General information
Like other software manufacturers, Microsoft also uses personal licenses. The use of Microsoft 365 (M365) therefore requires a personal Microsoft account. This LMU Microsoft account is created based on your data from the LMU and LRZ identity management system and controlled by the LMU.
This account is created either pseudonymously in the systems of Microsoft or from the connected identity management systems of the universities.
As a member of the LMU, you will receive a personal Microsoft account managed by the LMU. To do this, you must unlock your LMU user ID once in the LMU user account. After activation, the use of M365 and Microsoft products licensed for you is possible as long as and to the extent they are made available by LMU or as long as you are a member of the LMU. The activation can be undone in the LMU user account (see “Duration of storage of personal data”).
M365 is operated by Microsoft Corporation, Microsoft Corporation, One Microsoft Way Redmond, Washington 98052.
The contractual partner for the LMU is:
Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland.
When you create your LMU Microsoft account, Microsoft’s Terms of Use, Microsoft Product and Online Terms and Conditions and the LMU’s M365 usage notices apply. Here you can find Microsoft’s data protection information on M365.
Purpose of data processing
The purpose of the data processing is the use of an LMU Microsoft account and M365 as a software and cloud service solution to ensure the administration, operation of workplaces as well as the carrying out of studies, research and teaching at the LMU and all legal tasks of the LMU. M365 is a product package of Office programs and cloud services. The software serves the daily execution of office work, as a communication and organizational solution as well as for data storage and data exchange.
This includes, in particular, the use of the licensed products and services, provision of updates, guarantee of information security, and technical and customer support, including disclosure for the following purposes by Microsoft, whereby Microsoft acts here as its own controller:
- Billing and account management
- Remuneration
- Internal reporting and modelling
- Fight against fraud
- Cybercrime or cyberattacks
- Improving core functionality in terms of accessibility, data protection or energy efficiency
- Financial reporting
- Compliance with legal obligations
Statistics on usage are also produced.
The LMU does not process data for purposes other than those specified or permitted by law (e.g. for internal verification of security systems and to ensure internal network and information security in accordance with Article 6(1) of the BayDSG). LMU processes only the personal data that you have provided to us or which have been collected in an admissible manner as part of the activity at LMU (Art. 4 para. 2 BayDSG).
The LMU does not control performance or behavior based on your use of your LMU Microsoft account or M365.
In some cases (e.g. longer unavailability of the service) it may be necessary to contact you. If there is no equivalent or better way to inform you, we will use your personal data to contact you, e.g. via the information service of LMU.
Visibility of your activities
Since the LMU Microsoft account is an online account and M365 is a cloud-based offering with a very broad range of software and services, it is not possible to assess the visibility of your activities. The most common applications are discussed below.
- Your activities can be visible whenever you connect with other users as part of these cloud services.
- When files are shared via OneDrive or other cloud services, they can be visible to other users.
- You can search and invite other users as part of the cloud services. Your name and other data from your LMU Microsoft account may be visible.
- When collaborating on documents, the changes you or other shared documents, as well as metadata such as change times, etc., may be visible.
Usage profile
Your LMU Microsoft account contains in the initial filling only your first and last name, your LMU e-mail address stored in the user account and your affiliation status to the LMU. In some services, it is possible to add more information to the user profile. This is not necessary for the use of the service or for the performance of public tasks. The corresponding additions are voluntary, but should not be done for reasons of data economy.
Groups of persons concerned
- People who use or administer Microsoft 365
- Persons who are identified or identifiable in communication and documents
Legal basis
We process your data in accordance with and on the basis of the General Data Protection Regulation (GDPR), the Bavarian Data Protection Act (BayDSG) and the other applicable data protection regulations.
The processing of personal data for the use of M365 takes place within the framework of voluntary use in accordance with Article 6(1)(a) GDPR (consent), otherwise in the context of the performance of service tasks pursuant to Article 6(1)(e), Paragraph 2, 3 GDPR in conjunction with Article 4(1) BayDSG. in particular Article 11(1) BayEGovG, § 13(7) TMG, Art. 6 para., 1 BayDSG, Art. 10(1) BayHSchG, Art. 7 BayHO, Art. 20a GG, Art. 3, 3a, 141 In particular, these are:
For employees and staff:
- Art. 6(1)(b) GDPR in conjunction with Art. 4(1) BayDSG, Collective Agreement, Employment Contract, Collective Agreement, § 106 GewerbeordnungArt. 6 para. 1 lit. c GDPR in conjunction with Art. 4(1) BayDSG, Art. 33(5) GG
- Article 6(1)(c) GDPR in conjunction with § 3a(1) ArbStättV
For the teaching:
- Art. 6 para. 1 lit. e, para. 2, 3 GDPR in conjunction with Art. 4(1) BayDSG (Art. 55(2) BayHSchG)
For disclosure to Microsoft (beyond the order processing):
- Article 6(1)(b) GDPR, Art. 49(1)(c) GDPR (data categories 1 and 6) – for licensed persons
- Art. 5 (1) sentence 1 no. 2 BayDSG, Art. 49(1)(d) GDPR (data category 2.-5.,7.,8.) – for purposes not required by contract
For statistics:
- Article 6(1)(e) GDPR in conjunction with Art. 4(1) BayDSG, § 3 HStatG, Art. 10(1) BayHSchG, Art. 7 BayHO
Processing of personal data
The following data is synchronised between the LMU and Microsoft’s AzureAD:
- Name & first name
- LMU e-mail address
- Membership status (students, employees, other members)
Furthermore, registration events (last 30 days) are collected and processed in M365:
- Date
- Hour
- Application
- IP address indirectly Location
- Device information (device name, browser, operating system, link type)
- Date of first and last activity of the computer
- Presence status if applicable (depending on the service used)
Provisions in the sense of data protection
In the implementation of M365, LMU has in particular taken into account the data protection principles of data minimisation, privacy by default and privacy by design as far as technically possible. The logging of the use of the services of M365 is anonymised.
A productivity assessment feature is not enabled.
The inventory function/telemetry is switched off as far as technically possible.
Data transmission
In order to enable the use of your LMU Microsoft account and M365 according to the above purposes, personal data must be transferred to other recipients:
- Microsoft Ireland Operations Limited in the context of order processing and contract performance.
- Microsoft Corporation, for the purpose of processing and fulfilling the contract and fulfilling its own purposes
- as well as subcontractors and support service providers.
Microsoft processes the data on our behalf and may only use the data according to our instructions and for our purposes. However, Microsoft also uses personal data for its own purposes and is to be regarded as its own controller.
The transfer of personal data in the context of the use of M365 in third countries without an adequacy decision and without appropriate safeguards similar to the level of EU security cannot be completely excluded.
Guarantees for the international transfer of data to Microsoft Corporation and sub-processors constitute the standard contractual clauses that have been agreed and any return exemptions in individual cases pursuant to Art. 49 (1) sentence 1 lit. a, c, d GDPR. (as far as relevant)
The IT Law Office of Bavarian universities and universities analysed the judgment of the CJEU in Case C-311/18 of 16 July 2020 and, in consultation with the CIOs of the Bavarian state universities and universities and their data protection officers in accordance with clause 4 g of the Standard Contractual Clauses, informed the Bavarian State Commissioner for Data Protection that the guarantees contained in clause 5b of the standard contractual clauses can be fulfilled in all respects and at any time.
With regard to the M365 Azure cloud, Microsoft adheres to the C5 standard issued by BSI for Germany. Microsoft confirms that the data will only be stored locally within Germany. Further information can be found at Cloud Computing Compliance Controls Catalog (C5).
This assessment is based on the publicly available information provided by Microsoft and the assessment of NOYB.
In addition, Microsoft is certified under the EU-U.S. Data Privacy Framework of July 10, 2023. The adequacy decision for the EU-U.S. Data Privacy Framework confirms that the U.S. ensures an adequate level of protection for personal data transferred from the EU to companies participating in the EU-U.S. Data Privacy Framework. The requirements of the General Data Protection Regulation (GDPR) for data processing continue to apply.
Duration of storage of personal data
Data categories
1. Documents and files
2. Tasks and solutions
3. Communication data
4. Basic personal data
5. Authentication data
6. Contact information
7. Profiling
8. Logfile with access
9. System generated log data
Retention and deletion of data
The stored data will be processed as long as and to the extent necessary for the respective purpose of data processing in the context of the use of your LMU Microsoft account and M365.
The data will be stored for up to 90 days after deleting an LMU Microsoft account and then deleted. Blocking an LMU user ID or changing the license assignment does not change it.
Number by data category: 1-3 cancellation period: 90 days after deletion of the content data, after the necessity ceases to exist
Number according to data categories: 4-7 cancellation period 90 days after deletion of the account on request or after objection
Number by data category: 8.9 Cancellation period 180 days
Information on existing rights
You have the right to obtain information about the data stored about you (Art. 15 GDPR). Should incorrect personal data be processed, you have a right to rectification (Art. 16 GDPR). In addition, you have the right to erasure (Art. 17 GDPR), objection (Art. 21 GDPR), restriction (Art. 18 GDPR) and to withdraw consent for the future. The lawfulness of the data processing carried out on the basis of the consent until the withdrawal is not affected by this.
For reasons arising from your particular situation, you can also object to the processing of personal data concerning you by us at any time (Art. 21 GDPR). If the legal requirements are met, we will no longer process your personal data.
In addition, you have the right to lodge a complaint with a data protection supervisory authority in accordance with Art. 77 GDPR. The data protection supervisory authority responsible for the LMU is the Bavarian State Commissioner for Data Protection.
If you wish to exercise your rights or if you have any questions, please contact the responsible data processing department (see above). It checks whether the legal requirements are met and then takes the necessary measures.
For further information, please refer to the LMU’s privacy policy for the website.
Obligation to make available
Without the creation of an M365 account, a licensed use of M365 on the LMU is not possible.Insofar as the use of M365 serves the fulfilment of legal obligations and tasks or for the performance of the work and service tasks of the employees or employees, the data processing is necessary, otherwise voluntarily.
Current status
The data protection information in the current version applies.
Status: July 2021