Northern Protestant Church
The BigBrotherAward in the Category Civil Society goes to the
Church Office (Landeskirchenamt) of the Northern Protestant Church (Nordkirche),
because it relies exclusively on Microsoft services for its church IT. As a consequence, data on religious and civil activities of church members are falling into the hands of an untrustworthy US company. Surrendering data sovereignty in this way entails incalculable dangers.
I owe a lot to the protestant church. Helping in church as a child I learned about civil responsibility. As an organist I could develop my musical talents there. In the 1980s, together with many Christians, I was engaged for peace and for the environment. To this day, church remains a place for social activities – one reason for my membership in the Northern Church, which I support with my church taxes.
Data protection is not an important topic for their officials. The European General Data Protection Regulation contains a special exemption for churches. The Protestant Church in Northern Germany uses this to tread the wrong path.
On 25 February 2023 the governing body (Synod) of the Northern Protestant Church passed an IT law that was proposed by the Church Office “for fulfilling the ecclesiastical mission”.1 The law stipulates that Microsoft 365 shall be introduced uniformly in churches across the states of Hamburg, Schleswig-Holstein and Mecklenburg-Western Pomerania. For their more than 17,000 users – pastors, social workers, employees and volunteers – the Church Office will purchase licences for Exchange, SharePoint, OneDrive, Teams, Office and a lot of additional 365 apps, and local churches are obliged to migrate to the Microsoft cloud by 2028.
Other churches use Microsoft 365, too, which is already regrettable. But the Northern Church compels their member churches with the force of law to use, and pay for, Microsoft cloud services. And this comes just after the conference of the state data protection officers and the common delegate of the protestant churches had determined that Microsoft 365 cannot be used in compliance with data protection regulations.2 The Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik), the BSI, also found that it is nearly impossible to use Microsoft 365 without usage data and metadata ending up in the United States without any control over it.3 There were massive controversies within the church.4 What was criticised, among other things, was that in the long run licence fees would exceed the costs of Linux and free software alternatives. The major criticism, however, was the data protection issue, which was dismissed by the Church Office.
According to the church data protection law, the Church Office as the controller is responsible for compliance with data protection. Processors have to be “chosen carefully”.5 Requests from local churches to the Church Office to produce their data protection impact assessments6 were ignored. What will happen to data from church staff, from pastors, members and from confidential pastoral care, and how local churches should handle the risks, remains completely unclear. The Church Office does not want to – and probably cannot – clarify which data will end up in the USA.7
That is irresponsible. After all, just recently the foundation of the “Data Privacy Framework” was shaken. This agreement regulates that data can be lawfully transferred to the USA if two independent bodies watch over it. The Federal Trade Commission, FTC, monitors whether companies adhere to their data protection commitments. The “Data Protection Review Court” reviews complaints about US intelligence services accessing EU data. In June 2026 the US Supreme Court shattered the independence of these institutions by allowing Donald Trump to dismiss democratically appointed members of these offices. Independent control of data originating from the EU is, however, the pivotal condition for their transfer to the USA.8
Trump doesn’t care about data protection and obligates US companies to control and to harm his critics in Europe. Under the pretence of fighting terrorism and crime, his administration collects data for denouncing and deporting his critics and for preventing them from entering the country – in short: to silence them. The CLOUD Act, among others, obliges US companies to disclose to US agencies data being processed in Europe. For example, disfavoured judges at the International Criminal Court in The Hague were cut off from their Microsoft accounts, along with their ability to pay via Visa, Mastercard or PayPal. An EU commissioner was similarly sanctioned as well as the managing directors of HateAid, because they were promoting the rule of law in the Internet.9
Meanwhile, Trump presents himself on social media as Christ and Saviour.10 Selling Bibles was part of his re-election campaign.11 He vilified critics, such as bishop Mariann Budde as “Radical Left hard line Trump hater”.12 Instrumentalised US companies, including Microsoft, are not putting up a fight. On the contrary, they are giving in to his demands. There is therefore a real danger that data of the Northern Protestant Church stored by Microsoft will be used to the detriment of the affected people – especially if they have voiced criticism of un-Christian US policies.
Even the German federal government, the federal parliament (Bundestag) and state governments want to reduce their dependency on US digital companies.13 In France, government agencies and schools are migrating from Microsoft to European products.14 The German state of Schleswig-Holstein is trying to liberate itself completely from US-based service providers, and from Microsoft in particular.15
The Northern Protestant Church moves in the opposite direction and obligates even those local churches that are not using M365, to pay for M365 licences. The digital services required by churches could instead be procured from trustworthy companies in Europe. Such data-protection-compliant alternatives should be promoted specifically. Compelling local churches with the force of law to migrate into a digital dependency on Microsoft violates not only basic rights and freedoms but also Christian principles and the obligation of care for the parishioners.
The confidentiality of pastoral care and the confessional secret are among the world’s oldest data protection rules.16 Data from pastoral care are saved in M365, as well as everything that happens in the church, the parishes, and in the church administration. Almost all of this constitutes particularly sensitive data that enjoys strong legal protection because of its potential to be abused for discrimination, and because of its most private nature. Churches, notwithstanding all their religiously motivated autonomy, have to bring their data processing “in line” with the GDPR.17 Nothing of that can be seen with the Northern Protestant Church’s IT law.
The Northern Protestant Church is an extreme example of how digitalisation can endanger Christian and general societal involvement. Other organisations in churches and civil society also force us to use untrustworthy IT service providers. It is, for example, inexplicable to me that Greenpeace, with their important engagement for nature and environmental protection, relies on Google services, thereby offering their supporters’ data to the US administration on a platter.18 Data about political activities are specially protected by the GDPR, just like religious convictions.19 Whoever stands up for a “fairer world” should not cooperate with corporations that years ago touted their slogan, “don’t be evil”, but actually are “evil”.
It is hard for me to support an organisation whose stored information could eventually end up in the computers of US security agencies to be used for diabolical purposes. It is intolerable that local churches are compelled to give away the data of their millions of members – including mine – without any control, to a corporation that has made itself an accomplice to the current US administration.
To encourage churches, and more generally organisations of civil society, to pursue their emancipatory goals not only in the analogue field, but also use digital communication tools that are compatible with these goals, the Church Office of the Northern Protestant Church receives the BigBrotherAward 2026 in the category “Civil Society”.
Laudatio
1 Kirchengesetz über den Einsatz von einheitlicher Informationstechnologie in der Evangelisch-Lutherischen Kirche in Norddeutschland v. 26.05.2023, KABl. A Nr. 50 S. 106; KABl. A 2024 Nr. 23 S. 102. [Church Law on the use of uniform information technology in the Evangelical Lutheran Church in Northern Germany.]
2 Datenschutzkonferenz, AG DSK „Microsoft-Onlinedienste“, https://datenschutzkonferenz-online.de/media/dskb/2022_24_11_festlegung_MS365_zusammenfassung.pdf; ähnlich BfD EKD Tätigkeitsbericht 2021/2022, S. 66 ff., https://datenschutz.ekd.de/wp-content/uploads/2023/06/TB_2021_2022.pdf. [Data Protection Conference of the Protestant Church, evaluation of the data processing agreement with Microsoft Online Services]
3 BSI, Evaluierung der Telemetrie von Microsoft Office 365, https://www.bsi.bund.de/dok/14859576. [Federal Office for Information Security, evaluation of telemetry at Microsoft 365]
4 Lukic, Die Nordkirche verpflichtet zur Nutzung von Microsoft 365 [The Protestant Northern Churches mandates the use of Microsoft 365], 05.04.2024, https://kkrm.datenschutzbuero.hamburg/die-nordkirche-verpflichtet-zur-nutzung-von-microsoft365/.
5 § 30 Abs. 3 DSG-EKD – Kirchengesetz über den Datenschutz der Evangelischen Kirche in Deutschland v. 15.01.2025. [Church Law on Data Protection at the Protestant Church in Germany]
6 § 34 DSG-EKD.
7 A query by the speaker from 2026-07-06 remained unanswered, as did queries from within the regional church that were disclosed to the speaker.
8 Krempl, US-Urteil erschüttert das Fundament des transatlantischen Datentransfers [US ruling shakes the foundations of transatlantic data flows], 2026-06-30, short link: https://heise.de/-11349599.
9 Krempl, Strafgerichtshof: Microsofts E-Mail-Sperre als Weckruf für digitale Souveränität [Microsoft’s e-mail blocking is a wake-up call for digital sovereignty], 2025-05-18, short link: https://heise.de/-10387368, Prantl, In Acht und Bann [Spellbound], SZ 02.01.2026, 6; Lopinski, Wem gehört das Internet [Who owns the Internet?] SZ 21.01.2026, 6; Einreiseverbot gegen Europäer, die gegen Hass und Desinformation eintreten [Entry ban for Europeans who work against hatred and disinformation], DANA 1/2026, 39 f.
10 Hüffer, Donald Trump als KI-Christus: Der größte Künstler seit Nero [Donald Trump as ‘AI Christ’: the biggest artist since Nero], https://www.swr.de 14.04.2026.
11 „Make America pray again“ - Trump wirbt für Kauf spezieller Bibel-Exemplare [Trump promotes the purchase of bespoke bible edition], https://www.spiegel.de 23.03.2024.
12 Jackisch, Angebetet und kritisiert: Trumps Verhältnis zu den Kirchen [Revered and criticised: Trump’s relationship to churches], https://www.br.de 04.02.2026.
13 Ehlebracht/Rosenbach, Open Source statt Opel [Open Source instead of Opel], Der Spiegel Nr. 12/2026, 76 f.
14 Föderl-Schmid, Gegen die Übermacht [Against the overwhelming force], Süddeutsche Zeitung 14./15.02.2026, 26.
15 Sötje, Abkehr von Microsoft [Turning away from Microsoft], Kieler Nachrichten 06.09.2025, 1.
16 Weichert in Däubler/Wedde/Weichert/Sommer, EU-DSGVO und BDSG [EU GDPR and German Data Protection Law], 3. Aufl. 2024, Einleitung DSGVO Rn. 2.
17 Art. 91 section 1 GDPR.
18 Greenpeace.de als bevorzugte Quelle bei Google [Make Greenpeace a preferred source with Google], https://www.greenpeace.de/ueber-uns/greenpeace-als-bevorzugte-quelle.
19 Art. 9 GDPR.