


New South Wales Education Department Caught Unaware After Microsoft Teams Began Collecting Students' Biometric Data (theguardian.com) 34
New submitter optical_phiber writes: In March 2025, the New South Wales (NSW) Department of Education discovered that Microsoft Teams had begun collecting students' voice and facial biometric data without their prior knowledge. This occurred after Microsoft enabled a Teams feature called 'voice and face enrollment' by default, which creates biometric profiles to enhance meeting experiences and transcriptions via its CoPilot AI tool.
The NSW department learned of the data collection a month after it began and promptly disabled the feature and deleted the data within 24 hours. However, the department did not disclose how many individuals were affected or whether they were notified. Despite Microsoft's policy of retaining data only while the user is enrolled and deleting it within 90 days of account deletion, privacy experts have raised serious concerns. Rys Farthing of Reset Tech Australia criticized the unnecessary collection of children's data, warning of the long-term risks and calling for stronger protections.
The NSW department learned of the data collection a month after it began and promptly disabled the feature and deleted the data within 24 hours. However, the department did not disclose how many individuals were affected or whether they were notified. Despite Microsoft's policy of retaining data only while the user is enrolled and deleting it within 90 days of account deletion, privacy experts have raised serious concerns. Rys Farthing of Reset Tech Australia criticized the unnecessary collection of children's data, warning of the long-term risks and calling for stronger protections.
Use only OPEN SOURCE systems. NEVER Microsoft. (Score:1, Informative)
Re: Use only OPEN SOURCE systems. NEVER Microsoft. (Score:4, Insightful)
Re: (Score:2)
Also a good reason that all education shall be done on Open Source only, no matter if the proprietary software is given "for free".
So they aren't prepared how to use their computers when they enter the workforce / real life? I think you missed the purpose of education. Now if you suggest we should be teaching about Linux at church then I agree with you.
Re: (Score:2)
No one cares about your culture war. But here's a better question for you: What is the purpose of education? If you answer is:
a) Indoctrinate your political and social beliefs on others. - Then yes Opensource software is a great idea.
b) Prepare subjects for the world they will experience. - Then no, the openness is not a consideration, but rather what tools people are likely to be using in the future are.
Leave kids out of your culture/political war.
Re: Use only OPEN SOURCE systems. NEVER Microsoft. (Score:2)
What is your answer? Is it "c) Cement
Microsoft monopoly by addicting the new generation to its products so they can continue bombarding us with increasingly enshittified crap in the coming years with impunity"? It certainly seems so.
stronger protections that can't be waved with an E (Score:2)
stronger protections that can't be waved with an EULA or forced to give up to us app.
Time to jail MS executives... (Score:2, Flamebait)
These people think the law does not apply to them.
Re: Time to jail MS executives... (Score:4, Insightful)
We cannot jail them because, as they have demonstrated many times, the law does not apply to them.
Re: Time to jail MS executives... (Score:2)
It does not. That was proven when Bush's AG Ashcroft let Microsoft off with a hand slap instead of breaking them up.
We need worldwide Data / Privacy standards (Score:5, Interesting)
Unfortunately it has to be this way because even with "large" fines it's become a cost of doing business thing. Since business treats it that way, it needs to become a "put you out of business" kind of fine.
The fine should probably include a claw back of all compensation of C-Levels for the duration of the breach. They want to claim the ship only runs true with them at the helm, they have take the responsibility for everything the ship does daily.
Re: We need worldwide Data / Privacy standards (Score:2)
I think it should hit where it really hurts: putting people in jail. For some reason when companies do horrible stuff they get away with it by paying fines. Make it someone's personal responsibility.
so force them to live in australia? (Score:4, Funny)
so force them to live in australia?
Re: (Score:2)
I do agree that in the case of something like the opioid crisis the Sackler family helped create, with the associated loss of life, prison should be mandatory and scaling with the effect. As we look at the opioid crisis, tell me t
Re: (Score:2)
Except the problem here is government. It was the government that broke the law, when their IT group chose teams or perhaps accepted an updated EULA that violated their own data privacy laws. It does not sound like Microsoft ever offered or was asked to provide a customized teams, that did data collection differently.
Imagine if someone in the food service department went over to the local home store a bought a bunch of containers, not food safe, and put the school lunch supplies into them. Would you blam
Re: (Score:2)
But can an updated EULA override and signed contract?
Should the school just shutdown each time the EULA is updated for legal to look it over? (but even to log into set all users to disabled may need you to get past that new EULA)
Re:We need worldwide Data / Privacy standards (Score:4, Insightful)
Re: (Score:2)
No the School should not deploy software updates until any revisions to the EULA have been reviewed.
If Microsoft is in the habit of not allowing downlevel clients to connect for at least long enough for that to be possible and something else to be put in place if the changes are unacceptable, than the product was NEVER fit for use, and again the fault lies with the administrators that chose it.
It isnt like Microsoft does not have licensing groups that exist specifically to work with education, and other lar
Re: (Score:2)
That's not a good answer, because there ARE crucial updates.
Much better it just to ensure that EULAs have, at most, no legal force. Possibly they could be considered assault. (They clearly *are* a threat.)
and when web ui forces new EULA on cloud login? (Score:2)
and when web ui forces new EULA on cloud login?
Re: (Score:2)
Now we know, ironically, as you h
Re: We need worldwide Data / Privacy standards (Score:2)
This is an accurate take. Every entity which has a responsibility to protect others' data or any allegedly secure data and then chooses to use a Microsoft solution in particular (but really any closed source software) with the potential to intercept that data should be considered to be in violation of privacy laws. Microsoft is an especially egregious choice because the EULAs give them the right to take any data they like and show it to anyone for any purpose they deem relevant. No government entity should
Re: (Score:2)
Like the title says. I know governments will despise it, but it needs to happen. The law also needs penalties so severe, and immediately enacted upon breach, that it terrifies company leadership.
Errr, no company was the problem here. This was the government IT systems setup incorrectly. How do you legislate around your own incompetence? Which government department is responsible for fining itself?
Easy Fix... (Score:2, Informative)
Re: (Score:2)
Looks like they stop it it, and had MS delete data. Although MS claims it takes up to 90 days to delete data.
Big shock, violating children now (Score:3)
They violate the consent of adults with impunity, so of course they're going to do the same to children.
I was unaware (Score:3)
Since the dawn of Facebook I've been doing my best to keep out of databases, but I use Teams a lot for work, so presumably Microsoft has a lot of data on my face and voice now, all linked to a user ID that matches my real name and a geographical location that is significantly off by IP but very close to the billing address they have for my employer.
In other words, I have to assume I'm 'in the system' and no longer have the faintest hope of anonymity even against less than state-level actors.
I can guess why it was enabled by default (Score:2)
Tip of Microsoft's Anti-Privacy Iceberg (Score:2)
NSFW (Score:2)
Am I the only one who when they see "NSW" thinks it says "NSFW"?
Re: NSFW (Score:2)