As an Office 365 customer you have entrusted Microsoft to help protect your data. Microsoft values this trust and cares deeply about the privacy and security of your data. Microsoft strives to take a leadership role in industry privacy, security and compliance practices by following these trust principles.
Office 365 Trust Principles
Your Privacy Matters
We respect the privacy of your data
Leadership in Transparency
You know ‘where’ data resides, ‘who’ can access it and ‘what’ we do with it
Independently Verified
Compliance with World Class Industry standards verified by 3rd parties
Relentless on Security
Excellence in Cutting edge security practices
To gain your trust, we have proactively answered a broad range of security and privacy questions the Cloud Security Alliance suggests every customer should ask of their cloud service provider. The products that are covered by the trust center content are mentioned here.
Your Privacy Matters
We respect the privacy of your data
- No Advertising: Office 365 does not build advertising products out of Customer Data. We don’t scan your email or documents for building analytics, data mining, advertising, or improving the service.
- No Mingling: Office 365 always allows you to keep your Customer Data separate from consumer services.
- Data Portability: Office 365 Customer Data belongs to the customer. Customers can remove their data whenever they choose to. Learn more about data portability here.
- Learn more about what we do to help protect the privacy of your data here.
Leadership in Transparency
As an Office 365 customer, you know ‘where’ your data resides, ‘who’ can access it and ‘what’ we do with it
- Where: You know where Office 365’s major data centers and personnel are located and the logic used to determine where your data is stored.
- Who & What: We offer clear information on who can access your Office 365 Customer Data and under what circumstances they access it.
- How: Microsoft notifies you, if requested about changes in Office 365 data center locations.
- Learn more about how Microsoft is committed to help you comply with your regulatory requirements here.
Independently Verified
Compliance with World Class Industry standards verified by 3rd parties
- Certified for ISO 27001: ISO27001 is one of the best security benchmarks available across the world. Office 365 is the first major business productivity public cloud service to have implemented the rigorous set of physical, logical, process and management controls defined by ISO 27001.
- EU Model Clauses: In addition to EU Safe Harbor, Office 365 is the first major business productivity public cloud service provider willing to sign the standard contractual clauses created by the European Union (called the “EU Model Clauses”) with all customers. EU Model Clauses address international transfer of data. Visit here to get a signed copy of the EU Model Clauses from Microsoft.
- Data Processing Agreement. Microsoft offers a comprehensive standard Data Processing Agreement (DPA) to all customers. DPA addresses privacy, security and handling of Customer Data. Our standard Data Processing Agreement enables customers to comply with their local regulations. Visit here to get a signed copy of the DPA.
- Learn more about how Office 365 meets world class industry standards here.
Relentless on Security
Excellence in cutting edge security practices
- Deep Experience. We have developed our practices and policies as a result of over 15 years of experience in providing security for online data.
- Secure Development Lifecycle. Microsoft’s Secure Development Lifecycle ensures security and privacy is incorporated by design from software development to service operations.
- 5 Layers of Security. Data is secured in 5 different layers – Data, Application, Host, Network and Physical.
- Proactive Monitoring. We proactively monitor to identify potential unknown threats by predicting malicious behavior and monitoring for irregular events that may indicate threats.
- Access Restriction. Access to production servers is restricted to a small list of operations personnel.
- Learn more about our security practices here .

