Microsoft · Microsoft Privacy Statement (Legacy)

GDPR Data Controller Designation for EEA and UK Users

Medium severity
Share 𝕏 Share in Share

What it is

For users in the European Economic Area and United Kingdom, Microsoft Ireland Operations Limited is designated as the data controller responsible for how your personal data is handled.

Why it matters

Knowing who the legal data controller is enables EU and UK users to direct data rights requests and regulatory complaints to the correct entity, and determines which supervisory authority has jurisdiction.

Institutional analysis (Compliance & legal intelligence)

The designation of Microsoft Ireland Operations Limited as EEA/UK controller has implications for jurisdictional competence (Irish DPC as lead supervisory authority under GDPR's one-stop-shop mechanism), cross-border data transfer compliance, and the applicability of UK GDPR post-Brexit. Legal teams should confirm that data processing agreements with Microsoft entities reflect this controller designation.

🔒

Compliance intelligence locked

Regulatory citations, enforcement risk, and due diligence action items.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations. Professional: full compliance memo.

Consumer impact

Microsoft collects extensive personal data across its products including search history, voice recordings, location data, browsing behaviour, and inferred interests, and uses this data for targeted advertising and product improvement. Users' data may be shared with affiliates, advertising partners, and other third parties, and sensitive data such as health and biometric information may also be collected in certain contexts. You can review, download, or delete your personal data by visiting Microsoft's Privacy Dashboard at account.microsoft.com/privacy.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    EU/UK users can submit data subject access, deletion, or portability requests via the Microsoft Privacy Dashboard at account.microsoft.com/privacy.

Applicable agencies

  • State AG
    While GDPR is enforced by EU supervisory authorities, UK users may also engage the UK ICO, which functions similarly to a state-level data protection authority.
    File a complaint →

Provision details

Document information
Document
Microsoft Privacy Statement (Legacy)
Entity
Microsoft
Document last updated
March 5, 2026
Tracking information
First tracked
March 15, 2026
Last verified
March 15, 2026
Record ID
CA-P-00001004
Document ID
CA-D-00001
Evidence Provenance
Source URL
Wayback Machine
SHA-256
45f09bce08bba70d095c6310e3c8383cc7e2ee6d93fc0795641bd50132df016b
Verified
✓ Snapshot stored   ✓ Change verified
How to Cite
ConductAtlas Policy Archive
Entity: Microsoft | Document: Microsoft Privacy Statement (Legacy) | Record: CA-P-00001004
Captured: 2026-03-15 11:31:06 UTC | SHA-256: 45f09bce08bba70d…
URL: https://conductatlas.com/platform/microsoft/microsoft-privacy-statement-legacy/gdpr-data-controller-designation-for-eea-and-uk-users/
Accessed: April 4, 2026
Classification
Severity
Medium
Categories

Other provisions in this document