Hi !
This fall, we at SchoolSec (KS) sent out a survey to all the country's counties and municipalities to examine how municipal Norway uses Microsoft 365.
Now that we have completed a DPIA of Google Workspace for Education, one question we always get is different versions of "But, but, what about the DPIA of Microsoft 365 then?".
The fact that we often got this question, we assumed, said a lot about the need for a similar, national assessment of the privacy impacts of using M365 in schools.
However, because we cannot base our work on assumptions, we sent out a survey to all the country's counties and municipalities in the fall of 2024.
The goal was to find out which tools within M365 Norwegian school owners used, a bit about how they have set up the system, and not least which assessments (such as DPIA and ROS) had been carried out.
Several have conducted a ROS, fewer have done a DPIA
The survey shows that relatively few have conducted a DPIA. As for ROS (Risk and Vulnerability Analyses), it is somewhat better since several respondents state they have done these types of assessments.
However, some of the qualitative responses suggest that even though many report having done a ROS, there may be reason to question the quality of these assessments. Some state, for example, that these assessments are starting to get old, and that they have not been updated.
The fact that several are using the solution without having done a DPIA confirms our assumption that there is a need to do a national DPIA of Microsoft 365 just like for Google Workspace for Education.
We have published the results of the survey which you can download here!
What are we going to use this survey for?
Primarily, this survey was a confirmation of the need to conduct a national DPIA of the use of M365 in schools.
But we will also use it to set the framework for what we will assess in the M365 DPIA. That is the "scope" of the M365 DPIA. The idea is that the project group itself defines this.
But we would also like to hear from you! Do YOU have any thoughts on what you want from the DPIA of M365? What do you want it to answer? Are there any particularly difficult issues you have encountered when conducting a DPIA of M365 in your municipality?
Tell us by responding to this email!
I wish you a wonderful, privacy-friendly week-end!
Best regards,
Ida Thorsrud
Project manager national DPIA
This newsletter was translated from Norwegian to English with assistance from ChatGPT by OpenAI. While it guided our translation, we made independent editorial choices. Any discrepancies result from this combined approach.