SSPA: Supplier Security & Privacy Assurance Program
Sets privacy and security requirements for Microsoft suppliers and drives compliance to these requirements.
What is the Supplier Security and Privacy Assurance (SSPA) Program?
The Supplier Security and Privacy Assurance (SSPA) Program delivers Microsoft's data processing instructions, through the Microsoft Supplier Data Protection Requirements (DPR), to suppliers working with Personal Data and/or Microsoft Confidential Data.
SSPA drives compliance to these requirements through an annual compliance cycle; for new suppliers, work cannot start until this is complete. If a supplier is processing Personal Data and/or Microsoft Confidential Data, they will partner with their business sponsor to enroll in the SSPA Program. Suppliers may also be selected to provide independent assurance by completing an assessment against the DPR.
When is a supplier in scope for SSPA?
The scope of the Supplier Security and Privacy Assurance Program covers all suppliers globally that process Personal Data or Microsoft Confidential Data in connection with that supplier’s performance (e.g., provision of services, software licenses, cloud services), under the terms of its contract with Microsoft (e.g., Purchase Order terms, Master agreement) (“Perform”, “Performing” or “Performance”).
For definitions and examples of Personal Data and/or Microsoft Confidential Data, visit the Definitions section of the Supplier Data Protection Requirements (DPR), located below on this page. These examples are intended to serve as a guide. Use both the definitions and examples to determine what data is in-scope for SSPA management.
FAQs
Suppliers are a Data Subprocessor when Microsoft is the Data Processor, and the Customer is the Data Controller.
Subprocessors who process restricted and highly protected end-user personal data will need additional compliance requirements like the Independent Assessment (a third-party validation of their DPR). This occurs most often within or supporting Microsoft Enterprise or Commercial products and services or within large organizations like education.
Engagements with 3rd party suppliers for any of the Microsoft products or services with access to the protected end-user data are covered under the Microsoft Online Services, Commercial Support and Microsoft Industry Solutions, Microsoft FastTrack, PlayFab, or Minecraft EDU.
Resources
Privacy Fundamentals 101 training
We need data to innovate. Customers will only give us their data if they trust us. That’s why we have to get privacy and security right.
Privacy at Microsoft
It’s our mission to empower every person and every organization on the planet to achieve more. We are doing this by building an intelligent cloud, reinventing productivity and business processes and making computing more personal. In all of this, we will maintain the timeless value of privacy and preserve the ability for you to control your data.
Microsoft Trust Center
The future is in the Trusted Cloud. We built our Trusted Cloud on four foundational principles: security, privacy, compliance, and transparency.
Microsoft Privacy Statement
Your privacy is important to us. This privacy statement explains the personal data Microsoft processes, how Microsoft processes it, and for what purposes.