Auratech Legal Solutions

Microsoft 365 in Schools: Privacy, Cloud Services and GDPR Lessons

The use of Microsoft 365 in schools has become so ordinary that few centres still ask themselves on what legal basis they are doing it. The question came back sharply in April 2026, when the Spanish Data Protection Agency fined a school in Madrid over an equivalent suite — and the file makes clear that the problem was not the tool, but the missing paperwork.

The decision that matters for Spanish schools

Enforcement procedure PS-00607-2025, resolved on 15 April 2026, was brought against a private school in Madrid over its use of Google Workspace for Education. The fine was set at 20,000 euros and reduced to 12,000 after acknowledgement of liability and voluntary payment.

What matters is not the amount but the reasoning. The Agency found, first, an insufficient legal basis: the school had not established that the processing was necessary for the educational function, only that it was convenient. Second, a breach of the principles of lawfulness, fairness and transparency. And third, shortcomings in the information given to families and in the impact assessment, which did not analyse international data transfers.

That reasoning transfers point by point to any school using Microsoft 365, Google Workspace or an equivalent platform. The brand changes; the obligation does not.

What the European Data Protection Supervisor said about Microsoft 365

On 8 March 2024 the European Data Protection Supervisor found that the European Commission’s use of Microsoft 365 infringed the rules applicable to EU institutions. It identified four failures: purposes and data types not determined in the contracts, insufficiently documented instructions to the processor, international transfers without adequate safeguards, and unauthorised disclosures to third parties. It ordered the suspension, with effect from 9 December 2024, of data flows to third countries without an adequacy decision.

The Commission and Microsoft brought actions before the General Court. And on 11 July 2025 the Supervisor closed the investigation, considering the infringements remedied after a compliance report evidencing updated contracts, identified recipients, restricted transfers and implementation of the EU Data Boundary.

The operational conclusion is the good news in this story: Microsoft 365 in schools can be run lawfully. But not by default — only with specific contracts and bounded transfers.

The German turn and the Dutch assessments

In Germany, the conference of data protection authorities concluded in November 2022 that Microsoft 365 could not be operated in compliance. The Baden-Württemberg authority went further in April 2022 and ordered schools to stop using the tool unless compliance could be firmly demonstrated, recommending open-source alternatives instead.

That position has shifted. In November 2025 the Hesse authority concluded that compliant use by public bodies, schools included, is indeed possible — relying on the EU Data Boundary, on the new privacy architecture and, above all, on a public-sector-specific processing agreement negotiated with Microsoft. Compliance arrived when the contract did, not before.

In the Netherlands, impact assessments commissioned by central government and by the universities identified one high risk — potential access by United States authorities to sensitive data — and several lower risks around telemetry and limits on the right of access. Later assessments covering Copilot, updated in 2025 and 2026, conclude that deployment is possible with responsible adoption.

What a school needs to have in place

From the Spanish decision and the European one, a short and demanding list emerges.

Minors: where there is no margin

Article 7 of the Spanish Data Protection Act sets fourteen as the age from which a minor can consent on their own behalf; below that, it falls to those holding parental responsibility. In schools, the twenty-third additional provision of the Spanish Education Act allows the centre to collect the data needed for teaching and guidance, but expressly limits its use to that purpose: any other processing requires consent.

That is why the distinction the Agency drew between necessary and convenient matters so much. An email service for pupils may be necessary. That same service switching on profiling or advertising features never is.

The next front: AI in the classroom

The EU AI Act lists education and vocational training among the high-risk uses in Annex III. Following the reform introduced by the digital omnibus of July 2026, those obligations become enforceable on 2 December 2027. That is enough time to prepare an inventory of tools, but not a reason to ignore it: AI features already ship switched on in the suites schools have contracted.

A school needs someone to settle these questions in writing, and before the complaint arrives. At Auratech Legal we take on that role as external Data Protection Officer for educational institutions: the contract with the provider, the impact assessment, the information to families and a documented position on what may be switched on and what may not.

Exit mobile version