Windows 365 and data protection
Microsoft’s Data Protection Addendum (https://aka.ms/DPA) defines the company’s duties and responsibilities regarding the processing and safeguarding of customer data, professional services data, and personal data by its products and services. Windows 365 is a Microsoft Core Online Service and therefore, the cloud service portion of Windows 365 complies with the control standards and frameworks laid out by the System and Organization Controls (SOC) for service organizations. Windows 365 has SSAE 18 SOC 1 Type II and SSAE 18 SOC 2 Type II attestations.
Microsoft’s default setting is to keep customer data at rest within the geography where the Windows 365 tenant is deployed. However, if a customer provisions Windows 365 Cloud PCs within the same tenant to various available geographies, then for each Cloud PC, Microsoft will store Cloud PC customer data at rest within the respective geography.
Windows 365 is also compliant...