Skip to content

Data, privacy, and security for Models sold by Azure changed Microsoft, Sep 24, 2026

Microsoft · Sep 24, 2026 · 45 added, 37 removed · seen by the daily check

  1. Added: Non-English translations are provided for convenience only. Please consult the EN-US version of this document for the definitive version.
  2. Added: This article provides details regarding how data provided by you to Foundry Models sold by Azure in Microsoft Foundry are processed, used, and stored. A 'model sold by Azure' is an AI model designated and deployed as such in Foundry, and includes Azure OpenAI models. Models sold by Azure store and process data to provide the service and to monitor for uses that violate the applicable product terms. Please also see Microsoft Products and Services Data Protection Addendum , which governs data processing by Models sold by Azure. Foundry is an Azure service; learn more about applicable Azure compliance offerings.
  3. Removed: This article provides details regarding how data provided by you to the Azure OpenAI service is processed, used, and stored. Azure OpenAI stores and processes data to provide the service and to monitor for uses that violate the applicable product terms. Please also see the Microsoft Products and Services Data Protection Addendum , which governs data processing by the Azure OpenAI Service. Azure OpenAI is an Azure service; learn more about applicable Azure compliance offerings.
  4. Added: are NOT available to OpenAI or other providers of Models sold by Azure.
  5. Added: are NOT used by providers of Models sold by Azure to improve their models or services.
  6. Added: are NOT used to train any generative AI foundation models without your permission or instruction.
  7. Added: Customer Data, Prompts, and Completions are NOT used to improve Microsoft or third-party products or services without your explicit permission or instruction.
  8. Added: Your fine-tuned Models sold by Azure are available exclusively for your use.
  9. Added: Foundry is an Azure service; Microsoft hosts the Models sold by Azure in Microsoft's Azure environment and Models sold by Azure do NOT interact with any services operated by providers of Models sold by Azure, for example, OpenAI (e.g. ChatGPT, or the OpenAI API).
  10. Added: What data does Foundry process to provide Models sold by Azure?
  11. Added: Foundry processes the following types of data to provide Models sold by Azure:
  12. Added: Prompts and generated content . When prompts are submitted by the user, content is generated by the service, via the completions, chat completions, images, and embeddings operations.
  13. Added: Uploaded data . You can upload your own data for use with certain service features (e.g., fine-tuning , assistants API , batch processing ) using the Files API or vector store.
  14. Added: Data for stateful entities . When you use certain optional features of Models sold by Azure and Agents, such as the Responses API , the Threads feature of the Assistants API , and Stored completions, the service creates a data store to persist message history and other content, in accordance with how you configure the feature.
  15. Added: Augmented data included with or via prompts . When you use data associated with stateful entities, the service retrieves relevant data from a configured data store and augments the prompt to produce generations that are grounded with your data. Prompts may also be augmented with data retrieved from a source included in the prompt itself, such as a URL.
  16. Added: Training & validation data . You can provide your own training data consisting of prompt-completion pairs for the purposes of fine-tuning a model .
  17. Added: How does Foundry process data to provide Models sold by Azure?
  18. Removed: are NOT used to improve OpenAI models.
  19. Removed: are NOT used to train, retrain, or improve Azure OpenAI Service foundation models.
  20. Removed: are NOT used to improve any Microsoft or 3rd party products or services without your permission or instruction.
  21. Removed: Your fine-tuned Azure OpenAI models are available exclusively for your use.
  22. Removed: The Azure OpenAI Service is operated by Microsoft as an Azure service; Microsoft hosts the OpenAI models in Microsoft's Azure environment and the Service does NOT interact with any services operated by OpenAI (e.g. ChatGPT, or the OpenAI API).
  23. Removed: What data does the Azure OpenAI Service process?
  24. Removed: Azure OpenAI processes the following types of data:
  25. Removed: Prompts and generated content . Prompts are submitted by the user, and content is generated by the service, via the completions, chat completions, images, and embeddings operations.
  26. Removed: Uploaded data . You can provide your own data for use with certain service features (e.g., fine-tuning , assistants API , batch processing ) using the Files API or vector store.
  27. Removed: Data for stateful entities . When you use certain optional features of Azure OpenAI service, such as the Threads feature of the Assistants API and Stored completions, the service will create a data store to persist message history and other content, in accordance with how you configure the feature.
  28. Removed: Augmented data included with or via prompts . When using data associated with stateful entities, the service retrieves relevant data from a configured data store and augments the prompt to produce generations that are grounded with your data. Prompts may also be augmented with data retrieved from a source included in the prompt itself, such as a URL.
  29. Removed: Training & validation data . You can provide your own training data consisting of prompt-completion pairs for the purposes of fine-tuning an OpenAI model .
  30. Removed: How does the Azure OpenAI Service process data?
  31. Added: How Foundry processes your prompts via inferencing with Models sold by Azure to generate content (including when additional data from a designated data source is added to a prompt using Azure OpenAI on your data, Assistants, or batch processing).
  32. Removed: How the Azure OpenAI Service processes your prompts via inferencing to generate content (including when additional data from a designated data source is added to a prompt using Azure OpenAI on your data, Assistants, or batch processing).
  33. Added: How the Responses API feature stores data to persist message history.
  34. Added: How Foundry creates a fine-tuned (custom) model with your uploaded data.
  35. Added: How Foundry and Microsoft personnel analyze prompts and completions (text and image) for harmful content and for patterns suggesting the use of the service in a manner that violates the Code of Conduct or other applicable product terms.
  36. Removed: How the Azure OpenAI Service creates a fine-tuned (custom) model with your uploaded data.
  37. Removed: How the Azure OpenAI Service and Microsoft personnel analyze prompts and completions (text and image) for harmful content and for patterns suggesting the use of the service in a manner that violates the Code of Conduct or other applicable product terms.
  38. Added: Models sold by Azure (base or fine-tuned) deployed in your Foundry resource process your input prompts and generate responses with text, images, or embeddings. Prompts and completions are evaluated in real time for harmful content types and content generation is filtered based on configured thresholds. Learn more at Guardrails (previously content filters) overview .
  39. Added: Prompts and responses are processed within the customer-specified geography (unless you are using a Global or DataZone deployment type), but may be processed between regions within the geography for operational purposes (including performance and capacity management). See below for information about location of processing when using a Global or DataZone deployment type.
  40. Added: The models are stateless: no prompts or completions are stored in the model. Additionally, prompts and completions are not used to train, retrain, or improve the base models.
  41. Added: In addition to standard deployments, Foundry offers Models sold by Azure deployment options labeled as 'Global' and 'DataZone.' For any deployment type labeled 'Global,' prompts and responses may be processed in any geography where the relevant model sold by Azure is deployed (learn more about region availability of models ). For any deployment type labeled as 'DataZone,' prompts and responses may be processed in any geography within the specified data zone, as defined by Microsoft. If you create a DataZone deployment in a Foundry resource located in the United States, prompts and responses may be processed anywhere within the United States. If you create a DataZone deployment in a Foundry resource located in a European Union Member Nation, prompts and responses may be processed in that or any other European Union Member Nation. For both Global and DataZone deployment types, any data stored at rest, such as uploaded data, and including the abuse monitoring data store created for Global and DataZone deployments, is stored in the customer-designated geography. Only the location of processing is affected when a customer uses a Global deployment type or DataZone deployment type in Models sold by Azure; Azure data processing and compliance commitments remain applicable.
  42. Added: The Azure OpenAI "on your data" feature lets you connect data sources to ground the generated results with your data. The data remains stored in the data source and location you designate; Azure OpenAI does not create a duplicate data store. When a user prompt is received, the service retrieves relevant data from the connected data source and augments the prompt. The model processes this augmented prompt and the generated content is returned as described above. Learn more about how to use the On Your Data feature securely .
  43. Added: Some Models sold by Azure features store data in the service. This data is either uploaded by the customer, using the Files API or vector store, or is automatically stored in connection with certain stateful entities such as the Responses API, the Threads feature of the Assistants API, and Stored completions. Data stored for such features:
  44. Added: Is stored at rest in the Foundry resource in the customer's Azure tenant, within the same geography as the resource;
  45. Added: Is always encrypted at rest with Microsoft's AES-256-encryption by default, with the option of using a customer managed key (certain preview features may not support customer-managed keys). Microsoft-managed keys are always used to ensure baseline encryption for all stored data.
  46. Removed: Models (base or fine-tuned) deployed in your resource process your input prompts and generate responses with text, images, or embeddings. Customer interactions with the model are logically isolated and secured employing technical measures including but not limited to transport encryption of TLS1.2 or higher, compute security perimeter, tokenization of text, and exclusive access to allocated GPU memory. Prompts and completions are evaluated in real time for harmful content types and content generation is filtered based on configured thresholds. Learn more at Azure OpenAI Service content filtering .
  47. Removed: Prompts and responses are processed within the customer-specified geography (unless you are using a Global deployment type), but may be processed between regions within the geography for operational purposes (including performance and capacity management). See below for information about location of processing when using a Global deployment type.
  48. Removed: The models are stateless: no prompts or generations are stored in the model. Additionally, prompts and generations are not used to train, retrain, or improve the base models.
  49. Removed: In addition to standard deployments, Azure OpenAI Service offers deployment options labelled as 'Global' and 'DataZone.' For any deployment type labeled 'Global,' prompts and responses may be processed in any geography where the relevant Azure OpenAI model is deployed (learn more about region availability of models ). For any deployment type labeled as 'DataZone,' prompts and responses may be processed in any geography within the specified data zone, as defined by Microsoft. If you create a DataZone deployment in an Azure OpenAI resource located in the United States, prompts and responses may be processed anywhere within the United States. If you create a DataZone deployment in an Azure OpenAI resource located in a European Union Member Nation, prompts and responses may be processed in that or any other European Union Member Nation. For both Global and DataZone deployment types, any data stored at rest, such as uploaded data, is stored in the customer-designated geography. Only the location of processing is affected when a customer uses a Global deployment type or DataZone deployment type in Azure OpenAI Service; Azure data processing and compliance commitments remain applicable.
  50. Removed: The Azure OpenAI "on your data" feature lets you connect data sources to ground the generated results with your data. The data remains stored in the data source and location you designate; Azure OpenAI Service does not create a duplicate data store. When a user prompt is received, the service retrieves relevant data from the connected data source and augments the prompt. The model processes this augmented prompt and the generated content is returned as described above. Learn more about how to use the On Your Data feature securely .
  51. Removed: Some Azure OpenAI Service features store data in the service. This data is either uploaded by the customer, using the Files API or vector store, or is automatically stored in connection with certain stateful entities such as the Threads feature of the Assistants API and Stored completions. Data stored for Azure OpenAI Service features:
  52. Removed: Is stored at rest in the Azure OpenAI resource in the customer's Azure tenant, within the same geography as the Azure OpenAI resource;
  53. Removed: Can be double encrypted at rest , by default with Microsoft's AES-256 encryption and optionally with a customer managed key (except preview features may not support customer managed keys);
  54. Added: Models or features in preview might not support all of the above conditions.
  55. Removed: Azure OpenAI features in preview might not support all of the above conditions.
  56. Added: Creating a customized (fine-tuned) model . Learn more about how fine-tuning works . Fine-tuned models are exclusively available to the customer whose data was used to create the fine-tuned model, are encrypted at rest (when not deployed for inferencing), and can be deleted by the customer at any time. Training data uploaded for fine-tuning is not used to train any generative AI foundation models without your permission or instruction.
  57. Added: Batch processing . Learn more about how batch processing works . Batch processing is a Global deployment type; data stored at rest remains in the designated Azure geography until processing capacity becomes available; processing may occur in any geography where the relevant model sold by Azure is deployed (learn more about region availability of models ).
  58. Added: Responses API . Learn more about how the Responses API works. This API stores message history and other content related to message history. This is required for multi-turn conversations and workflows.
  59. Removed: Creating a customized (fine-tuned) model . Learn more about how fine-tuning works . Fine-tuned models are exclusively available to the customer whose data was used to create the fine-tuned model, are encrypted at rest (when not deployed for inferencing), and can be deleted by the customer at any time. Training data uploaded for fine-tuning is not used to train, retrain, or improve any Microsoft or 3rd party base models.
  60. Removed: Batch processing . Learn more about how batch processing works . Batch processing is a Global deployment type; data stored at rest remains in the designated Azure geography until processing capacity becomes available; processing may occur in any geography where the relevant Azure OpenAI model is deployed (learn more about region availability of models ).

22 more changed paragraphs are on the page itself.

About this change
Page
learn.microsoft.com/en-us/legal/cognitive-services/openai/data-privacy
Kind
Documentation
Text hash
0326b0b7081a to 8e4872094a3b
Dated by
the daily check that first read the new text

Terms changes by email

Mondays, only in weeks when a watched page changed.

Double opt-in. Unsubscribe any time.