Microsoft is committed to the highest levels of transparency, standards compliance and regulatory compliance. To help organizations meet national, regional and industry-specific requirements for the collection and use of personal data, Microsoft offers the most comprehensive compliance offering (including certifications and attestations) of any cloud service provider. This includes the world's first code of conduct for data protection in the cloud, ISO/IEC 27018. To learn more about Microsoft's best practices in the area of data protection, please visit the
following additional resources and the
Microsoft Service Trust Centerwhich provides information on compliance with data protection standards and regulatory requirements, such as International Organization for Standardization (ISO), Service Organization Controls (SOC), National Institute of Standards and Technology (NIST), Federal Risk and Authorization Management Program (FedRAMP) and the General Data Protection Regulation (GDPR).