, on Education.”

Other data processing activities for purposes different from those related to the services covered by this Agreement may require consent or another valid legal basis under Article 6 of the GDPR.

Subsequent sections will address considerations regarding situations that could lead to data processing not covered by the legal basis referred to in this section. These include the testing and verification of advanced technologies for Cloud-Based Educational Services, and the use of images and audiovisual material not necessary for the provision of educational and guidance services.

Page 37 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
Finally, it should be noted that everything stated regarding the lack of need to obtain the consent of the data subjects for the processing of data necessary for the provision of educational and guidance services in schools does not preclude the data subjects or their legal representatives from exercising any of their data protection rights in this regard.


(This document is not suitable for publication on the Council's website.) In particular, given that the legal basis for the processing referred to is that set out in Article 6.1(e) GDPR, the right to object referred to in Article 21.1 GDPR would apply:

“1. The data subject shall have the right to object at any time, on grounds relating to his or her particular situation, to processing of personal data concerning him or her which is based on points (e) or (f) of Article 6(1), including profiling based on those provisions. The controller shall cease processing the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.”

In short, if the interested party, either personally or through their legal representatives, exercises their right to object to the opening of a Microsoft account due to circumstances related to their particular situation, the responsible body should cease processing the data, with the consequent closure of the account, "unless it demonstrates compelling legitimate grounds for the processing that override the interests, rights, and freedoms of the interested party."

It would therefore be necessary to weigh the importance of using Microsoft services against their effects on the interested parties. If, as a result of the legitimate exercise of the right to object, with the stated requirements, the Microsoft account is closed within the framework of the Agreement, it is expected that the educational administration and the school will adopt the appropriate technical and organizational measures to ensure that the student does not suffer discrimination or unequal treatment in the enjoyment of educational and guidance services.

2. Considerations regarding the possible communication of data to the processor without the prior consent of the data subjects
2.1. Alleged facts that motivated the processing of the complaint.The communication of data concerning the user identifier of the Seneca Information System (IdEa identifier), name and surname, role (teacher/student), and center code to Microsoft Ireland Operations Limited without the prior consent of the data subjects is reported.

In this regard, clause 7.4 of the Agreement establishes that:

“7.4. For the registration of users in the Educational Cloud Services, the Regional Ministry of Education and Sport, as the data controller, provides the Collaborating Company, as the data processor, with the information described below:
• User identifiers (user identifier in the Seneca Information System, user name and surname, teacher/student role, and center code).”

2.2. Legal considerations regarding the possible existence of an infringement.

Page 38 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
Article 33.1 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights) stipulates that “Access by a data processor to personal data that is necessary for the provision of a service to the data controller shall not be considered a data transfer, provided that the provisions of Regulation (EU) 2016/679, this Organic Law, and its implementing regulations are met.”

[The text abruptly ends here, so the translation stops as well.] Therefore, pursuant to the provisions of Article 33.1 of the LOPDGDD (Spanish Data Protection Law), the access that Microsoft Ireland Operations Limited, as the data processor, makes to the personal data under the responsibility of the Regional Ministry of Educational Development and Vocational Training, pursuant to the Agreement signed between the Parties, is not considered a transfer of personal data and, therefore, contrary to the claimant's assertion, does not require the consent of the data subjects themselves, provided that the provisions of the GDPR and the LOPDGDD have been complied with.

This being the case, no infringement is found to have been committed by the entity against which the complaint was filed.

3. Considerations on the testing and verification of advanced technologies of Educational Cloud Services

3.1. Alleged facts that led to the processing of the complaint.

Regarding the reported processing of personal data to experimentally test and verify the use and possibilities of different advanced technologies of Cloud-Based Educational Services applied to the digital transformation of the education sector, such as big data and others related to the company's interests, without the prior consent of the students, Recital IX of the Agreement stipulates that "The Ministry of Education and Sport is interested in experimentally testing and verifying, together with the Collaborating Company, the use and possibilities of different advanced technologies of Cloud-Based Educational Services applied to the digital transformation of the education sector, such as: big data, analysis of indicators for learning, collaborative work, content personalization, cloud work, virtual reality, and augmented reality," and Clause Three of the Agreement, among the activities to be carried out, includes: "3.4. Possibility of experimentally testing and verifying the use and possibilities of different advanced technologies of the Services Educational technologies in the cloud applied to the digital transformation of the education sector, such as: big data, analysis of learning indicators, collaborative work, content personalization, cloud computing, virtual reality, and augmented reality.
In this regard, the Director General of Innovation and Teacher Training informed this Council in his report, dated November 8, 2024, that "The processing described in clause 3.4 of the agreement is not being carried out, nor is it planned."
3.2. Legal considerations regarding the possible existence of an infringement.

Clause One of the Agreement, concerning the “Purpose of the Agreement,” states that:
“The activities that the parties develop and, where applicable, agree upon within the monitoring committee provided for in Clause Nine, pursuant to Clauses Three and Four, shall also form part of the purpose of this Agreement, provided that this does not entail the adoption of commitments other than those contemplated in Clause Four, in which case, it would have to be agreed upon through the appropriate addendum to this Agreement.”

It is also worth noting that the Agreement stipulates in several sections that Microsoft Ireland Operations Limited will not process the data for its own purposes. For example:
Page 39 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
In section 7.11 “Obligations of the data processor. The data processor
is obligated to the following, and guarantees compliance by its personnel:
a. Use the personal data being processed, or those collected for inclusion, only
for the purpose of providing the Educational Cloud Services. Under no circumstances may it
use the data for its own purposes or for profiling of any kind. […]”
In Annex II, in the section relating to the “Data Protection Terms”, “Processing
of data to provide Online Services to the Client” it is stated that:
“When providing the Online Services, Microsoft will not use or process the Client's Data or Personal Data will not be used for: (a) user profiling, (b) advertising or similar commercial purposes, or (c) market research aimed at creating new features, services, or products, nor for any other purpose, unless such use or processing is carried out in accordance with the Customer's documented instructions.”
And in the section “Data Processing for Microsoft’s Legitimate Business Operations,” it states that:
“When carrying out processing activities for Microsoft’s legitimate business operations, Microsoft will not use or process Customer Data or Personal Data for: (a) user profiling, (b) advertising or similar commercial purposes, or (c) any purpose other than those set out in this section.”

Therefore, all the following considerations are based on the premise that all data processing carried out as a result of this Agreement will be for the purposes of the educational administration and not for the purposes of Microsoft Ireland Operations Limited.

If the reality were different and the data were processed for the purposes of Microsoft Ireland Operations Limited, it would be Microsoft Ireland Operations Limited, as the data controller, that would be responsible for any potential breaches of data protection regulations it might commit, since, according to Article 28.10 GDPR, “[…] if a processor infringes this Regulation by determining the purposes and means of processing, it shall be deemed to be a controller in respect of such processing.”

[…] if a processor infringes this Regulation by determining the purposes and means of processing, it shall be deemed to be a controller in respect of such processing. Having made this clarification, it must be reiterated that, as already mentioned in section 1.3 of Legal Basis Three, the legal framework for education legitimizes educational institutions, without needing to obtain the consent of the data subjects themselves, to process personal data relating to their family and social origin and environment, personal characteristics or conditions, the development and results of their schooling, as well as any other circumstances whose knowledge is necessary for the education and guidance of students; that is, only when necessary for the exercise of their educational function.

However, the purposes of the processing stated in section 3.4 of the Agreement are not sufficiently specific or explicit to comply with the aforementioned principle of “purpose limitation.” This is the case with expressions such as “Possibility of experimentally testing and verifying the use and possibilities of different advanced technologies of Cloud-Based Educational Services applied to the digital transformation of the education sector, such as: big data, analysis of learning indicators, collaborative work, content personalization, cloud-based work, virtual reality, and augmented reality,” which could refer to the processing of data to test practically any new technology, for purposes that are not very explicit.

Page 40 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
It could even involve profiling users, which might occur for this “content personalization.”

[Page 40 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal] In any case, this Council understands that the purposes of the indicated processing, given their experimental nature, the possible creation of profiles, and the lack of explicit definition thereof, cannot be considered necessary for the educational and guidance purpose of the students. Therefore, within the framework of all the considerations already set forth, it does not appear that they can be justified by the legitimacy granted for this purpose by the Twenty-Third Additional Provision of the LOE (Organic Law on Education).
It should also be noted that, as already stated, the data processed were originally collected for the purpose of the education and guidance of the students. Therefore, the subsequent processing of this data for different purposes would require providing adequate information to the data subjects, an appropriate legal basis such as free, specific, informed, and unambiguous consent, and other considerations that could be specified in the corresponding Data Protection Impact Assessment (DPIA), in accordance with Article 35 of the GDPR. Conducting a DPIA in this regard, whether independently

or integrated into a DPIA covering all services offered under the Agreement, would undoubtedly be mandatory

for the reasons set out in the section on considerations regarding conducting a DPIA.
Recall that clause 7.7 of the Agreement stipulates that “The data controller will require the express consent of the data subjects or their representatives for the processing of data not included among those that educational institutions may collect from students in accordance with Additional Provision 23 of Organic Law 2/2006, of May 3, on Education.”

Therefore, if personal data were to be processed for the purposes of testing and verifying advanced technologies of the Cloud-Based Educational Services, as outlined in clause 3.4 of the Agreement, it would require the prior consent of the data subjects or another valid legal basis; otherwise, it could constitute a data protection infringement.

Since no data processing has been carried out to date, it is not appropriate to declare a data protection infringement.

4. Security considerations regarding the use of the SENECA user identifier.

4.1. Alleged Facts that Motivated the Processing of the Complaint.

The complainant alleges a security risk when using IdEa credentials.

They allege that, specifically in the case of teachers, in addition to their name and surname, information is being provided about their teaching work, their workplace, and the IdEa identifier, which is used to access the Teacher Portal and SENECA, where a large amount of information is stored regarding their employment history, salary data, training data, procedures they have carried out with the administration, health information, and also data on the students they teach, including data on the special category.

It also states that this same risk to the security of personal data due to the delivery of IdEa credentials occurs with students, since these credentials grant access to PASEN, a platform where personal data such as grades, attendance records, absence justifications, communications with teachers, etc., are stored. This risk is aggravated by the fact that some of this data is of a special category and pertains to minors.

Page 41 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
4.2. Legal considerations regarding the possible existence of an infringement.

Clause 7.4 of the Agreement stipulates that: “For the registration of users in the Educational Services in the Cloud, the Ministry of Education and Sport, responsible for the processing, makes available to the Collaborating Company, as the data processor, the information described below:
User identifiers (user identifier in the Séneca Information System, user's name and surname, teacher role/student role, and center code)”
However, in this regard, the Director General of Advanced Technologies and Educational Transformation, in his report dated January 22, 2024, informed this body that “Both systems operate independently and, under no circumstances, does Microsoft have the ability to access the Séneca (PASEN) computer systems, which are duly protected under rigorous security measures,” and that “Microsoft receives the code IdEA, as well as the names and surnames of both teachers and students, excluding passwords. Access to Microsoft services is through the CAS (Centralized Authentication Service) identification system of the Regional Government of Andalusia, providing an additional layer of security.
Therefore, according to the statements of the Director General of Advanced Technologies and Educational Transformation, this body sees no evidence of the commission of a data protection infringement by the entity under investigation related to the security risk of using IdEA credentials.
5. Considerations on the possible processing of special categories of data.
5.1. Alleged facts that led to the initiation of the sanctioning procedure.
It is also claimed that at no time is consent obtained from students or their families for the processing of data relating to health, religion, ideology, beliefs, sexual life, or racial origin. Specifically, it alleges that during the use of Microsoft 365 platform applications, teachers or students themselves can upload documents to Drive, or send them via the platform's email, or create spreadsheets or text documents with information that reveals sensitive data about students. For example: an essay for the History subject asking for opinions on political ideologies, or the very common document shared to provide information to tutors before the evaluation, or when creating a shared folder with a student's psycho-pedagogical reports in Drive; sensitive data is facilitated without the knowledge and consent of the students and their families. In fact, these are procedures that are now carried out routinely.

5.2. Infringed provisions
Article 9 of the GDPR refers to the “Processing of special categories of personal data” and stipulates that:
“1. The processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation shall be prohibited.
Page 42 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
2. Paragraph 1 shall not apply where one of the following circumstances applies. following:

(a) the data subject has given explicit consent to the processing of those personal data for one or more of the specified purposes, except where Union or Member State law provides that the prohibition referred to in paragraph 1 cannot be overridden by the data subject;

[...]
(g) the processing is necessary for reasons of substantial public interest based on Union or Member State law, which must be proportionate to the objective pursued, respect the substance of the right to data protection and provide for appropriate and specific measures to safeguard the interests and fundamental rights of the data subject;

[...]

[...] And, according to Article 9.2 of the LOPDGDD:
“2. Data processing activities referred to in points (g), (h), and (i) of Article 9.2 of Regulation (EU) 2016/679, based on Spanish law, must be authorized by a law, which may establish additional requirements relating to their security and confidentiality. In particular, this law may authorize the processing of data in the health sector when required for the management of public and private healthcare and social assistance systems and services, or for the performance of an insurance contract to which the data subject is a party.”

Article 25 of the GDPR, concerning “Data protection by design and by default,” stipulates that:
“1. Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement, both at the time of determining the means of processing and at the time of processing itself, appropriate technical and organizational measures, such as pseudonymization, designed to effectively implement the principles of data protection, such as data minimization, and to integrate the necessary safeguards into the processing, in order to comply with the requirements of this Regulation and to safeguard the rights of data subjects.
2. The controller shall implement appropriate technical and organizational measures to ensure that, by default, only personal data that are necessary for each specific purpose of the processing are processed.” processing. This obligation will apply to the amount of personal data collected, the extent of its processing, its retention period, and its accessibility, [...].”
5.3. Legal considerations regarding the existence of an infringement.
It has already been mentioned that it would be possible, in certain cases, depending on the circumstances and if necessary to provide for the exercise of the educational function for the satisfaction of the right to education enshrined in Article 27.1 of the Spanish Constitution, to lift the prohibition on processing special categories of data mentioned in Article 9.1 GDPR, under the exception mentioned in Article 9.2(g) GDPR relating to reasons of essential public interest.

Page 43 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
This Council has expressed this view in Opinion 2/2023, of November 8, 2023, regarding the appropriateness of providing an educational center with a student's clinical health report, in accordance with data protection regulations.

Indeed, the educational administration may collect and process data from students and their parents or legal guardians, including special category data, without their consent when necessary for the performance of teaching and guidance functions, provided that all other requirements established by data protection regulations are met.However, considering the Agreement that is the subject of the claim, it has been verified that
clause 7.4 of the Agreement states that: “Under no circumstances will the Regional Ministry of Education and Sport provide the Collaborating Company with special categories of data as defined in Article 9 of the GDPR.”

From the above statement, it follows that, regardless of whether a circumstance exists that would allow lifting the general prohibition on processing special categories of data in this case, or whether such data is subject to a data processing agreement, the Regional Ministry decided that the services provided by Microsoft Ireland Operations Limited as part of the obligations under the Agreement did not, under any circumstances, include the processing of special categories of data.

Consequently, none of the special categories of data can be processed through the Cloud-Based Educational Services provided under the Agreement, as such processing would exceed its scope.

However, there is no doubt that, even if this is not the intention of the Regional Ministry and even if the data controller strictly adheres to the terms of the agreement, the risks that the actual situation will involve the processing of special categories of data are very high.

It should not be forgotten that this is a technological platform where documents freely created and written by students, teachers, and schools will routinely be stored, including text documents, spreadsheets, presentations, images, and videos that could very easily include special categories of data.

In fact, in the performance of routine educational tasks such as writing essays, assignments, or projects, there will be contexts in which this risk increases even further. By way of example,
it is reasonable to think that in a philosophy assignment, students might introduce
their own philosophical convictions or those of their family members, or in a history assignment, they might introduce
data that reveals their political opinions or religious beliefs. It should not be forgotten
that these are almost always minor students, not adult professionals, and therefore
it is not to be expected that their work will always have the same personal detachment and
scientific rigor that can be assumed of the work of adult professionals.

In this regard, the Regional Ministry has not demonstrated to this Council that it has adopted technical and
organizational measures aimed at members of the educational community, users of the Cloud-Based Educational Services, to limit the high risk that could be posed by system users
entering special categories of data.

This is because educational institutions legitimately process special categories of data when
the processing is necessary for their educational and guidance functions, which are not included
in the Agreement. Therefore, the instructions regarding the processing of personal data in the Cloud-Based Educational Services, if applicable, cannot in any case be the same as those for general educational and guidance activities.

Page 44 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
It is clear to everyone that the use of Educational Services in the Cloud alters the risks, nature
and scope of the processing of special categories of data and therefore warrants specific technical and organizational measures, such as specific training actions, clear instructions to users on the personal data that may be processed, or warnings that under no circumstances should personal data revealing ethnic or racial origin, political opinions, religious or philosophical beliefs, trade union membership data, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data relating to the sexual life or sexual orientation of a natural person.

Therefore, this Council concludes that the entity under investigation, faced with this high risk of processing special categories of data in the Cloud Educational Services and, consequently, the possible access of the data processor to said special categories of data whose processing is not the subject of the commission, has not proactively adopted technical and organizational measures to effectively apply the principles of data protection, such as data minimization, and with a view to ensuring that, by default, only the personal data necessary for each of the specific purposes of the processing are processed, thus violating the principles of data protection by design and by default set out in Article 25 of the GDPR.

5.4. Assessment of the allegations against the initiation agreement, evidence presented, or provisional measures.

The entity, in its written submissions to the Commencement Agreement, merely informs this
Council of a series of measures it is adopting, stating that “in accordance with the requirements of Article 25 of the GDPR, the Directorate General responsible for Innovation has been developing appropriate technical and organizational measures since the 2024-2025 academic year to limit the high risk of system users introducing special categories of data into the Microsoft platform. […]. In the current academic year, and with the aim of continuing to promote the transformation of schools into digitally competent educational organizations, the Technical Teaching Advisory Services support schools in the design and development of a personalized Digital Action Plan tailored to their school community, advising and providing guidance in accordance with the Organic Law on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD) and the provisions of the General Data Protection Regulation (GDPR), with special attention Article 25 and Article 13, providing guidelines to minimize the risk of users including special categories of data, as well as the use of inappropriate images and audiovisual material, while also providing them with information on the processing of personal data.

[…] As support resources, the ATD network has produced guides for developing the Digital Action Plan (accessible from the following URL: https://www.juntadeandalucia.es/educacion/portals/web/transformacion-digital-educativa/contenidos/-/contenidos/detalle/tde_guias_para_la_elaboracion_del_pad), proposing different lines of action and tasks for their implementation based on the various descriptors that make up the DigCompOrg framework, thus contributing to establishing standards and instructions for the responsible use of educational platforms used in the work. teacher
guaranteeing the privacy of personal data and the non-disclosure of special categories of data.” However, it has not provided this Council with documentary evidence that it has adopted technical and organizational measures to limit the high risk of system users introducing special categories of data into the Cloud Educational Services.
Page 45 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council Portal
Therefore, in accordance with all the above, we understand that the allegations presented do not invalidate the essential content of the declared infringement nor do they constitute sufficient justification or exculpation.
5.5. Assessment of the allegations to the proposed resolution, evidence presented, or provisional measures.

The entity, in its written response to the proposed resolution, reiterates the organizational measures adopted and informs this Council that the complete correction of this infraction is intrinsically linked to the implementation schedule of the Data Protection Impact Assessment (DPIA). However, it continues to fail to provide this body with documentary evidence of the specific technical and organizational measures implemented to prevent system users from introducing special categories of data into the Cloud-Based Educational Services.

Therefore, in accordance with all of the above, we understand that the presented allegations do not invalidate the essential content of the declared infraction nor do they constitute sufficient justification or exculpation.

5.6. Classification.

The facts attributed to the body in question, for the reasons stated, constitute the following infringement of the personal data protection regulations:
Failure to comply with the provisions relating to "the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39, 42 and 43" of the GDPR, as defined in Article 83.4(a) GDPR; classified for the purposes of the statute of limitations under the LOPDGDD as a serious infringement due to
violation of Article 25 of the GDPR, “Data protection by design and by default,” and, in particular, Article 73(d) of the LOPDGDD:
“The failure to adopt the appropriate technical and organizational measures to effectively implement the principles of data protection by design,
as well as the failure to integrate the necessary safeguards into the processing, as required by Article 25 of Regulation (EU) 2016/679.”

6. Considerations regarding compliance with the duty to inform data subjects.

6.1. Alleged facts that led to the initiation of the sanctioning procedure.

The complainant alleges that at no time before the creation of the accounts,
nor after, do the educational centers comply with the duty to inform established
in Article 13 of the GDPR, nor do they provide the affected parties with the basic information established in Article 11 of the LOPDGDD, nor do they indicate an electronic address or other means that allows
simple and immediate access to the remaining information.6.2. Infringed provisions.

Article 5.1(a) of the GDPR sets out the principles of “lawfulness, fairness and transparency” as follows: “(a) Personal data shall be: […] processed lawfully, fairly and transparently in relation to the data subject.”

Article 13 of the GDPR refers to the "Information to be provided when personal data are obtained from the data subject," and establishes that:
Page 46 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
"1. Where personal data relating to a data subject are obtained, the controller shall, at the time the data are obtained, provide the data subject with all of the following information:
a) the identity and contact details of the controller and, where applicable, of the controller's representative;
b) the contact details of the data protection officer, where applicable;
c) the purposes of the processing for which the personal data are intended and the legal basis for the processing;
d) where the processing is based on Article 6, paragraph 1, the following information: 1(f), the legitimate interests of the controller or of a third party;

e) the recipients or categories of recipients of the personal data, where applicable;

f) where applicable, the controller's intention to transfer personal data to a third country or international organisation and the existence or absence of an adequacy decision by the Commission, or, in the case of transfers referred to in Articles 46 or 47 or Article 49(1), second subparagraph, reference to the appropriate safeguards and the means by which to obtain a copy of them or where they have been made available.

2. In addition to the information referred to in paragraph 1, the controller shall provide the data subject, at the time the personal data are obtained, with the following information necessary to ensure fair and transparent processing:

a) the period for which the personal data will be stored or, where that is not possible, the criteria used to determine that period;

b) the existence of the right to request from the controller access to personal data concerning the data subject, and its rectification or erasure, or the restriction of its processing, or to object to the processing, as well as the right to data portability;

c) where the processing is based on point (a) of Article 6(1) or point (a) of Article 9(2), the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;

d) the right to lodge a complaint with a supervisory authority;

e) where the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, and where the data subject is obliged to provide the personal data and has been informed of the possible consequences of not providing such data;

f) the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4), and, at least in those cases, information significant
regarding the logic applied, as well as the significance and envisaged consequences of such
processing for the data subject.

3. Where the controller intends to further process personal data for a purpose other than that for which they were collected, the controller shall provide the data subject,
prior to such further processing, with information about that other purpose and any additional information relevant pursuant to paragraph 2.

4. The provisions of paragraphs 1, 2 and 3 shall not apply where and to the extent that
the data subject already has the information.

And Article 11 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights) provides, with respect to “Transparency and information to the data subject,” that:
“1. When personal data are obtained from the data subject, the data controller may comply with the duty to inform established in Article 13 of Regulation (EU) 2016/679 by providing the data subject with the basic information referred to in the following section and indicating an email address or other means that allows easy and immediate access to the remaining information.
2. The basic information referred to in the previous section must contain, at least:
a) The identity of the data controller and, where applicable, their representative.
b) The Purpose of the processing.

c) The possibility of exercising the rights established in Articles 15 to 22 of Regulation (EU) 2016/679.

If the data obtained from the data subject are to be processed for profiling purposes, the basic information shall also include this circumstance. In this case, the data subject must be informed of their right to object to automated individual decision-making that produces legal effects concerning them or similarly significantly affects them, where this right applies in accordance with Article 22 of Regulation (EU) 2016/679.

[...]
6.3. Legal considerations regarding the existence of an infringement.

The fact that the entity in question does not require the consent of the data subjects for the processing of personal data does not preclude it from duly complying with the other principles established in Article 5.1 of the GDPR, including the principle of transparency: “(a) Personal data shall be processed lawfully, fairly and transparently in relation to the data subject.”
Information must be provided to data subjects at the time of data collection if the data is obtained directly from them. The method for doing so is unrestricted, and the Regional Ministry has several options available.

In this regard, the Regional Ministry has been repeatedly asked for a copy of the clause(s) through which interested parties are informed of the processing of their personal data pursuant to Article 13 of the GDPR. The Director General of Innovation and Teacher Training informed the Regional Ministry that “The Regional Ministry of Educational Development and Vocational Training is currently working to include the necessary information on the processing of personal data under Article 13 of the GDPR in the student registration envelope. This information will be available during the registration process for the 2025/2026 academic year.”

Therefore, there is no evidence that students or their family members are being provided with the information required by Article 13 of the GDPR.

Nor has it been demonstrated that teaching staff are being informed about the processing of their personal data in accordance with the requirements of Article 13 of the GDPR.

Therefore, in relation to the facts underlying the claim, the conduct of the defendant entity, as data controller, constitutes, due to the circumstances described above, a substantial breach of Article 13 of the GDPR by failing to inform the data subjects.

6.4. Assessment of the allegations against the initiation agreement, evidence presented, and provisional measures.

The entity mentioned in the statement of allegations received by this Council on December 19, 2024, points out that “Finally, it should be noted that in addition to the corrective actions that are being developed in the areas of information and communication on the one hand, and in the continuing professional development of teachers in the field of digital teaching competence on the other, a specific information document is being prepared to inform interested parties about the processing of their personal data in accordance with the provisions of Article 13 GDPR and that will be included in the registration envelope for the 2025/2026 academic year.” However, it again merely informs this Council of the measures it will adopt without providing documentary evidence of having informed the data subjects about the processing of their personal data, thus complying with all the requirements of Article 13 of the GDPR. Therefore, we understand that the allegations presented do not invalidate the essential content of the declared infringement nor do they constitute sufficient justification or exculpation.

6.5. Assessment of the allegations against the proposed resolution, evidence presented, or provisional measures.

The entity, in its statement of allegations dated November 28, 2025, reiterates what it has already alleged, indicating that it is preparing the specific information document to inform the data subjects in accordance with Article 13 of the GDPR, with the commitment to include it in the registration envelope. Therefore, it again informs this body of the measures it will adopt
without providing documentary evidence of having informed the data subjects of the processing of their personal data
in accordance with the requirements of Article 13 GDPR.

Consequently, we understand that the allegations presented do not invalidate the essential content of the infringement declared to have been committed, nor do they constitute sufficient justification or exculpation.

6.6. Classification
The facts attributed to the body under investigation, for the reasons stated, constitute the following infringement of personal data protection regulations:
Failure to comply with the provisions relating to "the rights of data subjects under Articles 12 to 22" of the GDPR, classified under Article 83.5(b) GDPR; classified for the purposes of the statute of limitations in the LOPDGDD as a very serious infringement for violation of Article 13 of the GDPR:
“Information that must be provided when personal data are obtained from the data subject,”
in particular, in Article 72.1.h) of the LOPDGDD:
“The omission of the duty to inform the data subject about the processing of their personal data in accordance with the provisions of Articles 13 and 14 of Regulation (EU) 2016/679 and Article 12 of this Organic Law.”
7. Considerations Regarding Transfers of Personal Data to Third Countries or International Organizations

7.1. Alleged Facts that Led to the Initiation of the Sanctioning Procedure

The complainant also alleges the transfer of personal data to third countries or international organizations (hereinafter, international transfers) without complying with the requirements of the GDPR. Specifically, the complainant claims:

“Annex I of the agreement, “Terms of Online Services,” in the section “Data Protection and Security,” states that:
“The terms of the DPA (Data Protection Addendum) apply to the Online Services,
.... For the Main Online Services, ... and the location of inactive Customer Data can be found in Annex 1.”

In Annex 1: Notifications, the section “Location of Customer Data
without Activity for Core Online Services” states:
Page 49 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council Portal
“Office 365 Services. If the Customer provisions its tenant in Australia, Canada, the European Union, France, Germany, India, Japan, South Africa, South Korea, Switzerland, the United Kingdom, the United Arab Emirates, or the United States, Microsoft will store the following Customer Data at rest only within that Geo-area: (1) Exchange Online mailbox content (email body, calendar entries, and email attachments), (2) SharePoint Online site content and files stored on that site site and (3) files uploaded to OneDrive for Business.”

The European Commission does not consider many of these countries to have an adequate level of data protection.
And in the Data Protection Addendum (https://aka.ms/DPA), under the section “Data Transfer and Location - Data Transfers,” it states:
“The Customer designates Microsoft to transfer Customer Data and Personal Data to the United States or any other country in which Microsoft or its Sub-processors operate.”
I recall that the Court of Justice of the European Union (CJEU) invalidated Commission Decision (EU) 2016/1250 of 12 July 2016, known as the Privacy Shield, for data transfers to the United States.”

7.2. Infringed provisions.

Article 44 of the GDPR establishes the “General Principle of Transfers” by stipulating that:
“Transfers of personal data that are being processed or are to be processed after their transfer to a third country or international organisation shall only take place if, subject to the other provisions of this Regulation, the controller and the processor comply with the conditions laid down in this chapter, including those relating to onward transfers of personal data from the third country or international organisation to another third country or international organisation. All the provisions of this chapter shall apply in order to ensure that the level of protection of natural persons guaranteed by this Regulation is not undermined.”
Article 45.1 of the GDPR, for its part, regulates “Transfers based on a decision of adequacy” and states that: “A transfer of personal data to a third country or international organization may take place where the Commission has decided that the third country, a territory or one or more specific sectors of that third country, or the international organization concerned ensures an adequate level of protection. Such a transfer shall not require any specific authorization.”
And, Article 46, “Transfers with appropriate safeguards”:
“1. In the absence of a decision pursuant to Article 45(3), the controller or processor may transfer personal data to a third country or international organization only if it has provided appropriate safeguards and on the condition that the data subjects have enforceable rights and effective legal remedies.

2. The appropriate safeguards referred to in paragraph 1 may be provided, without requiring any express authorization from a supervisory authority, by:
(a) a legally binding and enforceable instrument between the public authorities or bodies; (b) Binding corporate rules pursuant to Article 47;

Page 50 of 73. Resolution RPS-2025/082, of 2 December - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council Portal
(c) Standard data protection clauses adopted by the Commission pursuant to the examination procedure referred to in Article 93(2);

(d) Standard data protection clauses adopted by a supervisory authority and approved by the Commission pursuant to the examination procedure referred to in Article 93(2);

(e) an approved code of conduct pursuant to Article 40, together with binding and enforceable commitments by the controller or processor in the third country to implement appropriate safeguards, including those relating to the rights of data subjects, or (f) an approved certification mechanism pursuant to Article 42, together with binding and enforceable commitments by the controller or processor in the third country to implement appropriate safeguards, including those relating to the rights of data subjects.

3. Where authorized by the competent supervisory authority, the appropriate safeguards referred to in paragraph 1 may also be provided, in particular, by: (a) contractual clauses between the controller or processor and the controller, processor, or recipient of the personal data in the third country or international organisation, or public provisions that include effective and enforceable rights for data subjects. [...]”.
Article 49 of the GDPR sets out “Exceptions for specific situations” by stating that:
“1. In the absence of an adequacy decision pursuant to Article 45(3) or appropriate safeguards pursuant to Article 46, including binding corporate rules, a transfer or set of transfers of personal data to a third country or international organisation shall only take place if one of the following conditions applies:
(a) the data subject has explicitly consented to the proposed transfer, having been informed of the possible risks to him or her resulting from the transfer due to the absence of an adequacy decision and appropriate safeguards;
(b) the transfer is necessary for the performance of a contract between the data subject and the controller or in order to take steps at the request of the data subject prior to entering into a contract;
(c) the transfer is necessary for entering into, or performing, a contract in the interests of the data subject between the controller and another natural or legal person; d) the transfer is necessary for important reasons of public interest;

e) the transfer is necessary for the establishment, exercise, or defense of legal claims;

f) the transfer is necessary to protect the vital interests of the data subject or of other persons, where the data subject is physically or legally incapable of giving consent;

g) the transfer is made from a public register which, under Union or Member State law, is intended to provide information to the public and is open to consultation by the general public or any person who can demonstrate a legitimate interest, but only to the extent that the conditions laid down by Union or Member State law for consultation are met in each particular case.

Page 51 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
When a transfer cannot be based on the provisions of Articles 45 or 46, including provisions on binding corporate rules, and none of the exceptions for specific situations referred to in the first paragraph of this section apply, it may only be carried out if it is not repetitive, affects only a limited number of data subjects, is necessary for the purposes of compelling legitimate interests pursued by the controller which are not overridden by the interests or fundamental rights and freedoms of the data subject, and the controller has assessed all the circumstances surrounding the data transfer and, based on this assessment, offered Appropriate safeguards regarding the protection of personal data. The controller shall inform the supervisory authority of the transfer. In addition to the information referred to in Articles 13 and 14, the controller shall inform the data subject of the transfer and the compelling legitimate interests pursued.

2. A transfer made pursuant to paragraph 1, first subparagraph (g), shall not cover all personal data or entire categories of personal data contained in the register. If the purpose of the register is consultation by persons with a legitimate interest, the transfer shall only take place at the request of such persons or if they are to be the recipients.

3. In paragraph 1, first subparagraph (a), (b) and (c), and second subparagraph, these shall not apply to activities carried out by public authorities in the exercise of their public powers.
4. The public interest referred to in paragraph 1, first subparagraph (d), shall be recognized by Union or Member State law applicable to the controller.

5. In the absence of a decision establishing the adequacy of the data protection, Union or Member State law may, for important reasons of public interest, expressly lay down limits on the transfer of specific categories of data to a third country or international organisation. Member States shall notify the Commission of such provisions.

6. The controller or processor shall document in the records referred to in Article 30 the assessment and appropriate safeguards referred to in paragraph 1, second subparagraph, of this Article.”
Finally, Article 42 of the LOPDGDD regulates the “Cases subject to prior authorization by the data protection authorities”, according to which:
“1. International data transfers to countries or international organizations
that do not have an adequacy decision approved by the Commission or that are not covered
by any of the safeguards provided for in the preceding article and in Article 46.2 of Regulation (EU) 2016/679, will require prior authorization from the Spanish Data Protection Agency or, where applicable, regional data protection authorities, which
may be granted in the following cases:
a) When the transfer intends to be based on the provision of adequate safeguards
based on contractual clauses that do not correspond to the standard clauses
provided for in Article 46.2, letters c) and d), of Regulation (EU) 2016/679.

b) When the transfer is carried out by one of the responsible parties or those in charge referred to in Article 77.1 of this Organic Law and is based on provisions incorporated into non-normative international agreements with other public authorities or bodies of third States, which incorporate effective and enforceable rights for the affected parties, including memoranda of understanding. The procedure will have a maximum duration of six months. […]”.
7.3. Legal considerations regarding the existence of an infringement.
Page 52 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
This body must remember that for there to be an international data transfer, it is necessary that the personal data subject to personal data processing be disclosed by transmission or made available in another way to recipients located outside the European Economic Area.
A) Therefore, it is necessary to analyze and determine, firstly, whether international transfers of personal data are made to third countries or international organizations in order to provide the services covered by the Convention.
Entering into the legal analysis of the international data transfers carried out by the entity in question, in Annex II of the Convention (terms of the DPA or Addendum of Data Protection

It is stipulated, with respect to Data Transfers, that taking into account the safeguards established therein, the customer designates Microsoft to transfer personal data to the United States or any other country in which Microsoft or its Subprocessors operate, and to store and process personal data for the purpose of providing the Online Services.

Furthermore, according to Annex 1 of the Agreement, section “Core Online Services”:
“Location of Customer Data at Rest for Core Online Services
For Core Online Services, Microsoft will store Customer Data at rest within certain significant geographic areas (each, a Geo-area) as indicated below, unless otherwise specified in the specific terms of the Online Service:
• Office 365 Services. If the Customer provisions its tenant in Australia, Canada, the European Union, France, Germany, India, Japan, South Africa, South Korea, Switzerland, In the United Kingdom, United Arab Emirates, or the United States, Microsoft will store the following Customer Data at rest only within that Geo-Area: (1) Exchange Online mailbox content (email body, calendar entries, and email attachment content), (2) SharePoint Online site content and files stored on that site, and (3) files uploaded to OneDrive for Business.

• Microsoft Intune Online Services. When the Customer provisions a Microsoft Intune tenant account for deployment in an available Geo-Area, Microsoft will store Customer Data at rest within that specific Geo-Area for that service, except as specified in the Microsoft Intune Trust Center.

• Microsoft Power Platform Core Services. If the Customer provides its tenant in Australia, Canada, Asia Pacific, France (excluding Microsoft Power Virtual Agents), India, Japan, the European Union, the United Kingdom, or the United States, Microsoft will store Inactive Customer Data only within that Geoarea, except as specified in the “Data Location” section of the Microsoft Power Platform Trust Center.

• Microsoft Azure Core Services. If the Customer configures a specific service for deployment within a Geoarea, then, for that service, Microsoft will store Customer Data at Rest within the specified Geoarea. Certain services may prevent the Client from configuring the deployment in a specific Geo-Area of the data center and may store backups in other locations.
Page 53 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council Portal
See the Microsoft Trust Center (which Microsoft may update from time to time, but to which Microsoft will not add exceptions regarding services existing in the general release) for more details.

• Microsoft Cloud App Security. If the Client provisions its tenant in the European Union or the United States, Microsoft will store inactive Client Data only within that Geo-Area, except as described in the Microsoft Cloud App Security Trust Center.

• Microsoft Cloud App Security. • Microsoft Dynamics 365 Core Services. When the Customer provides a Dynamics 365 Core Service for deployment in an available Geoarea, then, for that service, Microsoft will store Customer Data at rest within that specific Geoarea, except as described in the Microsoft Dynamics 365 Trust Center.

• Microsoft Defender Advanced Threat Protection Services.

When the Customer provisions a Microsoft Defender Advanced Threat Protection tenant for deployment in an available Geoarea, then, for that service, Microsoft will store Customer Data at rest within that specific Geoarea, except as specified in the Microsoft Defender Advanced Threat Protection Trust Center.

• Microsoft Threat Protection. When the Customer provisions a Microsoft Threat Protection tenant for deployment in an available geo-area, then, for that service, Microsoft will store Customer Data at rest within that specific geo-area, except as specified in the Microsoft Threat Protection Trust Center. In this regard, we must point out that the fact that data “at rest” or “inactive” is located within the European Economic Area does not mean that transfers to third countries or international organizations do not occur when such data is not “at rest.” Similarly, remote access from a third country (for example, in the context of support operations) offered by a service provider is also considered a transfer. Furthermore, it is not explained how Microsoft will apply the exceptions provided in the specific terms of the Online Service to the specific case of personal data covered by the Convention.

Finally, in response to this Council's specific request to provide the list of countries and companies... Recipients of international data transfers,
the defendant entity has provided the document entitled “Microsoft Online Services Subprocessors,” dated July 2, 2024. This document includes a list of the countries in which
Microsoft has data processing infrastructures, as well as its subprocessors
and the location where each of them processes personal data. Therefore, and according to the content of this document, international data transfers occur
from the European Union to the United States, Canada, Switzerland, the United Kingdom,
Serbia, India, China, Australia, Mexico, Brazil, Chile, Malaysia, Qatar, Singapore, South Africa,
Taiwan, the United Arab Emirates, and Israel.

Furthermore, the defendant entity informed this Council in its report of November 12,
2024, that:
“Generally, personal data is stored and processed exclusively within the EU/EFTA territory.” This commitment is called “EU Data Boundary” and constitutes an
Page 54 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council Portal
additional protection that Microsoft has gradually deployed in the service since 2023. The
only, limited exceptions to the EU Data Boundary are documented in
the product terms (last points on this webpage).”
However, this has not been documented.The Microsoft Products and Services Data Protection Addendum of January 2, 2024, merely states that:

“For Online Services under the EU Data Boundary plan, Microsoft will store and process Customer Data and Personal Data within the European Union, as set forth in the Product Terms. [...]”
However, this does not mean that the specific services Microsoft offers to the Ministry in compliance with this Agreement are included in the “EU Data Boundary plan,” nor does it state that all customers in the European Economic Area are subscribed to said “EU Data Boundary plan.”
No agreement between the parties or any other legally binding documentation has been provided to demonstrate that Microsoft applies the “EU Data Boundary plan” specifically to this Agreement.
In conclusion, regarding the existence of international transfers, the defendant has provided various seemingly contradictory pieces of information. The possible adherence of the entity under investigation to the so-called “EU Data Boundary Plan,” specifying its scope and concrete application within the framework of the processing activities contemplated in the Convention, or detailed and precise information on the definition of the term “Geoarea,” on the specific limitations imposed on the Core Online Services regarding the storage of personal data at rest, and on the application to the processing of such personal data in other ways (for example, transmission or remote access from a third country), could imply that there are no international transfers of personal data. However, until these elements are clarified and duly accredited, we must conclude that international transfers exist, based on the content of Annex II of the Convention (Data Protection Addendum), the document entitled “Microsoft Online Services Subprocessors,” and the content of the entity under investigation's responses to the requests of this Council.

B) Secondly, an analysis will be conducted to determine whether these international transfers of personal data are carried out in accordance with Articles 44 to 49 of the GDPR.


(This section appears to be incomplete and possibly contains errors.) As previously mentioned, for an international transfer of personal data to be compliant with the GDPR, in summary, it must:
− Be based on an adequacy decision (Article 45 GDPR): To date, the territories declared adequate are: Switzerland, Canada (with respect to entities subject to the scope of application of Canadian data protection law), Argentina, Guernsey, Isle of Man, Jersey, Faroe Islands, Andorra, Israel, Uruguay, New Zealand, Japan, United Kingdom, Republic of Korea, and the USA (Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the adequacy of the level of protection of personal data in the EU-US Data Privacy Framework pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council).

In the event that personal data is to be transferred to one of these countries for the purpose of providing a service, as indicated by the European Data Protection Board (see page 55 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal, hereinafter EDPB) in “Opinion 22/2024 on certain obligations arising from the dependence of processors and sub-processors,” the following must be verified:
- Whether the adequacy decision is in force.

- And whether the transfers made on behalf of the controller fall within the scope of that decision.

Without prejudice to any checks that may be necessary in the event of further transfers to third countries from the country with an adequacy decision.

− In the absence of an adequacy decision, through appropriate safeguards (Article 46 GDPR) by means of:
a) A legally binding and enforceable instrument between public authorities or bodies.

b) Binding corporate rules.

c) Standard contractual clauses for data protection adopted by the Commission.

On 4 June 2021, the European Commission published Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council. The new set of standard contractual clauses replaces its predecessors and is adapted to the GDPR, repealing the contractual clauses of European Commission Decisions 2001/497/EC, 2004/915/EC, and 2010/87/EU as of 27 September 2021. Contracts concluded before 27 September 2021 in accordance with the previous Decisions remained valid until 27 December 2022 and had to be adapted to the new standard contractual clauses approved by Implementing Decision (EU) 2021/914.

d) Standard data protection clauses adopted by a supervisory authority and approved by the Commission.

e) Codes of conduct, together with binding and enforceable commitments from the controller or processor in the third country to implement appropriate safeguards, including those relating to the rights of data subjects, or
f) Certification mechanisms, together with binding and enforceable commitments from the controller or processor in the third country to implement appropriate safeguards, including those relating to the rights of data subjects.

− Exceptions for specific situations: In the absence of an adequacy decision or appropriate safeguards, a transfer of personal data to a third country or international organization will only take place if one of the conditions of Article 49 GDPR is met, which does not appear to be the case given the processing in question, its repetitive nature, and the number of data subjects affected.

Page 56 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council Portal
With regard to the standard data protection clauses adopted by the Commission, in its judgment C-311/18 (Schrems II), the Court of Justice of the European Union (CJEU) concludes the following:
“Article 46(1) and (2)(c) of Regulation 2016/679 must be interpreted as meaning that the appropriate safeguards, enforceable rights and effective legal remedies required by those provisions must ensure that the rights of individuals whose personal data are transferred to a third country on the basis of standard data protection clauses enjoy a level of protection substantially equivalent
to that guaranteed within the European Union by the aforementioned Regulation, interpreted
in light of the Charter of Fundamental Rights of the European Union. To that end, the assessment of the level of protection guaranteed in the context of a transfer of that nature must, in particular, take into consideration both the contractual stipulations agreed between the controller or processor established in the European Union and the recipient of the transfer established in the third country concerned and, with regard to possible access by the public authorities of that third country to the personal data so transferred, the relevant elements of the legal system of that country and, in particular, those referred to in Article 45(2) of the aforementioned Regulation.”

And for greater clarity, paragraph 134 of the aforementioned Judgment states that:

“the contractual mechanism provided for in Article 46(2)(c) of the GDPR is based on the responsibility of the controller or processor established in the Union, as well as, subsidiarily, the competent supervisory authority. It is therefore primarily the responsibility of that controller or processor to verify, on a case-by-case basis and, if necessary, in cooperation with the recipient of the transfer, whether the law of the third country of destination guarantees adequate protection, in light of Union law, of the personal data transferred on the basis of standard contractual clauses for data protection, providing, where necessary, additional safeguards to those offered by such clauses.”

For its part, the EDPB published “Recommendations 01/2020 on measures to complement transfer instruments to ensure compliance with the EU level of protection for personal data,” to assist exporters with the complex task of assessing third countries and establishing appropriate complementary measures where necessary. These recommendations provide exporters with a series of steps, possible sources of information, and examples of complementary measures that could be applied.

In conclusion, and for the context of the personal data processing under analysis, it will be necessary to provide safeguards for all international transfers to any country where Microsoft and its sub-processors store or otherwise process personal data.

That is, each international transfer must be based on an adequacy decision or have appropriate safeguards, in accordance with Article 46 of the GDPR and the case law of the CJEU.

From the documentation provided by the defendant entity (document “Microsoft Online Services
Subprocessors”), the following types of international transfers can be inferred:
• To Microsoft in countries with an adequacy decision (USA, Canada, Israel, United Kingdom, Japan, Switzerland, among others).

• To Microsoft in countries with an adequacy decision (USA, Canada, Israel, United Kingdom, Japan, Switzerland, among others). Page 57 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
• To Microsoft in countries without an adequacy decision (Hong Kong, India, Mexico, Qatar, Singapore, among others)
• To Microsoft sub-managers in countries with an adequacy decision (Canada, UK, USA, Israel, among others)
• To Microsoft sub-managers in countries without an adequacy decision (Australia, Brazil, China, Singapore, India, among others).For international transfers based on an adequacy decision, no specific authorization is required. Specifically, with regard to transfers to the United States, on July 16, 2020, the Court of Justice of the European Union issued a judgment that annulled Commission Implementing Decision (EU) 2016/1250 of July 12, 2016, pursuant to Directive 95/46/EC of the European Parliament and of the Council, on the adequacy of the protection provided by the EU-U.S. Privacy Shield, which declared the Privacy Shield scheme to provide an adequate level of protection. However, the European Commission, on 10 July 2023, adopted Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the adequacy of the level of protection of personal data under the EU-U.S. Data Privacy Framework pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, declaring that the United States ensures an adequate level of protection for personal data transferred from the Union to U.S. entities listed on the EU-U.S. Data Privacy Framework List https://www.dataprivacyframework.gov/list. In this regard, this Council has been able to verify that Microsoft Corporation is listed therein. Furthermore, the entity under investigation has provided this Council with a copy of the “Data Transfer Agreement (P2P) between Microsoft Ireland Operations Limited and Microsoft Corporation,” an entity located in the United States, dated September 13, 2021. Specifically, it consists of the standard contractual clauses approved by the European Commission in Decision 2021/914 of June 4, 2021, under the ‘processor-to-processor transfer’ module, formalized between the aforementioned entities. From the responses dated November 11 and 26 to the two requests from this Council, it is concluded that the entity in question would consider the international transfers made to any other country (whether to Microsoft itself or its sub-processors) to be compliant with the GDPR, based on the content of Annex II of the Agreement (terms of the DPA or Data Protection Addendum) and the “Data Transfer Agreement (P2P) between Microsoft Ireland Operations Limited and Microsoft Corporation.”

However, considering the CJEU case law cited above, it cannot be concluded that these clauses, in general, without a specific analysis of each transfer and without the adoption, where appropriate, of the necessary complementary measures, can offer a level of protection substantially equivalent to that guaranteed within the European Union by the GDPR.

For the reasons stated above, this Council understands that the conduct of the
entity under investigation, as the data controller, violated Articles 44 to 49 of the GDPR by
transferring personal data to recipients located in third countries without complying with
the safeguards, requirements, or exceptions established in Articles 44 to 49 of the GDPR.

7.4. Assessment of the allegations against the initiation agreement, evidence presented, or provisional measures.

Regarding international data transfers to third countries, the entity under investigation simply reiterates what it has already stated to this Council, and therefore we refer
to what was stated in the previous section. Therefore, this body understands that
Page 58 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
the allegations presented do not invalidate the essential content of the declared infringement
nor do they constitute sufficient justification or exculpation.

7.5. Assessment of the allegations to the proposed resolution, evidence presented, or provisional measures.

The defendant alleges in essence that:
“[...]The international data transfer architecture of the data processor (Microsoft) strictly complies with Chapter V of the GDPR through a cascading system of guarantees that covers all possible scenarios, as detailed below:
1. Transfers to the USA: Coverage by Adequacy Decision (Art. 45 GDPR). It is a well-known and legally binding fact that the European Commission adopted Implementing Decision (EU) 2023/1795 of 10 July 2023, concerning the adequacy of the level of protection of personal data under the EU-US Data Privacy Framework. Microsoft Corporation is certified on the official list of said Framework.
Consequently, any data transfer to the parent company in the United States (the main destination of the alleged support transfers or infrastructure) is lawful ex lege under Article 45 of the GDPR, without the need for specific authorization or additional supplementary measures, as it is considered to offer a level of protection comparable to that of the European Union. The Draft Resolution fails to assess this fundamental fact that regulates the main data flow.

2. Transfers to third countries without adequacy: Adequate Safeguards (Art. 46 GDPR).

For those residual transfers that may occur to other countries without an adequacy decision (e.g., global technical support operations), the implementation of a triple "safety belt" that satisfies the requirements of Article 46 of the GDPR and the Schrems II ruling has been documented:

• Legal Level: Subscription to the updated Standard Contractual Clauses (SCCs) in accordance with Commission Implementing Decision (EU) 2021/914 (Module Processor-Processor-
in force between Microsoft Ireland Operations Ltd. and its sub-processors.

• Supplementary Contractual Level: Adherence to the "Addendum of Additional Guarantees" (DPA - Appendix C), submitted to the administrative file. This binding instrument obliges the supplier to legally challenge any request for data access by third-country governments that does not comply with international standards, guaranteeing the effective protection of the rights of data subjects.

• Technical and Security Level: Transfers are not carried out "in a vacuum," but are protected by technical measures certified under international standards ISO/IEC 27001 (Information Security), ISO/IEC 27017 (Cloud Security), and SOC 2 and SOC 3 audits. These certifications act as expert evidence that access to data is logically and physically restricted, encrypted in transit and at rest, neutralizing the risk of Unauthorized access in the destination country.

3. Minimization by design: "EU Data Boundary". Finally, it is reiterated that the deployment model is based on the EU Data Boundary, ensuring that the main storage and processing of student and faculty data takes place within the European Union, reducing international transfers to what is strictly necessary for the technical operation of the service. [...]”
However, none of the points raised are provided or justified in any documentation.
Therefore, this Council refers to what has already been stated in this regard in section 7.5 of this resolution, based on the documentation analyzed.

On the other hand, the defendant entity alleges that:
Page 59 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
“the measure of 'ordering [...] the suspension of data flows' is particularly burdensome and disproportionate to the public interest. This Department, as demonstrated, provides service to more than 561,000 students and 82,000 teachers through this platform. The suspension of the service, even if deferred, would cause serious harm to the essential public service of education (Article 27 of the Spanish Constitution), affecting the principle of the best interests of the child and the principle of continuity of public services. A paralysis of the pedagogical and communication tools in The methodology used by thousands of centers, which is based on this methodology, would imply a massive and unjustified disruption.

We understand that the Instruction itself has considered this harm by setting such a broad deadline (July 31, 2026). Therefore, we believe that the coercive measure of Article 58.2.j) (suspension) is not the most suitable, and that the measure of Article 58.2.d) (ordering operations to comply with the regulation) is more proportionate, as it calls for regularization within a timeframe, an objective that this Ministry shares and for which it is already working diligently.”

In this regard, this Council must point out that the application of the measure provided for in Article 58.2 j) GDPR, consisting of “ordering the suspension of data flows to a recipient located in a third country or to an international organization,” is fully justified. This is because the continued international data transfers, in the absence of adequate safeguards, compromise the rights of more than 640,000 users of the application, as indicated by the entity against which the proceedings have been initiated.

However, the entity against which the proceedings have been initiated is granted a generous period of six months, as acknowledged by the entity itself, until July 31, 2026, to adopt the necessary measures to comply with the requirements of the GDPR and cease committing a very serious infringement, thereby restoring compliance with European data protection regulations and preventing disruption to the provision of public education services during the school year.

Therefore, in accordance with all of the above, we understand that the allegations presented do not invalidate the essential content of the infringement declared to have been committed, nor do they constitute sufficient justification or exculpation.7.6. Classification.
The acts attributed to the body under investigation, for the reasons stated, constitute the following infringement of personal data protection regulations:
Failure to comply with the provisions relating to "transfers of personal data to a recipient in a third country or an international organization pursuant to Articles 44 to 49" of the GDPR, classified under Article 83.5.c) GDPR; classified for the purposes of the statute of limitations in the LOPDGDD as a very serious infringement for violation of Articles 44 to 49 of the GDPR “Transfers of personal data to third countries or international organizations” and, in particular, in Article 72.l) of the LOPDGDD:
“The international transfer of personal data to a recipient located in a third country or to an international organization, when the guarantees, requirements or exceptions established in Articles 44 to 49 of Regulation (EU) 2016/679 are not met.”

8. Considerations on the processing of photographs and audiovisual content
Page 60 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
8.1. Facts reported that led to the initiation of the disciplinary proceedings.

The complainant claims that clause 7.8 of the Agreement states: “the data controller must also assess, with regard to the processing of photographs and audiovisual content, whether these correspond to the purpose of the processing, being adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed, taking into consideration the principle of data minimization set out in Article 5.1 c) of the GDPR.” However, at no time has the Regional Ministry of Education established any mechanisms for assessing this content.

8.2. Infringed provisions.

Article 25 of the GDPR, concerning “Data protection by design and by default,” stipulates that:
“1. Taking into account the state of the art, the cost of implementation, and the nature, scope, context, and purposes of processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement, both at the time of determining the means of processing and at the time of processing itself, appropriate technical and organizational measures, such as pseudonymization, designed to effectively implement the data protection principles, such as data minimization, and to integrate the necessary safeguards into the processing, in order to comply with the requirements of this Regulation and to safeguard the rights of data subjects.
2. The controller shall implement appropriate technical and organizational measures with a view to ensuring that, by default, only personal data that are necessary for each individual are processed.” of the specific purposes of the processing.

This obligation will apply to the amount of personal data collected, the extent of its processing, its retention period, and its accessibility, [...]”.
8.3. Legal considerations regarding the existence of an infringement.
First, this body must remember that if the recording of images is carried out for exclusively educational purposes, the school or the educational administration is authorized to process them without needing to obtain the consent of the students or their parents or legal guardians.
However, when the recording does not correspond to this function, it will be necessary to obtain the consent of the data subjects, who must have been previously informed of the purpose of the recording. In this case, it will be especially relevant to clearly describe the purpose, informing whether the images will be accessible indiscriminately or limited to the school community.
Focusing on the Agreement that is the subject of the complaint, in clause 7.6. The same document stipulates that

"The Ministry of Education and Sport establishes that the data subjects for whom it is responsible may include minors, and that the categories of data to be processed may also include photographs and audiovisual content." Clause 7.8 further states that
"The data controller must also assess, in relation to the processing of photographs and audiovisual content, whether these correspond to the purpose of the processing,
being adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed, taking into consideration the principle of data minimization set out in Article 5.1.c) of the GDPR."

" Page 61 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
In this regard, the entity in question was requested to provide a copy of the instructions and protocols addressed to users who are members of the educational community regarding the photographs and audiovisual content that are appropriate to include in the Educational Cloud Services and those that should not be included.
... In response to this request, the entity in question reported on November 8, 2024, that:

“Regarding this matter, the following actions have been taken:
a) Publication of the Agreement document and its Addendum

https://juntadeandalucia.es/sites/default/files/2021-01/Convenio_31.pdf
b) In accordance with the Andalusian Plan for Ongoing Teacher Training, the Teacher Resource Centers (CEPs) have provided various training activities related to the use of the Microsoft platform. Similarly, support has been extended to those centers that have selected the Group Training or In-School Training modalities, linked to their Training Plan, concerning this platform.

c) Furthermore, a web space has been enabled within the website

https://eaprendizaje.ced.juntaandalucia.es/microsoft365/
d) All Andalusian educational centers They are developing their Digital Action Plan, a strategic document that details the coverage of digital educational services in the cloud through various lines of action. (It has established mechanisms for evaluating this content.)
It has not been deemed necessary to issue additional specific instructions on privacy and data protection policy, given that the agreement is protected under the existing legal framework in educational legislation.
In each educational center, the Organization and Operation Regulations (ROF), integrated within the Center Plan, establish mechanisms for evaluating this content through the provisions relevant to the use of photographic and audiovisual material.
The same applies to the Digital Action Plans of the educational centers.
Furthermore, during October 2024, the document “Guide on Personal Data Protection for Educational Centers” was disseminated to all Andalusian teachers through the Séneca messaging system. Andalusia”
(https://www.ctpdandalucia.es/sites/default/files/inline-files/guiaproteccion-datos-centros-educativos-andalucia.pdf).
Regardless of the above, the Regional Ministry of Educational Development and Vocational Training is working to publish instructions for all Andalusian teachers on the handling of photographs and audiovisual content in Educational Cloud Services. This will be available in the second quarter of the 2024/2025 academic year.
However, this Council has not been shown to have adopted measures by the entity in question aimed at users who are members of the educational community regarding the photographs and audiovisual content that are appropriate to include in Educational Cloud Services.
Page 62 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
vos in the Cloud and those that should not be included. Nor are there any references on the portal https://eaprendizaje.ce-
d.junta-andalucia.es/microsoft365/ that could be considered compliance with the obligation.

Consequently, in relation to the facts underlying the complaint, the conduct of the entity
initiated, as the data controller, failed to comply, due to the circumstances described above, with the aforementioned Article 25 GDPR, due to the lack of adoption of appropriate organizational measures to effectively apply the principles of data protection, such as the principle of data minimization, and to ensure that only the personal data necessary for each of the specific purposes of the processing are processed.

8.4. Assessment of the allegations against the initiation agreement, evidence presented, or measures provisional

As this Council has already pointed out, the entity in question alleges that ATDs have been appointed, distributed
among the Teacher Resource Centers and the Central Services of the Regional Ministry to support
the design and implementation of the Digital Action Plan for publicly funded schools in Andalusia. This network of ATDs has produced guides for the development of the Digital Action Plan, proposing different Lines of Action and tasks for its achievement based on the various descriptors that make up the DigCompOrg framework, thus contributing to establishing rules and instructions for the responsible use of educational platforms
used in teaching, guaranteeing the privacy of personal data and the non-disclosure of sensitive data. Furthermore, it alleges that in the communications and training sessions that the ATDs hold with the schools, the “Guide on the protection of personal data for educational centers in Andalusia” of this Council is being disseminated. as well as
“In each educational center, the Organization and Operation Regulations (ROF)
integrated within the Center Plan, will reflect the provisions relevant to the use of photographic and audiovisual material established in the Center's Digital Action Plan.”
However, once again, the entity under investigation merely informed this Council of the measures it plans to adopt, but has not provided this body with documentary evidence, either at the time of submitting its objections to the initial agreement or subsequently, of the implementation of instructions and protocols for users within the educational community regarding the photographs and audiovisual content that are appropriate to include in the Educational Services in the Cloud and those that should not be included, nor has it indicated the control and monitoring mechanisms in this regard.

In light of the foregoing, we understand that the objections presented do not invalidate the essential content of the declared infraction, nor do they constitute sufficient justification or exculpation.

8.5. Assessment of the objections to the proposed resolution, evidence presented, and provisional measures.

Once again, the entity involved in the proceedings, in its written response to the proposed resolution, reiterates the organizational measures adopted and informs this Council that the complete correction of this infraction is intrinsically linked to the implementation schedule of the Data Protection Impact Assessment (DPIA).

However, it does not provide documentary evidence of the adoption of specific instructions and protocols directed to users within the educational community regarding the photographs and audiovisual content that are appropriate and inappropriate to include in the Educational Cloud Services, which would achieve the complete correction of the infraction. Therefore, we understand that the allegations presented
Page 63 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
do not invalidate the essential content of the infringement declared to have been committed, nor do they constitute sufficient justification or exculpation.

8.6. Classification.
The facts attributed to the body against which proceedings have been initiated, for the reasons stated, constitute the following infringement of personal data protection regulations:
Failure to comply with the provisions relating to "the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39, 42 and 43" of the GDPR, classified in Article 83.4.a) GDPR; classified for the purposes of the statute of limitations under the LOPDGDD as a serious infringement due to a violation of Article 25 of the GDPR, "Data protection by design and by default," and, in particular, Article 73(d) of the LOPDGDD:
"The failure to adopt the appropriate technical and organizational measures to effectively implement the principles of data protection by design, as well as the failure to integrate the necessary safeguards into the processing, as required by Article 25 of Regulation (EU) 2016/679."

9. Considerations regarding the lack of information in the Record of Processing Activities
9.1. Facts that led to the initiation of the sanctioning procedure.

The entity involved has identified the following processing activities where the processing resulting from the Agreement is recorded:

"Andalusian Digital Educational Ecosystem" and

"Training Support Platforms," which are available, respectively, at

https://juntadeandalucia.es/protecciondedatos/detalle/180649.html and

https://juntadeandalucia.es/protecciondedatos/detalle/166533.html

In the section on "International Transfers," it states "none are foreseen" and

"no international data transfers will be carried out."

9.2. Infringed provisions.

Article 30 of the GDPR stipulates that:
“1. Each controller and, where applicable, its representative shall maintain a record of the processing activities carried out under its responsibility. This record shall contain all of the following information:
[…]
(e) where applicable, transfers of personal data to a third country or an international organization, including the identification of that third country or international organization and, in the case of transfers referred to in Article 49(1), second subparagraph, documentation of appropriate safeguards; [...]
9.3. Legal considerations regarding the existence of an infringement.
Throughout the proceedings, it has been established that international data transfers to third countries are carried out.
However, the section on international data transfers simply states that no international data transfers are foreseen or will not be carried out, when it should:
1. State that they occur.
2. Identify the third countries to which they are made.

Page 64 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
3. Identify the appropriate safeguards.

9.4. Assessment of the allegations against the initiation agreement, evidence presented, or provisional measures.

The entity involved indicates in its statement of allegations that “The competent Directorate General for Innovation will register a new specific data processing activity in the Register of Processing Activities of the Regional Ministry in relation to the execution of the COLLABORATION AGREEMENT BETWEEN THE REGIONAL MINISTRY OF EDUCATION AND SPORT OF THE ANDALUSIAN REGIONAL GOVERNMENT AND MICROSOFT IRELAND OPERATIONS LIMITED FOR THE PROVISION OF SERVICES IN THE CLOUD FOR EDUCATIONAL CENTERS IN PUBLIC SCHOOLS OWNED BY THE MINISTRY OF EDUCATION AND SPORT OF THE REGIONAL GOVERNMENT OF ANDALUSIA.”
Therefore, the body involved in the proceedings merely informs this Council of the measures it will adopt in the future without demonstrating compliance with them.
In light of the foregoing, we understand that the allegations presented do not invalidate the essential content of the declared infraction nor do they constitute sufficient justification or exculpation.
9.5. Assessment of the allegations to the proposed resolution, evidence presented, or provisional measures.
The entity involved alleges that “This Ministry reiterates what was stated in its statement of allegations of December 18, 2024: the formal omission in the existing RAT is acknowledged and immediate correction will be made.” This remedy will be implemented through the creation of a new processing activity specific to the Convention, which will include all the sections required by Article 30, including, in detail, those relating to international transfers, destination countries, and the safeguards applied. Therefore, we understand that the allegations presented do not invalidate the essential content of the infringement declared to have been committed, nor do they constitute sufficient justification or exculpation.

9.6. Classification.
The facts attributed to the body under investigation, for the reasons stated, constitute the following infringement of personal data protection regulations:
Failure to comply with the provisions relating to "the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39, 42, and 43" of the GDPR, classified in Article 83.4(a) GDPR; classified for the purposes of the statute of limitations under the LOPDGDD as a minor infringement due to a formal breach of Article 30 of the GDPR, "Record of processing activities," and, in particular, Article 74.l) of the LOPDGDD:
"Having a Record of processing activities that does not include all the information required by Article 30 of Regulation (EU) 2016/679."

10. Considerations regarding the performance of a Data Protection Impact Assessment

10.1. Facts that motivated the initiation of the sanctioning procedure.

The documentation in the file does not show that a DPIA was carried out, in accordance with Article 35 of the GDPR, prior to the start of the processing. This was confirmed by the Director General of Advanced Technologies and Educational Transformation when informing this Council that "There is no record of a data protection impact assessment prior to the signing of the agreement."

Page 65 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's website
10.2. Infringed provisions.

Article 35 of the GDPR establishes, with regard to the “Data Protection Impact Assessment,” that:
“1. Where a type of processing, in particular one using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to processing, carry out an assessment of the impact of the processing operations on the protection of personal data. A single assessment may address a number of similar processing operations that present similar high risks.
2. When carrying out the data protection impact assessment, the controller shall seek the advice of the data protection officer, if one has been appointed.
3. The data protection impact assessment referred to in paragraph 1 shall be required in particular in the case of:
(a) systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, such as profiling, and on which
4. The supervisory authority shall establish and publish a list of the types of processing operations that require a data protection impact assessment pursuant to paragraph 1. The supervisory authority shall communicate these lists to the Committee referred to in Article 68.5. The supervisory authority may also establish and publish a list of the types of processing that do not require data protection impact assessments. The supervisory authority shall communicate these lists to the Committee. [...]”.
For its part, Article 36.1 GDPR provides with regard to “Prior Consultation” that:
“The controller shall consult the supervisory authority before processing where a data protection impact assessment pursuant to Article 35 shows that processing would result in a high risk if the controller does not take measures to mitigate it.”
Pursuant to Article 35.4 GDPR, the Spanish data protection authorities have published, after being analyzed by the European Data Protection Board, a list of indicative processing activities that require an impact assessment in accordance with the aforementioned Article 3. This list is based on the criteria established by the Article 29 Working Party in guide WP248 “Guidelines on impact assessments for data protection activities.” https://www.ctpdandalucia.es/sites/default/files/inline-files/lista_dpia_art._35.4_rgpd_v1.pdf
Page 66 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
Data Protection Impact Assessment (DPIA) and to determine whether the processing "likely entails a high risk" for the purposes of the GDPR.
10.3. Legal considerations regarding the existence of an infringement.
In accordance with the provisions of paragraph 1 of Article 35 GDPR, the entity involved, in its capacity as data controller, should have carried out a DPIA prior to using the Educational Cloud Services, since two or more of the following conditions are met: Circumstances listed in the aforementioned indicative list of processing activities requiring a DPIA. Specifically, at least the following:
7. Processing activities involving the use of data on a large scale. To determine whether processing can be considered on a large scale, the criteria established in the Article 29 Working Party's guide WP243, "Guidelines on Data Protection Officers (DPOs)," will be considered.
The processing could potentially affect a very large number of students, plus their parents or guardians, and hundreds of thousands of teaching staff, according to official statistics from the Regional Ministry. Currently, according to figures provided by the entity under investigation, the system users are 525,743 students and 73,937 teaching and staff members, belonging to 1,048 educational centers.

9. Processing of data of vulnerable individuals or those at risk of social exclusion. including
data of children under 14 years of age, adults with some degree of disability, disabled persons,
persons accessing social services, and victims of gender-based violence, as well as their
descendants and persons under their guardianship and custody.

10. Processing that involves the use of new technologies or an innovative use of
established technologies, including the use of technologies on a new scale, with a
new objective, or combined with others, in a way that entails new forms of data collection and
use that pose a risk to the rights and freedoms of individuals. Currently,
this technology seems commonplace, but until the recent pandemic, very few
educational centers used it.

Additionally, the use of testing functionalities and the verification of advanced technologies of Cloud-Based Educational Services, if carried out, would require a separate
DPIA, either separately or within the framework of a general DPIA, since, in this case, the following additional circumstances could arise. The following are included:

“1. Processing that involves profiling or assessing subjects, including the collection of data on the subject in multiple areas of their life (work performance, personality, and behavior), covering various aspects of their personality or habits.”

“8. Processing that involves the association, combination, or linking of database records from two or more processing activities with different purposes or by different data controllers.”

In this regard, the entity under investigation has informed this Council that, to date, no use has been made of the testing and verification functionalities of the Cloud Educational Services and, therefore, no processing has been carried out. This means, on the one hand, that no infringement has occurred to date for failure to carry out a Data Protection Impact Assessment (DPIA) regarding the testing and verification activities of the Cloud Educational Services, without prejudice to the possible infringement for not having carried out a DPIA in general regarding the use of the entire platform. And on the other hand, that, in the event of carrying out such processing, the data controller would be in an optimal position to carry out the processing.
Page 67 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal The aforementioned DPIA should have been carried out with regard to the testing and verification activities of advanced technologies for Cloud-Based Educational Services: a stage prior to the start of data processing.

As already stated, prior to the general use of Cloud-Based Educational Services, the body in question should have carried out a DPIA; a necessary instrument to assess the technical and organizational measures to be implemented to guarantee data security, the international data transfers to be carried out, the specific data to be included, the purpose of the processing, etc., given that said processing, by its nature, scope, context, or purposes, may entail a high risk to the rights and freedoms of natural persons; a high risk that, as already stated, will be increased when the processing is carried out on a large scale (the personal data of more than 525,000 students is processed) and relates to data of vulnerable subjects, including data of children under fourteen years of age.

Therefore, a Data Protection Impact Assessment (DPIA) is required prior to the start of processing and, where applicable, depending on its outcome, subsequent consultation with this Council. However, to date, the entity under investigation has not demonstrated that said DPIA was carried out and, where applicable, that prior consultation with this body was held.

10.4. Assessment of the allegations against the initiation agreement, evidence presented, or provisional measures.

The entity under investigation states that “Currently, the Regional Ministry of Educational Development and Vocational Training is already conducting the data protection impact assessment study in order to establish a new collaboration agreement with the cloud-based educational services provider Microsoft, which will include a model of the controller-processor clause provided for in Executive Decision 2021/914 of the European Commission concerning standard contractual clauses for the transfer of personal data to third countries.” in accordance with EU Regulation 2016/679.” Consequently, since no proof of having carried out such an assessment has been provided to this Council to date, this Council understands that the allegations presented do not invalidate the essential content of the infringement declared to have been committed, nor do they constitute sufficient justification or exculpation.
10.5. Assessment of the allegations against the proposed resolution, evidence presented, or provisional measures.
The entity involved again acknowledges that a Data Protection Impact Assessment (DPIA) was not carried out prior to the signing of the Agreement in 2020 and states that this circumstance is already being rectified, having planned the execution of a DPIA as a prior and indispensable step for drafting the new Agreement. However, insofar as this Council has not been provided with proof of having carried out a DPIA, we understand that the allegations presented do not invalidate the essential content of the infringement declared to have been committed, nor do they constitute sufficient justification or exculpation. Sufficient exculpation.

10.6. Classification.
The facts attributed to the body against which proceedings have been initiated, for the reasons stated, constitute the following in-
infringement of personal data protection regulations:
Failure to comply with the provisions relating to "the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39, 42 and 43" of the GDPR, classified in Article
83.4.a) GDPR; classified for the purposes of the statute of limitations in the LOPDGDD as a serious infringement due to
violation of Article 35 GDPR "Data Protection Impact Assessment" and,
in particular, Article 73.t) LOPDGDD:
Page 68 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
"The processing of personal data without having carried out the impact assessment
of the processing operations on the protection of personal data in the cases
where it is required."

Fourth. On the identification of the responsible entity (Art. 89.3 LPAC).

In accordance with the provisions of Article 70.1 LOPDGDD, the Directorate General for Innovation and Teacher Training (Regional Ministry of Educational Development and Vocational Training) is identified as the entity responsible for the infringements.

Fifth. Declaration of the infringement and measures to be adopted (Art. 77.2 LPAC and 58.2 GDPR).

1. Article 77 LOPDGDD establishes the sanctioning regime applicable to certain categories
of data controllers or processors; including, among others:
"[…] c) [...] the Administrations of the autonomous communities and the entities that comprise the Local Administration.[...]”
In the aforementioned article, section 2 states that:
“When the data controllers or processors listed in section 1 commit any of the infringements referred to in Articles 72 to 74 of this Organic Law, the competent data protection authority shall issue a resolution declaring the infringement and establishing, where appropriate, the measures to be adopted to stop the conduct or correct the effects of the infringement committed, with the exception of that provided for in Article 58.2.i of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.[...]”.
Thus, in accordance with Article 77.2 of the LOPDGDD (Spanish Data Protection Law), the infringement or infringements described above must be declared.

2. Furthermore, regarding the measures to be adopted, Article 58.2 of the GDPR (General Data Protection Regulation) provides that:
“Each supervisory authority shall have all of the following corrective powers: […] (d) to order the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a specific manner and within a specified time limit; […] (f) to impose a temporary or permanent restriction on processing, including a prohibition; […] (j) to order the suspension of data flows to a recipient located in a third country or to an international organisation. […]”.
To determine the measures to stop the conduct or correct the effects of the infringement, and their implementation timeframe, consideration must be given to how these measures could disrupt the provision of the public education service during the school year.

These potential disruptions must be minimized when determining implementation deadlines, as they could negatively affect other fundamental rights, such as the right to education, and the principle of the best interests of the child in our legal system.

Therefore, deadlines that do not expire during the school year have been established for those measures whose implementation could disrupt educational services.

Page 69 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
For other measures that would not cause such disruptions, it has been considered that the entity under investigation is carrying out a Data Protection Impact Assessment (DPIA). Its results and action plan should directly influence all processing adjustments, from the information to be provided to data subjects to the safeguards for transfers to third countries. Therefore, a common implementation timeframe has been chosen for all these measures, including the accreditation of the DPIA, thus ensuring their consistency.

In the case at hand, the entity under investigation is ordered to:
a) Submit to the Council, within three months of notification of this resolution, an action plan outlining the measures to be adopted by the entity under investigation to remedy the detected non-compliance, the timetable for their implementation, and justification for said timetable. Specifically, the status of the commitment made in 2024 regarding the signing of the agreement regulating the service provided by Microsoft, which would address the various non-compliances indicated in this sanctioning procedure.

b) Submit to the Council, as soon as possible after notification of this resolution, and in any case, before July 31, 2026, documentation proving the adoption of technical and organizational measures to limit the high risk of system users introducing special categories of data into the Cloud-Based Educational Services.

c) Submit to the Council, as soon as possible after notification of this resolution, and in any case, before July 31, 2026, documentation proving the means used to inform data subjects (students, their family members, and teachers) about the processing of their personal data, complying with all the requirements of Article 13 and, where applicable, Article 14 of the GDPR, and the content of said information. d) It is also appropriate, in accordance with Articles 58.2.j) GDPR and 69.2 LOPDGD, to order the
controller to suspend data flows to the establishments of the
processor and its sub-processors located in third countries without an
adequacy decision, effective from 31 July 2026, except for those data flows for which, prior to that date, the body involved submits to the Council documentary evidence
that the data transfers to third countries without an adequacy decision carried out by the processor and its sub-processors comply with the guarantees, requirements or exceptions established in Articles 44 to 49 GDPR.

e) Submit to the Council, as soon as possible after notification of this resolution,
and in any case, before July 31, 2026, a copy of the instructions and protocols
addressed to users who are members of the educational community regarding the photographs and audiovisual content
that are appropriate to include in the Educational Cloud Services and those that should not be included, and an indication of the control and monitoring mechanisms in this regard.

f) Submit to the Council, as soon as possible after notification of this resolution,
and in any event, before 31 July 2026, documentary evidence that it has modified the section on international data transfers in the processing activities “Training Support Platforms” and “Andalusian Digital Educational Ecosystem,” complying with Article 30 GDPR and therefore incorporating information on “transfers of personal data to a third country or international organization, including the identification of that third country or international organization and, in the case of transfers referred to in Article 49(1), second subparagraph, documentation of appropriate safeguards.”

(g) Submit to the Council, as soon as possible after notification of this resolution, and in any case, before July 31, 2026, documentary evidence of the DPIA carried out, in accordance with the requirements of Article 35 GDPR.

Page 70 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
Sixth. Notifications and communications.

Regarding the notification of the resolution of the sanctioning procedure, Article 77.2 of the Organic Law on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD) provides that "[t]he resolution shall be notified to the controller or processor, to the body on which they hierarchically depend, if applicable, and to the data subjects who have the status of interested parties, if applicable."

Furthermore, Article 77.4 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights) states that "[t]he resolutions issued in relation to the measures and actions referred to in the preceding sections must be communicated to the data protection authority," and Article 77.5 of the LOPDGDD states that "[t]he actions taken and the resolutions issued under this article will be communicated to the Ombudsman or, where applicable, to the analogous institutions of the autonomous communities."

In view of the foregoing, the Director of the Andalusian Council for Transparency and Data Protection issues the following:
RESOLUTION
First. To declare that the General Directorate of Innovation and Teacher Training (Regional Ministry of Educational Development and Vocational Training), with Tax Identification Number NNNNN, has committed the following infringements:
a) Infringement classified under Article 83.4.a) GDPR and considered serious for the purposes of the statute of limitations under Article 73.d) LOPDGDD for violation of Article 25 GDPR concerning data protection by design and by default, in relation to the lack of adoption of organizational measures appropriate to effectively apply the principles of data protection by design and by default, as required by Article 25 GDPR, in reference to the lack of measures to minimize the risk of users including special categories of data in the system.
b) Infringement classified under Article 73.d) of the LOPDGDD. 83.5.b) GDPR and classified for the purposes of the statute of limitations as very serious,
in Article 72.1.h LOPDGDD for violation of Article 13 GDPR referring to the information that
must be provided when personal data are obtained from the data subject in relation to the omission
of the duty to inform data subjects about the processing of their personal data in accordance with the provisions of Article 13 GDPR.

c) Infringement classified in Article 13 GDPR. 83.5.c) GDPR and classified for the purposes of prescription as very serious
in article 72.l) LOPDGDD for violation of articles 44 to 49 GDPR referring to transfers of personal data to third countries or international organizations in relation to the international transfer of personal data to a recipient located in a third country or an international organization, when the guarantees, requirements or exceptions established in articles 44 to 49 of the GDPR are not met.

d) Infringement classified under Article 83.4.a) GDPR and considered serious for the purposes of the statute of limitations under Article 73.d) LOPDGDD for violation of Article 25 GDPR concerning data protection by design and by default, in relation to the failure to adopt organizational measures appropriate to effectively implement the principles of data protection by design and by default, as required by Article 25 GDPR, in reference to the lack of measures to minimize the risk of users including inappropriate images and audiovisual material in the system.

e) Infringement classified under Article 73.d) LOPDGDD. 83.4.a) GDPR and classified for the purposes of prescription as minor in
Article 74.l) LOPDGDD for formal infringement of Article 30 GDPR referring to the lack of information
in the record of processing activities regarding international data transfers.

Page 71 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's Portal
f) Infringement classified in art. 83.4.a) GDPR and classified for the purposes of prescription as serious in the
article 73.t) LOPDGDD for violation of article 35 GDPR referring to the impact assessment
relating to data protection in relation to the use of Educational Services in the
Cloud without having carried out the impact assessment required in article 35 GDPR.
Second. To order the Directorate General for Innovation and Teacher Training, in relation to the measures to be adopted to cease the conduct or correct the effects of the infringements committed, to:
a) Submit to the Council, within three months of notification of this resolution, an action plan
outlining the measures to be adopted by the entity involved to remedy the detected non-compliance, the timetable for their implementation, and justification for said timetable.

b) Submit to the Council, as soon as possible after notification of this resolution and, in any case, before July 31, 2026, documentation proving the adoption of technical and organizational measures to limit the high risk of system users introducing special categories of data into the Cloud-Based Educational Services.

c) Submit to the Council, as soon as possible after notification of this resolution and, in any case, before July 31, 2026, documentation proving the means by which the data subjects (students, their family members, and teaching staff) are informed of the processing of their personal data, complying with all the requirements of Article 13 GDPR and, where applicable, Article 14 GDPR, and the content of said information.

d) It is also appropriate, in accordance with Articles 58.2.j) GDPR and 69.2 LOPDGD, to order the controller to suspend data flows to the establishments of the processor and its sub-processors located in third countries without an adequacy decision, with effect from 31 July 2026, except for those data flows for which, as soon as possible and in any case, before that date, the body involved submits to the Council documentary evidence that the data transfers to third countries without an adequacy decision carried out by the processor and its sub-processors comply with the guarantees, requirements or exceptions established in Articles 44 to 49 GDPR.

e) Submit to the Council, as soon as possible after notification of this resolution and, in any case, before July 31, 2026, a copy of the instructions and protocols addressed to users who are members of the educational community regarding the photographs and audiovisual content that are appropriate to include in the Educational Cloud Services and those that should not be included, and an indication of the control and monitoring mechanisms in this regard.

f) Submit to the Council, as soon as possible after notification of this resolution and, in any event, before 31 July 2026, documentary evidence that it has modified the section on international data transfers in the processing activities “Training Support Platforms” and “Andalusian Digital Educational Ecosystem,” in compliance with Article 30 GDPR, and therefore incorporating information on “transfers of personal data to a third country or international organization, including the identification of that third country or international organization and, in the case of transfers referred to in Article 49(1), second subparagraph, documentation of appropriate safeguards.”

(g) Submit to the Council, as soon as possible after notification of this resolution,
and in any event, before July 31, 2026, documentary evidence of the DPIA carried out,
in accordance with the requirements of Article 35 GDPR.

Third. Notify the infringing authority of this resolution.

Fourth. This resolution shall be communicated to the Andalusian Ombudsman, in accordance with the provisions of Article 77.5 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights).
Page 72 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es
Document suitable for publication on the Council's website.
In accordance with the provisions of Article 50 of the LOPDGDD, this Resolution shall be made public, with the corresponding data redacted, once it has been notified to the interested parties.
Failure to comply with this resolution could constitute an infringement under Article 72.1.m) of the LOPDGDD, punishable in accordance with Article 58.2 of the GDPR.

Against this Resolution, which concludes the administrative process, an optional appeal for reconsideration may be filed with this Council within one month, or a direct appeal may be filed with the Administrative Court of Seville, as determined by rotation, within two months, in both cases counting from the day following notification, in accordance with the provisions of Articles 30.4, 123 and 124 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations and Articles 8.3 and 46.1 of Law 29/1998, of July 13, regulating the Contentious-Administrative Jurisdiction.

However, since this is an act concerning sanctions, the plaintiff may alternatively choose to file the aforementioned administrative appeal with the court or tribunal in whose jurisdiction they are domiciled, always understanding this choice to be limited to the jurisdiction of the High Court of Justice of Andalusia, in accordance with the provisions of paragraphs two and three of Article 14.1 of Law 29/1998, of July 13, regulating the Administrative Jurisdiction.

In accordance with the provisions of Article 90.3.a) of the LPACAP (Law on Administrative Procedure), the final administrative decision may be provisionally suspended if the interested party expresses to this Council their intention to file an administrative appeal and submits to it, once filed, the documentation that proves its filing. If the Council is not notified of the filing of an administrative appeal within the corresponding time limit, or if the appeal does not request the precautionary suspension of the resolution, the aforementioned suspension will be considered terminated.

THE DIRECTOR OF THE ANDALUSIAN TRANSPARENCY AND DATA PROTECTION COUNCIL
The original resolution is electronically signed.
Page 73 of 73. Resolution RPS-2025/082, of December 2 - PS-2024/088 - RCO-2023/037
www.ctpdandalucia.es