Dutch data protection agency says it found that Windows 10 may still be unlawfully collecting user data, refers Microsoft to its EU privacy regulator in Ireland
The Dutch data protection agency has asked Microsoft's lead privacy regulator in Europe to investigate ongoing concerns it has attached to how Windows 10 gathers user data.
Context & Ripple Effects
This referral is the latest move in a years-long European campaign against Windows 10 telemetry. The French CNIL served Microsoft formal notice over Windows 10 privacy failings back in 2016 (served notice for Windows 10 privacy failings), and after Microsoft's earlier defense that its collection practices were lawful (Microsoft defended its data collection practices), it added a privacy dashboard and granular controls in the Creators Update (added a privacy dashboard and granular controls).
What changed is the enforcement route: rather than acting alone, the Dutch agency is handing the case to Ireland's regulator, which leads GDPR supervision of Microsoft across the EU. The same Dutch authority's earlier probe into hidden telemetry already triggered an EU-wide investigation into Microsoft products used by EU institutions (triggered an EU investigation into Microsoft products used by EU institutions), and the EDPS later found the Commission's own use of Microsoft 365 breached privacy rules (EDPS found the Commission's Microsoft 365 use breached privacy rules) — so this referral lands on a regulator with a documented track record of concern.
First-order effects
- Ireland's data protection commission now carries the investigative burden as lead EU regulator, and Microsoft faces a formal GDPR examination of Windows 10 data gathering that could end in corrective orders or fines.
Second-order effects
- A finding against Windows 10 would pressure Microsoft's other EU-exposed products — the EU-institutions probe and the EDPS Microsoft 365 ruling show regulators are treating telemetry practices as a portfolio problem, not a single-product one.
Third-order effects
- If national agencies keep referring big-platform cases to the lead regulator, Europe's one-stop-shop mechanism consolidates into fewer, higher-stakes rulings that set de facto telemetry and consent standards for all OS vendors selling into the EU.
The trend: European regulators are escalating from piecemeal national notices to coordinated, lead-regulator enforcement of how operating systems collect user data.