StackLégal

Collaboration

GDPR Microsoft 365

In an indie stack, Microsoft 365 is used for Microsoft messaging, documents, and identity. Entity cited: Microsoft Corporation et Microsoft Ireland Operations Limited. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA Microsoft 365

Yes. Microsoft Products and Services Data Protection Addendum (document dated 22 May 2026 on the version consulted).

Read the DPA

Stated role

For personal data falling under the GDPR, the customer is controller and Microsoft is processor, or sub-processor if the customer is itself a processor. Microsoft also accepts independent-controller responsibilities for certain operational processing.

Personal data

Personal data the customer chooses to include, basic data (name, address, email, phone), authentication data (identifier, password), IP addresses and identifiers in cookies or similar technologies, location data, device identification, and internet-activity data.

Sub-processors of Microsoft 365

The Trust Center page points to the list of sub-processors of the online services covered by the DPA.

List published by the vendor

Transfers outside the EU

Hosting / location

For the Core Online Services, Microsoft stores Customer Data at rest in a geographic area provided for in the Product Terms. For EU Data Boundary services, storage and processing at rest in the EU and the EFTA. Microsoft may also transfer to the United States or any country where Microsoft or its sub-processors operate.

EU–United States Data Privacy Framework

Microsoft Corporation is registered. Exact EU-U.S. Data Privacy Framework status: Active - Re-certification under Review.

Data Privacy Framework sheet

Cookies

not disclosed

Typical use, written by StackLégal and not by the vendor: Microsoft messaging, documents, and identity.

History

Last update: October 4, 2026.

  1. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 4, 2026.

Frequently asked questions

Is Microsoft 365 a processor within the meaning of the GDPR?

For personal data falling under the GDPR, the customer is controller and Microsoft is processor, or sub-processor if the customer is itself a processor. Microsoft also accepts independent-controller responsibilities for certain operational processing.

What DPA does Microsoft 365 publish?

Yes. Microsoft Products and Services Data Protection Addendum (document dated 22 May 2026 on the version consulted). https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA

Which further sub-processors does Microsoft 365 publish?

The Trust Center page points to the list of sub-processors of the online services covered by the DPA. https://www.microsoft.com/en-us/trust-center/privacy/data-access

Where does Microsoft 365 state that it processes data, including outside the EU?

For the Core Online Services, Microsoft stores Customer Data at rest in a geographic area provided for in the Product Terms. For EU Data Boundary services, storage and processing at rest in the EU and the EFTA. Microsoft may also transfer to the United States or any country where Microsoft or its sub-processors operate.

Is Microsoft 365 registered under the EU–United States Data Privacy Framework?

Microsoft Corporation is registered. Exact EU-U.S. Data Privacy Framework status: Active - Re-certification under Review. https://www.dataprivacyframework.gov/participant/6474

Which personal data does Microsoft 365 mention?

Personal data the customer chooses to include, basic data (name, address, email, phone), authentication data (identifier, password), IP addresses and identifiers in cookies or similar technologies, location data, device identification, and internet-activity data.

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets collaboration

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.