149 Total
51 High severity
75 Medium severity
23 Low severity
Stay ahead of the changes
Track Microsoft Azure and get the diff the day its terms change.
Summary

This is Microsoft's global Privacy Statement covering the full range of Microsoft consumer and enterprise products, including Windows, Microsoft 365, Azure, Bing, Copilot, Xbox, Teams, and OneDrive. The statement discloses that Microsoft may use personal data, including prompts, voice data, browsing history, and file content, to develop and train AI models including large language models, with opt-out available only in certain markets and for specific services. The statement also discloses that organizational account holders, such as employers or schools, may access and process employees' or students' communications, files, and interaction data associated with Microsoft products used under those accounts.

Analysis

This document is Microsoft's global Privacy Statement (last updated June 2026), governing the collection, use, disclosure, and retention of personal data across Microsoft's consumer and enterprise product portfolio, including Azure, Microsoft 365, Windows, Bing, Copilot, Xbox, Teams, OneDrive, and associated services. The statement asserts that Microsoft collects a broad range of personal data categories including identifiers, biometric data, voice data, location data, browsing history, content of files and communications, and inferred interests, and states that this data is used to provide products, develop and train AI models including large language models, deliver personalized advertising, and operate business functions. Notably, the statement authorizes the use of personal data to develop and fine-tune AI models, including LLMs, with an opt-out mechanism available only in certain markets and for specific Copilot services, and discloses data sharing with named third-party advertising partners including Facebook, Yahoo, Taboola, Outbrain, and Xandr; the statement also asserts broad content-access rights for organizational accounts, where employers or schools may access communications, files, and interaction data associated with work or school accounts. The document engages GDPR, CCPA and applicable U.S. state privacy laws, COPPA, Brazil's LGPD, Japan's Act on the Protection of Personal Information, the EU-U.S. and Swiss-U.S. Data Privacy Frameworks, and industry self-regulatory frameworks including the NAI, DAA, EDAA, and DAAC; compliance obligations vary significantly by jurisdiction, and the document's assertion of legitimate interests as a legal basis for processing, as well as its AI training data use provisions, may require evaluation under GDPR Article 6 and applicable EU AI Act requirements. The statement designates Microsoft Ireland Operations Limited as the data controller for EEA, UK, and Switzerland users, commits to DPF binding arbitration for residual complaints, and acknowledges FTC investigatory authority over Microsoft's DPF compliance.

What this means for you

The agreement establishes that Microsoft collects a broad range of personal data categories, including biometric data, voice data, precise and imprecise location data, browsing history, file and communication content, and inferred interests, across its full product portfolio. Under these terms, Microsoft may use personal data to develop and fine-tune AI models including large language models, with opt-out available only in certain markets and for specific Copilot services; users in markets where this applies can opt out via the Microsoft Privacy Dashboard or in-product controls. You can opt out of personalized advertising through Microsoft's Personalized Ads and Offers page, manage data access and deletion requests through the Microsoft Privacy Dashboard, and submit data rights requests via Microsoft's privacy support and requests page.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

7 important changes detected

11 versions captured · Last updated: June 2026

What changed Microsoft Azure's privacy policy was updated on June 30, 2026 to add 'MSN' to the table of contents in the Entertainment and related services section. The policy previously listed 'Windows Mixed Reality' as the final entertainment product mentioned. The updated policy now includes 'MSN' between 'Microsoft Store' and 'Windows Mixed Reality'. This is a formatting and organizational change that clarifies which Microsoft services are covered under the privacy statement.
Why this matters The updated privacy policy now explicitly lists MSN in the table of contents under Entertainment and related services, clarifying that MSN's data practices are covered by this privacy statement. This change adds transparency about which Microsoft properties are governed by the stated privacy rules. No new rights or obligations are created by this change.
View full change record →
What changed Microsoft Azure updated its privacy policy table of contents on June 28, 2026, reorganizing and renaming several product categories. Specific changes include renaming 'Microsoft Launcher' to 'Microsoft Family Safety', removing 'Microsoft Translator' from the list, removing 'Phone Link - Link to Windows' and replacing it with 'Linked Mobile Experiences on Windows', and removing 'Silverlight' and 'Microsoft Edge Legacy and Internet Explorer' from the product-specific details section. These appear to be organizational and product portfolio updates rather than substantive changes to privacy practices or user rights.
Why this matters The updated privacy policy reflects organizational changes to Microsoft's product portfolio and documentation structure. These changes appear to be administrative restructuring of the policy table of contents rather than substantive modifications to how personal data is collected, used, or protected. The privacy practices themselves are not materially altered by these formatting and product listing updates.
View full change record →

June 26, 2026 low

Microsoft updated its Privacy Statement on June 26, 2026, restructuring and revising 879 sentences while adding 211 new ones across 1,628 total sentences. The company reorganized the document's table of …

View change record →
April 19, 2026 medium

Microsoft Azure updated its privacy policy on April 19, 2026, making several changes to how it handles your data and communicates with you. The company added language stating it may …

View change record →
April 1, 2026 medium

Microsoft revised how it explains data retention. Previously, the policy listed specific criteria for deciding how long to keep data, including examples like documents in OneDrive. Now the policy provides …

View change record →
March 13, 2026 low

Microsoft Azure's privacy policy now discloses that if you consent to receive marketing communications via phone, the company may contact you using automated dialing systems and artificial or prerecorded voices, …

View change record →
March 6, 2026 medium

Microsoft updated its data retention policy on March 6, 2026, to provide more specific guidance on how long it keeps your data and under what circumstances. The new language clarifies …

View change record →
Featured, High severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

149 provisions
12 featured
20 clause types
51 high severity
Data Collection 31 6 high
Show all 31 data collection provisions
Enforcement Actions 1 1 high
Stay ahead of the changes

Monitoring

Microsoft Azure has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Advertising Data Sharing with Third Parties and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
DMA
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured September 11, 2026 01:18 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000018
Version ID CA-V-006836
SHA-256 8cc3268c690cd30a6630093a10a5bf7ad5ffd1ccbcb200e944e034c545773738
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans