Definitions (1)
Definitions (2)
Definitions (3)
100

a breach of security leading to the accidental or Unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Microsoft Personal Data or Microsoft Confidential Data transmitted, stored or otherwise Processed by Supplier or its Subcontractors

Data Incident

100

the entity that determines the purposes and means of the Processing of Personal Data

Controller

100

small text files stored on devices by websites and/or applications that contain information used to recognize a Data Subject or a device

Cookies

200

the right to access, delete, edit, export, restrict, or object to Processing

Data Subject Rights

200

an entity that processes Personal Data on behalf of another entity

Processor

200

a third-party to whom supplier delegates its obligations in connection with the contract covering their Performance, including a supplier affiliate not contracting directly with Microsoft

Subcontractor

300

any operation or set of operations which is performed on any Microsoft Personal Data or Confidential Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction

Process

300

any Personal Data Processed by or on behalf of Microsoft

Microsoft Personal Data

300

any information which, if compromised through confidentiality or integrity means, can result in significant reputational or financial loss for Microsoft. This includes Microsoft hardware and software products, internal line-of-business applications, pre-release marketing materials, product license keys, and technical documentations related to Microsoft products and services

Microsoft Confidential Data

400

a third party that Microsoft engages to Perform, where the Performance includes Processing of Microsoft Personal Data for which Microsoft is a Processor

Subprocessor

400

security vulnerability related to Supplier’s handling of Microsoft Personal Data or Microsoft Confidential Data

Data Incident

400

an identifiable natural person who can be identified, directly or indirectly, in particular by referencing an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

Data Subject