Microsoft revised how it explains data retention. Previously, the policy listed specific criteria for deciding how long to keep data, including examples like documents in OneDrive. Now the policy provides a higher-level framework mentioning purposes for retention, data sensitivity, and legal obligations, but directs users to product documentation for specifics. The practical effect is less transparency about retention timelines in the main privacy policy itself.
Consumers: You no longer get a clear explanation of how long Microsoft keeps your data in the privacy policy itself; you have to look elsewhere.
Microsoft's privacy policy now provides a less detailed explanation of how long your data is retained. Previously, the policy included specific examples, such as how long deleted emails remain in your system before final deletion, and listed criteria for deciding retention periods. Now those details are consolidated into a more general statement pointing readers to separate product documentation. This means you'll need to consult multiple documents to understand retention timelines for specific services, which reduces transparency at the point of reading the main privacy policy.
→ Review the relevant product documentation (e.g., OneDrive, Outlook, Azure) referenced in the updated privacy policy to understand retention timelines specific to each service you use.
→ If you require clear retention commitments before using Microsoft services, contact Microsoft directly to confirm retention periods for your use case.
ConductAtlas has recorded 2 material changes to this document (since March 2026). An additional minor or cosmetic changes were excluded.
Replaced specific criteria and examples with general factors (purpose, sensitivity, legal obligation); directs to product documentation for details.
Deleted specific example that Deleted Items remain for up to 30 days; removed mention of automated privacy dashboard controls.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
Microsoft modified its retention disclosure to use higher-level criteria (purpose, sensitivity, legal obligation) rather than specific examples and decision trees. The policy now directs users to product documentation for granular details. For organizations conducting vendor …
Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.
Unlock the full institutional analysis — InsightConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-001202.
Microsoft Azure's privacy policy was updated on June 30, 2026 to add 'MSN' to the table of contents in the …
Microsoft Azure updated its privacy policy table of contents on June 28, 2026, reorganizing and renaming several product categories. Specific …
Microsoft updated its Privacy Statement on June 26, 2026, restructuring and revising 879 sentences while adding 211 new ones across …
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Get alerted when this policy changes again, including what changed and why it matters.