Skip to main content
Cloud / Azure / Products / EU Data Boundary - Data Processing Within the EU and EFTA

EU Data Boundary - Data Processing Within the EU and EFTA

EU Data Boundary: Microsoft's commitment to store and process customer data and personal data for Azure, Microsoft 365, Dynamics 365, and Power Platform within the EU and EFTA.

security
Pricing Model No separate billing; a contractual commitment that is part of the Microsoft online services, not a service of its own
Availability EU and EFTA countries; Microsoft names datacenters in Austria, Belgium, Denmark, Finland, France, Germany, Greece, Ireland, Italy, Netherlands, Norway, Poland, Spain, Sweden, and Switzerland
Data Sovereignty Customer data and pseudonymized personal data stored and processed in the EU/EFTA; Professional Services Data stored at rest there
Reliability No SLA; a contractual commitment rather than a technical service SLA

The EU Data Boundary is Microsoft’s contractual commitment to store and process customer data and personal data for its enterprise online services within the EU and EFTA.

What is the EU Data Boundary?

The EU Data Boundary is a geographically defined boundary within which Microsoft has committed to store and process customer data and personal data for its enterprise online services, including Azure, Dynamics 365, Power Platform, and Microsoft 365. Professional Services Data is stored at rest within the boundary for these services.

An important distinction: this is a program and a contractual commitment, not an Azure service you deploy. The online services in scope are identified in the Microsoft Product Terms as part of the services agreements.

Microsoft declared the program complete in April 2026. At the same time, the documentation notes that Microsoft continues to deploy more services and service capabilities within the EU Data Boundary and updates its documentation accordingly.

Core Features

  • Scope: customer data and personal data for EU Data Boundary Services are stored and processed in datacenters located in EU or EFTA countries
  • Country coverage: all 27 EU member states plus the EFTA countries Liechtenstein, Iceland, Norway, and Switzerland
  • Datacenters: Microsoft names locations in Austria, Belgium, Denmark, Finland, France, Germany, Greece, Ireland, Italy, the Netherlands, Norway, Poland, Spain, Sweden, and Switzerland
  • Pseudonymization: personal data in system-generated logs must be pseudonymized, for example through encryption, masking, tokenization, or data blurring
  • Transparency about exceptions: remaining transfers outside the boundary are documented
  • Service-specific configuration: Azure, Microsoft 365, and Dynamics 365 / Power Platform each have their own rules for coming into scope

Typical Use Cases

Evidence in a GDPR context
Organizations that must demonstrate to regulators or internal data protection bodies where customer data is stored and processed.

Public procurement
Tenders with requirements for EU-based data storage, where the contractual commitment forms part of the bid evaluation.

Tenant and resource configuration
Projects that align existing Azure resources, Microsoft 365 tenants, and Power Platform environments so that they fall within scope.

Risk assessment of remaining transfers
Analysis of the exceptions documented by Microsoft and their relevance to your own data categories.

Benefits

  • A contractually anchored commitment rather than a mere configuration option
  • A consistent framework across Azure, Microsoft 365, Dynamics 365, and Power Platform
  • Mandatory pseudonymization of personal data in system-generated logs
  • Documented exceptions that allow for a defensible risk assessment
  • A clearly delimited country scope covering the EU and EFTA

Integration with innFactory

As an indirect Microsoft CSP partner, innFactory helps you set up your Azure environment so that it falls within the scope of the EU Data Boundary: region selection, handling of non-regional services, Azure Resource Manager configuration, and the documentation your data protection organization needs.

We show how such requirements are anchored technically in our article on Azure Landing Zones. For organizations bound by professional secrecy, our article on section 203 of the German Criminal Code in the public cloud covers the additional requirements.

Contact us for a no-obligation consultation on data residency and compliance on Microsoft Azure.

Typical Use Cases

Demonstrating EU-based data processing to regulators
GDPR programs with data residency requirements
Public sector and regulated industries in the EU and EFTA
Configuring Azure resources and tenants to fall within EU Data Boundary scope
Assessing exceptions and remaining data transfers

Technical Specifications

0th Services in scope per Microsoft: Azure, Dynamics 365, Power Platform, and Microsoft 365 (referred to in the documentation as "EU Data Boundary Services")
1st EU countries: Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden
2nd EFTA countries: Liechtenstein, Iceland, Norway, Switzerland
3rd Microsoft requires all personal data in system-generated logs to be pseudonymized (encryption, masking, tokenization, data blurring)
4th Azure: regional services deployed in an EU Data Boundary region are in scope; a separate configuration guide covers non-regional services
5th Microsoft 365: customers with a sign-up location in the EU or EFTA are in scope; customers with Multi-Geo Capabilities are not
6th Dynamics 365 and Power Platform: tenant and environments must be in the "European Union (EU) and European Free Trade Association (EFTA)" macro region geography, with a billing address in an EU Data Boundary country

Frequently Asked Questions

Is the EU Data Boundary a service I can purchase?

No. The EU Data Boundary is a geographically defined boundary and a contractual commitment by Microsoft, not a deployable resource. The online services in scope are identified in the Microsoft Product Terms as part of the services agreements.

Is the EU Data Boundary complete?

Microsoft publicly stated its completion in April 2026: "We also completed the EU Data Boundary, enabling European customer data to be stored and processed within the EU." (Microsoft On the Issues, April 29, 2026). The documentation also notes that Microsoft continues to deploy more services and service capabilities within the EU Data Boundary.

Which countries make up the EU Data Boundary?

The EU Data Boundary consists of the countries of the European Union and the European Free Trade Association (EFTA). The EFTA countries are Liechtenstein, Iceland, Norway, and Switzerland. It uses Microsoft datacenters announced or currently operating in Austria, Belgium, Denmark, Finland, France, Germany, Greece, Ireland, Italy, the Netherlands, Norway, Poland, Spain, Sweden, and Switzerland.

Are there exceptions where data leaves the EU?

Yes. Microsoft states explicitly that the commitments are subject to limited circumstances in which customer data, personal data, and Professional Services Data will continue to be transferred outside the EU Data Boundary. Those cases are described in detail in the EU Data Boundary documentation.

How do I make sure my Azure resources are in scope?

For Azure, regional services that you deploy in an EU Data Boundary region are in scope. For non-regional Azure services, Microsoft provides a separate configuration guide. To store Professional Services Data for Azure within the EU Data Boundary, you must additionally configure Azure Resource Manager accordingly.

What happens to personal data in log files?

Microsoft requires all personal data in system-generated logs to be pseudonymized, using techniques such as encryption, masking, tokenization, and data blurring. Retention policies set to the minimum required time, regular checks, and access controls that limit rehydration or reidentification apply in addition.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.

Microsoft Solutions Partner

innFactory is a Microsoft Solutions Partner. We provide expert consulting, implementation, and managed services for Azure.

Microsoft Solutions Partner Microsoft Data & AI

Ready to start with EU Data Boundary - Data Processing Within the EU and EFTA?

Our certified Azure experts help you with architecture, integration, and optimization.

Schedule Consultation