Microsoft Azure

Last Reviewed: 22 Jun 2026

Data Use Review

At a Glance

The "Processing for Business Operations Incident to Providing the Products and Services to Customer" section of Microsoft's DPA explicitly obtains the Customer's authorisation for Microsoft to act as an independent data controller of certain personal data that it would otherwise be processing as a data processor, in connection with "business operations processing". We recommend this contract (and in particular, the "Processing for Business Operations Incident to Providing the Products and Services to Customer" section) is manually reviewed to ensure the data use terms are acceptable to you.

Company & Product Details

HQ

United States

Products

Azure Cloud Services

Product description

Cloud computing platform offering infrastructure, data, analytics, AI, networking, and security services to businesses globally.

What data is being processed?

Basic personal data (name, address, contact details), authentication data, unique identification numbers, pseudonymous identifiers, financial and insurance information, commercial information, biometric information, location data, photos/video/audio, internet activity, device identification, profiling data, HR and recruitment data, education data, citizenship and residency information, and special categories of data as elected by the Customer

Document Details

Date of DPA

22 May 2026

Additional date information

Document states "Last updated May 22, 2026" and "These commitments are binding on Microsoft as of May 22, 2026." This is the worldwide edition (WW) of the Microsoft Products and Services Data Protection Addendum, published in English on May 22, 2026. Summary of changes in this version: "05/22/2026 – Added clarification of subprocessors that support artificial intelligence functionality in the Notice and Controls on use of Subprocessors section." Downloaded from the Microsoft Licensing docs direct docx link.

What jurisdictions are covered?

The DPA explicitly covers the European Economic Area (EEA) and EU member states (GDPR), the United Kingdom (UK Data Protection Act 2018; IDTA), Switzerland (Swiss Data Protection Laws), and the United States (CCPA, HIPAA, FERPA, CJIS). EU Data Act (Regulation (EU) 2023/2854) is also explicitly addressed. The GDPR Terms attachment applies to all customers effective May 25, 2018.

Is the DPA incorporated into service or customer agreements?

Yes
The DPA states: "The DPA is incorporated by reference into the Product Terms and other Microsoft agreements. The parties also agree that, unless a separate Professional Services agreement exists, this DPA governs the processing and security of Professional Services Data." (Introduction). The DPA is described as "an addendum to the Product Terms site (and formerly OST)." It also forms part of volume licensing agreements and is binding via the Product Terms. The GDPR Terms apply to all customers effective May 25, 2018, regardless of the version of Product Terms applicable.

Location & Transfers

Where is data held or processed?

European Union, European Free Trade Association, Not Explicitly Stated For EU Data Boundary Services, the DPA explicitly commits that Microsoft will store and process Customer Data, Personal Data, and Professional Services Data at rest within the European Union and the European Free Trade Association (EFTA). For Core Online Services generally, Customer Data is stored at rest within certain major geographic areas (Geos) as set forth in the Product Terms — the specific countries are not named in the DPA itself. Customer may not be transferred to, or stored and processed in, a geographic location except in accordance with the DPA Terms (section "Data Transfers and Location").

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
The 2021 Standard Contractual Clauses (EU Commission Decision 2021/914, processor-to-processor module) are implemented by Microsoft for all transfers of Customer Data, Professional Services Data, and Personal Data out of the EU, EEA, UK, and Switzerland (section "Data Transfers"). The IDTA (International Data Transfer Addendum, UK ICO template B.1.0) is additionally implemented for UK transfers. Microsoft is also certified to the EU-U.S. and Swiss-U.S. Data Privacy Frameworks and the UK Extension to the EU-U.S. Data Privacy Framework. GDPR Terms at Attachment 1 are incorporated and apply to all processing within the scope of the GDPR.

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Microsoft implements and maintains appropriate technical and organisational measures to protect Customer Data, Professional Services Data, and Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access, as set forth in a Microsoft Security Policy (section "Security Practices and Policies"). Specific measures include: ISO 27001, ISO 27002, and ISO 27018 compliance; encryption of Customer Data in transit and at rest; role-based access controls and least-privilege mechanisms; no standing access by Microsoft personnel to Customer Data for Core Online Services; regular independent third-party audits; and the security measures in Appendix A for Core Online Services and Professional Services. Pseudonymisation and encryption, ongoing confidentiality/integrity/availability/resilience, and a process for regularly testing and evaluating technical and organisational measures are also referenced.

Non Processor Data Use

Does the company process data solely as a processor?

No
In the the "Processing for Business Operations Incident to Providing the Products and Services to Customer" section, Microsoft explicitly reserves the right to act as an independent data controller for "business operations incident to providing the Products and Services." Specifically, Customer authorises Microsoft to create aggregated statistical, non-personal data from pseudonymised identifiers (such as pseudonymised usage logs) and to calculate statistics related to Customer Data or Professional Services Data - which, remains personal data, under the GDPR definition, and my be data initially processed by Microsoft as a processor - for purposes of billing, compensation, internal reporting (forecasting, revenue, capacity planning, product strategy), and financial reporting (section "Processing for Business Operations"). It is unclear what legal basis customers would have for authorising this use. The most likely legal basis would be "legitimate interest", for which the customer should do a "Legitimate Interest Assessment" - but the need to do this is not mentioned by Microsoft. Microsoft states it is "accepting the added responsibilities of a data controller under GDPR for such processing" (section "Processor and Controller Roles and Responsibilities"). Microsoft commits not to use data for user profiling or advertising, and processing must be without accessing or analysing the content of Customer Data. This is a limited but explicit controller rights claim, triggering Data Use Review.

Subprocessing

General authorization

General
Customer consents to Microsoft engaging Subprocessors, including Microsoft Affiliates (section "Notice and Controls on use of Subprocessors"). This constitutes prior written general consent for subcontracting as required under the SCCs and GDPR Terms (Article 28(2)). Microsoft publishes a list of Subprocessors on its website. For new Subprocessors accessing Customer Data (Online Services): at least 6 months' notice required. For Subprocessors that support artificial intelligence functionality: at least 30 days' notice, with Customer ability to disable use of that subprocessor until at least 6 months after notice. For new Subprocessors accessing Professional Services Data or Personal Data not in Customer Data: at least 30 days' notice. Customer may terminate the affected subscription without penalty within the relevant notice period if they do not approve a new Subprocessor (section "Notice and Controls on use of Subprocessors", updated May 2026).

Do all the DPA terms flow down to sub-processors?

Yes
Microsoft ensures via written contracts that Subprocessors may only access and use Customer Data, Professional Services Data, or Personal Data to deliver the services for which Microsoft retained them, and must provide at least the level of data protection required of Microsoft by the DPA (section "Notice and Controls on use of Subprocessors"). Microsoft agrees to oversee Subprocessors to ensure these contractual obligations are met. Microsoft remains fully liable to Customer for the performance of any other processor's obligations where that processor fails to fulfil their data protection obligations.

Is data only processed on the instruction of the controller?

Yes
Microsoft will use and otherwise process Customer Data, Professional Services Data, and Personal Data only (a) to provide Customer the Products and Services in accordance with Customer's documented instructions and (b) for business operations incident to providing the Products and Services to Customer (section "Nature of Data Processing; Ownership"). Customer's agreement, including the DPA Terms, product documentation, and Customer's use and configuration of features, constitutes Customer's complete documented instructions (section "Processor and Controller Roles and Responsibilities"). Microsoft shall not use Customer Data for user profiling, advertising, or market research without Customer's documented instructions. Microsoft shall immediately inform Customer if, in its opinion, an instruction infringes the GDPR.

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
Microsoft will make available to Customer, consistent with the functionality of the Products and Services and Microsoft's role as processor, the ability to fulfil data subject requests to exercise their rights under the GDPR. If Microsoft receives a request directly from a data subject, it will redirect the data subject to make their request directly to Customer, with Customer responsible for responding. Microsoft shall comply with reasonable requests by Customer to assist with Customer's response to such a data subject request (section "Data Subject Rights; Assistance with Requests"). The GDPR Terms also reference Microsoft's obligation to assist with requests for exercising data subject rights under Chapter III of the GDPR.

Does the contract include staff confidentiality clauses?

Yes
Microsoft will ensure that its personnel engaged in processing Customer Data, Professional Services Data, and Personal Data (i) process such data only on instructions from Customer or as described in the DPA, and (ii) are obligated to maintain the confidentiality and security of such data even after their engagement ends. Microsoft provides periodic and mandatory data privacy and security training and awareness to employees with access to such data in accordance with applicable Data Protection Requirements and industry standards (section "Processor Confidentiality Commitment"). The GDPR Terms also require that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

Are there audit rights for the data?

Structured
Microsoft conducts its own regular third-party audits (at least annually per applicable control standard/framework, by qualified independent auditors at Microsoft's selection and expense) and makes the resulting Microsoft Audit Reports available at https://servicetrust.microsoft.com/ (section "Auditing Compliance"). Customer's additional on-site or independent audit rights are available only where existing Microsoft Audit Reports cannot reasonably satisfy Customer's audit requirements under Data Protection Requirements. Any such additional audit must be conducted by an independent, accredited third-party firm; scope, timing, duration, and fees must be mutually agreed in advance; Customer bears all costs including reasonable costs for Microsoft's time. The auditor must be given access to relevant processing systems and supporting documentation (section "Auditing Compliance").

Is there assistance with DPIA requests?

Yes
Microsoft will assist Customer in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR, taking into account the nature of processing and the information available to Microsoft (GDPR Terms, Article 28(3)(f)). This includes assistance with Data Protection Impact Assessments (Article 35) and prior consultation with supervisory authorities (Article 36). Microsoft will also make available all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and allow for and contribute to audits.

How much notice is provided for data breaches?

Microsoft will promptly and without undue delay notify Customer of a Security Incident (accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Data, Professional Services Data, or Personal Data) and will (1) notify Customer of the incident; (2) investigate and provide detailed information; (3) take reasonable steps to mitigate effects and minimise damage (section "Security Incident Notification"). The GDPR Terms confirm notification "without undue delay after becoming aware of a Personal Data breach" per Article 33(2), with information required under Article 33(3) to the extent reasonably available. No specific number of hours is prescribed in the DPA body. Notification may be by any means Microsoft selects, including email.

What happens to the data on termination?

During the term of Customer's subscription, Customer has the ability to access, extract and delete Customer Data stored in each Online Service. After expiry or termination, Microsoft retains Customer Data in a limited function account for 90 days so Customer may extract data. After that 90-day period, Microsoft will disable the account and delete Customer Data and Personal Data within an additional 90 days, unless authorised to retain (section "Data Retention and Deletion"). For Professional Services Data and Software, deletion occurs after the business purposes are fulfilled or upon Customer's request. GDPR Terms confirm deletion or return of all Personal Data at the choice of Customer after the end of the provision of services.