Azure OpenAI (EU Data Zone)
Microsoft Ireland Operations Ltd. · IE · Last reviewed: 2026-08-24
Data Protection Contracts
100/100Microsoft provides an Article 28 processing agreement; the full text has been reviewed. The sub-processor regime is strict: six months' notice generally, 30 days for AI sub-processors with an option to disable them up to six months after the notice.
jaSource: Microsoft Products and Services Data Protection Addendum, Stand 22.05.2026, Abschnitt 'Notice and Controls on use of Subprocessors' — Microsoft benachrichtigt über jeden neuen Subprozessor 'at least 6 months in advance of providing that Subprocessor with access to Customer Data or for subprocessors that support artificial intelligence functionality, 30 days' notice with the ability to disable use of that subprocessor until at least 6 months after notice'. Weisungsbindung, Vertraulichkeit und Betroffenenrechte im Abschnitt 'Processing of Personal Data; GDPR'; Sicherheitsmaßnahmen in Appendix A; EU Data Boundary im Abschnitt 'Data Transfers and Location' verankert. (reviewed 2026-08-24)
The data processing agreement incorporates the 2021 EU Standard Contractual Clauses for every transfer out of the European Economic Area, the United Kingdom and Switzerland. An additional safeguards addendum goes further: Microsoft undertakes to challenge government disclosure orders, to disclose only the minimum necessary if compelled, and to indemnify data subjects for damage caused by a disclosure that breaches Chapter V of the General Data Protection Regulation.
jaSource: Microsoft Products and Services Data Protection Addendum, Stand 22.05.2026, Definition '2021 Standard Contractual Clauses' (Beschluss 2021/914/EG vom 04.06.2021, Modul Verarbeiter-zu-Verarbeiter zwischen Microsoft Ireland Operations Limited und Microsoft Corporation); Abschnitt 'Data Transfer' — alle Übermittlungen aus EWR/UK/Schweiz unterliegen den SCCs, Übermittlungen aus dem UK zusätzlich dem IDTA; Sicherheitsmaßnahmen nach Anhang II der SCCs; Appendix C 'Additional Safeguards Addendum' — Anfechtungspflicht, Grundsatz der Minimaloffenlegung und Entschädigung Betroffener bei Verstößen gegen Kapitel V DSGVO. (reviewed 2026-08-24)
The data processing agreement commits to a stated notification deadline: security incidents are reported "promptly and without undue delay and, in any event, within 72 hours". Notification includes investigating the incident, providing detailed information about it, and taking reasonable steps to limit the damage; Microsoft additionally assists with the customer's own notification to the supervisory authority under Article 33 GDPR. The 72-hour chain towards our own customers can therefore be passed through.
jaSource: Microsoft Products and Services Data Protection Addendum, Stand 22.05.2026, Abschnitt 'Security Incident Notification' — 'Microsoft will promptly and without undue delay (1) notify Customer of the Security Incident; (2) investigate the Security Incident and provide Customer with detailed information about the Security Incident; (3) take reasonable steps to mitigate the effects and to minimize any damage'; Unterstützung bei der Meldung nach Art. 33 DSGVO ebendort. Die bezifferte Frist steht in Appendix A – Security Measures, 'Information Security Incident Management / Incident Response Process': 'For each security breach that is a Security Incident, notification by Microsoft … will be made without undue delay and, in any event, within 72 hours.' (reviewed 2026-08-24)
Data Residency & Sovereignty
50/100The EU data boundary is anchored in the data processing agreement: for the services it covers, storage and processing take place within the EU or EFTA. Our resource is located in Sweden and the deployment type was confirmed per model as a Data Zone deployment. That deployment type binds processing to the EU as a whole rather than to Sweden alone — requests may be processed in any EU Member State. Data at rest remains in the chosen geography.
jaSource: Microsoft Products and Services DPA, Stand 22.05.2026 + Microsoft Learn, 'Data, privacy, and security for Foundry Models sold by Azure' (Stand 18.05.2026) + Bereitstellungsdialog je Modell, bestätigt 2026-08-04, DPA, Abschnitt 'Data Transfers and Location' — 'For EU Data Boundary Services, Microsoft will store and process Customer Data, Personal Data, and store Professional Services Data at rest within the European Union and the European Free Trade Association (EFTA) as set forth in the Product Terms.' Microsoft Learn: 'For any deployment type labeled as DataZone, prompts and responses may be processed in any geography within the specified data zone … If you create a DataZone deployment in a Foundry resource located in a European Union Member Nation, prompts and responses may be processed in that or any other European Union Member Nation'; ruhende Daten einschließlich des Missbrauchsdatenspeichers verbleiben in der vom Kunden bestimmten Geografie. (reviewed 2026-08-24)
Microsoft maintains a public sub-processor list and announces additions six months in advance, or 30 days for AI sub-processors, with the option to disable them up to six months after the announcement. The list is not confined to the EU, however: in the AI sub-processor category OpenAI is listed with 'Worldwide' as its processing location, Anthropic and GitHub with the United States. Those entries are attributed broadly to 'Microsoft Online Services', whereas the EU data boundary is anchored per product in the Product Terms.
teilweiseSource: Microsoft Online Services Subprocessors, Stand 23.06.2026 + Microsoft Products and Services Data Protection Addendum, Stand 22.05.2026, Subprozessorenliste, Abschnitt 3 'Artificial Intelligence Subprocessors' — OpenAI OpCo, LLC mit Verarbeitungsort 'Worldwide', Anthropic PBC und GitHub, Inc. mit 'United States', Fireworks AI, Inc. mit Kanada, Deutschland, Island, Japan und den USA, jeweils zugeordnet zu 'Microsoft Online Services'. DPA, Abschnitt 'Notice and Controls on use of Subprocessors' (Ankündigungsfristen und Abschaltrecht) sowie die EU-Data-Boundary-Zusage, die Speicherung und Verarbeitung für die erfassten Dienste an EU und EFTA bindet. (reviewed 2026-08-24)
The contracting entity is Microsoft Ireland Operations Ltd., registered in Ireland, with Microsoft Corporation in the United States as its parent. The company is therefore indirectly subject to US access law; the EU data boundary does not change the ownership structure.
neinSource: Microsoft Customer Agreement, Kanal Individual, geprüft 2026-07-23, Vertragspartei Microsoft Ireland Operations Ltd. (IE), Konzernmutter Microsoft Corporation (US) (reviewed 2026-07-23)
Data Use
67/100There is no zero-retention commitment: prompts and completions may be stored and reviewed by Microsoft employees for abuse detection. This does not affect every request, however, but only those the content classifier rates as harmful or that form part of a suspicious usage pattern. Review of these is automated by default and involves no storage; only where automated review does not reach sufficient confidence is human review added, and only for that is data stored. Access requires secure workstations and case-by-case approval, the store sits in the chosen region, and for deployments in the European Economic Area the reviewing employees are located there as well. The documentation no longer states a retention period.
teilweiseSource: Microsoft Learn, 'Foundry Models sold by Azure abuse monitoring' (Stand 13.05.2026) + 'Data, privacy, and security for Foundry Models sold by Azure' (Stand 18.05.2026), beide abgerufen 24.08.2026, Abuse monitoring, Abschnitt 'Review and Decision' — nur 'Prompts and completions that are flagged through content classification and/or identified as part of a potentially abusive pattern of use' gelangen in die Prüfung; zur automatisierten Prüfung: 'prompts and completions that undergo such review are not stored by the abuse monitoring system or used to train the AI model or other systems'; menschliche Sichtung nur, 'when automated review doesn't meet applicable confidence thresholds', über Secure Access Workstations mit Just-In-Time-Freigabe; 'For Models sold by Azure deployed in the European Economic Area, the authorized Microsoft employees are located in the European Economic Area.' Data privacy, Abschnitt 'Preventing abuse' — Speicherort des Missbrauchsdatenspeichers in der Geografie der Kundenressource. Keine Angabe einer Aufbewahrungsfrist mehr; die früher dokumentierten 30 Tage stehen in der aktuellen Fassung nicht. (reviewed 2026-08-24)
The Universal License Terms expressly commit that Microsoft will not use customer data to train generative AI foundation models except on the customer's documented instructions. Output content counts as customer data and the rights to it remain with the customer.
jaSource: Microsoft Universal License Terms for Online Services, geprüft 2026-07-23, GenAI-Sektion: Trainingsausschluss und Zuordnung der Ausgabeinhalte (reviewed 2026-07-23)
The training exclusion applies contractually with no separate opt-out. For storage and human review in abuse detection there is an opt-out procedure, 'modified abuse monitoring'. It is open only to managed customers on an Enterprise Agreement or MCA-E, requires a documented reason grounded in a recognised compliance framework or a contractual obligation, and is approved case by case. It cannot be applied for on our contract type; the restriction was rechecked on 24 August 2026 and remains unchanged.
teilweiseSource: Microsoft Learn, 'Foundry Models sold by Azure abuse monitoring' und 'Limited access to Azure OpenAI in Microsoft Foundry Models' (abgerufen 24.08.2026) + Microsoft Universal License Terms, Abuse monitoring, Abschnitt 'Modified abuse monitoring' — 'Microsoft allows customers who meet additional Limited Access eligibility criteria to apply to modify abuse monitoring'; Limited Access: Verfügbarkeit nur für von einem Microsoft-Kundenteam betreute Kunden beziehungsweise ein zulässiges Programm, Entscheidung durch das Gating- und Trust-&-Safety-Team. Trainingsausschluss vertraglich in den Universal License Terms, ohne Abwahl erforderlich. (reviewed 2026-08-24)
Certifications
75/100The data processing agreement contractually obliges Microsoft to ensure its security measures meet the requirements of ISO 27001, ISO 27002 and ISO 27018, and forbids dropping those standards without an equivalent successor. Azure OpenAI sits within the Azure compliance scope; the evidence is retrievable through the Service Trust Portal.
jaSource: Microsoft Products and Services Data Protection Addendum, Stand 22.05.2026 + Microsoft Service Trust Portal, Abschnitt 'Data Security' — 'those measures shall comply with the requirements set forth in ISO 27001, ISO 27002, and ISO 27018' sowie 'Microsoft will not eliminate ISO 27001, ISO 27002, ISO 27018 or any standard or framework in the table for Core Online Services in the Product Terms, unless it is no longer used in the industry and it is replaced with a successor (if any)'. Vertragliche Pflicht, nicht bloße Selbstauskunft — gleiche Belegart wie beim CDPA von gcp-vertex. (reviewed 2026-08-24)
Azure OpenAI falls within the audit scope of the SOC 1, SOC 2 and SOC 3 reports for Azure, which are retrievable through the Service Trust Portal. We have not, however, reviewed a scope overview naming the service explicitly, and no BSI C5 attestation covering Azure OpenAI has been evidenced to us.
teilweiseSource: Microsoft Service Trust Portal, Azure-Compliance-Geltungsbereich (geprüft 23.07.2026), SOC 1, SOC 2 und SOC 3 für Azure über das Service Trust Portal; kein geprüfter Geltungsbereichsnachweis mit namentlicher Nennung von Azure OpenAI und kein C5-Testat vorgelegt. Gleiche Kalibrierung wie bei aws-bedrock und gcp-vertex, die für denselben Nachweisstand ebenfalls 'Teilweise' erhalten. (reviewed 2026-08-24)
AI Act Readiness
100/100Pure inference and hosting provider for third-party models: the Article 53 documentation duty under the AI Act binds the provider of the GPAI model, not the operator of the inference. Azure OpenAI serves exclusively models from OpenAI, so the duty sits there. Microsoft does publish its own transparency note for the service, but that is responsible-AI documentation, not Article 53 model documentation.
nicht_anwendbarSource: Verordnung (EU) 2024/1689 (KI-VO) + Transparenzhinweis für Azure OpenAI in Microsoft Foundry Models (abgerufen 24.08.2026), Art. 53 Abs. 1 i. V. m. Art. 3 Nr. 3 KI-VO — Pflichten des Anbieters eines GPAI-Modells. Der Transparenzhinweis dokumentiert Zweck, Fähigkeiten, Grenzen und Guardrails des Dienstes und nimmt an keiner Stelle auf Art. 53 KI-VO Bezug. Modellkatalog des Dienstes: ausschließlich OpenAI-Modelle (GPT- und o-Serie, Embeddings). (reviewed 2026-08-24)
Both Microsoft and OpenAI appear on the signatory list of the EU General-Purpose AI Code of Practice. OpenAI is the one that counts here: the Code addresses providers of general-purpose AI models, and Azure OpenAI serves OpenAI's models. Microsoft's own signature covers Microsoft's own models, not the ones offered here.
jaSource: EU-Signatarliste GPAI Code of Practice — 00_Uebergreifend/EU_GPAI-CoP-Signatarliste_2026-07-27.pdf, Signatarliste-Einträge Microsoft UND OpenAI (00_Uebergreifend/EU_GPAI-CoP-Signatarliste_2026-07-27.pdf, Abschnitt 'Signatories of the code of practice'). Der Kodex adressiert laut Seite 1 'providers of general-purpose AI models' — bei einem Hosting-Angebot ist das der Modellanbieter, nicht der Hoster. Dieselbe Logik, die bei den reinen Inferenz-Anbietern zu 'nicht_anwendbar' führt. (reviewed 2026-08-24)
Contract Quality & Transparency
83/100The customer agreement, data processing agreement, product terms and the code of conduct for AI services are publicly available without registration and have been reviewed in full.
jaSource: Microsoft Customer Agreement, Products and Services DPA, Universal License Terms, Enterprise AI Services Code of Conduct, Öffentliche Abrufbarkeit ohne Anmeldung, Volltextprüfung 2026-07-23 (reviewed 2026-07-23)
Microsoft commits to 99.9 % monthly availability for Foundry Models — the product family under which Azure OpenAI is listed — and grants graduated service credits if it falls short. The service level agreement is bindingly incorporated through the customer agreement. Credits apply only to models in the 'Sold by Azure' category; the GPT models used here fall within it, the Developer tier does not.
jaSource: Service Level Agreement for Microsoft Online Services, Stand 10.08.2026 + Microsoft Customer Agreement (abgelegt 23.07.2026), SLA, Abschnitt 'Foundry Models' — Dienstgutschrift 10 % bei einer Uptime Percentage unter 99,9 % und 25 % unter 99 %; Service Level Exception: Gutschriften nur für 'Foundry Models Sold by Azure', Developer-Tarif ausgenommen. Allgemeiner Teil: 'Claims' (Frist 60 Tage bei Microsoft Azure) und 'Service Credits are your sole and exclusive remedy'. Microsoft Customer Agreement: Gewährleistung, dass jeder Online Service dem einschlägigen SLA entspricht, SLA-Definition und Rangfolge der Vertragsdokumente. (reviewed 2026-08-24)
Liability is capped for both parties at the subscription fees paid in the twelve months before the incident, with unlimited exceptions for breaches of confidentiality, infringement of intellectual property rights, defence obligations, and wilful misconduct or gross negligence. That matches the market standard. Liability relating to customer data is expressly carved back out of those exceptions, so there is no separate higher limit for data protection damage.
teilweiseSource: Microsoft Customer Agreement, Kanal Individual (abgelegt 23.07.2026), Abschnitt 'Limitation of liability' — lit. b Deckel auf die Abonnemententgelte der zwölf Monate vor dem auslösenden Vorfall; lit. e Ausschluss mittelbarer und Folgeschäden; lit. f Ausnahmen (Vertraulichkeit, Defense of Third-Party Claims, Schutzrechte, Vorsatz und grobe Fahrlässigkeit) mit ausdrücklichem Rückausschluss 'except for all liability related to Customer Data and Professional Service Data, which will remain subject to the limitations and exclusions above'; lit. i Sonderregeln bei Anwendung deutschen Rechts. (reviewed 2026-08-24)
Do you represent Azure OpenAI (EU Data Zone) and think something is inaccurate? Write to legal@kontinent.ai. We check every report and correct verified errors with full transparency.
Report error