Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This is Microsoft's global Privacy Statement covering the full range of Microsoft consumer and enterprise products, including Windows, Microsoft 365, Azure, Bing, Copilot, Xbox, Teams, and OneDrive. The statement discloses that Microsoft may use personal data, including prompts, voice data, browsing history, and file content, to develop and train AI models including large language models, with opt-out available only in certain markets and for specific services. The statement also discloses that organizational account holders, such as employers or schools, may access and process employees' or students' communications, files, and interaction data associated with Microsoft products used under those accounts.
This document is Microsoft's global Privacy Statement (last updated June 2026), governing the collection, use, disclosure, and retention of personal data across Microsoft's consumer and enterprise product portfolio, including Azure, Microsoft 365, Windows, Bing, Copilot, Xbox, Teams, OneDrive, and associated services. The statement asserts that Microsoft collects a broad range of personal data categories including identifiers, biometric data, voice data, location data, browsing history, content of files and communications, and inferred interests, and states that this data is used to provide products, develop and train AI models including large language models, deliver personalized advertising, and operate business functions. Notably, the statement authorizes the use of personal data to develop and fine-tune AI models, including LLMs, with an opt-out mechanism available only in certain markets and for specific Copilot services, and discloses data sharing with named third-party advertising partners including Facebook, Yahoo, Taboola, Outbrain, and Xandr; the statement also asserts broad content-access rights for organizational accounts, where employers or schools may access communications, files, and interaction data associated with work or school accounts. The document engages GDPR, CCPA and applicable U.S. state privacy laws, COPPA, Brazil's LGPD, Japan's Act on the Protection of Personal Information, the EU-U.S. and Swiss-U.S. Data Privacy Frameworks, and industry self-regulatory frameworks including the NAI, DAA, EDAA, and DAAC; compliance obligations vary significantly by jurisdiction, and the document's assertion of legitimate interests as a legal basis for processing, as well as its AI training data use provisions, may require evaluation under GDPR Article 6 and applicable EU AI Act requirements. The statement designates Microsoft Ireland Operations Limited as the data controller for EEA, UK, and Switzerland users, commits to DPF binding arbitration for residual complaints, and acknowledges FTC investigatory authority over Microsoft's DPF compliance.
The agreement establishes that Microsoft collects a broad range of personal data categories, including biometric data, voice data, precise and imprecise location data, browsing history, file and communication content, and inferred interests, across its full product portfolio. Under these terms, Microsoft may use personal data to develop and fine-tune AI models including large language models, with opt-out available only in certain markets and for specific Copilot services; users in markets where this applies can opt out via the Microsoft Privacy Dashboard or in-product controls. You can opt out of personalized advertising through Microsoft's Personalized Ads and Offers page, manage data access and deletion requests through the Microsoft Privacy Dashboard, and submit data rights requests via Microsoft's privacy support and requests page.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
7 important changes detected
11 versions captured · Last updated: June 2026
Microsoft updated its Privacy Statement on June 26, 2026, restructuring and revising 879 sentences while adding 211 new ones across 1,628 total sentences. The company reorganized the document's table of …
View change record →Microsoft Azure updated its privacy policy on April 19, 2026, making several changes to how it handles your data and communicates with you. The company added language stating it may …
View change record →Microsoft revised how it explains data retention. Previously, the policy listed specific criteria for deciding how long to keep data, including examples like documents in OneDrive. Now the policy provides …
View change record →Microsoft Azure's privacy policy now discloses that if you consent to receive marketing communications via phone, the company may contact you using automated dialing systems and artificial or prerecorded voices, …
View change record →Microsoft updated its data retention policy on March 6, 2026, to provide more specific guidance on how long it keeps your data and under what circumstances. The new language clarifies …
View change record →Every distinct legal provision identified in this document. Featured provisions appear above with analysis.
Microsoft Azure has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Cross-platform context
See how other platforms handle Advertising Data Sharing with Third Parties and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.