What was said in Paris
Nadella told the VivaTech 2018 audience that Microsoft has to operate in a way that acknowledges that privacy is a human right. MediaPost's Larissa Faw dated her report May 24, 2018. The "05/25/2018" in the headline refers to the day Europe's GDPR became law, not to the day of the speech. Microsoft's own French newsroom had announced that Nadella would give his keynote on May 24, and described it as focused on AI's opportunities and challenges and on the responsibility that must come with them.
Per MediaPost, Nadella also made these points:
- Microsoft was implementing the GDPR guidelines across its regions, and had "the scale to recognize and act."
- The company was sharing ethical principles developed by an in-house committee, in the hope that others would adopt similar values.
- Microsoft "isn't about celebrating tech breakthroughs" on its own, and wants to collaborate with others.
- MediaPost's closing line says Azure tools are available to every developer across all languages and platforms.
The phrase was not new for Nadella. Coverage of his Build keynote earlier in May 2018 shows he praised the upcoming EU regulation, called privacy a human right, and described GDPR as "a sound, good regulation." He kept repeating it. At Future Decoded in London that November, he called GDPR "a great start" and said it set the bar for how people need to think about privacy worldwide.
What Microsoft committed to on GDPR
The keynote line is rhetoric. Microsoft's May 21, 2018 post from Chief Privacy Officer Julie Brill is where the concrete claims sit.
- Scale of effort. Microsoft said more than 1,600 engineers across the company had worked on GDPR projects, and that it had redesigned tools, systems and processes since the regulation was enacted in 2016. These figures are Microsoft's own account of its preparation, not an independent audit.
- Rights beyond Europe. Microsoft said it would extend the rights at the heart of GDPR to all of its consumer customers worldwide. It described these Data Subject Rights as the right to know what data is collected, to correct it, to delete it and to take it elsewhere. It pointed to its privacy dashboard as the tool for managing that data.
- Legal scope. The same post says GDPR is an EU regulation that creates new rights specifically for individuals in the EU. The worldwide extension was therefore a voluntary Microsoft decision, not something the law required.
- Privacy statement. Microsoft also published an updated privacy statement for consumer products and services, reflecting the wider rights.
- A data protection officer. In March 2018 Microsoft appointed Steve May, a privacy leader in its Windows and Devices Group, as European Data Protection Officer. He was to be based in Dublin and report to the chief privacy officer. That shows organizational preparation, but it does not show how complete the compliance was.
What it means for enterprise and IT admins
For administrators, the more durable material is contractual. Microsoft's GDPR documentation says its GDPR Terms commit it to processor requirements under Article 28. Those cover:
- using subprocessors only with the controller's consent;
- processing data only on the controller's instructions;
- security measures appropriate to the risk;
- breach notification and assistance;
- assisting with data subject requests;
- deleting or returning data at the end of service.
Microsoft says it extends these terms, effective May 25, 2018, to customers of generally available enterprise software licensed under Microsoft software license terms. This applies where Microsoft is a processor or subprocessor of personal data, and for as long as it offers or supports the version.
The caveats matter in practice:
- Different or lesser commitments may apply to beta or preview software, to materially modified software, and to software not made generally available.
- Some products may send telemetry or other data to Microsoft by default. Product documentation explains how to turn this off or configure it.
That last point is the one for admins to check. Contractual terms and default telemetry settings are separate things, and this guidance comes from Microsoft's current page, so it should not be read as a description of every product's behavior in 2018.
The "Digital Geneva Convention" claim needs trimming
MediaPost says Microsoft would lead a coalition to ensure all organizations are protected from cybercrime. That compresses and widens what Microsoft actually proposed.
Brad Smith introduced the idea in February 2017 at the RSA Conference. He called on governments to adopt a Digital Geneva Convention committing them to protect civilians from nation-state attacks in times of peace, and described tech companies as a neutral "Digital Switzerland." It was aimed at governments and state-sponsored attacks. It was not a promise to stop cybercrime generally, and it was not a treaty.
In November 2017 Smith said the concept requires as much as a decade of work. He argued for near-term steps alongside it, building on existing international law.
What the sources don't establish
- The ethics committee. MediaPost does not name the committee or list its principles. Other coverage notes Nadella pointing to Microsoft's internal efforts to establish an ethics board for AI, but that does not confirm MediaPost's description.
- The Azure line. MediaPost's sentence names no products, languages, platforms, release date or availability limits. The sources reviewed do not tie it to a specific VivaTech launch. Microsoft's separate Build event earlier in May 2018 is a different announcement and should not be treated as corroboration.
- Present-day status. None of this shows how well Microsoft's GDPR compliance has held up, or what its privacy dashboard offers today.
Takeaways
- The VivaTech remarks were a leadership message. The binding commitments are in Microsoft's GDPR terms and its May 2018 consumer-rights announcement.
- The worldwide extension of GDPR-style rights applied to consumer customers and was voluntary. The enterprise GDPR terms are contractual and carry the version, preview and telemetry caveats above.
- The Digital Geneva Convention was an advocacy proposal aimed at governments and state-backed attacks. It was not an enacted protection.
- The "privacy is a human right" line recurred across Build, VivaTech, Future Decoded and Davos. It was a consistent Nadella theme, not a one-off.
For anyone auditing a Microsoft environment today, the useful step is to read the current data protection terms and each product's telemetry documentation, rather than rely on keynote language.
References
- Microsoft's Nadella: 'Privacy Is A Human Right' 05/25/2018 - MediaPost MediaPost · Fri, 02 Oct 2026 16:25:06 GMT
- Microsoft's Nadella: 'Privacy Is A Human Right' 05/25/2018 mediapost.com
- Microsoft’s commitment to GDPR, privacy and putting customers in control of their own data - Microsoft On the Issues blogs.microsoft.com