Skip to content

Commit d7989ef

Browse files
authored
Merge pull request #5655 from MikeRayMSFT/20180424_UpdatePrivacySupplement
Update privacy policy
2 parents cb08067 + b976611 commit d7989ef

1 file changed

Lines changed: 53 additions & 45 deletions

File tree

Lines changed: 53 additions & 45 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
---
2-
title: "SQL Server Privacy Supplement | Microsoft Docs"
3-
ms.date: "2/22/2018"
4-
ms.prod: sql
5-
ms.prod_service: sql
2+
title: "SQL Server privacy supplement | Microsoft Docs"
3+
ms.date: "4/24/2018"
4+
ms.prod: "sql-non-specified"
5+
ms.prod_service: "sql-non-specified"
66
ms.service: ""
77
ms.component: "sql-non-specified"
88
ms.reviewer: ""
@@ -18,21 +18,22 @@ ms.author: "craigg"
1818
manager: craigg
1919
ms.workload: "Active"
2020
---
21-
# SQL Server Privacy Supplement
21+
# SQL Server privacy supplement
2222
[!INCLUDE[appliesto-ss-xxxx-xxxx-xxx-md](../includes/appliesto-ss-xxxx-xxxx-xxx-md.md)]
2323

24-
This article summarizes the behavior of different data objects used within SQL Server and how the objects are used to pass information of a personal or confidential manner. The data classification in this article only applies to versions of the SQL Server on-premises product. It does not apply to the items:
24+
This article summarizes the behavior of different data objects used within SQL Server and how the objects are used to pass information of a personal or confidential manner. This article serves as an addendum to the overall [Microsoft Privacy Statement](https://go.microsoft.com/fwlink/?LinkId=521839). The data classification in this article only applies to versions of the SQL Server on-premises product. It does not apply to the items:
2525

2626
- Azure SQL Database
2727
- SQL Server Management Studio (SSMS)
2828
- SQL Server Data Tools (SSDT)
2929
- SQL Operations Studio
30+
- Database Migration Assistant
31+
- SQL Server Migration Assistant
32+
- MS-SQL Extension
3033

3134
Definition of *Permitted usage Scenarios*. For the context of this article, Microsoft defines “Permitted Usages Scenarios” as actions or activities that are initiated by Microsoft.
3235

33-
***
34-
35-
>## Access Control
36+
## Access control
3637

3738
Credential-related information used to secure logins, users, or accounts within a SQL Server installation.
3839

@@ -41,15 +42,15 @@ Credential-related information used to secure logins, users, or accounts within
4142
- Passwords
4243
- Certificates
4344

44-
### Permitted Usage Scenarios
45+
### Permitted usage scenarios
4546

46-
|Scenario |Access Restrictions |Retention Requirements |
47+
|Scenario |Access restrictions |Retention requirements |
4748
|---------|---------|---------|
4849
|These credentials never leave the user machine via Usage Feedback. |- |- |
4950
|Crash Dumps may contain Access Control Data. |- |Crash Dumps: Maximum 30 days. |
50-
|These credentials never leave the user machine via User Feedback unless Customer injects it manually |Limit to Microsoft internal use with no third-party access. |User Feedback: Max 1 year |
51+
|These credentials never leave the user machine via User Feedback unless customer injects it manually |Limit to Microsoft internal use with no third-party access. |User Feedback: Max 1 year |
5152
|
52-
>## Customer Content
53+
## Customer content
5354

5455
Customer content is defined as data stored within user tables, directly or indirectly. The data includes statistics or user literals within query texts that might be stored within user tables.
5556

@@ -59,20 +60,20 @@ Customer content is defined as data stored within user tables, directly or indir
5960
- Statistics objects containing copies of values within the rows of any user table.
6061
- Query texts containing literal values.
6162

62-
### Permitted Usage Scenarios
63-
|Scenario |Access Restrictions |Retention Requirements |
63+
### Permitted usage scenarios
64+
|Scenario |Access restrictions |Retention requirements |
6465
|---------|---------|---------|
6566
|This data does not leave the user machine via Usage Feedback. |- |- |
6667
|Crash Dumps may contain Customer Content and be emitted to Microsoft. |- |Crash Dumps: Max 30 days. |
6768
|Customers with their consent can send User Feedback that contains Customer Content to Microsoft. |Limit to Microsoft internal with no third-party access. Microsoft can expose the data to the original customer. |User Feedback: Max 1 year |
6869

69-
>## End-User Identifiable Information (EUII)
70+
## End-user identifiable information (EUII)
7071

7172
Data received from a user, or generated from their use of the product.
7273
- Linkable to an individual user.
7374
- Does not contain content.
7475

75-
### Examples end-User identifiable information
76+
### Examples of end-user identifiable information
7677

7778
- Interface Identification. The Full IP address
7879
- Machine Name
@@ -81,78 +82,85 @@ Data received from a user, or generated from their use of the product.
8182
- Location Information
8283
- Customer Identification
8384

84-
### Permitted Usage Scenarios
85+
### Permitted usage scenarios
8586

86-
|Scenario |Access Restrictions |Retention Requirements|
87+
|Scenario |Access restrictions |Retention requirements|
8788
|---------|---------|---------|
8889
|This data does not leave the user machine via Usage Feedback. |- |- |
89-
|Crash Dumps may contain EUII and be emitted to Microsoft. |- |Crash Dumps: Max 30 days |
90-
|Customer Identification ID may be emitted to Microsoft to deliver new hybrid and cloud features that the users have subscribed to. |- |Currently no such hybrid or cloud features exist.|
91-
|Customers with their consent can send User Feedback that contains Customer Content to Microsoft.|Limit to Microsoft internal use with no third-party access. Microsoft can expose the data to the original customer. |User Feedback: Max 1 year |
90+
|Crash dumps may contain EUII and be emitted to Microsoft. |- |Crash dumps: Max 30 days |
91+
|Customer identification ID may be emitted to Microsoft to deliver new hybrid and cloud features that the users have subscribed to. |- |Currently no such hybrid or cloud features exist.|
92+
|Customers with their consent can send User Feedback that contains customer content to Microsoft.|Limit to Microsoft internal use with no third-party access. Microsoft can expose the data to the original customer. |User feedback: Max 1 year |
9293

93-
>## Internet-Based Services Data
94+
## Internet-based services data
9495

9596
Data needed to provide Internet-based services, per the SQL Server EULA.
9697

9798
### Examples of Internet-based services data
9899

99-
- Computer Specification Information
100+
- Computer specification information
100101
- Browser name/version
101102
- SQL Server version
102-
- Language Code
103-
- An IP Address with certain octets removed
104-
- Map Data
103+
- Language code
104+
- An IP address with certain octets removed
105+
- Map data
105106

106-
### Permitted Usage Scenarios
107+
### Permitted usage scenarios
107108

108-
|Scenario |Access Restrictions |Retention Requirements|
109+
|Scenario |Access restrictions |Retention requirements|
109110
|---------|---------|---------|
110111
|May be used by Microsoft to improve features and/or fix bugs in current features. |Limit to Microsoft internal use with no third-party access. Microsoft can expose the data to the original customer. For example, dashboards |Min 90 days - Max 3 years |
111112
|Customers with their consent can send User Feedback that contains Customer Content to Microsoft. |Limit to Microsoft internal use with no third-party access. |Customers with their consent can send User Feedback that contains Customer Content to Microsoft. |
112113
|Power View and SQL Reporting Services Map Item(s) may send data for use of Bing Maps. |Limit to session data |- |
113114

114-
>## System Metadata
115+
## System metadata
115116

116-
Data generated in the course of running the server. The data does not contain Customer content.
117+
Data generated in the course of running the server. The data does not contain customer content.
117118

118119
### Examples of system metadata
119120

120121
The following are considered system metadata when they do not inlcude customer content, customer access control, or EUII:
121122

122123
- Database GUID
123-
- Hash of Machine Name
124-
- Hash of Instance Name
125-
- Hash of Application Name
126-
- Behavioral/Usage Data
124+
- Hash of machine name
125+
- Hash of instance name
126+
- Application name
127+
- Behavioral/usage data
127128
- SQL Customer Experience improvement program data (SQLCEIP)
128129
- Server configuration data, for example settings of sp_configure
129130
- Feature configuration data
130-
- Event Names and Error Codes
131+
- Event names and error codes
132+
133+
Microsoft does examine application name values set by other programs that use SQL Server (example: Sharepoint or 3rd party packaged programs and includes this information in System Metadata sent to Microsoft when Usage Data is enabled). Customers should not place personal data, such as end-user identifiable information, in System Metadata fields or create applications designed to store personal data in these fields.
131134

132-
### Permitted Usage Scenarios
135+
### Permitted usage scenarios
133136

134137
|Scenario |Access Restrictions |Retention Requirements|
135138
|---------|---------|---------|
136139
|May be used by Microsoft to improve features and or fix bugs in current features.|Limit to Microsoft internal use with no third-party access. |Min 90 days - Max 3 years |
137-
|May be used to make suggestions to the customer. For example, “Based on your usage of the product, consider using feature X since it would perform better.” |Microsoft can expose the data to the original customer, for example through dashboards. |Customer Data Security Logs: Min 3 years - Max 6 years |
140+
|May be used to make suggestions to the customer. For example, “Based on your usage of the product, consider using feature *X* since it would perform better.” |Microsoft can expose the data to the original customer, for example through dashboards. |Customer Data Security Logs: Min 3 years - Max 6 years |
138141
May be used by Microsoft for future product planning. |Microsoft may share this information with other hardware and software vendors to improve how their products run with Microsoft software. |Min 90 days - Max 3 years|
139142
|May be used by Microsoft to provide cloud-based services based on emitted Usage Feedback. For example, a customer dashboard showing feature usage across all SQL Server installations in an organization. |Microsoft can expose the data to the original customer, for example, through dashboards. |Min 90 days - Max 3 years |
140143
|Customers with their consent can send User Feedback that contains Customer Content to Microsoft. |Limit to Microsoft internal with no third-party access. Microsoft can expose the data to the original customer. |User Feedback: Max 1 year |
144+
|May use database name and application name to categorize databases and applications into known categories, for example, those that may be running software provided by Microsoft or other companies.|Limit to Microsoft internal with no third-party access.|Min 90 days - Max 3 years |
141145

142-
>## Object Metadata
146+
## Object metadata
143147

144-
Data that describes or is used to configure servers, databases, tables, and other resources. Object metadata includes database table and column names but not the contents of database rows or other Customer Content. Customers should not place personal data, such as end-user identifiable information in Object Metadata fields or create applications designed to store personal data in these fields.
148+
Data that describes or is used to configure servers, databases, tables, and other resources. Object metadata includes database table and column names but not the contents of database rows or other Customer Content. Customers should not place personal data, such as end-user identifiable information in Object Metadata fields or create applications designed to store personal data in these fields. For the permitted usage scenario's below, only hash form is used to determine usage patterns to improve the product.
145149

146150
### Examples of object metadata
147151

148152
- SQL Server database names
149-
- Table names and Column names
150-
- Statistics Names
153+
- Table names and column names
154+
- Statistics names
151155

152-
### Permitted Usage Scenarios
156+
### Permitted usage scenarios
153157

154-
|Scenario |Access Restrictions |Retention Requirements|
158+
|Scenario |Access restrictions |Retention requirements|
155159
|---------|---------|---------|
156160
|May be used by Microsoft to improve features and or fix bugs in current features. |Limited to Microsoft internal use with no third-party access. |Min 90 days - Max 3 years|
157161

158-
[!INCLUDE[get-help-options](../includes/paragraph-content/get-help-options.md)]
162+
## Telemetry controls
163+
164+
Instructions on how telemetry can be turned on/off in product can be referenced here - https://support.microsoft.com/en-us/help/3153756/how-to-configure-sql-server-2016-to-send-feedback-to-microsoft.
165+
166+
[!INCLUDE[get-help-options](../includes/paragraph-content/get-help-options.md)]

0 commit comments

Comments
 (0)