Provision record
Microsoft Azure · Azure Terms · View original document ↗

DPA sets Customer Data processing obligations

High severity High confidence Explicit document language Common · 279 of 352 platforms

Key Facts

What does the Data Protection Addendum set forth?
Microsoft Azure states that the Data Protection Addendum sets forth the obligations of both the customer and Microsoft with respect to the processing and security of Customer Data and Personal Data in connection with Azure.
What are the obligations set forth in the Data Protection Addendum?
Microsoft Azure states that the Data Protection Addendum sets forth the obligations of both the customer and Microsoft with respect to the processing and security of Customer Data and Personal Data in connection with Azure.
Stay ahead of the changes
Track Microsoft Azure and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF

This analysis describes what Microsoft Azure's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Data processing and security obligations for Customer Data and Personal Data are not contained in the main Azure agreement but are established in a separate document — the DPA — which both parties are bound by.

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 10, 2026
First Seen
Jul 10, 2026
Last Seen
This clause type exists across 3333 other provisions on other platforms.

Consumer impact (what this means for users)

Your obligations, and Microsoft Azure's obligations, regarding the processing and security of Customer Data and Personal Data are defined in the DPA, a document separate from the main Azure terms.

How other platforms handle this

MyFitnessPal Medium

We use your personal information to comply with applicable legal and regulatory obligations and respond to legally valid requests and communications from law enforcement authorities to the extent required by applicable law.

Lyft Medium

We may infer certain information from your interactions with the Lyft Platform and other personal information available to us. For example, if you frequently ride to or from airports, we may infer you are a frequent traveler.

Square Medium

we may use this information to make it easier for you to find the people you want to send payments to, for account and identity verification and fraud prevention purposes, to reduce the risk you will send payments to the wrong person, or to provide other personalized services.

See all platforms with this clause type →
▸ View Original Clause Language DOCUMENT RECORD
"
The Microsoft Products and Services Data Protection Addendum ("DPA") sets forth your and Microsoft's obligations with respect to the processing and security of Customer Data and Personal Data in connection with Azure.

Excerpt from Microsoft Azure's Azure Terms

Applicable regulations

CCPA/CPRA
California, USA
Colorado AI Act
US-CO
CAN-SPAM
United States Federal
ePrivacy Directive
European Union
FTC Act Section 5
United States Federal
GDPR
European Union

Provision details

Document information
Document
Azure Terms
Entity
Microsoft Azure
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
May 10, 2026
Record ID
CA-P-056211
Document ID
CA-D-00650
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
2ea7e4bc16e092405516d7a210be7f3b823c306ec35fe496e200abc795cf5f1e
Analysis generated
May 8, 2026 07:54 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Microsoft Azure
Document: Azure Terms
Record ID: CA-P-056211
Captured: 2026-05-08 07:54:51 UTC
SHA-256: 2ea7e4bc16e09240…
URL: https://conductatlas.com/platform/microsoft-azure/azure-terms/provision/CA-P-056211/dpa-sets-customer-data-processing-obligations/
Accessed: Aug. 18, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Microsoft Azure's DPA sets Customer Data processing obligations clause do?

Data processing and security obligations for Customer Data and Personal Data are not contained in the main Azure agreement but are established in a separate document — the DPA — which both parties are bound by.

How does this clause affect you?

Your obligations, and Microsoft Azure's obligations, regarding the processing and security of Customer Data and Personal Data are defined in the DPA, a document separate from the main Azure terms.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 279 platforms. See the full comparison.

Is ConductAtlas affiliated with Microsoft Azure?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Microsoft Azure.