Friday, 21 August 2026
Nigeria Communications Week
E-Business

Microsoft Adopts First International Cloud Privacy Standard

Comms Week23 Feb 20150 Comments
Microsoft Adopts First International Cloud Privacy Standard
Kindly share this post

Microsoft recently made history as the first major cloud provider to adopt the world’s first international standard for cloud privacy. It’s another reason customers can move with confidence to the…


Microsoft recently made history as the first major cloud provider to adopt the world’s first international standard for cloud privacy. It’s another reason customers can move with confidence to the Microsoft Cloud.

The standard in question may seem technical, but it has important practical benefits for enterprise customers around the world, said Brad Smith, general counsel & executive vice president, Legal and Corporate Affairs, Microsoft.

According to Smith, it is known as ISO/IEC 27018, and it was developed by the International Organization for Standardization (ISO) to establish a uniform, international approach to protecting privacy for personal data stored in the cloud.

The British Standards Institute (BSI) has now independently verified that in addition to Microsoft Azure, both Office 365 and Dynamics CRM Online are aligned with the standard’s code of practice for the protection of Personally Identifiable Information (PII) in the public cloud. And similarly, Bureau Veritas has done the same for Microsoft Intune.

Why does this matter?

Smith said in a blog post that the reasons are multiple.

From the perspective of adherence to ISO 27018 assures enterprise customers that privacy will be protected in several distinct ways including you are in control of your data. Our adherence to the standard ensures that we only process personally identifiable information according to the instructions that you provide to us as our customer and You know what’s happening with your data. Adherence to the standard ensures transparency about our policies regarding the return, transfer, and deletion of personal information you store in our data centers.

“We’ll not only let you know where your data is, but if we work with other companies who need to access your data, we’ll let you know who we’re working with. In addition, if there is unauthorized access to personally identifiable information or processing equipment or facilities resulting in the loss, disclosure or alteration of this information, we’ll let you know about this,” he said.

Also, Microsoft provides strong security protection for user’s data.

Smith said, “Adherence to ISO 27018 provides a number of important security safeguards. It ensures that there are defined restrictions on how we handle personally identifiable information, including restrictions on its transmission over public networks, storage on transportable media, and proper processes for data recovery and restoration efforts. In addition, the standard ensures that all of the people, including our own employees, who process personally identifiable information must be subject to a confidentiality obligation.

“Your data won’t be used for advertising. Enterprise customers are increasingly expressing concerns about cloud service providers using their data for advertising purposes without consent. The adoption of this standard reaffirms our longstanding commitment not to use enterprise customer data for advertising purposes.

“We inform you about government access to data. The standard requires that law enforcement requests for disclosure of personally identifiable data must be disclosed to you as an enterprise customer, unless this disclosure is prohibited by law. We’ve already adhered to this approach (and more), and adoption of the standard reinforces this commitment.

“All of these commitments are even more important in the current legal environment, in which enterprise customers increasingly have their own privacy compliance obligations. We’re optimistic that ISO 27018 can serve as a template for regulators and customers alike as they seek to ensure strong privacy protection across geographies and vertical industry sectors”.

The announcement is just one way Microsoft has been working to help strengthen privacy and compliance protections for our customers in the cloud.

C
Published by

Comms Week

Trained and practicing journalist passionate about telecommunications, fintech, cybersecurity, and digital economy reporting.

More in E-Business
E-Business

The Biggest Cost of Nigeria’s Crypto Stamp Duty Not 1.5%, But What Happens Next

By Chike Onwuegbuchi17 Aug 2026

There is a strange thing about regulation: everybody wants clarity until clarity comes with a bill. Given that is probably why the conversation around Nigeria’s proposed 1.5% stamp duty on virtual asset transactions has quickly become a debate about the number. Is 1.5% too much? Will it make crypto more expensive? Will users simply move elsewhere?

E-Business

Analytics Intelligence Partners Open Access Data Centres to Advance Sovereign AI and Cloud Solutions Across Africa

By Chike Onwuegbuchi17 Aug 2026

Analytics Intelligence [AI], a leading provider of artificial intelligence and data analytics solutions, has entered into a strategic partnership with Open Access Data Centres (OADC), a WIOCC Group company, to develop sovereign AI and cloud solutions that enable African enterprises to deploy secure, scalable, and locally hosted AI infrastructure.