Skip to content

Conversation

@akirayuppie
Copy link

This FAQ addition addresses a common question from Japanese enterprise customers regarding compliance with the Act on the Protection of Personal Information (APPI) in the context of Microsoft Defender for Identity (MDI). Specifically, it clarifies whether end-user consent is required for overseas data transfer when using MDI.

Justification and Accuracy:
The content has been carefully reviewed against official guidance from Japan’s Personal Information Protection Commission (PPC), particularly Q&A 12-3, as well as legal commentaries. According to the PPC and current legal interpretations, providing personal data to Microsoft as part of using MDI is classified as “outsourcing” rather than a “provision to a third party in a foreign country.” Therefore, explicit end-user consent for cross-border data transfer is not required, as long as the proper contractual and supervisory safeguards are in place.

This clarification is important for legal compliance and customer assurance. The FAQ content accurately reflects the current legal requirements and aligns with both Japanese government guidance and Microsoft’s standard contractual obligations.

This FAQ addition addresses a common question from Japanese enterprise customers regarding compliance with the Act on the Protection of Personal Information (APPI) in the context of Microsoft Defender for Identity (MDI). Specifically, it clarifies whether end-user consent is required for overseas data transfer when using MDI.

Justification and Accuracy:
The content has been carefully reviewed against official guidance from Japan’s Personal Information Protection Commission (PPC), particularly Q&A 12-3, as well as legal commentaries. According to the PPC and current legal interpretations, providing personal data to Microsoft as part of using MDI is classified as “outsourcing” rather than a “provision to a third party in a foreign country.” Therefore, explicit end-user consent for cross-border data transfer is not required, as long as the proper contractual and supervisory safeguards are in place.

This clarification is important for legal compliance and customer assurance. The FAQ content accurately reflects the current legal requirements and aligns with both Japanese government guidance and Microsoft’s standard contractual obligations.
@learn-build-service-prod
Copy link
Contributor

Learn Build status updates of commit a4e9b6c:

✅ Validation status: passed

File Status Preview URL Details
defender-for-identity/technical-faq.yml ✅Succeeded

For more details, please refer to the build report.

@akirayuppie
Copy link
Author

akirayuppie commented Oct 10, 2025

The fact has been reviewed by CELA. @Dansimp may I ask review and merge please?

@learn-build-service-prod
Copy link
Contributor

Learn Build status updates of commit b52cc25:

✅ Validation status: passed

File Status Preview URL Details
defender-for-identity/technical-faq.yml ✅Succeeded

For more details, please refer to the build report.

@learn-build-service-prod
Copy link
Contributor

Learn Build status updates of commit 9d7fc09:

✅ Validation status: passed

File Status Preview URL Details
defender-for-identity/technical-faq.yml ✅Succeeded

For more details, please refer to the build report.

@akirayuppie
Copy link
Author

@DebLanger may I ask please have a look at and make it publish?
The fact was came from CELA so this is surely true.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant