Hello, @Sebastian Pacheco !
Where can I find confirmation that Azure is GDPR compliant?
There isn't really a short version of this answer, unfortunately, as GDPR compliance relies on a Data Controller (you in the case of Azure) and a Processor (Azure/Microsoft in this case). This means that outside of perhaps ISO 27701 (PIMS), there isn't really a single certification you can point to. There are Azure based GDPR guides to make sure that you are in compliance as a Data Controller as well as information about how Azure is in compliance as a Processor however this is usually broken down into different scenarios.
Data Controller Compliance (you):
This depends largely on what you do with Azure so the GDPR compliance documentation and guides are what you'll need to guarantee that you are in compliance with GDPR when using Azure:
- Microsoft 365 GDPR action plan — Top priorities for your first 30 days, 90 days, and beyond
- General Data Protection Regulation Summary
- Trust Center: Safeguard individual privacy with cloud services from Microsoft
Processor Compliance (Azure/Microsoft):
Here is the definitive list of Azure, Dynamics 365, and Microsoft 365 compliance offerings (GDPR is under regional at the bottom):
https://learn.microsoft.com/en-us/compliance/regulatory/offering-home?view=o365-worldwide
Navigating to this takes us to the General Data Protection Regulation Summary where we cover things like Data Controllers (Controllers) and Processors. Under the accountability readiness checklist, you'll see that Microsoft Azure, Dynamics 365, and Power Platform services are certified to ISO 27701 (PIMS):
To support the General Data Protection Regulation (GDPR) when using Microsoft Azure, Dynamics 365, and Power Platform use the set of privacy and security controls for personal data processors:
- ISO/IEC 27701 standard for privacy management requirements
- ISO/IEC 27001 standard for security techniques requirements Microsoft Azure, Dynamics 365, and Power Platform services are certified to ISO 27701 (PIMS).
There are also several specific scenarios:
- Azure Data Subject Requests for the GDPR and CCPA
- Microsoft Azure, Dynamics 365, and Power Platform breach notification under the GDPR
- Data Protection Impact Assessments: Guidance for Data Controllers Using Microsoft Azure
Another valuable resource is the GDPR FAQ in the GDPR overview:
https://learn.microsoft.com/en-us/compliance/regulatory/gdpr#gdpr-faqs
Quick Links:
- General Data Protection Regulation Summary
- Trust Center: Safeguard individual privacy with cloud services from Microsoft
- Azure, Dynamics 365, and Microsoft 365 compliance offerings
- ISO/IEC 27701:2019: Privacy Information Management
- Microsoft 365 GDPR action plan — Top priorities for your first 30 days, 90 days, and beyond
- Blog: Protecting privacy in Microsoft Azure: GDPR, Azure Policy Updates
- Blog: Safeguard individual privacy rights under GDPR with the Microsoft intelligent cloud
- Blog: New capabilities to enable robust GDPR compliance
I hope this has been helpful! Your feedback is important so please take a moment to accept answers.
If you still have questions, please let us know what is needed in the comments so the question can be answered. Thank you for helping to improve Microsoft Q&A!