149 Total
51 High severity
75 Medium severity
23 Low severity
Stay ahead of the changes
Track Microsoft Azure and get the diff the day its terms change.
Summary

This is Microsoft's master privacy statement covering consumer and enterprise products including Windows, Microsoft 365, Azure, Bing, Copilot, Xbox, Teams, OneDrive, and dozens of other services. The statement discloses that Microsoft collects identifiers, biometric data, voice clips, browsing history, precise and imprecise location data, content of files and communications, and inferred interests, and the terms authorize use of this data to develop and fine-tune AI models including large language models, with an opt-out available in some markets. The statement further authorizes sharing of personal data with advertising partners including Xandr, Facebook, Yahoo, The Trade Desk, Taboola, and Outbrain for personalized advertising, while stating that email content, human-to-human chat, voice mail, and personal files stored in cloud storage are not used to target ads.

Analysis

This is Microsoft's comprehensive Privacy Statement (last updated June 2026), governing the collection, use, disclosure, and retention of personal data across Microsoft's consumer and enterprise product portfolio, including Azure, Microsoft 365, Windows, Bing, Copilot, Xbox, and related services. The statement asserts that Microsoft collects a broad range of data categories including identifiers, biometric data, voice data, browsing history, location data, device and usage data, content of files and communications, and inferred interests, and the terms authorize use of this data to provide products, develop and train AI models including large language models, deliver personalized advertising, and conduct business operations. Notably, the statement explicitly authorizes the use of personal data to develop and fine-tune AI models and LLMs, and discloses that Copilot conversation data may be used for AI model training in some markets unless users opt out; the statement also asserts broad data retention authority tied to business and legal necessity without specifying fixed retention periods for most data types. The statement engages GDPR, CCPA and applicable U.S. state data privacy laws, COPPA, Brazil's LGPD, and the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks, with Microsoft Ireland Operations Limited designated as the EEA and UK data controller; compliance considerations include adequacy of Data Privacy Framework certifications post-Schrems II, the sufficiency of opt-out mechanisms for AI training data use under GDPR legitimate interests claims, and the scope of children's data protections under COPPA and applicable state laws. Institutional compliance teams should evaluate whether the statement's legitimate interests bases for AI training and advertising data processing satisfy GDPR balancing requirements, whether GPC signal response mechanisms constitute compliant opt-out under applicable U.S. state laws, and whether enterprise customers' data processing agreements under the Products and Services DPA adequately delineate controller and processor responsibilities.

What this means for you

The agreement establishes that Microsoft collects a wide range of data categories including biometric data, voice clips, browsing history, precise location, content of files and communications, and inferred interests across its product portfolio. Under these terms, Microsoft authorizes use of personal data to develop and fine-tune AI models including large language models, and in some markets Copilot conversation data may contribute to AI model training unless users opt out through product settings or the Microsoft Privacy Dashboard. You can manage advertising preferences, AI personalization opt-outs, and data access or deletion requests through the Microsoft Privacy Dashboard at account.microsoft.com/privacy, and can submit data rights requests via Microsoft's privacy support and requests page.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

7 important changes detected

9 versions captured · Last updated: June 2026

What changed Microsoft Azure's privacy policy was updated on June 30, 2026 to add 'MSN' to the table of contents in the Entertainment and related services section. The policy previously listed 'Windows Mixed Reality' as the final entertainment product mentioned. The updated policy now includes 'MSN' between 'Microsoft Store' and 'Windows Mixed Reality'. This is a formatting and organizational change that clarifies which Microsoft services are covered under the privacy statement.
Why this matters The updated privacy policy now explicitly lists MSN in the table of contents under Entertainment and related services, clarifying that MSN's data practices are covered by this privacy statement. This change adds transparency about which Microsoft properties are governed by the stated privacy rules. No new rights or obligations are created by this change.
View full change record →
What changed Microsoft Azure updated its privacy policy table of contents on June 28, 2026, reorganizing and renaming several product categories. Specific changes include renaming 'Microsoft Launcher' to 'Microsoft Family Safety', removing 'Microsoft Translator' from the list, removing 'Phone Link - Link to Windows' and replacing it with 'Linked Mobile Experiences on Windows', and removing 'Silverlight' and 'Microsoft Edge Legacy and Internet Explorer' from the product-specific details section. These appear to be organizational and product portfolio updates rather than substantive changes to privacy practices or user rights.
Why this matters The updated privacy policy reflects organizational changes to Microsoft's product portfolio and documentation structure. These changes appear to be administrative restructuring of the policy table of contents rather than substantive modifications to how personal data is collected, used, or protected. The privacy practices themselves are not materially altered by these formatting and product listing updates.
View full change record →

June 26, 2026 low

Microsoft updated its Privacy Statement on June 26, 2026, restructuring and revising 879 sentences while adding 211 new ones across 1,628 total sentences. The company reorganized the document's table of …

View change record →
April 19, 2026 medium

Microsoft Azure updated its privacy policy on April 19, 2026, making several changes to how it handles your data and communicates with you. The company added language stating it may …

View change record →
April 1, 2026 medium

Microsoft revised how it explains data retention. Previously, the policy listed specific criteria for deciding how long to keep data, including examples like documents in OneDrive. Now the policy provides …

View change record →
March 13, 2026 low

Microsoft Azure's privacy policy now discloses that if you consent to receive marketing communications via phone, the company may contact you using automated dialing systems and artificial or prerecorded voices, …

View change record →
March 6, 2026 medium

Microsoft updated its data retention policy on March 6, 2026, to provide more specific guidance on how long it keeps your data and under what circumstances. The new language clarifies …

View change record →
Featured, High severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

149 provisions
12 featured
20 clause types
51 high severity
Data Collection 31 6 high
Show all 31 data collection provisions
Enforcement Actions 1 1 high
Stay ahead of the changes

Monitoring

Microsoft Azure has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Advertising Data Sharing with Third Parties and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
DMA
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured August 1, 2026 01:17 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000018
Version ID CA-V-005451
SHA-256 038c77f4e0e0960bdacc607fc616e0fe9c09d77f584fa91f8e3c4c3050fea6dd
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans