In the SC-900 exam, the privacy section asks about "how Microsoft transparently discloses the way it protects customer data" and "how organizations manage the personal data rights of their employees and customers."
Service Trust Portal — Microsoft's Transparency Window
When choosing a hospital, you'd want to check how many points it scored on a health inspection and what certifications it holds. The same applies when a company uses Microsoft Azure or Microsoft 365. You need to verify: "Has Microsoft's data center received ISO 27001 certification?", "Has it passed a SOC 2 audit?", "Does it comply with our industry's regulations?"
The Service Trust Portal (servicetrust.microsoft.com) is the portal where Microsoft transparently publishes this information. It is freely accessible to anyone and provides official documentation on Microsoft's security and compliance.
Types of Information Provided
Audit Reports: Audit results conducted by independent external auditing firms for ISO 27001, SOC 1/2, FedRAMP, PCI DSS, and more. The key point is that these are verified by an independent third party.
Compliance Guides: Guidance on how to use Microsoft services in compliance with regulations, organized by industry (financial, healthcare, education, government) and by country.
White Papers and FAQs: Documents explaining technical details such as Azure's encryption methods, data residency policies, and security architecture.
Trust Documents: Documents describing how security is implemented in Microsoft services. For example, explaining "how data is encrypted in Microsoft's cloud services."
The core value of this portal is that instead of simply saying "trust us," it provides objective evidence in the form of independent audit results.
Microsoft's Privacy Principles
Many companies say "we value your personal information," but they are often unclear on exactly how they protect it. Microsoft publicly commits to 6 principles and operates according to them.
Think of parents managing a young child's diary. The child can view it whenever they want (control), the contents are not disclosed without permission (transparency), it is kept safely (security), it is legally protected (legal protection), it is not used for advertising (limited collection), and it is used only for the child's benefit (accountability). Microsoft's 6 principles are exactly these kinds of commitments.
The 6 Privacy Principles
Principle 1 — Control: Users have control over their own data. They can check what data is being collected and request deletion when needed.
Principle 2 — Transparency: Microsoft clearly discloses what data it collects and how it is used. There is no hidden data collection.
Principle 3 — Security: Collected data is protected by strong security measures including encryption and access controls.
Principle 4 — Strong Legal Protections: When governments or agencies request user data, Microsoft applies strict legal standards and advocates for users' rights legally.
Principle 5 — No Content-Based Targeting: Microsoft does not use the content of users' emails, chats, or documents for advertising targeting. This is an important distinction from some other companies.
Principle 6 — Accountability: Collected data is used only in ways that benefit users, and Microsoft is accountable for that use.
!Microsoft's 6 privacy principles
Microsoft Privacy Statement
The Microsoft Privacy Statement is an official public document that specifies the types of data Microsoft collects, why it is collected, how it is used, and how it is protected. Anyone can review it at privacy.microsoft.com.
Microsoft Priva — Managing Personal Data Risk in Organizations
As regulations like GDPR and national privacy laws have tightened, businesses face a new challenge. They need to identify and manage: "Where and how much personal information about our employees and customers exists in our systems?", "Are we storing more than necessary?", "Are employees transmitting personal information incorrectly?"
Microsoft Priva is a service that automatically discovers personal data risks within an organization and handles rights requests from data subjects (the individuals whose data it is). It consists of two core capabilities.
Priva Privacy Risk Management — Automatically Detecting Personal Data Risks
Identifying where and how much patient personal information is stored across a large hospital's IT systems is a monumental task. Priva Privacy Risk Management automatically scans the Microsoft 365 environment and identifies three types of risk.
Detecting Excessive Data Storage
Personal information should be deleted once its collection purpose has been fulfilled. In practice, however, employee files that are years old, information about customers who have already left, and outdated contracts often sit untouched throughout various systems. Priva automatically finds this data and flags it: "This data has been retained for too long."
Detecting Risky Data Transfers
It detects situations where an employee sends a file containing customer personal information to a personal email address, or transfers it to an external service that has not been security-vetted.
Identifying Unused Personal Data
It finds personal data that has been left untouched, with no one accessing it, for an extended period. Unused data is a security risk in the event of an incident and is even more vulnerable because no one is actively managing it.
When Priva Privacy Risk Management discovers a risk, it notifies the responsible party and helps automatically apply data minimization policies.
Priva Subject Rights Requests — Handling Data Subject Rights Requests
Under the European Union's GDPR and national privacy laws, individuals have the following rights with respect to their data:
Right of access: "Show me what data you hold about me" Right to rectification: "Correct the inaccurate parts of my data" Right to erasure (right to be forgotten): "Delete all data you have about me" Right to object: "I object to my data being used for a specific purpose"
These requests are called "Subject Rights Requests." Legally, organizations must typically respond within 30 days.
The challenge is that when a single customer submits a deletion request, that customer's data may be scattered across dozens of locations — CRM systems, email servers, SharePoint, OneDrive, and more. Processing this manually could take weeks.
Priva Subject Rights Requests automates this process. When a request comes in, it automatically searches the entire Microsoft 365 environment for that individual's data, provides a review workflow, and tracks progress to ensure the request is handled within the legal deadline.
Exam Key Points
"Microsoft audit reports and compliance documentation" -- Service Trust Portal
"6 privacy principles" -- Microsoft's Privacy Principles
"No ad targeting based on email content" -- No Content-Based Targeting principle
"Identify personal data risks within the organization" -- Priva Privacy Risk Management
"Manage GDPR data deletion/access requests" -- Priva Subject Rights Requests
"Right to be forgotten, right of access" -- Data Subject Rights
Service Trust Portal is where external audit results are provided
Priva = Privacy risk management + Subject rights request handling