Share via

Compliance perspective on the usage of Azure open AI

2026-05-05T20:03:52.3+00:00
  • Could you provide documentation confirming GDPR compliance and relevant safeguards?
  • Does our existing Microsoft DPA cover Azure OpenAI Service, or is a separate agreement required?
Azure OpenAI in Foundry Models

Answer accepted by question author

  1. Karnam Venkata Rajeswari 2,800 Reputation points Microsoft External Staff Moderator
    2026-05-05T20:33:10.54+00:00

    Hello Sreerenjith,

    Welcome to Microsoft Q&A .Thank you for reaching out to us.

    Azure OpenAI Service is governed under the Products and Services Data Protection Addendum (DPA), which defines the contractual framework for processing and protecting customer data.

    • The DPA automatically applies to Azure services, including Azure OpenAI
    • No separate agreement is required specifically for Azure OpenAI Service
    • The DPA covers:
      • Processing of Customer Data and Personal Data
      • Security and confidentiality commitments
      • Sub-processor governance
      • Support for data subject rights under GDPR

    As for GDPR roles

    • Service provider operates as a Data Processor
    • Customer organization operates as a Data Controller, responsible for:
      • Defining lawful basis of processing
      • Controlling data usage and classification
      • Ensuring compliance within applications

    Azure OpenAI operates within an enterprise compliance framework that supports GDPR-aligned deployments through strong technical and organizational controls.

    Key safeguards include

    1. Data usage restrictions - Prompts, outputs, embeddings, and fine-tuning data are not used to train foundation models without explicit permission.
    2. Data isolation - Customer data is logically isolated within the service architecture
    3. Encryption
      1. Data in transit: TLS encryption
      2. Data at rest: Encrypted using platform-managed or customer-managed keys
    4. Compliance standards - Alignment with ISO 27001, ISO 27701, and SOC frameworks
    5. Data residency - Deployment can be aligned to supported regions to address data residency requirements
    6. Controlled monitoring - Limited data processing may occur for abuse detection under strict access controls

    The following references might be helpful , please check them out

     

    Thank you

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.