149 Total
51 High severity
75 Medium severity
23 Low severity
Stay ahead of the changes
Track Microsoft Azure and get the diff the day its terms change.
Summary

This is Microsoft's global Privacy Statement, covering data collection and use across consumer and enterprise products including Windows, Microsoft 365, Copilot AI services, Azure, Bing, Edge, Teams, Xbox, and OneDrive. The statement discloses that Microsoft collects and uses personal data including voice clips, biometric identifiers, AI prompts and conversation history, browsing and search history, location data, and file content to provide services, train and fine-tune AI models including large language models, and deliver personalized advertising on Microsoft and third-party platforms. Users whose birthdate in their Microsoft account identifies them as under 18 are excluded from personalized advertising, and health data submitted to Copilot Health is stated to not be used for AI model training or advertising.

Analysis

This document is Microsoft's global Privacy Statement, last updated June 2026, governing the collection, use, storage, and disclosure of personal data across Microsoft's consumer and enterprise product portfolio, including Azure, Microsoft 365, Copilot AI services, Windows, Xbox, Bing, Edge, Teams, OneDrive, and associated services. The statement asserts that Microsoft collects identifiers, contact details, payment data, biometric data, voice data, browsing and search history, location data, device and usage data, content from files and communications, and AI interaction data including prompts, conversation history, and uploaded files, and the terms authorize use of this data to provide services, improve and develop products, train and fine-tune AI models including large language models, and deliver personalized advertising on Microsoft and third-party properties. The statement covers data transfers internationally including to jurisdictions the European Commission has not deemed adequate, with Standard Contractual Clauses cited as the primary transfer mechanism, and Microsoft asserts compliance with the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks; the document also states that in enterprise and developer product contexts, agreement terms with customers control over this privacy statement, which creates materially distinct data governance obligations for enterprise versus consumer users. The statement engages GDPR, CCPA, LGPD, COPPA, U.S. state data privacy laws, Japan's Act on the Protection of Personal Information, and the EU AI Act regulatory environment; jurisdiction-dependent compliance obligations are acknowledged throughout, including separate U.S. State Data Privacy Notice and Consumer Health Data Privacy Policy references for U.S. users, and the document designates Microsoft Ireland Operations Limited as the EU, UK, and Swiss data controller.

What this means for you

The agreement authorizes Microsoft to collect voice data, biometric identifiers, AI prompt and conversation history, browsing and search history, precise and imprecise location data, and file content across its consumer product portfolio, and states that this data may be used to develop, train, and fine-tune AI models including large language models. Under these terms, personalized advertising is delivered on Microsoft and third-party properties using behavioral, demographic, and cross-device data, with opt-out available via the Microsoft Personalized Ads and Offers page; the statement also discloses that Microsoft receives and responds to the Global Privacy Control browser opt-out signal in certain jurisdictions. You can access, export, delete, or restrict certain personal data through the Microsoft Privacy Dashboard at account.microsoft.com/privacy, submit data protection requests via the privacy support and requests page, opt out of personalized advertising at the Microsoft Personalized Ads and Offers page, and opt out of AI training data use in markets where that option is disclosed.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

7 important changes detected

9 versions captured · Last updated: June 2026

What changed Microsoft Azure's privacy policy was updated on June 30, 2026 to add 'MSN' to the table of contents in the Entertainment and related services section. The policy previously listed 'Windows Mixed Reality' as the final entertainment product mentioned. The updated policy now includes 'MSN' between 'Microsoft Store' and 'Windows Mixed Reality'. This is a formatting and organizational change that clarifies which Microsoft services are covered under the privacy statement.
Why this matters The updated privacy policy now explicitly lists MSN in the table of contents under Entertainment and related services, clarifying that MSN's data practices are covered by this privacy statement. This change adds transparency about which Microsoft properties are governed by the stated privacy rules. No new rights or obligations are created by this change.
View full change record →
What changed Microsoft Azure updated its privacy policy table of contents on June 28, 2026, reorganizing and renaming several product categories. Specific changes include renaming 'Microsoft Launcher' to 'Microsoft Family Safety', removing 'Microsoft Translator' from the list, removing 'Phone Link - Link to Windows' and replacing it with 'Linked Mobile Experiences on Windows', and removing 'Silverlight' and 'Microsoft Edge Legacy and Internet Explorer' from the product-specific details section. These appear to be organizational and product portfolio updates rather than substantive changes to privacy practices or user rights.
Why this matters The updated privacy policy reflects organizational changes to Microsoft's product portfolio and documentation structure. These changes appear to be administrative restructuring of the policy table of contents rather than substantive modifications to how personal data is collected, used, or protected. The privacy practices themselves are not materially altered by these formatting and product listing updates.
View full change record →

June 26, 2026 low

Microsoft updated its Privacy Statement on June 26, 2026, restructuring and revising 879 sentences while adding 211 new ones across 1,628 total sentences. The company reorganized the document's table of …

View change record →
April 19, 2026 medium

Microsoft Azure updated its privacy policy on April 19, 2026, making several changes to how it handles your data and communicates with you. The company added language stating it may …

View change record →
April 1, 2026 medium

Microsoft revised how it explains data retention. Previously, the policy listed specific criteria for deciding how long to keep data, including examples like documents in OneDrive. Now the policy provides …

View change record →
March 13, 2026 low

Microsoft Azure's privacy policy now discloses that if you consent to receive marketing communications via phone, the company may contact you using automated dialing systems and artificial or prerecorded voices, …

View change record →
March 6, 2026 medium

Microsoft updated its data retention policy on March 6, 2026, to provide more specific guidance on how long it keeps your data and under what circumstances. The new language clarifies …

View change record →
Featured, High severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

149 provisions
12 featured
20 clause types
51 high severity
Data Collection 31 6 high
Show all 31 data collection provisions
Enforcement Actions 1 1 high
Stay ahead of the changes

Monitoring

Microsoft Azure has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Advertising Data Sharing with Third Parties and similar clauses.

Compare across platforms →
Archival ProvenanceSource & Archival Record
Last Captured August 1, 2026 01:17 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000018
Version ID CA-V-005451
SHA-256 038c77f4e0e0960bdacc607fc616e0fe9c09d77f584fa91f8e3c4c3050fea6dd
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans