Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The statement discloses that Microsoft participates in the EU-U.S. Data Privacy Framework, its UK Extension, and the Swiss-U.S. DPF, and has certified compliance with the applicable DPF Principles. Microsoft retains liability for onward transfers of DPF-protected data to third-party agents where those agents process data inconsistently with DPF requirements.
This analysis describes what Microsoft Azure's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the legal mechanism Microsoft relies on for transfers of personal data from the EU, UK, and Switzerland to the United States, and defines Microsoft's liability posture for downstream processing by third-party agents, which is directly relevant to enterprise customers and institutional procurement teams evaluating cross-border data transfer risk.
Microsoft now discloses that it may contact you by phone for marketing using automated dialers and AI-generated voices if you have consented to marketing communications, which represents a new disclosure of contact method and technology type. The company has also reorganized its data retention policy to state it retains data for broader business purposes including improving products and protecting systems, while removing previous specific examples and retention criteria, making it less clear exactly how long specific types of your data will be kept. You should review your consent settings for marketing communications and verify what contact methods you have authorized, particularly if you have concerns about automated or AI-generated calls.
View change record →Microsoft's privacy policy now provides a less detailed explanation of how long your data is retained. Previously, the policy included specific examples, such as how long deleted emails remain in your system before final deletion, and listed criteria for deciding retention periods. Now those details are consolidated into a more general statement pointing readers to separate product documentation. This means you'll need to consult multiple documents to understand retention timelines for specific services, which reduces transparency at the point of reading the main privacy policy.
View change record →Microsoft's updated retention policy provides greater specificity about how long your data persists and under what conditions it is deleted. The policy now explicitly states that deleted items from OneDrive and Outlook.com may remain in Microsoft's systems for up to 30 days before permanent removal, even after you empty the Deleted Items folder. Additionally, the updated terms clarify that retention periods depend on whether you have an expectation that Microsoft will keep the data until you actively remove it, and whether automated controls exist to let you access and delete data yourself. You can review Microsoft's privacy dashboard to exercise available deletion controls and understand which services retain your data under these criteria.
View change record →The agreement establishes that personal data transferred from the EU, UK, and Switzerland to the United States is governed by the applicable Data Privacy Framework Principles, with Microsoft retaining liability for agent processing that is inconsistent with those principles. EU, UK, and Swiss users may raise DPF-related complaints with Microsoft, and unresolved complaints may be referred to binding arbitration under the DPF.
Cross-platform context
See how other platforms handle Cross-Border Data Transfers and Data Privacy Framework Compliance and similar clauses.
Compare across platforms →Monitoring
Microsoft Azure has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Microsoft Corporation complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Microsoft Corporation has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF. In the context of an onward transfer, Microsoft Corporation has responsibility for the processing of personal data it receives under the DPF and subsequently transfers to a third party acting as an agent on our behalf. Microsoft Corporation remains liable under the DPF if our agent processes such personal data in a manner inconsistent with the DPF, unless Microsoft Corporation can prove that we are not responsible for the event giving rise to the damage.Excerpt from Microsoft Azure's Microsoft Privacy
1. REGULATORY LANDSCAPE: This provision directly engages GDPR Chapter V, which governs international data transfers and requires an appropriate safeguard such as standard contractual clauses or an adequacy decision for transfers to non-EEA countries. The EU-U.S. DPF operates as an adequacy mechanism following the European Commission's adequacy decision. The FTC holds investigatory and enforcement authority over DPF compliance by U.S. companies. The UK ICO and Swiss FDPIC are the relevant authorities for UK Extension and Swiss-U.S. DPF disputes respectively. 2. GOVERNANCE EXPOSURE: Medium. The DPF provides a recognized legal mechanism for EU-to-U.S. transfers, but the adequacy decision may be subject to future legal challenge, as was the case with predecessor frameworks. The statement also references reliance on standard contractual clauses as an alternative or supplementary safeguard. Enterprise customers should assess whether their data processing agreements with Microsoft specify which transfer mechanism applies to their data. 3. JURISDICTION FLAGS: EU and EEA users have direct rights under the DPF to file complaints with EU Data Protection Authorities if DPF Principles are violated. UK users may raise complaints with the ICO. Swiss users may raise complaints with the FDPIC. The availability of binding arbitration under the DPF provides a residual dispute resolution mechanism for EU and Swiss individuals whose complaints are not resolved through other channels. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers contracting with Microsoft for services involving transfers of personal data from the EU, UK, or Switzerland to the United States should confirm that applicable enterprise agreements specify the operative transfer mechanism and include appropriate DPA provisions. The statement's disclosure that DPF Principles prevail over the privacy statement in the event of conflict should be noted in contract reviews. 5. COMPLIANCE CONSIDERATIONS: Legal teams should monitor the status of the EU-U.S. DPF adequacy decision and ensure that alternative transfer mechanisms such as standard contractual clauses are in place as a contingency. Data mapping should identify which personal data flows from EU, UK, or Swiss users to Microsoft's U.S. data centers and confirm that applicable transfer mechanisms are documented. Organizations should assess whether Microsoft's DPF certification covers all Microsoft entities and services relevant to their use case.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes the legal mechanism Microsoft relies on for transfers of personal data from the EU, UK, and Switzerland to the United States, and defines Microsoft's liability posture for downstream processing by third-party agents, which is directly relevant to enterprise customers and institutional procurement teams evaluating cross-border data transfer risk.
The agreement establishes that personal data transferred from the EU, UK, and Switzerland to the United States is governed by the applicable Data Privacy Framework Principles, with Microsoft retaining liability for agent processing that is inconsistent with those principles. EU, UK, and Swiss users may raise DPF-related complaints with Microsoft, and unresolved complaints may be referred to binding arbitration under …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Microsoft Azure.