Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This is Microsoft's master privacy statement covering consumer and enterprise products including Windows, Microsoft 365, Azure, Bing, Copilot, Xbox, Teams, OneDrive, and dozens of other services. The statement discloses that Microsoft collects identifiers, biometric data, voice clips, browsing history, precise and imprecise location data, content of files and communications, and inferred interests, and the terms authorize use of this data to develop and fine-tune AI models including large language models, with an opt-out available in some markets. The statement further authorizes sharing of personal data with advertising partners including Xandr, Facebook, Yahoo, The Trade Desk, Taboola, and Outbrain for personalized advertising, while stating that email content, human-to-human chat, voice mail, and personal files stored in cloud storage are not used to target ads.
This is Microsoft's comprehensive Privacy Statement (last updated June 2026), governing the collection, use, disclosure, and retention of personal data across Microsoft's consumer and enterprise product portfolio, including Azure, Microsoft 365, Windows, Bing, Copilot, Xbox, and related services. The statement asserts that Microsoft collects a broad range of data categories including identifiers, biometric data, voice data, browsing history, location data, device and usage data, content of files and communications, and inferred interests, and the terms authorize use of this data to provide products, develop and train AI models including large language models, deliver personalized advertising, and conduct business operations. Notably, the statement explicitly authorizes the use of personal data to develop and fine-tune AI models and LLMs, and discloses that Copilot conversation data may be used for AI model training in some markets unless users opt out; the statement also asserts broad data retention authority tied to business and legal necessity without specifying fixed retention periods for most data types. The statement engages GDPR, CCPA and applicable U.S. state data privacy laws, COPPA, Brazil's LGPD, and the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks, with Microsoft Ireland Operations Limited designated as the EEA and UK data controller; compliance considerations include adequacy of Data Privacy Framework certifications post-Schrems II, the sufficiency of opt-out mechanisms for AI training data use under GDPR legitimate interests claims, and the scope of children's data protections under COPPA and applicable state laws. Institutional compliance teams should evaluate whether the statement's legitimate interests bases for AI training and advertising data processing satisfy GDPR balancing requirements, whether GPC signal response mechanisms constitute compliant opt-out under applicable U.S. state laws, and whether enterprise customers' data processing agreements under the Products and Services DPA adequately delineate controller and processor responsibilities.
The agreement establishes that Microsoft collects a wide range of data categories including biometric data, voice clips, browsing history, precise location, content of files and communications, and inferred interests across its product portfolio. Under these terms, Microsoft authorizes use of personal data to develop and fine-tune AI models including large language models, and in some markets Copilot conversation data may contribute to AI model training unless users opt out through product settings or the Microsoft Privacy Dashboard. You can manage advertising preferences, AI personalization opt-outs, and data access or deletion requests through the Microsoft Privacy Dashboard at account.microsoft.com/privacy, and can submit data rights requests via Microsoft's privacy support and requests page.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
7 important changes detected
9 versions captured · Last updated: June 2026
Microsoft updated its Privacy Statement on June 26, 2026, restructuring and revising 879 sentences while adding 211 new ones across 1,628 total sentences. The company reorganized the document's table of …
View change record →Microsoft Azure updated its privacy policy on April 19, 2026, making several changes to how it handles your data and communicates with you. The company added language stating it may …
View change record →Microsoft revised how it explains data retention. Previously, the policy listed specific criteria for deciding how long to keep data, including examples like documents in OneDrive. Now the policy provides …
View change record →Microsoft Azure's privacy policy now discloses that if you consent to receive marketing communications via phone, the company may contact you using automated dialing systems and artificial or prerecorded voices, …
View change record →Microsoft updated its data retention policy on March 6, 2026, to provide more specific guidance on how long it keeps your data and under what circumstances. The new language clarifies …
View change record →Every distinct legal provision identified in this document. Featured provisions appear above with analysis.
Microsoft Azure has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Cross-platform context
See how other platforms handle Advertising Data Sharing with Third Parties and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.