Microsoft revised its data retention policy language on April 1, 2026. Previously, the policy outlined specific retention criteria including whether customers expected data retention until deletion, whether automated deletion controls existed, and whether data was sensitive in type. The updated terms consolidate retention rationale into a broader set of purposes: operating the business, meeting contractual and legal obligations, improving products and services, protecting system and customer safety, and resolving disputes. The policy now directs users to product documentation for specific retention periods rather than describing retention criteria in the main policy.
Consumers: The policy no longer explains in one place how Microsoft decides how long to keep your data; instead you must consult individual product documentation.
The updated policy now grounds data retention in five broad business purposes: operating the business, meeting contractual and legal obligations, improving and developing products and services, protecting system and customer safety, and resolving disputes. Previously, the policy articulated specific criteria for determining retention periods, including customer expectations for retention until manual deletion, availability of automated deletion controls, and data sensitivity. The revised language removes these granular criteria and instead requires users to consult individual product documentation to understand when their specific data will be deleted. This shifts the burden of finding retention timelines from the main policy statement to separate product-specific documents.
→ Review the product-specific documentation for each Microsoft service you use to determine retention periods for your data.
→ If you rely on documented retention timelines for personal data management planning, confirm those timelines remain unchanged in the product documentation.
This is the 2nd significant Transparency Removal change Microsoft has made since ConductAtlas began monitoring.
ConductAtlas has recorded 3 material changes to this document (since March 2026).
3 of Microsoft's significant changes have been classified as negative for consumers.
Removed explicit criteria (customer expectations, automated controls, data sensitivity) and replaced with five broad business purposes; specific retention periods now found in product documentation.
Removed detailed explanation of Outlook and OneDrive deletion workflows and 30-day post-deletion retention window; general reference to deletion process now appears only in product documentation.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
Microsoft consolidated retention rationale language and moved specific retention period specifications from the main privacy statement to product-level documentation. This change may affect how organizations document their compliance with data retention principles under GDPR Article …
Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.
Unlock the full institutional analysis — InsightConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-001197.
Microsoft updated its Privacy Statement in an update detected on August 1, 2026, making changes primarily to document structure, formatting, …
Microsoft's privacy policy table of contents was updated on June 30, 2026, with a single sentence modification. The specific textual …
Microsoft's Privacy Statement table of contents was reorganized on June 28, 2026. Several product and feature references were relocated or …
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Get alerted when this policy changes again, including what changed and why it matters.