Microsoft commits that its AI systems will protect users' personal information, apply privacy-by-design principles, and handle data only in appropriate ways.
This provision affects how Microsoft AI processes personal data from users of products like Copilot and Azure AI, but the phrase 'appropriate ways' is undefined, leaving significant discretion to Microsoft regarding what constitutes acceptable use of personal information in AI contexts.
How other platforms handle this
Netflix operates from the United States and relies on a number of legal mechanisms to transfer personal information from the European Economic Area (EEA), United Kingdom, Switzerland, and other countries to the United States or other countries. In particular, Netflix uses standard contractual clause...
In connection with any merger, sale of company assets, financing or acquisition of all or a portion of our business by another company;
For joint marketing with other financial companies - To offer our products and services to you. Our joint marketing partners include our banking partner, nbkc bank, and other financial services companies.
AI systems process vast amounts of personal data, and this commitment is relevant to how Microsoft's AI products handle sensitive information, but the standards referenced are vague and no specific data subject rights are granted here.
(1) REGULATORY FRAMEWORK: GDPR Art. 5 (data processing principles), Art. 25 (data protection by design and by default), and Art. 22 (automated decision-making) are directly implicated. CCPA/CPRA §1798.100 et seq. governs California residents' rights over personal data used in AI systems. HIPAA 45 CFR Part 164 applies where Microsoft AI processes protected health information. EU AI Act Art. 10 requires data governance measures for personal data used in high-risk AI training and operation. Enforcement authorities include EU DPAs (GDPR), California Privacy Protection Agency (CCPA/CPRA), and HHS OCR (HIPAA). (2)
Compliance intelligence locked
Regulatory citations, enforcement risk, and due diligence action items.
Watcher: regulatory citations. Professional: full compliance memo.
Your genetic data may be transferred to a new owner as a business asset. Here is what the Terms of Service actually say and what you can do right now.