Privacy for Microsoft 365 for enterprise

When an organization is considering relying on Microsoft 365 for communication and collaboration, privacy is something that needs to be addressed at every level. The topics we discuss in this article should address your privacy concerns when planning your Microsoft 365 implementation, or at any point during Microsoft 365 usage.

What personal data does Microsoft 365 collect and for what purposes does Microsoft 365 use this data?

Microsoft processes the personal data in Microsoft 365 to deliver the services and for the purposes outlined in the Product Terms and the Microsoft Online Services Data Protection Addendum (DPA). Microsoft 365, as an integrated set of cloud-based services, processes various types of personal data as part of delivering the services.

To the extent Microsoft 365 processes personal data with Microsoft's legitimate business operations, Microsoft is an independent data controller for such use and is responsible for complying with all applicable laws and controller obligations.

Our customers are controllers for the data provided to Microsoft, as set forth in the Product Terms and the Microsoft Online Services Data Protection Addendum (DPA), and they determine legal basis of processing. Microsoft, in turn, processes the data on the customers' instructions, as a processor.

What third parties have access to personal data?

Microsoft won't disclose personal data except:

  1. as the customer directs (including as required to complete phone calls);
  2. as described in the Online Service Terms (such as the use of authorized subcontractors to provide certain components of services);
  3. as required by law.

If law enforcement contacts Microsoft with a demand, Microsoft will attempt to redirect the law enforcement agency to request that personal data directly from the customer. If compelled to disclose personal data to law enforcement, Microsoft will promptly notify the customer and provide a copy of the demand unless legally prohibited from doing so. For more information about data that we disclose in response to requests from law enforcement and other government agencies, please see our Law Enforcement Requests Report.

Where does Microsoft 365 transfer and store personal data?

Personal data is transferred and stored as set forth in the Online Service Terms, the Product Terms and the Microsoft Online Services Data Protection Addendum (DPA).

We have information on the Microsoft 365 Data Residency overview and definitions if you need to learn more.

How long does Microsoft 365 retain personal data?

Microsoft 365 retains your data for the minimum amount of time necessary to deliver the service.

Because this data is required to provide the service, this typically means that we retain personal data until the user stops using Microsoft 365, or until the user deletes personal data. If a user (or an administrator on the user's behalf) deletes the data, Microsoft will ensure that all copies of the personal data are deleted within 30 days.

If a company terminates service with Microsoft, corresponding personal data will all be deleted between 90 and 180 days of service termination.

In some circumstances, local laws require that Microsoft 365 retains telephone records (for billing purposes) for a specific period of time, in those circumstances Microsoft 365 follows the law for each region.

Additionally, if a company requests that Microsoft 365 holds a user's data to support a legal obligation, Microsoft will respect the company administrator's request.

If Microsoft 365 processes any personal data based on consent, you may have the right to withdraw your consent at any time. You should direct your request to withdraw consent to your administrator, where your administrator is the controller of the personal data at issue.

Contact Details of Microsoft's Data Protection Officer

If you have a privacy concern, complaint or question for the Microsoft Chief Privacy Officer and EU Data Protection Officer, contact us by using our web form. Our EU Data Protection Officer is located at Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Telephone: +353 1 706 3117. You can also raise a concern or lodge a complaint with a data protection authority or other official with jurisdiction.

Windows Privacy Compliance Guide

Understand how privacy works in Microsoft Viva

Microsoft Teams privacy

Overview of privacy controls for Microsoft 365 Apps for enterprise

Online Service Terms

Product Terms

Microsoft Online Services Data Protection Addendum (DPA)