Most enterprises assume that if a vendor calls itself “enterprise‑ready” and posts a privacy policy, the hard work of CCPA and GDPR compliance is already done — the new TrustThis.org benchmark shows that assumption is dangerously wrong for the majority of mainstream platforms.
Background...
Microsoft has been ordered by Austria’s data protection authority to stop deploying tracking cookies on a pupil’s devices after a regulator found the cookies were installed without valid consent and were being used for purposes that go beyond purely educational needs. The ruling — the latest in...
Microsoft está siendo investigada en la Unión Europea tras una denuncia que acusa a la compañía de procesar ilegalmente datos personales de palestinos y ciudadanos europeos para fines de vigilancia militar israelí, una acusación que pone en el centro al servicio en la nube Microsoft Azure, al...
Microsoft's cloud is at the center of the latest legal escalation over how hyperscale platforms handle government intelligence workloads after the Irish Council for Civil Liberties (ICCL), working with the international rights group Eko, filed a formal complaint with Ireland’s Data Protection...
Microsoft’s Azure cloud now sits at the center of a major data‑privacy and human‑rights controversy after the Irish Council for Civil Liberties (ICCL) lodged a formal GDPR complaint alleging Microsoft Ireland unlawfully processed and enabled the transfer of Palestinian personal data used by the...
The Irish Council for Civil Liberties (ICCL) has lodged a formal complaint with Ireland’s Data Protection Commission (DPC) alleging that Microsoft Ireland unlawfully processed data on behalf of the Israeli Defence Forces in a manner that enabled mass surveillance, the transfer of large volumes...
Microsoft is facing a formal complaint to the Irish Data Protection Commission alleging the company aided the Israeli military in removing or obscuring evidence of mass surveillance of Palestinians stored in European cloud data centres — a development that sharpens legal, technical and...
The Austrian data protection authority has found that Microsoft’s widely used Microsoft 365 Education platform illegally tracked students, failed to provide full access to their personal data, and attempted to shift GDPR responsibilities onto schools and education authorities — a ruling that...
SURF’s updated Data Protection Impact Assessment (DPIA) has moved two of four previously flagged high privacy risks for Microsoft 365 Copilot in education down to medium, but important hazards — notably AI inaccuracy (hallucinations) and an 18‑month retention window for pseudonymized telemetry —...
Dutch education and research network SURF’s Data Protection Impact Assessment (DPIA) of Microsoft 365 Copilot finds persistent privacy and safety gaps that make the service unsuitable for broad use in schools and research institutions — and even after ongoing talks with Microsoft, two of the...
ai governance
ai hallucinations
automation bias
data retention
data security
data-subject-rights
dpia
edtech
education technology
gdpr
institution
microsoft copilot
on-premise-processing
privacy
provenance
research institutions
risk management
surfing
telemetry
transparency
Microsoft will begin installing the Microsoft 365 Copilot app automatically on Windows devices that already have the Microsoft 365 desktop apps, a background rollout that starts this fall and is expected to reach completion by mid‑November — but it won’t happen for devices in the European...
2025
admin center
admin controls
ai productivity
app integration
applocker
auto install
automation
background install
copilot
copilot rollout
data governance
data residency
deployment
device management
device settings
eea
eea carve-out
eea exclusion
end users
endpoint management
enterprise it
enterprise rollout
european economic area
fall 2025 rollout
gdpr
group policy
help desk
helpdesk planning
intune
it admin
it administration
it governance
licensing
licensing gating
microsoft 365
microsoft 365 apps admin center
microsoft copilot
microsoft education
microsoft office
modern app settings
onboarding discovery
opt-out
policy management
powershell
powershell uninstall
privacy
privacy compliance
privacy telemetry
productivity tools
registry
regulatory compliance
remote provisioning
rollout
security
security compliance
srp
start menu
telemetry
tenant opt-out
turnoffwindowscopilot
user adoption
user experience
user training
windows
windows 11
windows deployment
windows management
windows update
Norway’s legal profession is at a decisive inflection point: by combining strict, fjord‑tested data protection rules with a newly modernised Lawyer Act, Norwegian firms can safely harvest huge productivity gains from generative AI — but only if they pick tools and deployment patterns that...
ai governance
audit rights
contractual dpa
data residency
data security
datatilsynet
dms integration
dpia
ediscovery
eu ai act
gdpr
lawyer act
legal ai
norway
personal data
regulatory compliance
sandbox
tech litigation
tenant isolation
vault
There has been a sharp and measurable shift in how Irish mid‑market executives view artificial intelligence: the proportion who described AI as “over‑rated” or mostly hype has collapsed, firms are moving rapidly to formalise generative‑AI rules for staff, yet anxiety about data privacy has never...
ai
ai governance
artificial intelligence
cybersecurity
data loss prevention
digital trust
eu ai act
gdpr
governance
ireland
microsoft copilot
mid-market
midmarket ai
pilot program
policy
privacy
regulatory compliance
shadow ai
smes
vendor due diligence
Universitätsmedizin Göttingen (UMG Göttingen) has moved from proof‑of‑concept to production by expanding its deployment of Sectra’s enterprise imaging technology to include the Sectra Amplifier Service, a managed AI‑as‑a‑service hosted in Microsoft Azure that integrates validated third‑party AI...
Hotels face a crossroads: artificial intelligence promises smarter personalization and leaner operations, but when guest names, preferences or booking histories are casually copy-pasted into public chatbots the consequences can be legal, financial and reputational — as Amsterdam-based middleware...
ai
cdp
copilot
data residency
data security
dlp
enterprise ai
gdpr
governance
guest-data
hospitality
hotel
llms
middleware
privacy
prompt injection
risk management
shadow ai
siem
Windows 11’s AI-first push has turned into a study in contradictions: promising productivity shortcuts and local intelligence on one hand, and on the other hand delivering a fragmented, confusing, and sometimes privacy-ambiguous user experience that many feel undermines the core job of an...
ai credits
ai ux
cloud ai
copilot
enterprise it
fragmentation
gdpr
hardware gating
microsoft copilot
neural processing units
npu
on-device ai
privacy
recall feature
security
software monetization
windows 10 end of support
windows 11
Microsoft's candid admission that it “cannot guarantee” European customer data will never be handed to U.S. authorities has turned a long‑standing corporate argument about cloud sovereignty into a live-policy moment — and prompted sharp public ripostes from regional players such as OVHcloud’s...
byok
cloud act
cloud sovereignty
cross-border data
cryptographic keys
customer managed keys
data governance
data localization
data residency
data sovereignty
eu data boundary
gdpr
microsoft eu data
operational sovereignty
ovhcloud
privacy
sovereign cloud
tech sovereignty
vendor lock-in
Zscaler’s claim that its cloud sees “over half a trillion transactions a day” has suddenly become more than a brag about scale — it’s the center of a fresh privacy controversy after external reports and researcher commentary interpreted CEO remarks to mean Zscaler is using customer logs and full...
ai training
cloud security
data containment
data governance
data residency
data security
gdpr
logs
model training
multi-tenant
privacy
regulatory compliance
soc 2
telemetry
third-party audit
token masking
vendor risk
zscaler
Last week’s headlines brought a stark reminder that identity is the new battlefield: a major US credit union disclosed a breach that exposed entire customer identity kits, researchers revealed Android malware weaponizing NFC to enable real-time payment fraud, UK regulators tightened the rules on...
Microsoft has opened a formal, externally supervised review into allegations that its Azure cloud was used to store and process vast quantities of intercepted Palestinian communications — a probe that elevates a months‑long ethics and policy crisis inside the company into an urgent legal...
ai ethics
civil society
cloud computing
cloud contracts
corporate governance
covington burling
data residency
data security
employee activism
external review
gdpr
human rights
israel palestine
microsoft
microsoft azure
palestinian data
privacy
regulatory challenges
sovereign cloud
surveillance