SSPA : Supplier Security & Privacy Assurance Program

What is the Supplier Security and Privacy Assurance (SSPA) Program?

The Supplier Security and Privacy Assurance (SSPA) Program delivers Microsoft's data processing instructions, through the Microsoft Supplier Data Protection Requirements (DPR), to suppliers working with Personal Data and/or Microsoft Confidential Data.

SSPA drives compliance with these requirements through an annual compliance cycle; for new suppliers, work cannot start until this is complete. If a supplier processes Personal Data and/or Microsoft Confidential Data, they will partner with their business sponsor to enroll in the SSPA Program. Suppliers may also be selected to provide independent assurance by assessing the DPR.

Compliance with SSPA is essential to protect sensitive data from unauthorized access or disclosure. It is also essential to maintain regulatory compliance and mitigate third-party service risks.

When is a supplier in scope for SSPA?

The scope of the Supplier Security and Privacy Assurance Program covers all suppliers globally that process Personal Data or Microsoft Confidential Data in connection with that supplier’s performance (e.g., provision of services, software licenses, cloud services), under the terms of its contract with Microsoft (e.g., Purchase Order terms, Master agreement) (“Perform”, “Performing” or “Performance”).

For definitions and examples of Personal Data and/or Microsoft Confidential Data, visit the Definitions section of the Supplier Data Protection Requirements (DPR), located below on this page. These examples are intended to guide. Use both definitions and examples to determine what data is in scope for SSPA management.

For More Information

Read More