Skip to main content Azure Dynamics 365 Microsoft 365 Office 365 Power Platform SQL Server System Center Windows Windows 365 Windows Server Product licensing briefs Product licensing search Licensing Terms Overview Software Assurance Benefits Getting Software Assurance Resources Microsoft Customer Agreement Enterprise Agreement Microsoft Products and Services Agreement (MPSA) Open Value Select Plus Licensing program guides Software development companies Microsoft solution providers Services Provider License Agreement (SPLA) Microsoft Partner Network Find a Microsoft partner For SMBs For Consumers For Students For Enterprises For Government organizations For Educational institutions For Nonprofit organizations Tools and resources Product fulfillment Volume Licensing Service Center (VLSC) VLSC training and resources Business Center (for MPSA customers) Business Center training and resources Overview Software Assurance Benefits Getting Software Assurance Resources Contact a Volume Licensing Activation Center Access the Volume Licensing Service Center Find training and resources for the VLSC Contact Support for the Volume Licensing Service Center Find support for Microsoft products Get help with Windows Get help with Office Find answers on Microsoft forums Licensing News Microsoft Security Azure Dynamics 365 Microsoft 365 Microsoft Teams Windows 365 Microsoft AI Azure Space Mixed reality Microsoft HoloLens Microsoft Viva Quantum computing Sustainability Education Automotive Financial services Government Healthcare Manufacturing Retail Find a partner Become a partner Partner Network Microsoft Marketplace Software companies Blog Microsoft Advertising Developer Center Documentation Events Licensing Microsoft Learn Microsoft Research View Sitemap
Search Terms


Privacy & Security Terms


General

The Privacy & Security Terms were formerly contained in Attachment 1 to the Online Services Terms.

The Data Protection Addendum, or DPA (defined in the Glossary) sets forth the parties obligations with respect to the processing and security of Customer Data, Professional Services Data, and Personal Data by the Products. The Data Protection Addendum can be downloaded here https://aka.ms/DPA. In the event of any conflict or inconsistency between the DPA and any other terms in Customer’s licensing agreement (including these terms), the DPA shall prevail.

Exceptions to the DPA

The Privacy and Security Terms in the table below modify or supplement the DPA for each of the identified Products.

Product FamilyOnline ServicePrivacy & Security Terms
Microsoft AzureWeb IQThe Data Protection Addendum does not apply to use of Web IQ; the Microsoft Privacy Statement (https://privacy.microsoft.com/privacystatement) applies. When using Web IQ, Customer Data will flow outside Customer's compliance and Geo boundary.
Microsoft FoundryThe DPA does not apply to use of Grounding with Bing Search and/or Grounding with Bing Custom Search through Microsoft Foundry (including when used through Microsoft Foundry Agent service, Responses API in Microsoft Foundry Models, and/or Web Knowledge Source in Microsoft Foundry Knowledge); the Microsoft Privacy Statement applies. When using Grounding with Bing Search and/or Grounding with Bing Custom Search, Customer Data will flow outside Customer’s compliance and Geo boundary.
Azure AI Services

Services in Containers

Because the operating environment of containers installed on Customer's dedicated hardware is not under Microsoft's control, the terms of the DPA do not apply to those containers, except to the extent a) any Personal Data is collected in connection with a billing endpoint, or b) Customer Data is provided to Microsoft for custom model training prior to download of the Service operating in the container.

Inactive Services Configurations and Custom Models

For the purposes of data retention and deletion, a Services configuration or custom model that has been inactive may at Microsoft's discretion be treated as an Online Service for which the Customer's subscription has expired. A configuration or custom model is inactive if for 90 days (1) no calls are made to it; (2) it has not been modified and does not have a current key assigned to it and; (3) Customer has not signed in to it.

Multi-Cloud Scanning Connectors for Microsoft Purview

To enable interoperability with Customer's deployments with other cloud providers, Microsoft may operate within such other clouds certain optional, discrete data scanner functionality for Customer's data hosted in such other clouds (the "Multi-Cloud Scanning Connectors for Microsoft Purview"). Microsoft will disclose in its documentation how Customer may enable and use the Multi-Cloud Scanning Connectors for Microsoft Purview. For clarity, the Multi-Cloud Scanning Connectors for Microsoft Purview is a separate add-on to Microsoft Purview. The Multi-Cloud Scanning Connectors for Microsoft Purview is not a Microsoft Azure Core Service and the following sections of the DPA do not apply to the Multi-Cloud Scanning Connectors for Microsoft Purview: "Educational Institutions", "CJIS Customer Agreement", "HIPAA Business", and "Appendix A - Security Measures".

With respect solely to the Multi-Cloud Scanning Connectors for Microsoft Purview, the following modifications to the DPA apply:

  • Data Access: Microsoft employs least privilege access mechanisms to control access to Customer Data (including any Personal Data therein). Microsoft employs role-based access controls to ensure that Microsoft's access to Customer Data required for service operations is for an appropriate purpose and approved with management oversight.
  • Auditing Compliance: Microsoft's commitments in the Auditing Compliance section of the DPA do not extend to third-party computers, computing environments or physical data centers used by the Multi-Cloud Scanning Connectors for Microsoft Purview.

Standard data protection terms offered by those other cloud providers govern your use of the Multi-Cloud Scanning Connectors for Microsoft Purview while the add-on is hosted in such other clouds.

Visual Studio App CenterThe privacy statement located at https://aka.ms/actestprivacypolicy applies to Customer’s use of Visual Studio App Center Test. Customer may not use Visual Studio App Center Test to store or process Personal Data.
SQL Managed Instance enabled by Azure ArcThe terms of the DPA do not apply to processing of data in SQL Managed Instance enabled by Azure Arc running in an environment outside of Microsoft's control, except to the extent any Personal Data is collected to enable Azure management services and to meter usage for billing purposes.
Microsoft Genomics

The Microsoft Privacy Statement located at https://aka.ms/privacy applies to Customer's use of Microsoft Genomics and not the DPA, except that this Microsoft Genomics section controls to the extent it conflicts with the Microsoft Privacy Statement. 

Broad License Terms

Microsoft Genomics includes access to the Genetic Analysis Toolkit (GATK) from the Broad Institute, Inc. ("Broad"). Use of the GATK and any related documentation as part of Microsoft Genomics is also subject to Broad's GATK End User License Agreement ("Broad EULA" located here https://software.broadinstitute.org/gatk/eula/index?p=Azure).

Microsoft may collect and share with Broad certain statistical and technical information regarding Customer's usage of the GATK. Customer authorizes Microsoft to report to Broad Customer's status as a user of the GATK in Microsoft Genomics.

Azure SQL EdgeThe terms of the DPA do not apply to Azure SQL Edge installed on Customer’s IoT Device, except to the extent any Personal Data is collected to enable Azure management services and to meter usage for billing purposes, because the operating environment of such IoT Devices is not under Microsoft’s control.
Azure LocalMicrosoft will be a controller of Personal Data when customers turn on collection of Windows diagnostic data as described in product documentation. When Microsoft is a controller, Microsoft will handle this Personal Data in accordance with the Microsoft Privacy Statement at aka.ms/privacy, and the DPA terms do not apply.
Azure Stack Hub

Microsoft will be a controller of Personal Data when customers turn on collection of Windows diagnostic data as described in the Product documentation. When Microsoft is a controller, Microsoft will handle this Personal Data in accordance with the Microsoft Privacy Statement at aka.ms/privacy, and the DPA terms do not apply.  

If a Microsoft Cloud Agreement or Microsoft Customer Agreement Customer uses Azure Stack Hub software or services that are hosted by a Reseller, such use will be subject to Reseller’s privacy practices, which may differ from Microsoft’s.

Azure VMware Solution

Professional Services Data Transfer to VMware

If customer contacts Microsoft for technical support relating to Azure VMware Solution and Microsoft must engage VMware for assistance with the issue, Microsoft will transfer the Professional Services Data and the Personal Data contained in the support case to VMware. The transfer is made subject to the terms of the Support Transfer Agreement between VMware and Microsoft, which establishes Microsoft and VMware as independent processors of the Professional Services Data. Before any transfer of Professional Services Data to VMware will occur, Microsoft will obtain and record consent from customer for the transfer.

VMware Data Processing Agreement

Once Professional Services Data is transferred to VMware (pursuant to the above section), the processing of Professional Services Data, including the Personal Data contained the support case, by VMware as an independent processor will be governed by the VMware Data Processing Agreement for Microsoft AVS Customers Transferred for L3 Support (https://docs.broadcom.com/doc/global-customers-dpa). Customer also gives authorization to allow its representative(s) who request technical support for Azure VMware Solution to provide consent on its behalf to Microsoft for the transfer of the Professional Services Data to VMware.

BingBingThe Data Protection Addendum does not apply to Bing Search Services or to any use of Bing within a Product. For any component of a Product that is powered by Bing, as disclosed in the product documentation, the Microsoft Privacy Statement (https://privacy.microsoft.com/privacystatement) applies.
Bing Maps

Bing Maps Privacy

The Microsoft Privacy Statement (https://privacy.microsoft.com/privacystatement) and privacy terms in the Microsoft Bing Maps Platform API Terms of Use apply to Customer’s use of Bing Maps and Bing Maps Mobile Asset Management Platform.

GitHubGitHub OfferingsNotwithstanding anything to the contrary in Customer's volume licensing agreement (including these Product Terms and the DPA), the GitHub Privacy Statement available at https://aka.ms/github_privacy and the GitHub Data Protection Agreement at https://aka.ms/github_dpa will apply to Customer's use of GitHub Offerings, including GitHub Enterprise licensed standalone or as Visual Studio Enterprise or Professional with GitHub Enterprise.
Office 365 ServicesOffice 365 EducationIf Customer is provisioned outside of the EU or EFTA, and Customer has an Office 365 Education subscription but has not purchased an Advanced Data Residency for Education add-on, then notwithstanding the "Location of Customer Data at Rest for Core Online Services" section of the Product Terms, Microsoft may provision Customer's Office 365 Education tenant in, transfer Customer Data to, and store Customer Data at rest anywhere within the European Union or North America. If Customer is provisioned in the EU or EFTA, and Customer has an Office 365 Education subscription but has not purchased an Advanced Data Residency for Education add-on, then notwithstanding the "Location of Customer Data at Rest for Core Online Services" section of the Product Terms, Microsoft may provision Customer's Office 365 Education tenant in, transfer Customer Data to, and store Customer Data at rest anywhere within the European Union.
Microsoft Dynamics 365 ServicesDynamics 365 Business Central and Dynamics 365 Finance in Denmark

Bookkeeping Laws and Regulations

These terms apply only to Customers with an enterprise in Denmark as required under the Bookkeeping Act. The DPA governs how Microsoft handles Customer Data in Dynamics 365 Business Central and Dynamics 365 Finance, except for the retention, deletion, and disclosure of Accounting Materials. In the event of any conflict or inconsistency between the DPA and any other terms in Customer's licensing agreement, these terms shall prevail. 

Definitions

"Accounting Materials" means all documents that comprise bookkeeping, including any recorded transactions and receipts and other data (including Personal Data) for an enterprise that Customer provides or is provided on behalf of Customer in a Digital Standard Bookkeeping System, as required by the Bookkeeping Act. 

"Bookkeeping Act" means the Danish Bookkeeping Act of 24 May 2022 and any issued executive orders that regulate the bookkeeping and accounting obligations of enterprises, as well as providers of Digital Standard Bookkeeping Systems, in Denmark.

"Danish Authority" means any (i) Danish public authority that has the necessary legal right to inspect an enterprise and request its Accounting Materials under the Bookkeeping Act or other relevant laws; or (ii) liquidator, bankruptcy trustee, or reorganizer that has taken over management of the enterprise.

"Digital Standard Bookkeeping System" means a digital service or software containing functions that enables enterprises to record and store Accounting Materials, or at least a complete backup copy of the same on a server hosted by the provider or another third-party according to the Bookkeeping Act's regulations and standards.

Data Retention and Deletion of Accounting Materials

By using Dynamics 365 Business Central or Dynamics 365 Finance, Customer agrees that Microsoft or its affiliates, in accordance with their legal obligation, can copy, store, and retain Customer's Accounting Materials for 5 years from the end of the financial year of the related recorded transactions and receipts ("Retention Period"), even if Customer changes its bookkeeping system, goes bankrupt, or is liquidated, as required by the Bookkeeping Act. Microsoft will store Customer's Accounting Materials at rest in a Microsoft-managed storage in the same location as the primary computer equipment processing the Customer Data for these services or the European Union. During the Retention Period, Customer cannot access, extract, correct, or delete any of its Accounting Materials from this storage. Microsoft will use the same security measures to protect Customer's Accounting Materials as it uses to protect other Customer Data. After the Retention Period ends, Microsoft will delete Customer's Accounting Materials. Microsoft has no liability for the deletion of Customer's Accounting Materials.

Disclosure of Accounting Materials

Microsoft will disclose or provide access to Customer's Accounting Materials to Danish Authorities as necessary to satisfy a request compelling such disclosure as required by the Bookkeeping Act. Other data a Customer stores in these Digital Standard Bookkeeping Systems is not subject to disclosure. The Danish Authorities are only authorized to request Accounting Materials from providers of Digital Standard Bookkeeping Systems if obtaining the information directly from the enterprise is not possible. Microsoft has no liability for the disclosure of Customer's Accounting Materials to any Danish Authority.

Microsoft Relationship Sales

LinkedIn Sales Navigator

LinkedIn Sales Navigator is provided by LinkedIn Corporation. Customer may use the LinkedIn Sales Navigator Service only to generate sales leads. Each user of LinkedIn Sales Navigator must be a member of LinkedIn and agree to be bound by the LinkedIn User Agreement available at https://www.linkedin.com/legal/preview/user-agreement. Despite anything to the contrary in Customer's volume licensing agreement (including these Product Terms), the LinkedIn Privacy Policy available at https://www.linkedin.com/legal/privacy-policy will apply to Customer's use of the LinkedIn Sales Navigator service. LinkedIn Corporation (as data processor) and Customer (as data controller) will comply with the terms of the LinkedIn Data Processing Agreement located at https://legal.linkedin.com/dpa

Microsoft 365Legacy Glint ServicesCustomer's access to and use of Legacy Glint Services are governed by the terms set forth in Customer's most recently active LinkedIn Order Form(s) for Legacy Glint Services. No Microsoft terms, including without limitation the Microsoft Product Terms, DPA, or any agreements between Customer and Microsoft shall apply to Legacy Glint Services.
Other Online ServicesMicrosoft Intune If Intune Company Portal App is used to manage devices, the terms that apply to Microsoft Intune Online Services (as defined in the Core Online Services table in these Privacy & Security Terms) apply to the use of Intune Company Portal App. Microsoft’s commitments related to Intune Company Portal App do not extend to data processing, policies, or practices of third-party providers of mobile platforms on which Intune Company Portal App operates (e.g., Apple, Google).
Managed Devices and ApplicationsMicrosoft Managed Desktop (MMD) integrates data (including Customer Data) between other Microsoft Products including Windows, Microsoft Entra ID, Microsoft Intune, Microsoft Defender for Endpoint, Office, and Online Services as configured by Customer, if any (collectively for purposes of this provision the "MMD Integrated Services").  Once data is transferred between the MMD Integrated Services, that data is governed by the Product Terms applicable to the service in which it resides.
Microsoft Dragon CoPilot

Use of data. As part of Microsoft’s processing of Customer Data to provide Dragon Copilot, Customer instructs Microsoft (and its Subprocessors) to:

  1. Process (including via human review) Customer Data for the purpose of training and developing the AI/ML models (including, without limitation, the generative AI foundational models and speech recognition and natural language understanding models) and features of Dragon Copilot and successor products and services;
  2. Process PHI (as defined below) to create de-identified health information in accordance with 45 C.F.R. § 164.514(b) and use and disclose such de-identified health information for any purpose permitted by law. This de-identified health information will be considered as excluded from the definition of Confidential Information under the Customer’s volume licensing agreement; and
  3. Process PHI to provide Data Aggregation services to Customer as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B).

Protected Health Information” or “PHI has the definition set forth under the HIPAA Business Associate Agreement available at http://aka.ms/BAA (“BAA”).

Customer Data may contain PHI. Microsoft may use PHI for the purposes detailed under (1) above in accordance with the use permissions under Section 2.b of the BAA.

If Customer does not agree with the instructions above, Customer should not use (or should discontinue its use of) Dragon Copilot.

For more detail, see https://aka.ms/DragonData.

The standard terms regarding “Data Retention and Deletion”, including the 90-day retention period following expiration or termination of a Customer’s subscription, will apply to free trials of Dragon Copilot.

Nuance Speech Data

The following terms apply to customers of Dragon Copilot who are also customers of the Dragon Medical One and/or Dragon Ambient eXperience (DAX) Copilot:

By using Dragon Copilot, Customer instructs Microsoft to access and process Nuance Speech Data solely for the purpose of optimizing, adapting, and enhancing Customer’s Dragon Copilot speech recognition experience. Microsoft will process the Nuance Speech Data in accordance with Customer’s volume licensing agreement, including but not limited to the DPA.

Dragon Copilot Subprocessors

Information about Subprocessors used by Microsoft in conjunction with Dragon Copilot can be accessed at https://aka.ms/hls-subprocessor-list.

Product FamilySoftware ProductPrivacy & Security Terms
Infrastructure and Other ServersAzure FXT Edge Filer

Data Collection

The Data Protection Addendum applies to the Product, except (1) the DPA's statement of compliance with ISO 27001, ISO 27002, and ISO 27018 does not apply, and (2) use of all data processed by Internet-based Features is governed by the Microsoft Privacy Statement (aka.ms/privacy) and not the DPA, unless other terms accompany such Internet-based Features.

SQL ServerSQL Server