{"id":1034194,"date":"2020-04-16T08:34:15","date_gmt":"2020-04-16T07:34:15","guid":{"rendered":"https:\/\/pulse.microsoft.com\/?p=1034194"},"modified":"2025-04-18T10:53:11","modified_gmt":"2025-04-18T09:53:11","slug":"microsoft-update-microsoft-365-copilot-data-privacy-impact-assessment","status":"publish","type":"post","link":"https:\/\/pulse.microsoft.com\/nl-nl\/slimmer-werken\/na\/microsoft-update-microsoft-365-copilot-data-privacy-impact-assessment\/","title":{"rendered":"Microsoft Update: Microsoft 365 Copilot Data Privacy Impact Assessment"},"content":{"rendered":"<p><b><span data-contrast=\"auto\">Microsoft Update: Microsoft 365 Copilot Data Privacy Impact Assessment<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">In December 2024, Strategic Vendor Management of the Dutch Ministry of Justice (SLM) and SURF published their Data Privacy Impact Assessment (DPIA) of Microsoft 365 Copilot, containing their concerns based on 4 high risks. This overarching DPIA is designed to support SLM and SURF in their role in procuring technology services for the central government and educational entities. This DPIA supports individual government organizations and educational institutions in performing their own DPIAs for their specific processing activities of personal data in the potential use of Microsoft 365 Copilot.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/pulse.microsoft.com\/nl-be\/work-productivity-nl-be\/na\/fa2-979641\/\"><span data-contrast=\"none\">In a response<\/span><\/a><span data-contrast=\"auto\">, Microsoft\u2019s Chief Technology Officer, Enterprise and Devices, Ale\u0161 Hole\u010dek, shared our commitment to ongoing work between the parties to help address the concerns SLM and SURF raised regarding the Dutch governments and education, sector\u2019s intended use of Microsoft 365 Copilot.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">In this blogpost we share an update about the progress and measures we introduced to meet our commitments to SLM and SURF in a manner that will benefit all our commercial customers. Microsoft has investigated and is of the view that it has addressed the specific observations of SLM and SURF by implementing solutions ahead of the target date of April 4<\/span><span data-contrast=\"auto\">th<\/span><span data-contrast=\"auto\">.\u00a0 We shared an update on the work completed in support of Microsoft\u2019s commitments in a follow-up letter, <a href=\"https:\/\/pulse.microsoft.com\/wp-content\/uploads\/2025\/04\/v2-Response-to-MS-Letter-from-12.16.24.pdf\">published here<\/a><\/span><span data-contrast=\"auto\">. We are confident that these changes will enable a reassessment of the prior \u2018high risk\u2019 determinations. <\/span><\/p>\n<p><span data-contrast=\"auto\">The follow-up letter states how Microsoft has addressed the concerns on\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ol>\n<li data-leveltext=\"%1.\" data-font=\"\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><strong>Retention time of diagnostic data\u00a0<\/strong><\/li>\n<li data-leveltext=\"%1.\" data-font=\"\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><strong>Data Subject Access Request output\u00a0<\/strong><\/li>\n<li data-leveltext=\"%1.\" data-font=\"\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><strong>Required service data and diagnostic data transparency\u00a0<\/strong><\/li>\n<li data-leveltext=\"%1.\" data-font=\"\" data-listid=\"3\" data-list-defn-props=\"{&quot;335552541&quot;:0,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769242&quot;:[65533,0],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;%1.&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><strong>Accuracy of personal data in Copilot outputs\u00a0<\/strong><\/li>\n<\/ol>\n<p><span data-contrast=\"auto\">On the topic of accuracy, Microsoft demonstrated further investments, such as the recent ISO 42001 certification and will continue to invest in this topic. Our perspective remains that both Microsoft and organizations themselves have a shared responsibility to address potential risks related to inaccurate generative AI output. Organizations have a responsibility to educate their users to understand that Microsoft 365 Copilot is a generative AI tool that predicts text recommendations. It is intended to assist users and is not intended to, and should not be used to, replace user decision-making.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">We welcome the ongoing dialogue and take pride in the progress made to assist both SLM and SURF and their constituents in their deployment of AI technologies. At Microsoft, we are always prioritizing the privacy and security of our customers&#8217; data. <\/span><b><span data-contrast=\"auto\">Our commitment to GDPR compliance remains unwavering.<\/span><\/b><span data-contrast=\"auto\"> Microsoft has also developed additional services such as the Microsoft EU Data Boundary that guarantees the processing and storage of data in Europe. We are continuously working to meet the evolving and different needs of our customers and are creating higher standards every day.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Update: Microsoft 365 Copilot Data Privacy Impact Assessment\u00a0 In December 2024, Strategic Vendor Management of the Dutch Ministry of Justice (SLM) and SURF published their Data Privacy Impact Assessment (DPIA) of Microsoft 365 Copilot, containing their concerns based on 4 high risks. This overarching DPIA is designed to support SLM and SURF in their [&hellip;]<\/p>\n","protected":false},"author":924,"featured_media":1034146,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"class_list":["post-1034194","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","specials-slimmer-werken","stories-managing-your-data-nl-nl","stories-hoe-kan-ik-veilig-gegevens-beheren-gegevensbeheer","businessPriorities-digital-transformation-nl-nl"],"_links":{"self":[{"href":"https:\/\/pulse.microsoft.com\/nl-nl\/wp-json\/wp\/v2\/posts\/1034194"}],"collection":[{"href":"https:\/\/pulse.microsoft.com\/nl-nl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pulse.microsoft.com\/nl-nl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pulse.microsoft.com\/nl-nl\/wp-json\/wp\/v2\/users\/924"}],"replies":[{"embeddable":true,"href":"https:\/\/pulse.microsoft.com\/nl-nl\/wp-json\/wp\/v2\/comments?post=1034194"}],"version-history":[{"count":5,"href":"https:\/\/pulse.microsoft.com\/nl-nl\/wp-json\/wp\/v2\/posts\/1034194\/revisions"}],"predecessor-version":[{"id":1034555,"href":"https:\/\/pulse.microsoft.com\/nl-nl\/wp-json\/wp\/v2\/posts\/1034194\/revisions\/1034555"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pulse.microsoft.com\/nl-nl\/wp-json\/wp\/v2\/media\/1034146"}],"wp:attachment":[{"href":"https:\/\/pulse.microsoft.com\/nl-nl\/wp-json\/wp\/v2\/media?parent=1034194"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pulse.microsoft.com\/nl-nl\/wp-json\/wp\/v2\/categories?post=1034194"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}