Redigeeri

Privacy and personal data in Intune

Microsoft Intune operates as a data processor on behalf of the customer as necessary to provide customers with the requested service as set forth in the Microsoft Online Services Terms (OST). Personal data is provided directly through Customer Administrator use of Intune through the Azure portal or Microsoft Intune admin center, or from customer devices when enrolled for management. Personal data is also collected at third-party services per the customer's instructions such as setting up Apple Volume Purchasing Program. Customers can receive, transmit, and store data on devices managed by Intune. Personal data is processed and stored within the audited compliance boundary of the Intune service under the technical security measures assured through Microsoft Online Services Terms (OST).

To help Intune admins understand how your data's privacy is protected, this article explains how Intune collects, stores, retains, processes, secures, shares, audits, and exports personal data. It also covers how to review, correct, and delete your personal data.

Microsoft Intune doesn't use any personal data collected as part of providing the service for profiling, advertising, or marketing purposes.

Note

If you're interested in viewing or deleting personal data, see the Azure Data Subject Requests for the GDPR article. If you're looking for general info about GDPR, see the GDPR section of the Service Trust portal.

Compliance certifications

Intune is covered under several compliance certifications, and regulatory standards. The following table provides a sample of the key certifications that are covered:

Certification or Standard Description Applicability
GDPR EU General Data Protection Regulation for data privacy European Union
ISO 27001 International standard for information security management Global
HIPAA U.S. Health Insurance Portability and Accountability Act United States
SOC 2 Type 2 Service Organization Controls for data security Global

Note

Microsoft Intune helps your organization meet regulatory compliance standards. Intune supports additional certifications, such as ISO 22301, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 27701, SOC 1 Type 2, SOC 3, and WCAG.

For a complete list, see Microsoft compliance offerings.

Your company terms and conditions

In addition to the Microsoft Privacy Statement, you can include privacy statements in your company's terms and conditions for end users. Such privacy statements can include information about the usage and privacy of the end user's personal data.

You can display your company's terms and conditions in the Intune Company Portal app. This way, users can review the terms and conditions, including the privacy statement, before they enroll in Intune and access company assets and data.

Next steps

Find out more about how Intune collects, stores and processes, and shares personal data.