CA-C-001079
Microsoft — Microsoft Privacy Statement (Legacy)
Entity
Date detected
April 19, 2026
Effective date
April 19, 2026
Severity
Direction
Negative
Affected users
all users outlook.com users onedrive users
Taxonomy
Retention change
Changes
+2 sentences added · −11 sentences removed · 10 sentences modified
Share 𝕏 Share in Share 🔒 PDF
Watch Microsoft Get alerts when this policy changes.
Watch — Free

Event Summary

Microsoft modified its data retention policy language on April 19, 2026. Previously, the policy described specific retention criteria including whether customers expected data to be retained until they removed it, and whether automated deletion controls existed. The updated language simplifies retention guidance by stating that Microsoft retains personal data to provide services, fulfill transactions, and for legitimate purposes including legal obligations, business operations, and dispute resolution. The revised policy removes granular examples (like email deletion procedures) and instead directs users to product documentation, while adding new retention justifications around improving products, protecting systems, and customer safety.

MEDIUM

Consumer Impact

The updated policy establishes additional grounds on which Microsoft may retain personal data. While the prior version tied retention to specific user expectations and available deletion controls, the revised language authorizes retention for 'operating our business, meeting our contractual and legal obligations, improving and developing our products and services, protecting the safety and security of our systems and customers, and resolving disputes.' This expands the stated purposes beyond transaction fulfillment and legal compliance. The updated policy directs users to product-specific documentation for retention details rather than providing explicit deletion procedures and timelines in the privacy statement itself.

Governance Analysis

The updated terms establish broader grounds for retaining personal data, expanding from transaction and legal necessity to include business operations and product development. This change affects how long data may be retained and the purposes Microsoft may rely on to justify that retention, shifting retention decisions away from unified policy guidance into product-specific documentation that users must actively consult.

Available Actions

Review product-specific retention documentation for services you use (OneDrive, Outlook.com, etc.) to understand actual data deletion timelines.

Check your account settings in Microsoft privacy dashboard for any available controls over data retention or automatic deletion of old data.

If No Action Is Taken

Personal data will be retained under the expanded purposes stated in the policy, which now include business operations and product improvement beyond legal requirements.

Without consulting product-specific documentation, you may not understand how long Microsoft retains particular data types or what deletion options are available.

Historical Context

ConductAtlas has recorded 4 material changes to this document over 44 days of monitoring (since March 2026). An additional minor or cosmetic changes were excluded.

4 of Microsoft's significant changes have been classified as negative for consumers.

Key Clauses Affected

Data retention purposes clause

Expanded from legal compliance and transaction fulfillment to include business operations, product development, safety, and dispute resolution.

Retention criteria reference

Changed from explicit policy statement of deletion procedures and storage limits to delegation to product-specific documentation.

Marketing communications consent

Added explicit authorization to use auto-dialer and AI-generated voice for marketing calls to consenting phone numbers.

Full clause-by-clause analysis available with Professional.
These clauses may change again. Get alerted when they do. Watch Microsoft — Free

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
b8c5474c7d089106c6ef8aa469baaab3d68c47dcaea7519ed1c518a26aa0c0fe
March 5, 2026 06:14 UTC
✓ Verified
Current Version
df6d59073298e33eb92498505dee7c3099cd31586ddc77e63dd8c5451ad917cf
April 19, 2026 06:03 UTC
✓ Verified
Change Detected
April 19, 2026 06:03 UTC
Analysis Methodology
Citation Record
Entity: Microsoft
Document: Microsoft Privacy Statement (Legacy)
Record ID: CA-C-001079
Captured: 2026-04-19 06:03:07 UTC
URL: https://conductatlas.com/change/2026-04-19-microsoft-microsoft-privacy-statement-legacy-1079/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.

Impact Summary

1
New obligations
1
Expanded
Consumers Expanded

Microsoft can now point to more reasons to keep your data, not just legal requirements and fulfilling what you asked for.

Data controllers Shifted

Organizations must check individual product policies to understand how long data is actually retained, rather than relying on a central privacy policy.

For legal and compliance teams

Institutional Analysis

Assessment

This change broadens the stated legal bases for data retention across Microsoft's product portfolio. The updated language adds operational and business development justifications alongside legal obligations. Organizations evaluating Microsoft as a vendor should review product-specific documentation to understand actual retention timelines, as the privacy statement now explicitly delegates retention details to individual product policies rather than providing unified guidance. For data controllers or processors reliant on standard contractual clauses or data processing agreements, this shift in retention justification may require review of underlying vendor contracts to confirm alignment with organizational data retention policies and applicable law.

Regulatory Exposure

GDPR, CCPA, PIPEDA

Full compliance analysis

Obligation analysis, escalation trigger, board language, and recommended action.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations + obligations. Professional: full compliance memo.

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-001079.

Full Changes

See the full side-by-side comparison of every sentence added, removed, and modified.

🔒 Full diff — Watcher

Document Context

Version history → Policy drift analysis → Document page →
Document
Microsoft Privacy Statement (Legacy)
Entity
Microsoft
Captured
April 19, 2026
Source URL
https://www.microsoft.com/en-us/privacy/privacystatement
Other changes to Microsoft Privacy Statement (Legacy)
Previous change Apr 8, 2026
Microsoft's Privacy Statement was updated on April 8, 2026, with 2 sentences added, 11 sentences removed, and 10 sentences modified. …
Low Neutral
View full version history →
More from Microsoft
Apr 19, 2026 Low
Microsoft Responsible AI Standard

Microsoft updated three passages in its Responsible AI Principles on April 19, 2026. The first change revised the opening tagline …

Apr 19, 2026 Low
Responsible AI

Microsoft updated three phrases in its Responsible AI document. The opening tagline changed from 'Build your business with trustworthy AI' …

Apr 8, 2026 Low
Microsoft Privacy Statement (Legacy)

Microsoft's Privacy Statement was updated on April 8, 2026, with 2 sentences added, 11 sentences removed, and 10 sentences modified. …

Track Microsoft policy changes

Get alerted when this policy changes again — including what changed and why it matters.

Prefer a weekly summary instead?

Get the biggest policy changes across 320+ platforms every Sunday.