
What the February 2025 announcement states
Microsoft's announcement of 26 February 2025, credited to its chief privacy officer and a Microsoft 365 vice-president, states that European commercial and public-sector customers can now store and process customer data and pseudonymised personal data for core Microsoft cloud services within the EU Data Boundary. The boundary covers Microsoft 365, Dynamics 365, Power Platform and most Azure services, and extends to professional-services data generated through technical-support interactions. The post also states plainly that limited security-related transfers can still occur, describing essential data moving outside the boundary when a coordinated global security response requires it, and that some Azure services need additional customer configuration to bring professional-services data fully into scope.
How the boundary actually works
Microsoft's living reference document, What is the EU Data Boundary?, as retrieved on 16 September 2026, explains that the boundary is not a single switch. For Microsoft 365, a tenant is in scope if its sign-up location is in the EU or EFTA, unless it has purchased Multi-Geo capabilities, in which case it falls outside the boundary regardless of the tenant's listed region. For Dynamics 365 and Power Platform, an organisation must both provision its environment in the EU/EFTA macro-region and maintain an EU-country billing address; meeting only one condition does not qualify. For Azure, only workloads deployed in an EU or EFTA region count, and non-regional services need separate configuration. The document also describes system-generated logs, which can contain personal data tied to user actions, as pseudonymised rather than removed, because fully anonymising them would defeat their purpose of diagnosing and securing the service.
What this commitment does not settle
A data-residency boundary answers where data is stored and processed, not who can access it or under what legal process. The same documentation notes that authorised Microsoft personnel can work with pseudonymised logs without needing to reidentify individuals, which is a narrower promise than saying nobody can ever see the underlying data. A customer that needs data to never leave the EU under any circumstance, including a security incident, will find the announcement's own exception is the boundary of the boundary.
- Does your specific service and deployment region actually qualify, given the Multi-Geo and billing-address conditions?
- What does a coordinated global security response mean in the underlying data-processing agreement, not just the blog post?
- Who inside Microsoft can access pseudonymised logs from your tenant, and under what oversight?
The announcement marks a real completion of a multi-year infrastructure project, but a residency commitment is a geography answer, not a full access-control answer, and the two should not be assumed to be the same thing.
Sources & reading trail
Announces completion of the EU Data Boundary for core Microsoft cloud services, and states that limited security-related transfers can still occur.
Source published: 26 February 2025 · Retrieved: 16 September 2026
Documents, as a living reference, which services are in scope, which countries form the boundary, and how a tenant's region and configuration determine whether it is covered.
Source published: Not established · Retrieved: 16 September 2026
Announcements and papers establish the record; the friction reading and the adoption questions are Productivity Atlas editorial analysis. This retrospective draft does not imply the site published on the event date.