CA-C-001202
Microsoft Azure — Microsoft Privacy
Date detected
April 1, 2026
Effective date
April 1, 2026
Severity
Direction
Negative
Affected users
all users
Taxonomy
Transparency removal
Changes
+1 sentence added · −11 sentences removed · 9 sentences modified
Share 𝕏 Share in Share 🔒 PDF
Watch Microsoft Azure Get alerts when this policy changes.
Watch — Free

Event Summary

Microsoft revised how it explains data retention. Previously, the policy listed specific criteria for deciding how long to keep data, including examples like documents in OneDrive. Now the policy provides a higher-level framework mentioning purposes for retention, data sensitivity, and legal obligations, but directs users to product documentation for specifics. The practical effect is less transparency about retention timelines in the main privacy policy itself.

MEDIUM

Consumer Impact

Microsoft's privacy policy now provides a less detailed explanation of how long your data is retained. Previously, the policy included specific examples, such as how long deleted emails remain in your system before final deletion, and listed criteria for deciding retention periods. Now those details are consolidated into a more general statement pointing readers to separate product documentation. This means you'll need to consult multiple documents to understand retention timelines for specific services, which reduces transparency at the point of reading the main privacy policy.

Governance Analysis

The privacy policy is the primary document users and regulators consult to understand how companies handle data. By moving retention details from the policy to scattered product documentation, Microsoft reduced transparency at the point of disclosure, making it harder for users and compliance teams to understand how long their data is kept. This shift also complicates vendor audits and Data Processing Agreement alignment.

Available Actions

Review the relevant product documentation (e.g., OneDrive, Outlook, Azure) referenced in the updated privacy policy to understand retention timelines specific to each service you use.

If you require clear retention commitments before using Microsoft services, contact Microsoft directly to confirm retention periods for your use case.

If No Action Is Taken

You will not have access to a single, clear explanation of how long Microsoft retains your data; you may not find detailed retention information without visiting multiple product-specific pages.

If you delete data (e.g., empty your Deleted Items folder), you will not know from the main privacy policy how long it remains in Microsoft's systems before permanent removal.

Organizations auditing Microsoft's data handling practices will spend more time locating retention policies across multiple product documentations instead of reviewing one comprehensive policy.

Historical Context

ConductAtlas has recorded 2 material changes to this document (since March 2026). An additional minor or cosmetic changes were excluded.

Key Clauses Affected

Data retention framework

Replaced specific criteria and examples with general factors (purpose, sensitivity, legal obligation); directs to product documentation for details.

Removal of retention period examples

Deleted specific example that Deleted Items remain for up to 30 days; removed mention of automated privacy dashboard controls.

Full clause-by-clause analysis available with Professional.
These clauses may change again. Get alerted when they do. Watch Microsoft Azure — Free

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
b00f93e97712c94234c217fb26263315378680077cada036ee4ced9e4b67b11c
March 13, 2026 06:00 UTC
✓ Verified
Current Version
9747780db9713278eb767f30b62e22d28d9779dfd8af583372a209ed3f6f92c8
April 1, 2026 06:04 UTC
✓ Verified
Change Detected
April 1, 2026 06:04 UTC
Analysis Methodology
Citation Record
Entity: Microsoft Azure
Document: Microsoft Privacy
Record ID: CA-C-001202
Captured: 2026-04-01 06:04:02 UTC
URL: https://conductatlas.com/change/2026-04-01-microsoft-azure-microsoft-privacy-1202/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.

Impact Summary

1
Protection removed
Consumers Removed

You no longer get a clear explanation of how long Microsoft keeps your data in the privacy policy itself; you have to look elsewhere.

For legal and compliance teams

Institutional Analysis

Assessment

Microsoft modified its retention disclosure to use higher-level criteria (purpose, sensitivity, legal obligation) rather than specific examples and decision trees. The policy now directs users to product documentation for granular details. For organizations conducting vendor assessments, privacy impact assessments, or data processing impact analyses, this change means retention timelines are no longer fully specified in the central privacy policy; compliance teams will need to cross-reference product documentation. This may affect how data retention is represented in Data Processing Agreements and privacy notices served to customers. GDPR Article 5(1)(e) and similar global data minimization principles require that data be kept no longer than necessary; whether Microsoft's framework adequately demonstrates compliance with those principles may depend on clarity and accessibility of the referenced product documentation.

Regulatory Exposure

GDPR (Articles 5, 17, 32), CCPA (California Consumer Privacy Act disclosure requirements), UK Data Protection Act 2018, applicable data retention laws in jurisdictions where Microsoft operates

Full compliance analysis

Obligation analysis, escalation trigger, board language, and recommended action.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations + obligations. Professional: full compliance memo.

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-001202.

Full Changes

See the full side-by-side comparison of every sentence added, removed, and modified.

🔒 Full diff — Watcher

Document Context

Version history → Policy drift analysis → Document page →
Document
Microsoft Privacy
Entity
Microsoft Azure
Captured
April 1, 2026
Source URL
https://privacy.microsoft.com/en-us/privacystatement
Other changes to Microsoft Privacy
Previous change Mar 13, 2026
Microsoft Azure's privacy policy now discloses that if you consent to receive marketing communications via phone, the company may contact …
Low Neutral
Next change Apr 19, 2026
Microsoft Azure updated its privacy policy on April 19, 2026, making several changes to how it handles your data and …
Medium Negative
View full version history →
More from Microsoft Azure
Apr 19, 2026 Medium
Microsoft Privacy

Microsoft Azure updated its privacy policy on April 19, 2026, making several changes to how it handles your data and …

Mar 13, 2026 Low
Microsoft Privacy

Microsoft Azure's privacy policy now discloses that if you consent to receive marketing communications via phone, the company may contact …

Mar 6, 2026 Medium
Microsoft Privacy

Microsoft updated its data retention policy on March 6, 2026, to provide more specific guidance on how long it keeps …

Track Microsoft Azure policy changes

Get alerted when this policy changes again — including what changed and why it matters.

Prefer a weekly summary instead?

Get the biggest policy changes across 320+ platforms every Sunday.