Track 1 platform and get the weekly governance digest. No credit card required.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This is Microsoft's main privacy policy, covering how Microsoft collects and uses your personal data across products like Windows, Microsoft 365, Bing, Xbox, Cortana, Teams, and Copilot AI features. The most important thing to know is that Microsoft collects a wide range of data including your name, location, device identifiers, browsing and search history, voice recordings, and the content of files and communications, and uses this data for advertising, product improvement, and AI model development in some contexts. You can review and manage many of your privacy choices, delete your data, and adjust personalization and advertising settings through your Microsoft account privacy dashboard at account.microsoft.com/privacy.
This document is Microsoft's global Privacy Statement, last updated March 2026, governing the collection, use, and sharing of personal data across Microsoft's consumer and enterprise products and services, with its legal basis rooted in consent, contractual necessity, legitimate interests, and legal obligation depending on jurisdiction. The statement asserts that Microsoft collects a broad range of personal data including name, contact information, device and usage data, location, biometric data (voiceprints and facial recognition in applicable products), browsing history, search queries, and content of communications, and the terms authorize use of this data for product improvement, personalization, advertising, and security purposes. Notably, the statement includes specific provisions for AI and Copilot capabilities, enterprise online services, children's data, and U.S. state-level privacy rights, and it distinguishes between Microsoft acting as a data controller for consumer products and as a data processor when enterprise customers deploy its services, a distinction that materially affects which rights consumers can exercise directly against Microsoft. The statement engages GDPR for EU/EEA users, CCPA and a range of U.S. state privacy laws for U.S. residents, COPPA for children under 13, and relevant frameworks in other jurisdictions; the statement acknowledges that data may be transferred internationally and that Microsoft relies on Standard Contractual Clauses and other transfer mechanisms. Material compliance considerations include the breadth of data collected for AI and Copilot features, the layered controller-processor structure in enterprise contexts, and Microsoft's stated reliance on legitimate interests as a processing basis in some contexts, which may require evaluation under GDPR's balancing test.
Institutional analysis available with Professional
Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.
Start Professional free trial4 important changes detected
5 versions captured · Last updated: April 2026
Microsoft Azure's privacy policy now discloses that if you consent to receive marketing communications via phone, the company may contact you using automated dialing systems and artificial or prerecorded voices, …
View change record →Microsoft updated its data retention policy on March 6, 2026, to provide more specific guidance on how long it keeps your data and under what circumstances. The new language clarifies …
View change record →Monitoring
Microsoft Azure has updated this document before.
Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.
Professional Governance Intelligence
Need provision-level monitoring and regulatory mapping?
Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.
Start Professional free trialCross-platform context
See how other platforms handle AI and Copilot Data Use and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.