Microsoft Azure
Last Reviewed: 22 Jun 2026
At a Glance
The "Processing for Business Operations Incident to Providing the Products and Services to Customer" section of Microsoft's DPA explicitly obtains the Customer's authorisation for Microsoft to act as an independent data controller of certain personal data that it would otherwise be processing as a data processor, in connection with "business operations processing". We recommend this contract (and in particular, the "Processing for Business Operations Incident to Providing the Products and Services to Customer" section) is manually reviewed to ensure the data use terms are acceptable to you.
Company & Product Details
HQ
United States
Products
Azure Cloud Services
Product description
Cloud computing platform offering infrastructure, data, analytics, AI, networking, and security services to businesses globally.
What data is being processed?
Basic personal data (name, address, contact details), authentication data, unique identification numbers, pseudonymous identifiers, financial and insurance information, commercial information, biometric information, location data, photos/video/audio, internet activity, device identification, profiling data, HR and recruitment data, education data, citizenship and residency information, and special categories of data as elected by the Customer
Document Details
Date of DPA
22 May 2026
Additional date information
Document states "Last updated May 22, 2026" and "These commitments are binding on Microsoft as of May 22, 2026." This is the worldwide edition (WW) of the Microsoft Products and Services Data Protection Addendum, published in English on May 22, 2026. Summary of changes in this version: "05/22/2026 – Added clarification of subprocessors that support artificial intelligence functionality in the Notice and Controls on use of Subprocessors section." Downloaded from the Microsoft Licensing docs direct docx link.
What jurisdictions are covered?
The DPA explicitly covers the European Economic Area (EEA) and EU member states (GDPR), the United Kingdom (UK Data Protection Act 2018; IDTA), Switzerland (Swiss Data Protection Laws), and the United States (CCPA, HIPAA, FERPA, CJIS). EU Data Act (Regulation (EU) 2023/2854) is also explicitly addressed. The GDPR Terms attachment applies to all customers effective May 25, 2018.
Is the DPA incorporated into service or customer agreements?
Link
Location & Transfers
Where is data held or processed?
European Union, European Free Trade Association, Not Explicitly Stated For EU Data Boundary Services, the DPA explicitly commits that Microsoft will store and process Customer Data, Personal Data, and Professional Services Data at rest within the European Union and the European Free Trade Association (EFTA). For Core Online Services generally, Customer Data is stored at rest within certain major geographic areas (Geos) as set forth in the Product Terms — the specific countries are not named in the DPA itself. Customer may not be transferred to, or stored and processed in, a geographic location except in accordance with the DPA Terms (section "Data Transfers and Location").
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
Microsoft implements and maintains appropriate technical and organisational measures to protect Customer Data, Professional Services Data, and Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access, as set forth in a Microsoft Security Policy (section "Security Practices and Policies"). Specific measures include: ISO 27001, ISO 27002, and ISO 27018 compliance; encryption of Customer Data in transit and at rest; role-based access controls and least-privilege mechanisms; no standing access by Microsoft personnel to Customer Data for Core Online Services; regular independent third-party audits; and the security measures in Appendix A for Core Online Services and Professional Services. Pseudonymisation and encryption, ongoing confidentiality/integrity/availability/resilience, and a process for regularly testing and evaluating technical and organisational measures are also referenced.
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
Microsoft will promptly and without undue delay notify Customer of a Security Incident (accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Data, Professional Services Data, or Personal Data) and will (1) notify Customer of the incident; (2) investigate and provide detailed information; (3) take reasonable steps to mitigate effects and minimise damage (section "Security Incident Notification"). The GDPR Terms confirm notification "without undue delay after becoming aware of a Personal Data breach" per Article 33(2), with information required under Article 33(3) to the extent reasonably available. No specific number of hours is prescribed in the DPA body. Notification may be by any means Microsoft selects, including email.
What happens to the data on termination?
During the term of Customer's subscription, Customer has the ability to access, extract and delete Customer Data stored in each Online Service. After expiry or termination, Microsoft retains Customer Data in a limited function account for 90 days so Customer may extract data. After that 90-day period, Microsoft will disable the account and delete Customer Data and Personal Data within an additional 90 days, unless authorised to retain (section "Data Retention and Deletion"). For Professional Services Data and Software, deletion occurs after the business purposes are fulfilled or upon Customer's request. GDPR Terms confirm deletion or return of all Personal Data at the choice of Customer after the end of the provision of services.