• 4 mins read
  • Published

Andalusia Sanctioned for Sharing Student Data with Microsoft

Richard Reid RUSSPAIN.com

Post by Richard Reid

Andalusia Sanctioned for Sharing Student Data with Microsoft RUSSPAIN.com © russpain.com
Andalusia Sanctioned for Sharing Student Data with Microsoft © russpain.com

Andalusia's government faces sanctions after transferring data of over 500,000 minors to Microsoft. The regional authority failed to protect sensitive information, raising concerns about privacy and compliance with EU law.

The Andalusian regional government has been formally sanctioned for transferring the personal data of more than half a million students and tens of thousands of teachers to Microsoft, in exchange for free access to the company’s virtual education platform. The Council for Transparency and Data Protection of Andalusia found that, over the past six years, the Junta failed to safeguard the privacy of 525,000 minors, 74,000 teachers, and around 1,000 schools, violating several articles of the European General Data Protection Regulation (GDPR).

The Council imposed six sanctions on the regional government—two classified as very serious, three as serious, and one as minor. However, no financial penalty was issued. The most severe infractions involved transferring personal data to third countries without adequate guarantees, including destinations such as the United Arab Emirates, South Africa, and India, and failing to inform students and staff about how their data would be used. The Council highlighted that the European Commission does not consider many of these countries to have sufficient data protection standards.

Serious breaches also included the lack of measures to minimize the risk of leaks involving highly sensitive data, such as health information, and the storage of inappropriate images and videos on Microsoft’s cloud. The Junta did not conduct the legally required impact assessment, nor did it register the international transfers of minors’ data, as required by law. The data was handed over without prior consent from students or teachers, in return for free use of Microsoft’s virtual tools, including Office applications, OneDrive, and Teams.

According to the Council, the regional government failed to implement technical and organizational safeguards to limit the high risks associated with uploading special category data—such as health, religion, ideology, beliefs, sexual life, or racial origin—to the cloud. Everyday school activities, like sharing political opinions in essays or uploading psychopedagogical reports, often resulted in sensitive information being processed without the knowledge or consent of students and their families.

This is not the first time Andalusia has faced criticism for its handling of educational data. In 2020, a similar agreement with Google led to the exposure of data from over 738,000 minors and 43,000 teachers, which was also censured by the Data Protection authority. Both Microsoft and Google now dominate the virtual learning environment for 1.2 million students in the region, representing two-thirds of Andalusia’s primary and secondary education system.

The Council’s decision to avoid a financial penalty was based on the need to protect the right to education and prevent disruption to essential digital services. The Junta now has until July 31 to present a new action plan, developed with Microsoft, to address the identified failures and limit ongoing risks. The current agreement with Microsoft, first signed in 2020 and renewed in 2022 and 2024, is set to expire in November, with a new contract expected before then.

Microsoft has not been sanctioned by the Andalusian authority and declined to clarify its compliance with European regulations, stating only that it is committed to data protection laws. The regional government has downplayed the impact of the sanctions, claiming it already has a corrective plan similar to the one previously approved for Google. However, critics argue that the repeated breaches reflect a deeper issue with reliance on foreign tech giants and the lack of transparency in handling sensitive educational data.

For context, the issue of data misuse and regulatory oversight has surfaced in other regions as well. For example, a recent case in Valencia involved authorities uncovering a large-scale investment fraud, as detailed in this report on a Ponzi scheme investigation. While the circumstances differ, both cases highlight the challenges Spanish authorities face in protecting citizens’ interests amid complex digital and financial environments.

Under EU law, health data and other special categories are subject to strict protection due to the potential impact on individuals’ privacy and fundamental rights. The Andalusian Council’s resolution emphasizes that, while safeguarding education is a priority, authorities must also ensure robust data protection. The regional education department is expected to deliver a comprehensive risk assessment and corrective plan this summer. The ongoing debate underscores the tension between digital modernization in schools and the imperative to uphold privacy standards for minors and educators.

Also read