The European Union’s branch, specialized in privacy law, havedeclared(ok, not publicly but those rascals at Reuters got a hold of some private docs it seems) that they intend to delve deeper into Microsoft’s personal identification scheme after an analysis of the technology raised concerns with the group. Apparently, there is some question as to whether or not Passport holds up to data protection laws under the EU.

The EU document said controllers wanted to examine more closely whether .NET Passport users were fully aware that some of their data would sometimes be transferred to a party other than Microsoft, possibly located in a third country.

The officials questioned the value and quality of the consent given by users to such operations, and the data protection rules of the Web Sites affiliated to .NET Passport.

The experts also said they wanted to weigh the security risks associated with such transfers.

It sounds like the larger concern is whether people are fully aware of exactly how Microsoft treats your data. Similar rules are in place in the States regarding disclosure of data transmission which makes me wonder if the problem is merely one of wording in Microsoft’suser agreement. From the privacy statement: