
Microsoft and GDPR
CertReports found no public GDPR evidence for Microsoft as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Scope
- JB
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Microsoft: Inactive | Live pagesha256 8afd131274 |
- Kind
- listing
- Issued or listed
- 12 Aug 2016
- Scope
- Microsoft collects data from Microsoft product users and employees, external staff, candidates and guests through interactions with them and through their interactions with Microsoft products, in accordance with the Microsoft Privacy Statement (for Microsoft product users) and the Microsoft Global Data Privacy Notice for Employees, External Staff, Candidates and Guests. The personal data we process related to product users is provided by data subjects directly, and we get some of it by collecting data about interactions, use, and experiences with our products. The data we collect depends on the context of interactions with Microsoft and the choices users make, including privacy settings and the products and features used. We also obtain data about users from third parties. Microsoft uses the data we collect to provide rich, interactive experiences. In particular, we use data to provide our products, which includes updating, securing, and troubleshooting, as well as providing support. Microsoft processes data to improve and develop our products, personalize our products and make recommendations, and advertise and market to users, which includes sending promotional communications, targeting advertising, and presenting relevant offers. We also use the data to operate our business, which includes analyzing our performance, meeting our legal obligations, developing our workforce and doing research. The personal data Microsoft processes related to employees, external staff, candidates and guests is processed to administer the employment contract, offer letter or other commitments we have made to the individual, and for other overriding and legitimate business purposes, legally required purposes, and other uses where permissible and in accordance with applicable laws and consultation requirements, as further detailed in the Microsoft Global Data Privacy Notice for Employees, External Staff, Candidates and Guests. Microsoft data processing also includes sharing data, when it is required to provide the service or carry out the transactions requested. We share personal data with consent or to complete any transaction or provide any product data subjects have requested or authorized. We also share data with Microsoft-controlled affiliates and subsidiaries; with vendors working on our behalf; when required by law or to respond to legal process; to protect our customers; to protect lives; to maintain the security of our products; and to protect the rights and property of Microsoft and its customers. All U.S. subsidiaries using the Microsoft brand name are covered entities, as well as those subsidiaries listed above, which use different names. Certain Microsoft U.S. entities continue to maintain their own DPF certification, including LinkedIn Corporation and GitHub.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Microsoft Corporation: Inactive | Live pagesha256 c92d6b0268 |
- Kind
- listing
- Issued or listed
- 25 Nov 2016
- Scope
- Xandr provides an advertising technology platform that allows websites, apps and other internet-connected properties to generate revenue by showing advertisements to their users, and allows marketers and other advertisers to show advertisements to individuals online who may be interested in their products or services. The platform is designed to enable these advertising purposes through the use of non-personally identifiable information, which includes such things as browser type, cookie id, IP address, device identifiers, web pages or apps visited or used, date and time that web pages or apps were visited or used. The platform serves clients and delivers advertising globally. Xandr provides tools that enable buyers and sellers of online advertising to communicate and transact with each other using personal business contact information about themselves and each other which they provide. Xandr uses personal business contact information to market to business clients globally. Xandr may share non-personally identifiable information with partners and service providers for the purpose of operating, managing, maintaining, or enhancing Xandr’s services, including for the safety and security of the platform and the online industry, or as required by law.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Xandr Inc.: Inactive | Live pagesha256 562e605b98 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Microsoft GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Cloud and hosting category) whose GDPR row is verified or vendor-stated, ranked by similarity.