Change record
CA-C-001202
Microsoft Privacy | Microsoft Azure
Date detected
April 1, 2026
Effective date
April 1, 2026
Severity
Direction
Negative
Taxonomy
Transparency removal
Changes
+1 sentence added · −11 sentences removed · 9 sentences modified

Impact Summary

Medium Negative for users
Affected users
All users

Microsoft revised how it explains data retention. Previously, the policy listed specific criteria for deciding how long to keep data, including examples like documents in OneDrive. Now the policy provides a higher-level framework mentioning purposes for retention, data sensitivity, and legal obligations, but directs users to product documentation for specifics. The practical effect is less transparency about retention timelines in the main privacy policy itself.

1 protection removed

Consumers: You no longer get a clear explanation of how long Microsoft keeps your data in the privacy policy itself; you have to look elsewhere.

Stay ahead of the changes
Track Microsoft Azure and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF

What this means for you

Microsoft's privacy policy now provides a less detailed explanation of how long your data is retained. Previously, the policy included specific examples, such as how long deleted emails remain in your system before final deletion, and listed criteria for deciding retention periods. Now those details are consolidated into a more general statement pointing readers to separate product documentation. This means you'll need to consult multiple documents to understand retention timelines for specific services, which reduces transparency at the point of reading the main privacy policy.

What you can do

Review the relevant product documentation (e.g., OneDrive, Outlook, Azure) referenced in the updated privacy policy to understand retention timelines specific to each service you use.

If you require clear retention commitments before using Microsoft services, contact Microsoft directly to confirm retention periods for your use case.

Historical Context

ConductAtlas has recorded 2 material changes to this document (since March 2026). An additional minor or cosmetic changes were excluded.

Key Clauses Affected

Data retention framework

Replaced specific criteria and examples with general factors (purpose, sensitivity, legal obligation); directs to product documentation for details.

Removal of retention period examples

Deleted specific example that Deleted Items remain for up to 30 days; removed mention of automated privacy dashboard controls.

Full clause-by-clause analysis available with Insight.

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
b00f93e97712c94234c217fb26263315378680077cada036ee4ced9e4b67b11c
March 13, 2026 06:00 UTC
✓ Verified
Current Version
9747780db9713278eb767f30b62e22d28d9779dfd8af583372a209ed3f6f92c8
April 1, 2026 06:04 UTC
✓ Verified
Change Detected
April 1, 2026 06:04 UTC
Analysis Methodology
Citation Record
Entity: Microsoft Azure
Document: Microsoft Privacy
Record ID: CA-C-001202
Captured: 2026-04-01 06:04:02 UTC
URL: https://conductatlas.com/change/2026-04-01-microsoft-azure-microsoft-privacy-1202/
Accessed: Aug. 11, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
For legal and compliance teams

Institutional Analysis

Assessment

Microsoft modified its retention disclosure to use higher-level criteria (purpose, sensitivity, legal obligation) rather than specific examples and decision trees. The policy now directs users to product documentation for granular details. For organizations conducting vendor …

🔒 Full institutional analysis

Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.

Unlock the full institutional analysis — Insight

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-001202.

Full Changes

View complete diff →

Document Context

Version history → Policy drift analysis → Document page →
Document
Microsoft Privacy
Entity
Microsoft Azure
Captured
April 1, 2026
Source URL
https://privacy.microsoft.com/en-us/privacystatement
Other changes to Microsoft Privacy
Previous change Mar 13, 2026
Microsoft Azure's privacy policy now discloses that if you consent to receive marketing communications via phone, the company may contact …
Low Neutral
Next change Apr 19, 2026
Microsoft Azure updated its privacy policy on April 19, 2026, making several changes to how it handles your data and …
Medium Negative
View full version history →
More from Microsoft Azure
Jun 30, 2026 Low
Microsoft Privacy

Microsoft Azure's privacy policy was updated on June 30, 2026 to add 'MSN' to the table of contents in the …

Jun 28, 2026 Low
Microsoft Privacy

Microsoft Azure updated its privacy policy table of contents on June 28, 2026, reorganizing and renaming several product categories. Specific …

Jun 26, 2026 Low
Microsoft Privacy

Microsoft updated its Privacy Statement on June 26, 2026, restructuring and revising 879 sentences while adding 211 new ones across …

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Stay ahead of the changes

Track Microsoft Azure policy changes

Get alerted when this policy changes again, including what changed and why it matters.

All Microsoft Azure changes →