European Data Protection Authority's ruling and lessons learned for Vietnam

Insights
European Data Protection Authority's ruling and lessons learned for Vietnam
Posted on: 17/06/2025

    Global digital transformation is taking place at a rapid pace, cloud services such as Microsoft 365[1] have become indispensable tools for public organizations as well as private organizations. However, the use of these platforms poses a major challenge in terms of personal data protection, especially when data is transferred outside the domestic jurisdiction. The case of the European Commission (EC) being investigated and sanctioned by the European Data Protection Authority (EDPS) for using Microsoft 365 is a wake-up call for the protection of personal data in the public sector of many countries. The EDPS decision not only sheds light on the gaps in data management of one of the most powerful bodies in the European Union (EU), but also provides important lessons for countries like Vietnam, where the legal framework for protecting personal data is being built.

     

     

    1. EDPS Decision on EC Use of Microsoft 365 Services

    Background of the case

    In May 2021, EDPS launched an investigation into the EC's use of Microsoft 365, following the Schrems II (2020) ruling by the European Court of Justice (CJEU). The ruling declared the EU-U.S. Data Transfer Agreement (Privacy Shield) invalid due to concerns about U.S. intelligence surveillance, raising questions about the legality of transferring personal data outside the EU. The investigation focused on the Inter-Institutional Licensing Agreement 2021 (ILA 2021) between the EC and Microsoft Ireland, which looked at compliance with Regulation (EU) 2018/1725 – the data protection legal framework applicable to EU authorities (EUIs).

    The EDPS decision, published on March 8, 2024, determined that the EC violated three main aspects: (1) Lack of safeguards for data transfers outside the EU/EEA, (2) Lack of clarity in the contract with Microsoft, and (3) Data processing violations. These violations not only expose the lack of transparency in the contract with Microsoft, but also show the EC's deep dependence on a technology provider outside of Europe[2].

    Details of EC violations

    First, there is a lack of clarity in the contract with Microsoft

    In its contract with Microsoft, the EC did not fully define the types of personal data collected and the specific, clear purpose for which it was collected. This resulted in the inability to ensure that the data was processed only for its intended purposes and not used for other purposes. Contractual terms such as "diagnostic data" or "data generated from services" are too generic to meet the transparency requirements of Regulation (EU) 2018/1725. This allows Microsoft to process data for purposes that are not approved by the EC, such as product improvements, violating the principle of limitation of purposes.

    Second, lack of safeguards for data transfers outside the EU/EEA  

    The EC does not implement adequate safeguards to ensure that personal data transferred outside the EU/EEA (mainly to the US) has the same level of protection. In the period 2021-2023, in the absence of an EU-US data transfer agreement, the EC did not carry out data transfer mapping exercises to identify destinations, recipients, and safeguards. This increases the risk of data being monitored by US intelligence, in violation of Article 48 of Regulation (EU) 2018/1725.

    Third, violations of data processing  
    The EC also violated data processing regulations, including the transfer of personal data made on behalf of the EC. In this case, the EC did not guarantee that Microsoft would only process the data in accordance with the documented instructions, resulting in the risk of unauthorized disclosure. Microsoft Ireland may decide on certain aspects of the processing on its own, acting as a data controller rather than just a data processor. The lack of oversight of sub-processors increases the risk of data being shared with unauthorized third parties.

    Remedies

    In its decision, EDPS imposes strict remedies, including:

    Pause international data flows. The EC must stop all data flows from Microsoft 365 to non-EU/EEA countries without an adequacy decision by December 9, 2024.

    Bring processing into compliance. The EC must amend its contract with Microsoft, perform data transfer mapping exercises, and ensure Microsoft only processes data in accordance with EC guidelines for the same period of time as the suspension of international data flows.

    The EC submitted a compliance report on December 6, 2024, but EDPS is still evaluating. The EDPS decision is currently being appealed by the EC and Microsoft in the CJEU (T-262/24 and T-265/24 cases), complicating enforcement.

    The EC-Microsoft 365 incident is a historic milestone in data protection activities in the EU. It highlights the risks of public institutions relying on cloud services from U.S. providers, especially amid EU-US regulatory tensions over data transfers. The EDPS decision emphasizes the role of supervisory authorities in ensuring the exemplary performance of public institutions, while sending a strong message to the private sector about compliance with data protection regulations such as the GDPR.

     

    Microsoft 365. Source: Teknertia

     

    2. Experience for Vietnam

    Vietnam is in the process of finalizing the Draft Law on Personal Data Protection, which is expected to be promulgated in 2025. The EC-Microsoft 365 case provides many important lessons and experiences for bill drafting agencies as well as data protection supervisory agencies in Vietnam in the future, especially in the context of digital transformation and the popularity of cloud services such as Microsoft 365.

    First, build a clear and detailed legal framework

    Regulation (EU) 2018/1725 provides specific requirements for contracting with cloud providers, including defining the type of data, the purposes for which it is processed, and safeguards for international data transfers. The lack of clarity in the EC's ILA 2021 contract is the main cause of the breach. Therefore, the Draft Law on Personal Data Protection now requires organizations to be transparent about the purpose of data processing and data protection when transferred abroad. However, the law needs to add:

    1. Cloud contract specifics. Vietnam needs to clearly stipulate the terms that must be included in the contract with a vendor such as Microsoft, including the list of sub-processors, the type of data, and the purpose of processing.
    2. Data transfer assessment process. Ask organizations to implement a data transfer mapping plan, similar to the EDPS requirement, to identify destinations and protections.
    3. Sub-processors monitoring mechanism. Monitoring third parties in data processing is extremely important and urgent to ensure that sub-processors fully comply with data protection obligations as the original data holder.

    Second, Vietnam should establish an independent and strong supervisory body

    It can be seen that EDPS operates independently, has the power to investigate, impose remedies (such as suspending data flow), and take the case to court. The decision to deal with the EC demonstrates the important role of an independent and robust supervisory body in ensuring compliance, even with the national authorities, of the European bloc.

    The draft Law on Personal Data Protection has proposed the establishment of a personal data protection agency managed by the Ministry of Public Security, but it is unclear about its powers and resources. We believe that when this agency is established in practice, it is necessary to (1) Ensure independence. The supervisory agency must be independent of the Government and businesses to avoid conflicts of interest. (2)  Strong empowerment. This includes the right to investigate, impose remedies (such as fines, suspend data processing), and prosecute violations. Only a regulatory agency with sufficient power, resources and mechanisms can handle complex violations by agencies and businesses in personal data protection that are somewhat chaotic in Vietnam. (3) Strong enough resources. As mentioned above, empowering an independent body to monitor and enforce personal data protection laws requires ensuring the investment of budget and personnel to handle complex cases, such as the use of cloud services mentioned in this article.

    Thirdly, it is recommended to conduct training and improve the capacity of human resources

    EDPS provides in-depth training on AI and data protection for employees and Data Protection Officers (DPOs) of EUIs. This helps them understand the risks from new technologies, such as cloud services, and take appropriate measures.

    Awareness of data protection in Vietnam is still low, especially among public agencies and small and medium-sized enterprises (SMEs). To solve it, a substantive and effective DPO training program is needed. It is very necessary to develop courses on cloud services, international data transfer, and data protection impact assessment (DPIA) in Vietnam in the coming time. In addition, conducting international learning and cooperation is necessary in the context of Vietnam. Learning from organizations such as EDPS to apply best practices in training and monitoring modern and innovative activities of technology companies around the world.

    EDPS's decision to use Microsoft 365 cloud services by EC is a strong warning about the data protection risks of relying on foreign cloud services. Violations of the limitation of purpose, international data transfers, and unauthorized disclosures demonstrate the need for clear legal frameworks, strong supervisory authorities, and domestic technological solutions. For Vietnam, this case provides a roadmap to finalize  the Draft Law on Personal Data Protection and build an effective monitoring system. By learning from EDPS, Vietnam can ensure citizens' privacy in the digital age, while promoting safe and sustainable digital transformation for the nation's major goals in the coming time.


     

    [1] Microsoft 365 software is a cloud-based productivity platform, belonging to Microsoft, a U.S. multinational corporation headquartered in Redmond, Washington; specializing in developing, producing, trading software copyrights and supporting a wide range of computer-related products and services