Prototype — static build (Lane C). Content mirrored from the Zoho CMS staging site.
Home › Research › Enterprise Agreements

Enterprise Agreements

An enterprise service is not governed by one contract. A master agreement sets the framework and incorporates other documents by reference — product terms, addenda, service-specific terms, policies, and SLAs — each of which can change on its own schedule. These pages track the agreement stacks of two vendors, Microsoft and Google.

2 vendor stacks · updated monthly · last check 2026-10-11

Latest changes

Most recent check 2026-10-11 — 15 instruments verified against their live documents,3 changed, 7 not reachable. Unreachable is a coverage gap, not a finding of “no change”.

Coverage after the 2026-10-11 sweep: 36 of 36 tracked instruments have a monitored public source. Every tracked instrument is now monitorable.

  • 2026-10-11Product Terms — Summary of Changes (microsoft) — Live change log confirms a monthly cadence; newest published update is 1 Oct 2026, and the past 12 months record AI/privacy-relevant edits (1 Aug 2026 Privacy & Security Terms added Web IQ to the DPA-exceptions table; 15 Jun 2026 added link to Data Residency for M365 Copilot and Copilot Chat; 15 Sep 2026 Glossary added definition of 'Microsoft AI Customer Solution'). source Major · 13/15
  • 2026-10-11Products & Services Data Protection Addendum (DPA) (microsoft) — DPA version advanced from v.1 Sep 2025 (as previously recorded) to the current 22 May 2026 English release (aka.ms/DPA redirects to the licensing-docs page listing 22 May 2026 as the newest version). source Major · 9/15
  • 2026-10-11Google Terms of Service (google) — Google Terms of Service now show an effective date of 30 July 2026 (registry recorded no date); service-specific/Generative-AI Prohibited Use Policy cross-references present. source Minor · 7/15
The basis of comparison

The monthly agreement-stack check treats each document as a tracked row and diffs it over time. These are the signals it compares for every instrument.

Version / effective date (DPA versions; master-agreement dates; Product Terms update dates).

Content hash / change-log entry (Microsoft "Summary of Changes"; Google terms update history).

New-feature carve-out text — does newly released AI functionality sit inside or outside protections?

Data-use / retention statements (for example, Workspace Privacy Hub feedback retention).

Subprocessor lists (additions and removals; processing locations).

Glossary / definitions (Microsoft) — meaning-level change across the stack.

Precedence / order-of-precedence clauses — any reordering changes how documents are read.

New instruments appearing in the stack, or instruments renamed or withdrawn.

Data-residency commitments (for example, Copilot).

Each check produces updated rows in the agreement registry, a dated entry in each stack page's activity log, and a developments note — each carrying the original source URL.

Compiled from public vendor documents and the tracked change log. Not legal advice — verify against the primary source before relying on it.

Changelog

The full running log of every agreement-stack check, newest first. Each entry carries the source URL it was observed at.

  • 2026-10-11Product Terms — Summary of Changes (microsoft) — Live change log confirms a monthly cadence; newest published update is 1 Oct 2026, and the past 12 months record AI/privacy-relevant edits (1 Aug 2026 Privacy & Security Terms added Web IQ to the DPA-exceptions table; 15 Jun 2026 added link to Data Residency for M365 Copilot and Copilot Chat; 15 Sep 2026 Glossary added definition of 'Microsoft AI Customer Solution'). source
  • 2026-10-11Products & Services Data Protection Addendum (DPA) (microsoft) — DPA version advanced from v.1 Sep 2025 (as previously recorded) to the current 22 May 2026 English release (aka.ms/DPA redirects to the licensing-docs page listing 22 May 2026 as the newest version). source
  • 2026-10-11Google Terms of Service (google) — Google Terms of Service now show an effective date of 30 July 2026 (registry recorded no date); service-specific/Generative-AI Prohibited Use Policy cross-references present. source