Framework hub
Microsoft SSPA
Microsoft
Microsoft Supplier Privacy and Assurance Standards for suppliers in Microsoft’s information supply chain, assessed against Data Protection Requirements (DPR).
HLD Group maintains policies and controls mapped to this framework as part of our security and compliance programme. This hub describes programme alignment — not a third-party certification or attestation unless separately agreed in your contract.
Programme focus areas
- DPR assessment
- Subprocessor management
- Privacy by design
Policies meeting this framework
The following published policies and programme documents are mapped to Microsoft SSPA. Status: published and under periodic review.
- Privacy PolicyPublished
How personal data is collected, used, stored, and shared.
v2.0 · review every 365 days
- Vendor & third-party risk policyPublished
Assessment and ongoing management of suppliers and subprocessors.
v1.4 · review every 365 days
- Access control policyPublished
Granting, reviewing, and revoking access to systems and data.
v2.0 · review every 180 days
- Incident response planPublished
Detecting, responding to, and recovering from security incidents.
v3.0 · review every 180 days
Assurance note
Programme alignment means HLD maintains controls, policies, and monitoring mapped to Microsoft SSPA requirements appropriate to our services and risk profile. It does not by itself constitute certification, authorization, or a SOC/ISO audit report. Customers requiring formal attestations should contact [email protected].