Old version
March 6, 2026 18:27 UTC
b8c5474c7d089106c6ef8aa469baaab3d68c47dcaea7519ed1c518a26aa0c0fe
CA-V-000014
New version
April 19, 2026 06:13 UTC
df6d59073298e33eb92498505dee7c3099cd31586ddc77e63dd8c5451ad917cf
CA-V-000726
Share 𝕏 Share in Share
Change Summary
Microsoft Azure updated its privacy policy on April 19, 2026, making several changes to how it handles your data and communicates with you. The company added language stating it may contact you by phone using automated dialers and AI-generated voices if you consent to marketing communications. It also simplified and reorganized its data retention section, clarifying that it keeps your data while you use its services and for business, legal, and security purposes, but removed some specific examples and details about how long it retains different types of information.
medium severity
2 Sentences added
11 Sentences removed
10 Sentences modified
2305 Sentences before
2296 Sentences after
Added
Removed
Modified
BeforeAfter
0Microsoft Privacy Statement Last Updated: February 2026 What's new?0Microsoft Privacy Statement Last Updated: March 2026 What's new?
215If you consent to receiving marketing communications to a phone number you provide us, we may contact you for marketing purposes using an auto-dialer and/or artificial/prerecorded voice, which may be generated using artificial intelligence.
732Back to top Our retention of personal data Microsoft retains personal data for as long as necessary to provide the products and fulfill the transactions you have requested, or for other legitimate purposes such as complying with our legal obligations, resolving disputes, and enforcing our agreements.733Back to top Our retention of personal data Microsoft retains personal data for as long as necessary to provide the products and services you use and to fulfill the transactions you request.
734We also retain personal data for other legitimate purposes such as operating our business, meeting our contractual and legal obligations, improving and developing our products and services, protecting the safety and security of our systems and customers, and resolving disputes.
734Other criteria used to determine the retention periods include: Do customers provide, create, or maintain the data with the expectation we will retain it until they affirmatively remove it?736See relevant product documentation for more information.
735Examples include a document you store in OneDrive, or an email message you keep in your Outlook.com inbox.737Criteria used to determine the retention periods include: The purposes for which we use the information.
736In such cases, we would aim to maintain the data until you actively delete it, such as by moving an email from your Outlook.com inbox to the Deleted Items folder, and then emptying that folder (when your Deleted Items folder is emptied, those emptied items remain in our system for up to 30 days before final deletion).738For example, when you store a document in OneDrive, we maintain the data until you actively delete it.
737(Note that there may be other reasons why the data has to be deleted sooner, for example if you exceed limits on how much data can be stored in your account.) Is there an automated control, such as in the Microsoft privacy dashboard, that enables the customer to access and delete the personal data at any time?739The nature and sensitivity of the information.
738If there is not, a shortened data retention time will generally be adopted.740For example, we maintain a shortened retention period for precise geolocation information.
739Is the personal data of a sensitive type?741Legal, contractual and other similar obligations we are subject to, including data retention laws, government orders to preserve data relevant to an investigation, or data retained for the purposes of litigation.
740If so, a shortened retention time would generally be adopted.742Conversely, we’ll remove unlawful content where required by law.
741Has Microsoft adopted and announced a specific retention period for a certain data type?Removed
742For example, for Bing search queries, we de-identify stored queries by removing the entirety of the IP address after 6 months, and cookie IDs and other cross-session identifiers that are used to identify a particular account or device after 18 months.Removed
743Has the user provided consent for a longer retention period?Removed
744If so, we will retain data in accordance with your consent.Removed
745Is Microsoft subject to a legal, contractual, or similar obligation to retain or delete the data?Removed
746Examples can include mandatory data retention laws in the applicable jurisdiction, government orders to preserve data relevant to an investigation, or data retained for the purposes of litigation.Removed
747Conversely, if we are required by law to remove unlawful content, we will do so.Removed
838Data retention .Removed
839For personalized advertising, we retain data for no more than 13 months, unless we obtain your consent to retain the data longer.Removed
853To opt out of receiving personalized advertising from Microsoft, visit our opt-out page.846To learn more about Microsoft’s use of data to deliver personalized advertising and to opt out of receiving personalized advertising from Microsoft, visit our opt-out page.
1332Retention and de-identification .Removed
1333We de-identify stored search queries by removing the entirety of the IP address after 6 months, and cookie IDs and other cross-session identifiers that are used to identify a particular account or device after 18 months.Removed
Stay ahead of the changes

Watch this before it changes again

Follow unlimited companies, monitor the clauses that matter across every platform, and get the full institutional analysis on what each change obligates you to do.