About SSPA

What is the Supplier Security and Privacy Assurance (SSPA) Program?

The Supplier Security and Privacy Assurance (SSPA) Program delivers Microsoft's data processing instructions, through the Microsoft Supplier Data Protection Requirements (DPR), to suppliers working with Personal Data and/or Microsoft Confidential Data.

SSPA drives compliance to these requirements through an annual compliance cycle; for new suppliers, work cannot start until this is complete. If a supplier is processing Personal Data and/or Microsoft Confidential Data, they will partner with their business sponsor to enroll in the SSPA Program. Suppliers may also be selected to provide independent assurance by completing an assessment against the DPR.

When is a supplier in scope for SSPA?

The scope of the Supplier Security and Privacy Assurance Program covers all suppliers globally that process Personal Data or Microsoft Confidential Data in connection with that supplier’s performance (e.g., provision of services, software licenses, cloud services), under the terms of its contract with Microsoft (e.g., Purchase Order terms, Master agreement) (“Perform”, “Performing” or “Performance”).

For definitions and examples of Personal Data and/or Microsoft Confidential Data, visit the Definitions section of the Supplier Data Protection Requirements (DPR), located below on this page. These examples are intended to serve as a guide. Use both the definitions and examples to determine what data is in-scope for SSPA management.


SSPA Program Guide, Supplier Data Protection Requirements (DPR), and Preferred Assessors List

Learn more about the SSPA Program through the Program Guide and explore the DPR to understand requirements for Personal Data and/or Microsoft Confidential Data. The current versions are available below in multiple languages, these documents are refreshed annually in November. We will be reducing the language support to 6 languages: English, French, Simplified Chinese, Japanese, Korean, and Spanish. Suppliers may use their own in-country translation service or utilize online translation tools.

 

Need help? Search the FAQs for answers to common questions, or if you can’t find what you’re looking for, contact support to receive assistance.

|

|

Suppliers are a Data Subprocessor when Microsoft is the Data Processor, and the Customer is the Data Controller.

 

Subprocessors who process restricted and highly protected end-user personal data will need additional compliance requirements like the Independent Assessment (a third-party validation of their DPR). This occurs most often within or supporting Microsoft Enterprise or Commercial products and services or within large organizations like education.

Engagements with 3rd party suppliers for any of the Microsoft products or services with access to the protected end-user data are covered under the Microsoft Online Services, Commercial Support and Microsoft Industry Solutions, Microsoft FastTrack, PlayFab, or Minecraft EDU.


Resources