Microsoft Professional Services data protection white paper

Overview of how Microsoft Services addresses security and privacy challenges.

Data protection white paper

Subprocessors and data privacy white paper

How Microsoft handles data in the cloud.

Subprocessors and data privacy white paper

Microsoft Professional Services Data Protection Addendum (MPSDPA)

Data protection terms for Microsoft Unified, Premier and Consulting customers.

MPSDPA

Microsoft Professional Services Limited Data Protection Addendum (MPSLDPA)

Data protection terms for preview, pilot, beta, and limited release offers. 

MPSLDPA

Online Services Terms (OST)

Terms for how you can use an online service are defined in the Volume Licensing Online Services Terms (OST) document and program agreement.

OST

Microsoft Online Services Data Protection Addendum

Data protection terms for Online Services.

Microsoft Online Services Data Protection Addendum

Resources that require authentication

Customers must login to the Microsoft Service Trust Portal with their Microsoft Account (MSA) for access. 

Standard responses to requests for information

Responses to common questions and inquiries. 

Standard responses to requests for information

Microsoft security program policy

Corporate-wide security policy.

View policy

ISO/IEC 27001:2013 & 27018 assessment report

Third-party independent audit assessment report verifying our compliance with ISO standards - 27001 and 27018 requirements.

View report

Microsoft Global Services Center IGD ISO/IEC 27001:2013 assessment report

Third-party independent audit assessment report verifying our compliance with ISO standards - 27001 and 27018 requirements for Hyderabad, Bengaluru, Charlotte, Warsaw, and Bucharest. 

View report

Microsoft Professional Services data ​access summary

Overview of different means by which Microsoft personnel may access customers' data (e.g. data transfer, remote access).

Data access summary

Microsoft support and consulting data classification summary

Overview of data classification definitions used internally by Microsoft Services for the protection of data.

Data classification summary

Handling customer content Q&A brief

Provides critical information on using data transfer and management (DTM) to ensure customers' sensitive or highly confidential data or content is protected at the right level.

Handling customer content Q&A brief

Microsoft Professional Services HITRUST control mapping

Control mappings focused on HITRUST obligations. The key links between Microsoft Services UCF and HITRUST are its mappings to ISO 27001, 27002, GDPR, and HIPAA.

HITRUST control mapping