About SSPA

What is the Supplier Security and Privacy Assurance (SSPA) Program?

The Supplier Security and Privacy Assurance (SSPA) Program delivers Microsoft's data processing instructions, through the Microsoft Supplier Data Protection Requirements (DPR), to suppliers working with Personal Data and/or Microsoft Confidential Data.

SSPA drives compliance to these requirements through an annual compliance cycle; for new suppliers, work cannot start until this is complete. If a supplier is processing Personal Data and/or Microsoft Confidential Data, they will partner with their business sponsor to enroll in the SSPA Program. Suppliers may also be selected to provide independent assurance by completing an assessment against the DPR.

When is a supplier in scope for SSPA?

The scope of the Supplier Security and Privacy Assurance Program covers all suppliers globally that process Personal Data or Microsoft Confidential Data in connection with that supplier’s performance (e.g., provision of services, software licenses, cloud services), under the terms of its contract with Microsoft (e.g., Purchase Order terms, Master agreement) (“Perform”, “Performing” or “Performance”).

For definitions and examples of Personal Data and/or Microsoft Confidential Data, visit the Definitions section of the Supplier Data Protection Requirements (DPR), located below on this page. These examples are intended to serve as a guide. Use both the definitions and examples to determine what data is in-scope for SSPA management.


SSPA Program Guide, Supplier Data Protection Requirements (DPR), and Preferred Assessors List

Learn more about the SSPA Program through the Program Guide and explore the DPR to understand requirements for Personal Data and/or Microsoft Confidential Data. The current versions are available below in multiple languages, these documents are refreshed annually in November. We will be reducing the language support to 6 languages: English, French, Simplified Chinese, Japanese, Korean, and Spanish. Suppliers may use their own in-country translation service or utilize online translation tools.

 

Need help? Search the FAQs for answers to common questions, or if you can’t find what you’re looking for, contact support to receive assistance.

|

|

If a privacy or security incident occurs, suppliers must inform Microsoft as detailed in the Data Protection Requirements (DPR).

 

The incident can be reported by emailing Supplier Incident Report (suppir@microsoft.com).


Resources