Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Microsoft boosts Office 365 regulatory compliance

Microsoft will make new contractual commitments for regulations in the U.S. and Europe

Microsoft has taken steps to make Office 365 more attractive to U.S. and European customers who have to comply with regulatory requirements related to data protection, the company is expected to announce Wednesday.

The new safeguards come primarily in the form of contractual commitments and new software features. Microsoft hopes the moves will lessen potential concerns about using its cloud-based applications, which are hosted in Microsoft data centers where customers' data is also stored.

When selling Office 365 in Europe, Microsoft will now sign contractual "model clauses" developed by the European Union, which establish safeguards and procedures for protecting data when it is transferred outside the E.U.

In European countries with additional requirements, Microsoft will include what it called a "data processing agreement" that goes beyond the E.U.'s Data Protection Directive rules.

In the U.S., for contracts with health-care companies that have to comply with the Health Insurance Portability and Accountability Act (HIPAA), Microsoft will include Business Associate Agreement (BAA) contract provisions drafted by the U.S. Department of Health that address legal requirements around patient data privacy and protection.

"We want to help customers move with confidence and security to the cloud and be compliant with obligations to HIPAA and E.U. data protection rules," said Stephen McGibbons, Microsoft CTO for the EMEA (Europe, Middle East and Africa) region.

Microsoft is also re-launching the Office 365 Trust Center, a website with information about the product's privacy and security practices that has been redesigned to make it easier to use.

Although businesses are becoming more comfortable with cloud-hosted software, companies in heavily regulated industries such as health care and finance tend to be more apprehensive, as they have to be careful not to run afoul of data-protection regulations.

"We want to make sure that customers using our cloud services can demonstrate that they're complying with their regulation responsibilities, and we also want to make it easier for customers to move to the cloud quickly," McGibbons said.

Juan Carlos Perez covers search, social media, online advertising, e-commerce, web application development, enterprise cloud collaboration suites and general technology breaking news for The IDG News Service. Follow Juan on Twitter at @JuanCPerezIDG.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Department of Health, IDG, Microsoft
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: applications, collaboration, e-mail, government, legislation, Microsoft, Office suites, Regulation, software
Latest Blog Posts
Whitepapers
  • Securing SOA and Web Services with Oracle Enterprise Gateway
    Companies worldwide are actively deploying service-oriented architecture (SOA) infrastructures using web services, both in intranet and extranet environments. While web services offer many advantages over traditional alternatives (e.g., distributed objects or custom software), deploying networks of interconnected web services still presents key challenges, especially in terms of security and management.
    Learn more »
  • The Big Six: The CIO Executive Council’s Frameworks for IT Value and Leadership
    This overview of six of the CIO Executive Council’s most important pieces of intellectual capital represents the thought leadership of literally hundreds of global CIOs spanning over half a decade. It is intended to convey the Council’s position on the current and future CIO role and the value that IT should be creating for the enterprise. We hope that it offers the IT community an intriguing and comprehensive roadmap for continued success.
    Learn more »
  • Gartner MarketScope for Application Life Cycle Management
    Organisations adopting agile practices, utilising global and distributed teams, or exploiting complex processes and technologies are most likely to benefit from using ALM tools to plan, manage and report on their development activities. This MarketScope assesses the market offerings and their providers.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.